Fortinet FCSS_NST_SE-7.4 Cert Guide PDF 100% Cover Real Exam Questions [Q16-Q41]

Share

Fortinet FCSS_NST_SE-7.4 Cert Guide PDF 100% Cover Real Exam Questions

Pass FCSS_NST_SE-7.4 Exam - Real Questions and Answers

NEW QUESTION # 16
Exhibit.

Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator do to fix the issue?

  • A. Disable webfilter-force-off.
  • B. Enable fortiguard-anycast.
  • C. Change protocol to TCP.
  • D. Increase webfilter-timeout.

Answer: A


NEW QUESTION # 17
Refer to the exhibit, which shows partial outputs from two routing debug commands.

Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?

  • A. Set the priority of the static default route using port2 to 1.
  • B. Set snat-route-change to enable.
  • C. Set the priority of the static default route using port1 to 10.
  • D. Set preserve-session-route to enable.

Answer: C


NEW QUESTION # 18
Refer to the exhibit, which shows the output of a BGP debug command.

Whatcan you conclude about the router in this scenario?

  • A. The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the 8GP session with the local router.
  • B. The BGP session with peer 10.127.0.75 is up.
  • C. All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.
  • D. An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.

Answer: B


NEW QUESTION # 19
An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.
If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?

  • A. diagnose sniffer packet any 'lp proto 50'
  • B. diagnose sniffer packet any 'udp port 4500'
  • C. diagnose sniffer packet any 'ah'
  • D. diagnose sniffer packet any 'udp port 500'

Answer: A


NEW QUESTION # 20
Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.

What two conclusions can you draw from the output? (Choose two.)

  • A. FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.
  • B. The name of the configured LDAP server is Lab.
  • C. FortiOS is performing the second step (Search Request) in the LDAP authentication process.
  • D. The user is authenticating using CN=John Smith.

Answer: C,D


NEW QUESTION # 21
Which two statements about Security Fabric communications are true? (Choose two.)

  • A. The default port for Neighbor Discovery can be modified.
  • B. FortiTelemetry must be manually enabled on the FortiGate interface.
  • C. FortiTelemetry and Neighbor Discovery both operate using TCP.
  • D. By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.

Answer: B,D


NEW QUESTION # 22
Refer to the exhibit, which shows the output of a policy route table entry.

Which type of policy route does the output show?

  • A. A regular policy route, which is associated with an active static route in the FIB
  • B. An ISDB route
  • C. A regular policy route
  • D. AnSD-WAN rule

Answer: B


NEW QUESTION # 23
Refer to the exhibit.

Assuming a default configuration, which three statements are true? (Choose three.)

  • A. User C: Fail. There is no route to 10.0.4.63 using port1 in the touting table.
  • B. User A: Pass. The default static route through wan1 passes the RPF check regardless of the source IP address.
  • C. User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table.
  • D. Strict RPF is enabled by default.
  • E. User B: Pass. FortiGate will use asymmetric routing using wan1 to reply to traffic for 95.56.234.24.

Answer: A,C,E


NEW QUESTION # 24
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.

What two conclusions can you draw Itom the output? (Choose two.)

  • A. The logon event can be seen on the collector agent installed on Windows.
  • B. FSSO is using agentless polling mode to detect logon events.
  • C. FSSO is using DC agent mode to detect logon events.
  • D. The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.

Answer: B,D


NEW QUESTION # 25
Which two statements are true regarding heartbeat messages sent from an FSSO collector agent to FortiGate?
(Choose two.)

  • A. The heartbeat messages can be seen using the command diagnose debug authd fsso list.
  • B. The heartbeat messages can be seen in the collector agent logs.
  • C. The heartbeat messages can be seen on FortiGate using the real-lime FSSO debug.
  • D. The heartbeat messages must be manually enabled on FortiGate.

Answer: B,C


NEW QUESTION # 26
What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow?
(Choose two.)

  • A. VIP or IP pool misconfiguration.
  • B. Trusted host list misconfiguration.
  • C. Packet was dropped because of policy route misconfiguration.
  • D. Packet was dropped because of traffic shaping.

Answer: A,B


NEW QUESTION # 27
Exhibit.

Refer to theexhibit,which shows the output of getsystem ha status.
NGFW-1 and NGFW-2 have been up for a week.
Which two statements about the output are true? (Choose two.)

  • A. If FGVM...649 is rebooted. FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.
  • B. If no action is taken, the primary FortiGate will leave the cluster because of the current sync status.
  • C. If port 7 becomes disconnected on the secondary, both FortiGate devices will elect itself as primary.
  • D. If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.

Answer: A,C


NEW QUESTION # 28
Which authentication option can you not configure under config user radius on FortiOS?

  • A. eap
  • B. mschap2
  • C. mschap
  • D. pap

Answer: A


NEW QUESTION # 29
Which statement about IKEv2 is true?

  • A. IKEv1and IKEv2 use same TCP port but run on different UDP ports.
  • B. IKEv1and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.
  • C. IKEv1and IKEv2 share the concept of phase1and phase2.
  • D. Both IKEv1and IKEv2 share the feature of asymmetric authentication.

Answer: B


NEW QUESTION # 30
Which exchange lakes care of DoS protection in IKEv2?

  • A. IKE_SA_NIT
  • B. IKE_Req_INIT
  • C. Create_CHILD_SA
  • D. IKE_Auth

Answer: B


NEW QUESTION # 31
In which two slates is a given session categorized as ephemeral? (Choose two.)

  • A. A UOP session with packets sent and received
  • B. A TCP session waiting for the SYN ACK
  • C. A TCP session waiting for FIN ACK
  • D. A UDP session with only one packet received

Answer: B,D


NEW QUESTION # 32
......

100% Free FCSS_NST_SE-7.4 Daily Practice Exam With 42 Questions: https://www.testkingpdf.com/FCSS_NST_SE-7.4-testking-pdf-torrent.html

Pass FCSS_NST_SE-7.4 Review Guide, Reliable FCSS_NST_SE-7.4 Test Engine: https://drive.google.com/open?id=1nZlYilfHnZ9YhfYvVjBfUS4qszOK0mvF