FCSS_EFW_AD-7.4 Exam Questions
78 real FCSS_EFW_AD-7.4 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51IPsec VPN
Refer to the exhibit, which shows the ADVPN network topology and partial BGP configuration. Which two parameters must an administrator configure in the config neighbor range for sp...
ADVPNBGP neighbor rangespoke BGP configroute reflector - Question #52IPsec VPN
Which two statements about IKEv2 are true if an administrator decides to implement IKEv2 in the VPN topology? (Choose two.)
IKEv2EAP authenticationElliptic Curve DHIKEv2 features - Question #53Security Profiles
Refer to the exhibit, which shows the FortiGuard Distribution Network of a FortiGate device. FortiGuard Distribution Network on FortiGate An administrator is trying to find the web...
web filteringFortiGuardflow-modeweb filter database - Question #54FortiManager Zero-Touch Provisioning
Refer to the exhibit. A pre-run CLI template that is used in zero-touch provisioning (ZTP) and low- touch provisioning (LTP) with FortiManager is shown. The template is not assigne...
ZTPLTPpre-run CLI templatesFortiManager provisioning - Question #55FortiManager Logging and Auditing
Refer to the exhibit, which shows a revision history window in the FortiManager device layer. The IT team is trying to identify the administrator responsible for the most recent up...
FortiManager revision historyaudit loggingsystem logsscript_manager - Question #56SSL/TLS Inspection
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration. Why is FortiGate unable to detect HTTPS attacks on...
SSL inspectiondeep inspectionserver certificateHTTPS security - Question #57SD-WAN and VPN
An administrator must enable direct communication between multiple spokes in a company's network. Each spoke has more than one internet connection. The requirement is for the spoke...
ADVPN 2.0SD-WANspoke-to-spoke VPNlink optimization - Question #58FortiManager Configuration Management
Refer to the exhibit, which shows device registration on FortiManager. What can you conclude about the Spoke-1 and Spoke-2 configurations with respect to the information cond: Modi...
FortiManagerdevice registrationconfiguration driftauto-update - Question #59Routing
While configuring the BGP protocol, an administrator applies the set network-import-check disable command under config network. What will FortiGate do as a result of this command?
BGPnetwork-import-checkroute advertisementrouting policy - Question #60High Availability
An administrator is configuring two FortiGate devices in an HA cluster. While configuring the devices, the administrator issues the following commands on both HA cluster members: I...
HA clusterlink failovergratuitous ARPMAC table update - Question #61
Refer to the exhibit, which shows an OSPF network. Which types of link-state advertisements (LSA) will NGFW-1 send, if it is a backup designated router (BDR)?
- Question #62
Which two statements about the Security Fabric are true? (Choose two.)
- Question #63
How would fec-ingress and fec-sgress IPsec configuration affect an IPsec tunnel?
- Question #64
Refer to the exhibit, which shows a partial routing table. What two conclusions can you draw from the FortiGate output shown in the exhibit? (Choose two.)
- Question #65
Refer to the exhibit, which shows an ADVPN network. An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2. What must the administrator co...
- Question #66FortiManager Object Management
Which statement about meta fields is true?
meta fieldsFortiManagerprovisioning templatesobject variables - Question #67
An administrator configured the following command on FortiGate. config router ospf set restart-mode graceful-restart Which two statements correctly describe the result of the above...
- Question #68
Which statement about network processor (NP) offloading is true?
- Question #69
Which two statements about IKE version 2 fragmentation are true? (Choose two.)
- Question #70
Refer to the exhibit, which shows an SSL certification inspection configuration. SSL certification inspection configuration While testing, the administrator updated the ssl-ssh-pro...
- Question #71
Refer to the exhibit, which shows information about an OSPF interface of hub router NGFW-1. How would you change the interface state of NGFW.1 to a Designated router, if the spoke...
- Question #72
An administrator must improve the resiliency of a link by minimizing data loss within the enterprise network that has full path redundancy. What should the administrator enable on...
- Question #73
An administrator must optimize the performance of real-time voice and video applications across a WAN link with high packet loss. Which combination of IPSec phase 1 parameters must...
- Question #74
You want to know which content processor (CP) model FortiGate contains. Which command should you enter?
- Question #75
An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode. Which two actions must the administrator take? (Cho...
- Question #76
Which two configurations are mandatory for an auto-discovery VPN (ADVPN) implementation on a hub? (Choose two.)
- Question #77
Refer to the exhibits. Network topology Output from the command config system ha A network diagram and the output from the command config system ha are shown. The administrator has...
- Question #78Routing
Refer to the exhibit. An administrator wants to expand the network by adding two additional FortiGate devices into AS 6500. Which configuration is the most effective way to improve...
BGProute reflectoriBGPAS convergence