FCSS_NST_SE-7.6 Exam Questions
101 real FCSS_NST_SE-7.6 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Resolve IPsec VPN Issues
During which phase of IKEv2 does the Diffie-Helman key exchange take place?
IKEv2Diffie-HellmanIKE_SA_INITkey exchange - Question #52Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows a partial output of the real-time LDAP debug. What two actions can the administrator take to resolve this issue? (Choose two.)
LDAPAD group membershipauthentication debuguser credentials - Question #53Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows a partial output of a real-time LDAP debug. What two conclusions can you draw from the output? (Choose two.)
LDAPsearch requestbind operationdebug output - Question #54Diagnose FortiGate Firewall Policies and NAT Issues
Refer to the exhibit, which shows the partial output of a diagnose command. Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)
pinhole sessionexpectation sessiondynamic portssession table - Question #55Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit showing a debug output. An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is d...
FSSODC agent modeTCP port mismatchcollector agent - Question #56Troubleshoot Routing Issues
Refer to the exhibits. An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix. Which two actions can the administra...
BGPprefix advertisementnetwork-import-checkroute policy - Question #57Diagnose High Availability Issues
Refer to the exhibit, which shows the output of diagnose sys session list. If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the...
HAsession synchronizationfailoversession table - Question #58Resolve Security Fabric Issues
What are two functions of automation stitches? (Choose two.)
automation stitchesSecurity Fabricsequential actionsdiagnostic commands - Question #59Diagnose FortiGate Firewall Policies and NAT Issues
Refer to the exhibit, which a network topology and a partial routing table. FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from p...
RPF checkasymmetric routingfirewall policyreturn traffic - Question #60Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows the partial output of FortiOS kernel slabs. Which statement is true?
kernel slabssession memoryFortiOS diagnosticstcp_session - Question #61Resolve Security Fabric Issues
Refer to the exhibit, which shows one way communication of the downstream FortiGate with the upstream FortiGate within a Security Fabric. What three actions must you take to ensure...
Security FabricFortiTelemetrydownstream authorizationTCP 8013 - Question #62Troubleshoot Routing Issues
Refer to the exhibit, which shows the partial output of a real-time OSPF debug. Why are the two FortiGate devices unable to form an adjacency?
OSPF adjacencyauthentication mismatchOSPF debugrouting protocol - Question #63Troubleshoot Routing Issues
Refer to the exhibit, which shows the output of the command get router info bgp neighbors 100.64.2.254 advertised-routes. What can you conclude from the output?
BGP advertised routesBGP neighborcommand outputroute advertisement - Question #64Troubleshoot SSL VPN Issues
Refer to the exhibit. The exhibit shows the output from using the command diagnose debug application samld -1 to diagnose a SAML connection. Based on this output, what can you conc...
SAML debugSSL VPNIdP addresssamld - Question #65Troubleshoot Routing Issues
Refer to the exhibit, which shows the modified output of the routing kernel. Which statement is true?
FIBrouting kernelstatic routeBGP route - Question #66Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic. What happens to the session information if a rout...
session managementroute changedirty sessionsession table - Question #67Analyze and Troubleshoot FortiGate Operation
Which three steps does FortiGate execute using the pull method to get antivirus and IPS updates? (Choose three.)
FortiGuard updatespull methodDNS resolutionantivirus IPS updates - Question #68Resolve IPsec VPN Issues
For IKEv2, which combination of payloads can INFORMATIONAL exchanges contain?
IKEv2INFORMATIONAL exchangeIKE payloadsIPsec protocol - Question #73Troubleshoot Proxy and Flow-based Inspection Issues
Which two configuration commands change the default behavior for proxy-based content- inspected traffic while FortiGate is in conserve mode? (Choose two.)
conserve modeAV failopenproxy inspectionmemory pressure - Question #74Analyze and Troubleshoot FortiGate Operation
When investigating FortiGuard connectivity issues, which action is a valid troubleshooting step?
FortiGuard connectivitymanagement VDOMauto-updatetroubleshooting steps - Question #75Analyze and Troubleshoot FortiGate Operation
Which two configuration changes can you apply to optimize memory use on FortiGate? (Choose two.)
memory optimizationsession TTLFortiGuard cacheflow-based inspection - Question #76Resolve IPsec VPN Issues
Refer to the exhibit, which contains the partial configuration of an IPsec VPN configuration. After reviewing the configuration, what can you conclude about the IPsec VPN Phase 1 s...
IPsec Phase 1route-based VPNIKE versionDPD - Question #77Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows the partial output of diagnose sys session stat. Which statement about the output shown in the exhibit is correct?
session statisticsTCP proto_statediagnose sys session statsession table - Question #78Troubleshoot Proxy and Flow-based Inspection Issues
Refer to the exhibit. Antivirus is unable to detect an infected file downloaded through HTTPS. Part of the configuration used for antivirus inspection is shown in the exhibit. Whic...
antivirusHTTPS inspectionSSL deep inspectionproxy inspection - Question #79Analyze and Troubleshoot FortiGate Operation
Which of the following regarding protocol states is true?
proto_stateTCP session statesession tableprotocol flags - Question #80Troubleshoot Routing Issues
Refer to the exhibit, which shows the output of a BGP debug command. Why has the local router at 172.16.23.58 been unable to establish adjacency with its only neighbor?
BGP adjacencyTCP handshakeBGP debugSYN/ACK - Question #81Troubleshoot Proxy and Flow-based Inspection Issues
Refer to the exhibit. FortiGate is in conserve mode as shown in the Event logs. Based on the information shown in the exhibit, what can you conclude about the FortiGate intrusion p...
conserve modeIPS failopenmemory exhaustioninspection bypass - Question #82Resolve IPsec VPN Issues
Refer to the exhibit, which shows the sniffer log on two FortiGate devices. The IPsec tunnel is up on both ends of the tunnel, but traffic is not flowing. Based on the information...
IPsec tunnelhardware offloadESP protocol 50sniffer - Question #83Troubleshoot Routing Issues
Which three conditions would prevent a static route from being used by the kernel to route traffic? (Choose three.)
static routeinterface downnext-hop reachabilityroute distance - Question #84Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows a partial output of diagnose npu np6 port-list on FortiGate 2000E. An administrator is unable to analyze traffic flowing between port1 and port17...
NPU offloaddiagnose snifferhardware accelerationNP6 fastpath - Question #85Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command. What two conclusions can you draw from the output? (Choose two.)
FSSOagentless pollingDC agent modereal-time debug - Question #86Troubleshoot Routing Issues
What are two reasons that an OSPF router does not have any type 5 link-state advertisements (LSAs) in its link-state database (LSDB)? (Choose two.)
OSPFtype 5 LSAstub areaASBR - Question #87Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows the partial output of diagnose sys session stat. An administrator has noticed unusual behavior from FortiGate. It appears that sessions are random...
session statisticsmemory conserve modesession flushdiagnose sys session - Question #88Resolve IPsec VPN Issues
Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?
IPsec VPNPhase 2tunnel statusdiagnose vpn tunnel list - Question #89Analyze and Troubleshoot FortiGate Operation
Which actions does FortiGate take after an administrator enables the auxiliary session setting? (Choose two.)
auxiliary sessionECMPNP6 offloadsession handling - Question #90Resolve IPsec VPN Issues
Refer to the exhibit, which contains a screenshot of some phase 1 settings. The VPN is up. To monitor traffic flow, the administrator enters the following CLI commands on an SSH se...
NAT traversalIKE port 500packet snifferUDP 4500 - Question #91Diagnose FortiGate Firewall Policies and NAT Issues
Refer to the exhibit, which shows a session table entry. Which statement about FortiGate behavior relating to this session is correct?
session tablecaptive portalfirewall policyauthentication redirect - Question #92Resolve IPsec VPN Issues
Which exchanges are the first two exchanges in IKEv2 negotiation?
IKEv2IKE_SA_INITIKE_AUTHVPN negotiation - Question #93Troubleshoot Proxy and Flow-based Inspection Issues
Refer to the exhibit. FortiGate is showing continuous high CPU usage. During a maintenance window the CLI command diagnose sys top displays the output shown in the exhibit. The CLI...
IPS enginehigh CPUipsengine daemonCPU troubleshooting - Question #94Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows the output of a diagnose command. The administrator did not override the FortiGuard FQDN or IP address in the FortiGate configuration. Which IP ad...
FortiGuardDNS resolutionservice.fortiguard.netdiagnose output - Question #95Troubleshoot Proxy and Flow-based Inspection Issues
Refer to the exhibit, which displays the output of a real-time debug. Which statement accurately describes this output?
web filterHTTPS inspectionserver certificate CNFortiGuard category - Question #96Troubleshoot Routing Issues
Refer to the exhibit, which shows the output of the get router info bgp summary command. Which statement regarding adjacencies between the local router and its neighbors is correct...
BGPadjacency failureBGP summaryAS number mismatch - Question #97Analyze and Troubleshoot FortiGate Operation
Refer to the exhibit, which shows output from a collector agent log. The collector agent is showing the status of a workstation as "Not Verified". What is a common cause for this m...
FSSOcollector agentworkstation verificationNetBIOS ports 139 445 - Question #98Troubleshoot Proxy and Flow-based Inspection Issues
Refer to the exhibit, which contains the output of a debug command. If the default settings are in place, what can you conclude about the conserve mode shown in the exhibit?
conserve modememory usageflow-based inspectionproxy-based inspection - Question #99Troubleshoot Routing Issues
Refer to the exhibit, which shows the output of a debug command. What needs to happen for the local router to be elected DR?
OSPFDR electionBDRrouter priority - Question #100Troubleshoot Routing Issues
Refer to the exhibit, which shows the output of a BGP debug command. What is the reason that the local FortiGate is not receiving any prefixes from its neighbors?
BGPTCP three-way handshakeneighbor adjacencyprefix advertisement - Question #101Resolve IPsec VPN Issues
Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command. Based on the output, which two statements are correct? (Choose two.)
IPsec VPNnpu_flaganti-replaySPI values - Question #102Resolve IPsec VPN Issues
Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. Reviewing the debug command, what is the current status of the traffic flowing through the...
IPsec VPNNPU offloadinbound SAtunnel traffic - Question #672Analyze and Troubleshoot FortiGate Operation
In an FSSO environment, a user is listed as active on FortiGate but cannot browse the internet. Which factor do you not need to verify as a potential problem?
FSSOfirewall policygroup membershipinternet access - Question #831Troubleshoot Routing Issues
Which statement best describes the full state when forming an OSPF adjacency between two peers?
OSPFfull stateLSDB synchronizationadjacency formation