Fortinet FCSS_NST_SE-7.4 Practice Test - Questions Answers, Page 3
List of questions
Related questions
Refer to the exhibit, which shows the output o! the BGP database.
Which two statements are correct? (Choose two)
The advertised prefix of 10.20.30.0'24 was configured using the network command.
The first four prefixes are being advertised using a legacy route advertisement.
The advertised prefix of 10.20.30.0'24 is being advertised through the redistribution of another routing protocol.
The output shows all prefixes advertised by all neighbors as well as the local router.
In which two slates is a given session categorized as ephemeral? (Choose two)
A UDP session with only one packet received
A UOP session with packets sent and received
A TCP session waiting for the SYN ACK
A TCP session waiting for FIN ACK
Refer to the exhibit, which shows the output of get router info bgp summary.
Which two statements are true? (Choose two)
The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.
The TCP connection with BGP neighbor 100.64.2.254 was successful.
The local FortiGate has received 18 packets from a BGP neighbor.
The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264
Which exchange lakes care of DoS protection in IKEv2?
Create_CHILD_SA
IKE_Auth
IKE_Req_INIT
IKE_SA_NIT
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.
What two conclusions can you draw Itom the output? (Choose two)
The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.
The logon event can be seen on the collector agent installed on Windows.
FSSO is using DC agent mode to detect logon events.
FSSO is using agentless polling mode to detect logon events.
An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.
If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?
diagnose sniffer packet any 'udp port 500'
diagnose sniffer packet any 'lp proto 50'
diagnose sniffer packet any 'udp port 4500'
diagnose sniffer packet any 'ah'
Refer to the exhibits.
An administrator Is expecting to receive advertised route 8.8.8.8/32 from FGT-A. On FGT-B, they confirm that the route is being advertised and received, however, the route is not being injected into the routing table. What is the most likely cause of this issue?
A batter route to the 8.8.8.8/32 network exists in the routing table.
FGT-B is configured with a prefix list denying the 8.8.8.8/32 network to be injected into the routing table.
The administrator has misconfigured redistribution of routes on FGT-A.
FGT-8 is configured with a distribution list denying the 8.8.8.8/32 network to be injected into the routing table.
Refer to the exhibit, which shows the output of a BGP debug command.
What can you conclude about the router in this scenario?
The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the 8GP session with the local router.
An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.
All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.
The BGP session with peer 10.127.0.75 is up.
Which two statements about an auxiliary session ate true? (Choose two)
With the auxiliary session selling disabled, only auxiliary sessions are offloaded.
With the auxiliary session setting enabled. ECMP traffic is accelerated to the NP6 processor.
With the auxiliary session setting enabled. Iwo sessions are created in case of routing change.
With the auxiliary session setting disabled, for each traffic path. FortiGate uses the same auxiliary session.
Exhibit.
Refer to the exhibit, which shows the output of diagnose automation test.
What can you observe from the output? (Choose two)
The automation stitch test is not being logged.
The automation stitch test failed but the HA failover was successful.
An HA failover occurred.
The test was unsuccessful.
Question