nerdexam
Fortinet

FCNSP · Question #51

The following diagnostic output is displayed in the CLI: diag firewall auth list policy iD. 9, srC. 192.168.3.168, action: accept, timeout: 13427 user: forticlient_chk_only, group: flag (80020)…

The correct answer is A. Firewall policy 9 has endpoint compliance enabled but not firewall authentication. See the full explanation below for the reasoning.

Question

The following diagnostic output is displayed in the CLI:

diag firewall auth list policy iD. 9, srC. 192.168.3.168, action: accept, timeout: 13427 user: forticlient_chk_only, group:

flag (80020): auth timeout_ext, flag2 (40): exact group iD. 0, av group: 0 ----- 1 listed, 0 filtered ------ Based on this output, which of the following statements is correct?

Options

  • AFirewall policy 9 has endpoint compliance enabled but not firewall authentication.
  • BThe client check that is part of an SSL VPN connection attempt failed.
  • CThis user has been associated with a guest profile as evidenced by the group id of 0.
  • DAn auth-keepalive value has been enabled.

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    7% (2)
  • C
    14% (4)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full FCNSP Practice