nerdexam
Fortinet

NSE4_FGT-6.2 · Question #95

Examine this FortiGate configuration: config system global set av-failopen pass end Examine the output of the following debug command: diagnose hardware sysinfo conserve memory conserve mode: on…

The correct answer is C. It is dropped. See the full explanation below for the reasoning.

Question

Examine this FortiGate configuration: config system global set av-failopen pass end Examine the output of the following debug command:

diagnose hardware sysinfo conserve

memory conserve mode: on total RAM: 3040 MB memory used: 2948 MB 97% of total RAM memory freeable: 92 MB 3% of total RAM memory used + freeable threshold extreme: 2887 MB 95% of total RAM memory used threshold red: 2675 MB 88% of total RAM memory used threshold green: 2492 MB 82% of total RAM Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection?

Options

  • AIt is allowed, but with no inspection.
  • BIt is allowed and inspected, as long as the inspection is flow based.
  • CIt is dropped.
  • DIt is allowed and inspected, as long as the only inspection required is antivirus.

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    77% (33)
  • D
    14% (6)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.2 Practice