ExamGecko
Home Home / Fortinet / FCSS_NST_SE-7.4

Fortinet FCSS_NST_SE-7.4 Practice Test - Questions Answers, Page 4

Question list
Search
Search

Refer to the exhibit, which shows partial outputs from two routing debug commands.

Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?

A.

Set snat-route-change to enable.

A.

Set snat-route-change to enable.

Answers
B.

Set the priority of the static default route using port2 to 1.

B.

Set the priority of the static default route using port2 to 1.

Answers
C.

Set preserve-session-route to enable.

C.

Set preserve-session-route to enable.

Answers
D.

Set the priority of the static default route using port1 to 10.

D.

Set the priority of the static default route using port1 to 10.

Answers
Suggested answer: D

What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two)

A.

Packet was dropped because of policy route misconfiguration.

A.

Packet was dropped because of policy route misconfiguration.

Answers
B.

Packet was dropped because of traffic shaping.

B.

Packet was dropped because of traffic shaping.

Answers
C.

Trusted host list misconfiguration.

C.

Trusted host list misconfiguration.

Answers
D.

VIP or IP pool misconfiguration.

D.

VIP or IP pool misconfiguration.

Answers
Suggested answer: C, D

Exhibit.

Refer to the exhibit, which shows the output of a session. Which two statements are true? (Choose Iwo)

A.

The TCP session has been successfully established.

A.

The TCP session has been successfully established.

Answers
B.

The session was initiated from an authenticated user.

B.

The session was initiated from an authenticated user.

Answers
C.

The session is being inspected using flow inspection.

C.

The session is being inspected using flow inspection.

Answers
D.

The session is being offloaded.

D.

The session is being offloaded.

Answers
Suggested answer: A, B

Refer to the exhibit, which shows the output of get router info ospf neighbor.

What can you conclude from the command output?

A.

The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.

A.

The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.

Answers
B.

All neighbors are in area 0.0.0.0.

B.

All neighbors are in area 0.0.0.0.

Answers
C.

The local FortiGate is the BDR.

C.

The local FortiGate is the BDR.

Answers
D.

The local FortiGate is not a DROther.

D.

The local FortiGate is not a DROther.

Answers
Suggested answer: A

Exhibit.

Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.

What three conclusions can you draw from these log entries? {Choose three)

A.

Remote registry is not running on the workstation.

A.

Remote registry is not running on the workstation.

Answers
B.

The user's status shows as 'not verified' in the collector agent.

B.

The user's status shows as 'not verified' in the collector agent.

Answers
C.

DNS resolution is unable to resolve the workstation name.

C.

DNS resolution is unable to resolve the workstation name.

Answers
D.

The FortiGate firmware version is not compatible with that of the collector agent.

D.

The FortiGate firmware version is not compatible with that of the collector agent.

Answers
E.

A firewall is blocking traffic to port 139 and 445.

E.

A firewall is blocking traffic to port 139 and 445.

Answers
Suggested answer: A, B, E

Which statement about protocol options is true?

A.

Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.

A.

Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.

Answers
B.

Protocol options give administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.

B.

Protocol options give administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.

Answers
C.

Protocol options allow administrators to configure the Any setting for all enabled protocols, which provides the most efficient use of system resources.

C.

Protocol options allow administrators to configure the Any setting for all enabled protocols, which provides the most efficient use of system resources.

Answers
D.

Protocol options allow administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.

D.

Protocol options allow administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.

Answers
Suggested answer: D

Which two statements about conserve mode are true? (Choose two)

A.

FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.

A.

FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.

Answers
B.

FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.

B.

FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.

Answers
C.

FortiGate exits conserve mode when the system memory goes below the configured green threshold.

C.

FortiGate exits conserve mode when the system memory goes below the configured green threshold.

Answers
D.

FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.

D.

FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.

Answers
Suggested answer: B, C

Which statement about parallel path processing is correct (PPP)?

A.

PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.

A.

PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.

Answers
B.

Only FortiGate hardware configurations affect the path that a packet takes.

B.

Only FortiGate hardware configurations affect the path that a packet takes.

Answers
C.

PPP does not apply to packets that are part of an already established session.

C.

PPP does not apply to packets that are part of an already established session.

Answers
D.

Software configuration has no impact on PPP.

D.

Software configuration has no impact on PPP.

Answers
Suggested answer: A

In IKEv2, which exchange establishes the first CHILD_SA?

A.

IKE_SA_INIT

A.

IKE_SA_INIT

Answers
B.

INFORMATIONAL

B.

INFORMATIONAL

Answers
C.

CREATE_CHILD_SA

C.

CREATE_CHILD_SA

Answers
D.

IKE_Auth

D.

IKE_Auth

Answers
Suggested answer: C

Which authentication option can you not configure under config user radius on FortiOS?

A.

mschap

A.

mschap

Answers
B.

pap

B.

pap

Answers
C.

mschap2

C.

mschap2

Answers
D.

eap

D.

eap

Answers
Suggested answer: D
Total 40 questions
Go to page: of 4