N7-EFW-7.0
![]() |
![]() |
![]() |
Title of test:![]() N7-EFW-7.0 Description: Meu Teste |




New Comment |
---|
NO RECORDS |
Which action will FortiGate take when using the default settings for SSL certificate inspection, where the server name indication not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate?. FortiGate uses the first entry listed in the SAN field in the server certificate. FortiGate uses the CN information from the subject field in the server certificate. FortiGate uses the SNI from the user's web browser. FortiGate closes the connection because this represents an invalid SSL/TLS configuration. View the following exhibit: What two statements about this session are correct? (Choose two.) Select one or more: This session terminates or originates on the FortiGate device. It is a UDP session that has seen traffic flow both ways. This is a TCP session that was blocked by firewall policy ID 0. It is a TCP session in SYN_SENT state. Refer to the exhibit, which contains the output of the diagnose vpn tunnel list. Which command will capture ESP traffic for the VPN named Dialup 0?. diagnose sniffer packet any 'ip proto 50'. diagnose sniffer packet any 'port 4500'. diagnose sniffer packet any 'esp and host 10.200.3.2'. diagnose sniffer packet any 'host 10.0.10.10'. Which three tasks are part of the manual registration process for adding a FortiGate device to FortiManager for central management? (Choose three.) Select one or more: Add the FortiManager IP address to the FortiGate central management configuration. Import the policy package from the managed FortiGate device. Start the rating services on FortiManager. In FortiManager, add the unregistered FortiGate device. Wait for the rating databases to download on FortiManager. An administrator wants to capture encrypted phase 2 traffic between two FortiGate devices using the built-in sniffer. If the administrator knows that there is no NAT device located between both FortiGate devices, which command should the administrator run?. diagnose sniffer packet any 'ah'. diagnose sniffer packet any 'udp port 4500'. diagnose sniffer packet an 'udp port 500'. diagnose sniffer packet any 'ip proto 50'. View the following exhibit: Which two statements about the BGP peer are true? (Choose two.) Select one or more: The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1. Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down. For the peer 10.125.0.60, the BGP state is Established. The local BGP peer has received a total of three BGP prefixes. Refer to the exhibit, which shows a partial routing table. Assuming all the appropriate firewall policies are configured, what two changes would an administrator need to make if they wanted to send traffic from a client directly connected to port3, to a server directly connected to port4? (Choose two.). Disable auto-asic-offload as this is not supported between VRF instances. Enable SNAT on the relevant firewall policies to prevent RPF check drops. Configure route leaking between port3 and port4. Configure RIPV2 to exchange route information between the VRF instances. Configure route leaking between VRF 12 and VRF 21. View the exhibit, which contains a hub-and-spoke VPN topology with two hubs. An administrator wants to configure ADVPN. Which ADVPN setting must be enabled in the tunnel between the Hub1 and Hub2 FortiGate devices? Select one: set auto-discovery-forwarder enabled. set auto-discovery-receiver enabled. set auto-discovery-ipsec enabled. set auto-discovery-sender enabled. Which statement about protocol options is true?. Protocol options allow administrators to configure a maximum number of sessions for each configured protocol. Protocol options allows administrators the ability to configure the Any setting for all enabled protocols which provides the most efficient use of system resources. Protocol options allows administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols. Protocol options allows administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on. View the following exhibit: Given the output showing a real-time debug, which statement describes why the update is failing? Select one: FortiGate is unable to establish a TCP connection with FDS. FortiGate is unable to resolve the required FQDN (service.fortiguard.net) for AV and IPS updates. The administrator should use the execute update-wf Command instead. The update should be using port 53 or port 8888, instead of port 443. An administrator has created a VPN community within VPN Manager on FortiManager. They also added gateways to the VPN community and are now trying to create firewall policies to permit traffic over the tunnel; however, the VPN interfaces are not listed as available options. What step must the administrator take to resolve this issue?. Install the VPN community and gateway configuration to the FortiGate devices, in order for the interfaces to be displayed within Policy & Objects on FortiManager. Create interface mappings for the IPsec VPN interfaces, before they can be used in a policy. Refresh the device status from the Device Manager so that FortiGate will populate the IPsec interfaces. Set up all of the phase1 settings in the VPN community that they neglected to set up initially. The interfaces will be automatically generated after the administrator configures all of the required settings. Which troubleshooting step is applicable when investigating antivirus and IPS update issues on FortiGate? Select one: Use the alternate service port 8888. Validate DNS resolution for update.fortiguard.net. Verify outbound ICMP connectivity. Use the diagnose debug rating command to check active servers. Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?. Non-DR and non-BDR routers form full adjacencies to DR only. Non-DR and non-BDR routers send link state updates and acknowledgements to 224.0.0.6. FortiGate first checks the OSPF ID to elect a DR. Only the DR receives link state information from non-DR routers. An administrator is configuring ADVPN in a hub-and-spoke topology. The administrator will use IBGP to route traffic between the VPN sites. Which IBGP setting needs to be enabled on the hub, for dynamic routing to work properly for on-demand tunnels? Select one: route-reflector-client. ibgp-multipath. next-hop-self. route-server-client. Which two conditions would prevent a static route from being added to the routing table? (Choose two.). There is another other route to the same destination, with a lower distance. The next-hop IP address is unreachable. The route has a lower priority value than another route to the same destination. The interface specified in the route configuration is down. View the exhibit, which contains the partial output of an IKE real-time debug. Which statement about this debug output is correct? Select one: It shows a phase 2 negotiation. Quick mode selectors do not match; therefore, the tunnel will not come up. It shows the negotiation of an IPsec tunnel in transport mode. The SA life soft and hard seconds do not match; therefore, the tunnel will not come up. Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week. Which two statements about the output are true? (Choose two.). If FGVM...649 is rebooted, FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster. If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset. If no action is taken, the primary FortiGate will leave the cluster due to the current sync status. If port7 becomes disconnected on the secondary both FortiGate devices will elect itself the primary. Examine these partial outputs from two routing debug commands: # get router info routing-table database S 0.0.0.0/0 [20/0] via 100.64.2.254, port2, [10/0] S *>0.0.0.0/0 [10/0] via 100.64.1.254, port1 # get router info routing-table all S* 0.0.0.0/0 [10/0] via 100.64.1.254, port1 Why is the default route that uses port2 not in the output of the second command? Select one: It has a higher distance than the default route using port1. It has a higher priority than the default route using port1. It is disabled in the FortiGate configuration. There can be only one default route present in an active routing table. In which two ways does FortiManager function when it is deployed as a local FDS? (Choose two.). It supports rating requests from non-FortiGate devices. It caches available firmware updates for unmanaged devices. It can be configured as an update server, a rating server, or both. It provides VM license validation services. Which two configuration changes can be applied to optimize the memory usage on FortiGate? (Choose two.) Select one or more: Use flow-based inspection. Increase the maximum file size for AV inspection. Increase TCP session timers. Reduce the FortiGuard cache TTL. Decrease the sessions TTL. Refer to the exhibit, which shows the output of a BGP debug command. Which statement explains why the state of the 10.200.3.1 peer is connect?. The router 10.200.3.1 has authentication configured for BGP and the local router does not. The local router has a different AS number than the remote peer. The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the openConfirm yet. The local router initiated the BGP session to 10.200.3.1 but did not receive a response. Which two statements correctly describe the characteristics of the Fortinet Security Fabric? (Choose two.) Select one or more: It provides a single pane of glass for reporting for all devices in the Security Fabric. The core of the Security Fabric includes FortiMail, FortiWeb, and FortiSandbox. It supports an open API, allowing third-party product integration. It contains individual management platforms for each device to provide granular control. Refer to the exhibit, which contains partial output from an IKE real- time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?. In the phase1 network configuration, set the IKE version to 2. In the phase1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms. In the phase1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms. In the phase1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms. Which three steps are executed to get antivirus and IPS updates using the pull method? (Choose three.) Select one or more: FortiGate contacts a DNS server to resolve the FortiGuard domain name. FortiGate registers its public IP address in FortiGuard. FortiGate gets a list of server IP addresses that can be contacted. FortiGate periodically queries for pending updates. FortiGate starts sending rating queries to one of the servers in the list. Which statement about administrative domains (ADOMs) on FortiManager is true? Select one: ADOMs allow grouping of managed devices based on management criteria and administrative access. The ADOM feature can be enabled by any administrative user. The number of configurable ADOMs is based on the FortiManager FortiCare service contract. FortiGate devices with multiple VDOMs must be assigned to the same ADOM on FortiManager. What does the dirty flag mean in a FortiGate session configured for NGFW policy mode?. The application or URL category is unknown and needs to be rescanned by the IPS engine to try to identify the Layer 7 details. Traffic has been identified as coming from an application that is not allowed and the relevant replacement message needs to be displayed to the user, if configured. The URL category for this session has been updated by FortiGuard and the session needs to be checked against the policy again to ensure proper web filtering is applied. The existing session table entry has been updated with the app_id and the firewall policy table needs to be checked for a match. View the following exhibit, which contains the sniffer output for a passive mode FTP request. An administrator has created the following custom IPS signature to block all FTP requests for passive mode: F-SBID (--attack_id 1002; --name "Block. FTP "; --protocol tcp; --flow from client; --pattern "PASV"; --no_case;) Soon after the signature is enabled in an active IPS sensor, some false positive detections are generated. Which option and value pair will allow more specific detection? Select one: --service ftp. --name "Block.FTP. PASV". --protocol ftp. --attack_id1001. Refer to the exhibit, which shows the output of a diagnose command. What can you conclude from the RTT value?. It determines which FortiGuard server is used for license validation. Its initial value is statically set to 10. Its value is incremented with each packet lost. Its value represents the time it takes to receive a response after a rating request is sent to a particular server. Which setting must be enabled in a spoke IPsec phase 1 configuration, to indicate that it wants to participate in ADVPN? Select one: auto-discovery-receiver. auto-discovery-forwarder. auto-discovery-sender. auto-discovery-ipsec. Refer to the exhibit, which contains the partial output of a diagnose command. Based on the output, which two statements are correct? (Choose two.). The remote gateway has quick mode selectors containing a destination subnet of 10.1.2.0/24. DPD is disabled. The remote gateway IP is 10.200.5.1. Anti-replay is enabled. What is an OSPF area border router? Select one: A router that is redistributing non-OSPF routes into the OSPF network. network. A router that is redistributing connected subnets into the OSPF network. A router with interfaces in multiple OSPF areas. A router with all its interfaces in the backbone area. Which statement about IKE and IKE NAT-T is true?. IKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface. They each use their own IP protocol number. They both use UDP as their transport protocol and the port number is configurable. IKE is the standard implementation for IKEv1 and IKE NAT-T is an extension added in IKEv2. Which layer of the FortiOS architecture does an application process or daemon run on?. Hardware. User space. Configuration layer. Kernel. Which two events can trigger an HA failover? (Choose two.) Select one or more: A session sync failure. A configuration sync failure. The physical disconnection of a monitored interface. The failure of a solid-state drive. Refer to the exhibit, which shows the output of diagnose sys session stat. Which statement about the output shown in the exhibit is correct?. There are 166 TCP sessions waiting to complete the three-way handshake. There are two sessions that have not been removed in case of any out-of-order packets that arrive. All the sessions in the session table are TCP sessions. 162 sessions have been deleted because of memory page exhaustion. When investigating FortiGuard connectivity issues, which action is a valid troubleshooting step? Select one: Configure a virtual IP to forward port 443 to the FortiGate external IP. Verify management VDOM internet access. Use the FortiGuard real-time debug command to verify rating requests. Verify that DNS requests are being proxied if auto-undate tunneling is enabled. Refer to the exhibit, which shows the output of a real-time debug. Which statement about this output is true?. This web request was inspected using the ftgd-allow web filter profile. FortiGate found the requested URL in its local cache. The requested URL belongs to category ID 255. The server hostname was extracted from the SNI in the client request, or from the CN in the server certificate. Refer to the exhibit, which shows the output of a debug command. What can be concluded from the debug command output?. The local FortiGate has a different MTU value from the OSPF router with ID 0.0.0.2, based on the state information. The OSPF router with the ID 0.0.0.69 has its OSPF priority set to 0. There are more than two OSPF routers on the wan2 network. The interface ToRemote is a broadcast OSPF network. An administrator has been assigned the task of creating a set of firewall policies which must be evaluated before any custom policies defined within the policy packages of managed FortiGate devices, across all 25 ADOMs in FortiManager. How should the administrator accomplish this task?. Move the FortiGate devices into a single globally scoped ADOM, and merge policy packages, inserting the new firewall policies at the top. Create a footer policy in the Global ADOM containing the firewall policies that must be evaluated first, and then assign this footer policy to all other ADOMS. Create a header policy in the Global ADOM containing the firewall policies that must be evaluated first, and then assign this header policy to all other ADOMS. Use a CLI script from the root ADOM on FortiManager to push these new policies to all FortiGate devices, through the FGFM tunnel. What are two functions of automation stitches? (Choose two.). An automation stitch configured to execute actions in parallel can be set to insert a specific delay between actions. Automation stitches can be configured on any FortiGate device in a Security Fabric environment. Automation stitches can be created to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds. An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action. Refer to the exhibit, which contains a CLI script configuration on FortiManager. An administrator configured the CLI script on FortiManager, but the script failed to apply any changes to the managed device after being executed. What are two reasons why the script did not make any changes to the managed device? (Choose two.). Static routes can be added using only TCL scripts. CLI scripts must start with #!. The commands that start with the # sign did not run. Incomplete commands can cause CLI scripts to fail. Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network. An administrator would like to test session failover between the two service provider connections. What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.). unset snat-route-change to return it to the default setting. Change the priority of the port1 static route to 11. Configure set snat-route-change enable. Change the priority of the port2 static route to 5. Refer to the exhibit, which shows partial outputs from two routing debug commands. Why is the port2 default route not in the second command output?. The port1 default route has a higher priority value than the default route using port2. The port1 default route has a lower distance than the default route using port2. The port2 interface is disabled in the FortiGate configuration. The port1 default route has a lower priority value than the default route using port2. You have configured FortiManager as a local FDS to provide FortiGate AV and IPS updates, but FortiGate devices are not receiving updates to their AV signature databases, IPS engines, or IPS signature databases. Which two settings need to be verified for these features to function? (Choose two.). FortiManager needs to be the license validation server for FortiGate devices trying to retrieve updated AV and IPS packages. FortiGate needs to have include-default-servers disabled under config system central-management. Service access needs to be enabled on FortiManager under System Settings > Network. FortiGate needs to have the server list entry for FortiManager set to server-type update under config system central-management. Which ADVPN configuration must be configured using a script on FortiManager?. Set protected network to all. Configure IP addresses on IPsec virtual interfaces terfaces. Enable AD-VPN in IPsec phase1. Disable add-route on hub. Refer to the exhibit, which shows a central management configuration. Which server will FortiGate choose for web filter rating requests, if 10.0.1.240 is experiencing an outage?. 10.0.1.242. Public FortiGuard servers. 10.0.1.243. 10.0.1.244. Which configuration can be used to reduce the number of BGP sessions in an IBGP network?. route-reflector enable. route-reflector-peer enable. route-reflector-server enable. route-reflector-client enable. In which two states is a given session categorized as ephemeral? (Choose two.). ATCP session waiting for FIN ACK. A UDP session with only one packet received. A TCP session waiting for the SYN ACK. A UDP session with packets sent and received. Refer to the exhibits, which contain the network topology and BGP configuration for a hub. An administrator is trying to configure ADVPN with a hub and spoke VPN setup using IBGP. All the VPNs are up and connected to the hub. The hub is receiving route information from both spokes over iBGP, however, the spokes are not receiving route information from each other. What change must the administrator make to the hub BGP configuration so that the routes learned from one spoke are forwarded to the other spoke?. Add a prefix list to the hub that permits routes to be shared between the spokes. Enable route redistribution under config router bgp. Configure the hub as a route reflector. Configure auto-discovery-sender on the hub. Refer to the exhibit, which shows a FortiGate configuration. An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy, however, the web filter is not inspecting any traffic that is passing through the policy. What must the admistrator change to fix the issue?. The administrator must disable webfilter-force-off. The administrator must increase webfilter-timeout. The administrator must change protocol to TCP. The administrator must enable fortiguard-anyeast. Which two statements about the Security Fabric are true? (Choose two). All FortiGate devices in the Security Fabric must have bidirectional FortiTelemetry connectivity. Branch FortiGate devices must be configured first. Only the root FortiGate collects network information and forwards it to FortiAnalyzer. FortiGate uses FortiTelemetry protocol to communicate with FortiAnalyzer. Refer to the exhibit, which contains the debug output of diagnose dvm device list. Which two statements about the output shown in the exhibit are correct? (Choose two.). There are pending device-level changes yet to be installed on Local-FortiGate. The policy package has been modified for Local-FortiGate. The FortiGate configuration is in sync with latest running revision history. ADOMS are disabled on the FortiManager. Which two statements about OCVPN are true? (Choose two.). OCVPN supports static and dynamic IPs in WAN interface. OCVPN offers only Hub-Spoke VPNs. FortiGate devices under different FortiCare accounts can be used to form OCVPN. Only root vdom supports OCVPN. Which two statements about an auxiliary session are true? (Choose two.). With the auxiliary session setting disabled, only auxiliary sessions will be offloaded. With the auxiliary session setting disabled, for each traffic path, FortiGate will use the same auxiliary session. With the auxiliary session setting enabled, two sessions will be created in case of routing change. With the auxiliary session setting enabled, ECMP traffic is accelerated to the NP6 processor. Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command Based on the output, which two statements are correct? (Choose two.). Hub2spoke1 is a policy-based VPN. Anti-replay is disabled. Phase 2 authentication is set to sha1 on both sides. Hub2Spoke1 is configured on interface wan2. Refer to the exhibits, which contain the network topology and BGP configuration for a hub. An administrator is trying to configure ADVPN with a hub-spoke VPN setup using iBGP. All the VPNs are up and connected to the hub. The hub is receiving route information from both spokes over iBGP: however, the spokes are not receiving route information from each other. What change must the administrator make to the hub BGP configuration so that the routes learned by one spoke are forwarded to the other spokes?. Configure an individual neighbor and remove neighbor-range configuration. Configure the hub as a route reflector client. Make the configuration of remote-as different from the configuration of local-as. Change the router id to 10.1.0.254. Which two statements about automation stitches are true? (Choose two.). An automation stitch consists of two parts, the troper and the actions. Automation stitches can be used only on FortiGate devices that are part of Security Fabric. Automation stitches can be created to send an email message when CPU or memory usage exceeds specified thresholds. Preconfigured automation stitches can be downloaded from FortiGuard servers. Which statement about NGFW policy-based application filtering is true?. The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT. After the application has been identified, the kernel uses only the Layer 4 header to match the traffic. FortiGate will drop all packets until the application can be identified. After IPS identifies the application, it adds an entry to a dynamic ISDB table. Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?. Only the DR receives link state information from non-DR routers. Non-DR and non-BDR routers will full adjacencies to DR and BDR only. FortiGate first checks the OSPF ID to elect a DR. BDR is responsible for forwarding link state information from one router to another. Refer to the exhibit, which contains partial output from an IKE real-time dobug. Tho administrator does not have access to the romoto gatoway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?. Change phase1 encryption to AESCBC and authentication to SHA2. Change phase1 encryption to 3DES and authentication to SHA128. Change phase1 encryption to AES256 and authentication to SHA256. Change phase1 encryption to AES128 and authentication to SHA512. Which ADVPN configuration must be configured using a script on FortiManager, when using VPN Manager to manage FortiGate VPN tunnels?. Enable AD-VPN in IPsec phase1. Configure IP addresses on IPsec virtual interfaces. Disable add-route on hub. Set protected network to all. Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate. An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovered that FortiGate is not matching the user-2 VPN for members of the Users-2 group. Which two changes must the administrator make to fix the issue? (Choose two.). Enable XAuth on both VPNs. Change to aggressive mode on both VPNs. Set up specific peer IDs on both VPNs. Use different pre-shared keys on both VPNs. Refer to the exhibit, which contains partial output from an IKE real-time debug. Why did the tunnel not come up?. The proposal ID does not match between local and remote gateways. The encapsulation method for phase2 is set to none on local and remote gateways. The Diffie-Hellman group does not match on the local and remote gateways. The local gateway has configured less secure encryption and hashing algorithms compared to the remote gateway. Refer to the exhibit, which shows the output of a web filtering diagnose command. Which configuration change would result in non-zero results in the cache statistics section?. set server-type rating under config system central-management. set webfilter-force-off disable under contig system fortiguard. set ngtw-mode policy-based under contig system settings. set webfilter-cache enable under config system fortiguard. Refer to the exhibit, which shows a FortiGate configuration. An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy, however, the web filter is not inspecting any traffic that is passing through the policy. What must the administrator do to fix the issue?. Enable fortiguard-anycast. Change protocol to TCP. Increase webfilter-timeout. Disable webfilter-force-off. Refer to the exhibit, which shows the output of a BGP debug command. What can be concluded about the router in this scenario?. The State/PEXRCd for neighbor 100.64.3.1 will not change until an administrator on the local router adjusts the inbound route filtering so that prefixes received can be added to the RIB. The BGP session with peer 10.127.0.75 is up. The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the BGP session with the local router. All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4. Refer to the exhibit, which contains a screenshot of some phase 1 settings. The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands to an SSH session on FortiGate: diagnose vpn ike log-filter dst-addr4 10.0.10.1 diagnose debug application ike -1 However, the IKE real-time debug does not show any output. Why?. The administrator must also run the command diagnose debug enable. The debug shows only error messages. If there is no output, then the phase 1 and phase 2 configurations match. The log-filter setting is incorrect. The VPN traffic does not match this filter. The administrator must enable the following real-time debug: diagnose debug application ipsec -1. How are bulk configuration changes made using FortiManager CLI scripts? (Choose two.). When run on the Device Database, changes are applied directly to the managed FortiGate device. When run on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation. When run on the Policy Package, ADOM database, you must use the installation wizard to apply the changes to the managed FortiGate device. When run on the All FortiGate in ADOM, changes are automatically installed without the creation of a new revision history. Refer to the exhibits, which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network. If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?. The session would be deleted, and the client would need to start a new session. The session would remain in the session table, and its traffic would egress from port1. The session would remain in the session table, but its traffic would now egress from both port1 and port2. The session would remain in the session table, and its traffic would egress from port2. Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.). OSPF link costs match. OSPF interface priority settings are unique. OSPF interface network types match. OSPF router IDs are unique. Authentication settings match. Which two statements about the Security Fabric are true? (Choose two.). Only the root FortiGate sends logs to FortiAnalyzer. Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer. Only FortiGate devices with fabric-object-unification set to default will receive and synchronize global CMDB objects sent by the root FortiGate. FortiGate uses FortiTelemetry protocol to communicate with FortiAnalyzer. Which two statements about application-layer test commands are true? (Choose two.). Some of them only display output, after you run the diagnose debug console enable command. Some of them can be used to restart an application. Some of them display real-time application debugs. Some of them display statistics and configuration information about a feature or process. Which two tasks are automated using the Import Configuration wizard on FortiManager? (Choose two.). Importing firewall address objects from managed devices. Importing interface mappings from managed devices. Importing static and dynamic route configurations from managed devices. Importing devices to FortiManager. Refer to the exhibit, which contains a TCL script configuration on FortiManager. An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any changes to the managed device after being run. Why did the TCL script fail to make any changes to the managed device?. The TCL script must start with #include <>. The TCL procedure run_cmd has not been created. There is no corresponding #! to signify the end of the script. The TCL procedure lacks the required loop statements to iterate through the changes. Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.). IPS failopen. mem failopen. AV failopen. UTM failopen. What is the diagnose test application ipsmonitor 99 command used for?. To enable IPS bypass mode. To provide information regarding IPS sessions. To disable the IPS engine. To restart all IPS engines and monitors. What is the diagnose test application ipsmonitor 5 used for?. To enable IPS bypass mode. To restart all IPS engines and monitors. To provide information regarding IPS sessions. To disable the IPS engine. Refer to the exhibit, which shows a session table entry. Which statement about FortiGate behavior relating to this session is true?. FortiGate is performing security profile inspection using the CPU. FortiGate applied only IPS inspection to this session. FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made. FortiGate forwarded this session without any inspection. Refer to the exhibit, which shows the output of a diagnose command. What can be concluded about the debug output in this scenario?. There is a natural correlation between the value in the Packets field and the value in the weight field. The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179. FortiGate used 64.26.151.37 as the initial server to validate its contract. Servers with a negative TZ value are less preferred for rating requests. Refer to the exhibit, which shows the output of diagnose sys session list. If the HA ID for the primary device is o, what will happen if the primary fails and the secondary becomes the primary?. The secondary device has this session synchronized; however, because application control is applied, the session will be marked dirty and have to be re-evaluated after fallover. The session will be removed from the session table of the secondary device due to the presence of allowed error packets, which will force the client to restart the session with the server. The session state will be preserved but the kernel will need to re-evaluate the session due to NAT being applied. Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server. Refer to the exhibit, which shows partial outputs from two routing debug commands. Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?. Set the priority of the static default route using port1 to 10. Set snat-route-change to enable. Set the priority of the static default route using port2 to 1. Set preserve-session-route to enable. Refer to the exhibit, which contains partial output from an IKE real-time debug. Which two statements about this debug output are correct? (Choose two.). The initiator provided remote as its IPsec peer ID. The local gateway IP address is 10.0.0.1. Perfect Forward Secrecy (PFS) is enabled in the configuration. It shows a phase 2 negotiation. An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device. What can the administrator do to fix this problem?. Configure set link-failed-signal enable under config system ha on both cluster members. Verify that the speed and duplex settings match between the FortiGate interfaces and the connected switch ports. Configure remote link monitoring to detect an issue in the forwarding path. Configure set send-garp-on-failover enable under config system ha on both cluster members. Refer to the exhibit, which shows the output of a diagnose command. What can you conclude from the output shown in the exhibit? (Choose two.). This is an expected session created by the IPS engine. This is a pinhole session created to allow traffic for a protocol that requires additional sessions to operate through FortiGate. Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next-hop IP address 10.200.1.1. Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next-hop IP address 10.0.1.10. Refer to the exhibit, which shows the output Which two statements about the output are true? (Choose two.). Based on the network type of port4, OSPF hello packets will be sent to 224.0.0.5. Based on the network type of port4, OSPF hello packets will be sent to 224.0.0.6. There are a total of 5 OSPF routers attached to the Port4 network segment. In the network connected to port4, two OSPF routers are down. Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command. Based on the output, which two statements are correct? (Choose two.). The npu_flag for this tunnel is 02. Anti-replay is enabled. O Different SPI values are a result of auto-negotiation being disabled for phase 2 selectors. The npu_flag for this tunnel is 03. Refer to the exhibit, which contains partial output from an IKE real-time debug. Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?. auto-discovery-forwarder. auto-discovery-shortest. auto-discovery-receiver. auto-discovery-sender. Refer to the exhibits, which contains the output of a debug command. If the default settings are in place, what can be concluded about the conserve mode shown in the exhibit?. FortiGate is currently blocking new sessions that require flow-based or proxy-based content inspection. FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that required proxy inspection. FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings due to use. FortiGate is currently allowing new sessions that require flow-based or proxy-based content inspection but is not performing inspection those sessions. Refer to the exhibit, which shows a session entry. Which statement about this session is true?. It is an ICMP session from 10.1.10.10 to 10.200.1.1. Return traffic to the initiator is sent to 10.1.0.1. It is an ICMP session from 10.1.10.1 to 10.200.5.1. Return traffic to the initiator is sent to 10.200.1.254. Refer to the exhibit, which shows a partial web filter profile configuration. Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?. FortiGate will exempt the connection, based on the Web Content Filter configuration. FortiGate will allow the connection, based on the URL Filter configuration. FortiGate will block the connection, based on the FortiGuard category based filter configuration. FortiGate will block the connection as an invalid URL. Which two statements about conserve mode are true? (Choose two.). FortiGate enters conserve mode when the system memory reaches the configured extreme threshold. FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold. FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold. FortiGate exits conserve mode when the system memory goes below the configured green threshold. |