Fortinet FCSS_NST_SE-7.4 Practice Test - Questions Answers, Page 2

List of questions
Question 11

Refer to the exhibit, which shows a session entry.
Which statement about this session is true?
Return traffic to the initiator is sent to 10.1.0.1.
Return traffic to the initiator is sent lo 10.200.1.254.
It is an ICMP session from 10.1.10.10 to 10.200.1.1.
It is an ICMP session from 10.1.10.1 to 10.200.5.1.
Question 12

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.
Which action will FortiGate take when using the default settings for SSL certificate inspection?
FortiGate uses the SNI from the user's web browser.
FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
FortiGate uses the first entry listed in the SAN field in the server certificate.
FortiGate uses the ZN information from the Subject field in the server certificate.
Question 13

Exhibit.
Refer to the exhibit, which contains partial output from an IKE real-time debug.
Which two statements about this debug output are correct? (Choose two)
Question 14

Exhibit.
Refer to the exhibit, which shows the output of a diagnose command.
What can you conclude about the debug output in this scenario?
Question 15

Refer to the exhibit, which shows the output of a policy route table entry.
Which type of policy route does the output show?
Question 16

Exhibit.
Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator do to fix the issue?
Question 17

Which statement about IKEv2 is true?
Question 18

Exhibit 1.
Exhibit 2.
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.
An administrator would like to lest session failover between the two service provider connections.
Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two)
Question 19

Refer to the exhibit, which shows the output of a debug command.
Which two statements about the output are true? (Choose two)
Question 20

Refer to the exhibit.
Which three pieces of information does the diagnose sys top command provide? (Choose three)
Question