ExamGecko
Home / Fortinet / FCSS_NST_SE-7.4 / List of questions
Ask Question

Fortinet FCSS_NST_SE-7.4 Practice Test - Questions Answers, Page 2

List of questions

Question 11

Report Export Collapse

Refer to the exhibit, which shows a session entry.

Fortinet FCSS_NST_SE-7.4 image Question 11 120488 10162024014809000000

Which statement about this session is true?

Return traffic to the initiator is sent to 10.1.0.1.

Return traffic to the initiator is sent to 10.1.0.1.

Return traffic to the initiator is sent lo 10.200.1.254.

Return traffic to the initiator is sent lo 10.200.1.254.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

It is an ICMP session from 10.1.10.1 to 10.200.5.1.

It is an ICMP session from 10.1.10.1 to 10.200.5.1.

Suggested answer: D
asked 16/10/2024
Musaddiq Shorunke
48 questions

Question 12

Report Export Collapse

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.

Which action will FortiGate take when using the default settings for SSL certificate inspection?

FortiGate uses the SNI from the user's web browser.

FortiGate uses the SNI from the user's web browser.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.

FortiGate uses the first entry listed in the SAN field in the server certificate.

FortiGate uses the first entry listed in the SAN field in the server certificate.

FortiGate uses the ZN information from the Subject field in the server certificate.

FortiGate uses the ZN information from the Subject field in the server certificate.

Suggested answer: C
asked 16/10/2024
Robinson Santos
42 questions

Question 13

Report Export Collapse

Exhibit.

Fortinet FCSS_NST_SE-7.4 image Question 13 120490 10162024014809000000

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Which two statements about this debug output are correct? (Choose two)

Perfect Forward Secrecy (PFS) is enabled in the configuration.

Perfect Forward Secrecy (PFS) is enabled in the configuration.

The local gateway IP address is 10.0.0.1.

The local gateway IP address is 10.0.0.1.

It shows a phase 2 negotiation.

It shows a phase 2 negotiation.

The initiator provided remote as its IPsec peer ID.

The initiator provided remote as its IPsec peer ID.

Suggested answer: C, D
asked 16/10/2024
Djordje Novakovic
42 questions

Question 14

Report Export Collapse

Exhibit.

Fortinet FCSS_NST_SE-7.4 image Question 14 120491 10162024014809000000

Refer to the exhibit, which shows the output of a diagnose command.

What can you conclude about the debug output in this scenario?

The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.

The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.

There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.

There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.

FortiGate used 64.26.151.37 as the initial server to validate its contract.

FortiGate used 64.26.151.37 as the initial server to validate its contract.

Servers with a negative TZ value are less preferred for rating requests.

Servers with a negative TZ value are less preferred for rating requests.

Suggested answer: B
asked 16/10/2024
pedro blanco
31 questions

Question 15

Report Export Collapse

Refer to the exhibit, which shows the output of a policy route table entry.

Fortinet FCSS_NST_SE-7.4 image Question 15 120492 10162024014809000000

Which type of policy route does the output show?

An ISDB route

An ISDB route

A regular policy route

A regular policy route

A regular policy route, which is associated with an active static route in the FIB

A regular policy route, which is associated with an active static route in the FIB

An SD-WAN rule

An SD-WAN rule

Suggested answer: A
asked 16/10/2024
Praneel Maharaj
28 questions

Question 16

Report Export Collapse

Exhibit.

Fortinet FCSS_NST_SE-7.4 image Question 16 120493 10162024014809000000

Refer to the exhibit, which shows a FortiGate configuration.

An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.

What must the administrator do to fix the issue?

Disable webfilter-force-off.

Disable webfilter-force-off.

Increase webfilter-timeout.

Increase webfilter-timeout.

Enable fortiguard-anycast.

Enable fortiguard-anycast.

Change protocol to TCP.

Change protocol to TCP.

Suggested answer: A
asked 16/10/2024
Shirish Astagikar
47 questions

Question 17

Report Export Collapse

Which statement about IKEv2 is true?

Both IKEv1 and IKEv2 share the feature of asymmetric authentication.

Both IKEv1 and IKEv2 share the feature of asymmetric authentication.

IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.

IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.

IKEv1 and IKEv2 use same TCP port but run on different UDP ports.

IKEv1 and IKEv2 use same TCP port but run on different UDP ports.

IKEv1 and IKEv2 share the concept of phase1 and phase2.

IKEv1 and IKEv2 share the concept of phase1 and phase2.

Suggested answer: B
asked 16/10/2024
Oleksandr Kondratchuk
37 questions

Question 18

Report Export Collapse

Exhibit 1.

Fortinet FCSS_NST_SE-7.4 image Question 18 120495 10162024014810000000

Exhibit 2.

Fortinet FCSS_NST_SE-7.4 image Question 18 120495 10162024014810000000

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.

An administrator would like to lest session failover between the two service provider connections.

Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two)

Change the priority of the port! static route to 11.

Change the priority of the port! static route to 11.

Change the priority of the port2 static route to 5.

Change the priority of the port2 static route to 5.

Configure unset snat-route-change to return it to the default setting.

Configure unset snat-route-change to return it to the default setting.

Configure set snat-route-change enable.

Configure set snat-route-change enable.

Suggested answer: A, D
asked 16/10/2024
Dustin Sickle
35 questions

Question 19

Report Export Collapse

Refer to the exhibit, which shows the output of a debug command.

Fortinet FCSS_NST_SE-7.4 image Question 19 120496 10162024014810000000

Which two statements about the output are true? (Choose two)

The interlace is part of the OSPF backbone area.

The interlace is part of the OSPF backbone area.

There are a total of five OSPF routers attached to the vorz4 network segment

There are a total of five OSPF routers attached to the vorz4 network segment

One of the neighbors has a router ID of 0.0.0.4.

One of the neighbors has a router ID of 0.0.0.4.

In the network connected to port4, two OSPF routers are down.

In the network connected to port4, two OSPF routers are down.

Suggested answer: A, D
asked 16/10/2024
Christopher Schmidt
43 questions

Question 20

Report Export Collapse

Refer to the exhibit.

Fortinet FCSS_NST_SE-7.4 image Question 20 120497 10162024014810000000

Which three pieces of information does the diagnose sys top command provide? (Choose three)

The miglogd daemon is running on CPU core ID 0.

The miglogd daemon is running on CPU core ID 0.

The diagnose sys top command has been running for 18 minutes.

The diagnose sys top command has been running for 18 minutes.

The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.

The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.

The cmdbsvr process is occupying 2.4% of the total user memory space.

The cmdbsvr process is occupying 2.4% of the total user memory space.

If the neweli daemon continues to be in the R state, it will need to be manually restarted.

If the neweli daemon continues to be in the R state, it will need to be manually restarted.

Suggested answer: A, B, D
asked 16/10/2024
Piotr Jakubowski
44 questions
Total 40 questions
Go to page: of 4
Search