FCSS_EFW_AD-7.6 Exam Questions
78 real FCSS_EFW_AD-7.6 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51VPN
Refer to the exhibit, which shows the ADVPN network topology and partial BGP configuration. Which two parameters must an administrator configure in the config neighbor range for sp...
ADVPNBGP neighbor rangeneighbor-groupprefix configuration - Question #52VPN
Which two statements about IKEv2 are true if an administrator decides to implement IKEv2 in the VPN topology? (Choose two.)
IKEv2EAP authenticationDiffie-HellmanVPN protocol - Question #53Security Fabric
Refer to the exhibit, which shows the FortiGuard Distribution Network of a FortiGate device. FortiGuard Distribution Network on FortiGate An administrator is trying to find the web...
web filteringFortiGuardflow-modeweb filter database - Question #54Security Fabric
Refer to the exhibit. A pre-run CLI template that is used in zero-touch provisioning (ZTP) and low- touch provisioning (LTP) with FortiManager is shown. The template is not assigne...
FortiManagerZTPCLI templatezero-touch provisioning - Question #55Security Fabric
Refer to the exhibit, which shows a revision history window in the FortiManager device layer. The IT team is trying to identify the administrator responsible for the most recent up...
FortiManagerrevision historyaudit trailconfiguration management - Question #56Advanced Threat Protection
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration. Why is FortiGate unable to detect HTTPS attacks on...
SSL inspectionHTTPSdeep inspectionserver certificate - Question #57SD-WAN
An administrator must enable direct communication between multiple spokes in a company's network. Each spoke has more than one internet connection. The requirement is for the spoke...
ADVPN 2.0SD-WANdynamic tunnellink optimization - Question #58Security Fabric
Refer to the exhibit, which shows device registration on FortiManager. What can you conclude about the Spoke-1 and Spoke-2 configurations with respect to the information cond: Modi...
FortiManagerdevice managementauto-updateconfiguration sync - Question #59Advanced Routing
While configuring the BGP protocol, an administrator applies the set network-import-check disable command under config network. What will FortiGate do as a result of this command?
BGPnetwork-import-checkroute advertisementBGP table - Question #60High Availability
An administrator is configuring two FortiGate devices in an HA cluster. While configuring the devices, the administrator issues the following commands on both HA cluster members: I...
HA clusterfailovergratuitous ARPMAC forwarding - Question #61Advanced Routing
Refer to the exhibit, which shows an OSPF network. Which types of link-state advertisements (LSA) will NGFW-1 send, if it is a backup designated router (BDR)?
OSPFBDRLSA typesABR - Question #62Security Fabric
Which two statements about the Security Fabric are true? (Choose two.)
Security FabricFortiTelemetryFortiAnalyzertopology sync - Question #63VPN
How would fec-ingress and fec-sgress IPsec configuration affect an IPsec tunnel?
FECIPsecpacket loss recoverytunnel redundancy - Question #64VPN
Refer to the exhibit, which shows a partial routing table. What two conclusions can you draw from the FortiGate output shown in the exhibit? (Choose two.)
IPsec routingnet-deviceadd-routequick mode selectors - Question #65VPN
Refer to the exhibit, which shows an ADVPN network. An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2. What must the administrator co...
ADVPNHub2Hubauto-discovery-forwarderoverlay routing - Question #66Security Fabric
Which statement about meta fields is true?
FortiManagermeta fieldsprovisioning templatesobject management - Question #67Advanced Routing
An administrator configured the following command on FortiGate. config router ospf set restart-mode graceful-restart Which two statements correctly describe the result of the above...
OSPFgraceful restartgrace LSAhelper mode - Question #68Security Fabric
Which statement about network processor (NP) offloading is true?
NP offloadingsession accelerationproxy-based securityfast-path - Question #69VPN
Which two statements about IKE version 2 fragmentation are true? (Choose two.)
IKEv2fragmentationfragment countreassembly - Question #70Advanced Threat Protection
Refer to the exhibit, which shows an SSL certification inspection configuration. SSL certification inspection configuration While testing, the administrator updated the ssl-ssh-pro...
SSL inspectionSNIcertificate validationsni-server-cert-check - Question #71Advanced Routing
Refer to the exhibit, which shows information about an OSPF interface of hub router NGFW-1. How would you change the interface state of NGFW.1 to a Designated router, if the spoke...
OSPFDR electionrouter priorityinterface state - Question #72Advanced Routing
An administrator must improve the resiliency of a link by minimizing data loss within the enterprise network that has full path redundancy. What should the administrator enable on...
BGPgraceful restartBFDlink resiliency - Question #73VPN
An administrator must optimize the performance of real-time voice and video applications across a WAN link with high packet loss. Which combination of IPSec phase 1 parameters must...
FECIPsec phase 1VoIP optimizationpacket loss - Question #74Troubleshooting
You want to know which content processor (CP) model FortiGate contains. Which command should you enter?
content processorhardware statusFortiGate hardwareCLI diagnostics - Question #75Advanced Threat Protection
An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode. Which two actions must the administrator take? (Cho...
application controlNGFW policy-based modeSSL inspectionconsolidated policy - Question #76VPN
Which two configurations are mandatory for an auto-discovery VPN (ADVPN) implementation on a hub? (Choose two.)
ADVPNhub configurationnet-deviceoverlay IP assignment - Question #77High Availability
Refer to the exhibits. Network topology Output from the command config system ha A network diagram and the output from the command config system ha are shown. The administrator has...
HA clusterheartbeat interfacecluster formationHA troubleshooting - Question #78Advanced Routing
Refer to the exhibit. An administrator wants to expand the network by adding two additional FortiGate devices into AS 6500. Which configuration is the most effective way to improve...
BGProute reflectoriBGP convergenceAS scaling