ExamGecko
Home Home / Fortinet / FCSS_NST_SE-7.4

Fortinet FCSS_NST_SE-7.4 Practice Test - Questions Answers, Page 2

Question list
Search
Search

List of questions

Search

Refer to the exhibit, which shows a session entry.

Which statement about this session is true?

A.

Return traffic to the initiator is sent to 10.1.0.1.

A.

Return traffic to the initiator is sent to 10.1.0.1.

Answers
B.

Return traffic to the initiator is sent lo 10.200.1.254.

B.

Return traffic to the initiator is sent lo 10.200.1.254.

Answers
C.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

C.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

Answers
D.

It is an ICMP session from 10.1.10.1 to 10.200.5.1.

D.

It is an ICMP session from 10.1.10.1 to 10.200.5.1.

Answers
Suggested answer: D

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.

Which action will FortiGate take when using the default settings for SSL certificate inspection?

A.

FortiGate uses the SNI from the user's web browser.

A.

FortiGate uses the SNI from the user's web browser.

Answers
B.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.

B.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.

Answers
C.

FortiGate uses the first entry listed in the SAN field in the server certificate.

C.

FortiGate uses the first entry listed in the SAN field in the server certificate.

Answers
D.

FortiGate uses the ZN information from the Subject field in the server certificate.

D.

FortiGate uses the ZN information from the Subject field in the server certificate.

Answers
Suggested answer: C

Exhibit.

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Which two statements about this debug output are correct? (Choose two)

A.

Perfect Forward Secrecy (PFS) is enabled in the configuration.

A.

Perfect Forward Secrecy (PFS) is enabled in the configuration.

Answers
B.

The local gateway IP address is 10.0.0.1.

B.

The local gateway IP address is 10.0.0.1.

Answers
C.

It shows a phase 2 negotiation.

C.

It shows a phase 2 negotiation.

Answers
D.

The initiator provided remote as its IPsec peer ID.

D.

The initiator provided remote as its IPsec peer ID.

Answers
Suggested answer: C, D

Exhibit.

Refer to the exhibit, which shows the output of a diagnose command.

What can you conclude about the debug output in this scenario?

A.

The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.

A.

The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.

Answers
B.

There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.

B.

There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.

Answers
C.

FortiGate used 64.26.151.37 as the initial server to validate its contract.

C.

FortiGate used 64.26.151.37 as the initial server to validate its contract.

Answers
D.

Servers with a negative TZ value are less preferred for rating requests.

D.

Servers with a negative TZ value are less preferred for rating requests.

Answers
Suggested answer: B

Refer to the exhibit, which shows the output of a policy route table entry.

Which type of policy route does the output show?

A.

An ISDB route

A.

An ISDB route

Answers
B.

A regular policy route

B.

A regular policy route

Answers
C.

A regular policy route, which is associated with an active static route in the FIB

C.

A regular policy route, which is associated with an active static route in the FIB

Answers
D.

An SD-WAN rule

D.

An SD-WAN rule

Answers
Suggested answer: A

Exhibit.

Refer to the exhibit, which shows a FortiGate configuration.

An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.

What must the administrator do to fix the issue?

A.

Disable webfilter-force-off.

A.

Disable webfilter-force-off.

Answers
B.

Increase webfilter-timeout.

B.

Increase webfilter-timeout.

Answers
C.

Enable fortiguard-anycast.

C.

Enable fortiguard-anycast.

Answers
D.

Change protocol to TCP.

D.

Change protocol to TCP.

Answers
Suggested answer: A

Which statement about IKEv2 is true?

A.

Both IKEv1 and IKEv2 share the feature of asymmetric authentication.

A.

Both IKEv1 and IKEv2 share the feature of asymmetric authentication.

Answers
B.

IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.

B.

IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.

Answers
C.

IKEv1 and IKEv2 use same TCP port but run on different UDP ports.

C.

IKEv1 and IKEv2 use same TCP port but run on different UDP ports.

Answers
D.

IKEv1 and IKEv2 share the concept of phase1 and phase2.

D.

IKEv1 and IKEv2 share the concept of phase1 and phase2.

Answers
Suggested answer: B

Exhibit 1.

Exhibit 2.

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.

An administrator would like to lest session failover between the two service provider connections.

Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two)

A.

Change the priority of the port! static route to 11.

A.

Change the priority of the port! static route to 11.

Answers
B.

Change the priority of the port2 static route to 5.

B.

Change the priority of the port2 static route to 5.

Answers
C.

Configure unset snat-route-change to return it to the default setting.

C.

Configure unset snat-route-change to return it to the default setting.

Answers
D.

Configure set snat-route-change enable.

D.

Configure set snat-route-change enable.

Answers
Suggested answer: A, D

Refer to the exhibit, which shows the output of a debug command.

Which two statements about the output are true? (Choose two)

A.

The interlace is part of the OSPF backbone area.

A.

The interlace is part of the OSPF backbone area.

Answers
B.

There are a total of five OSPF routers attached to the vorz4 network segment

B.

There are a total of five OSPF routers attached to the vorz4 network segment

Answers
C.

One of the neighbors has a router ID of 0.0.0.4.

C.

One of the neighbors has a router ID of 0.0.0.4.

Answers
D.

In the network connected to port4, two OSPF routers are down.

D.

In the network connected to port4, two OSPF routers are down.

Answers
Suggested answer: A, D

Refer to the exhibit.

Which three pieces of information does the diagnose sys top command provide? (Choose three)

A.

The miglogd daemon is running on CPU core ID 0.

A.

The miglogd daemon is running on CPU core ID 0.

Answers
B.

The diagnose sys top command has been running for 18 minutes.

B.

The diagnose sys top command has been running for 18 minutes.

Answers
C.

The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.

C.

The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.

Answers
D.

The cmdbsvr process is occupying 2.4% of the total user memory space.

D.

The cmdbsvr process is occupying 2.4% of the total user memory space.

Answers
E.

If the neweli daemon continues to be in the R state, it will need to be manually restarted.

E.

If the neweli daemon continues to be in the R state, it will need to be manually restarted.

Answers
Suggested answer: A, B, D
Total 40 questions
Go to page: of 4