Fortinet FCSS_NST_SE-7.6認証された練習解答、必ずあなたを試験合格させる![2026]
有効な合格方法Fortinet Certified Solution SpecialistのFCSS_NST_SE-7.6試験問題集
Fortinet FCSS_NST_SE-7.6 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
質問 # 18
Which exchange lakes care of DoS protection in IKEv2?
- A. IKE_Auth
- B. Create_CHILD_SA
- C. IKE_SA_NIT
- D. IKE_Req_INIT
正解:D
質問 # 19
Exhibit.
Refer to the exhibit, which contains a screenshot of some phase 1 settings.
The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands on an SSH session on FortiGate:
However, the IKE real-time debug does not show any output. Why?
- A. The administrator must also run the command diagnose debug enable.
- B. The log-filter setting is incorrect. The VPN traffic does not match this filter.
- C. The debug shows only error messages. If there is no output, then the phase 1 and phase 2 configurations match.
- D. Replace diagnose debug application ike -1 with diagnose debug application ipsec -1.
正解:A
質問 # 20
In the SAML negotiation process, which section does the Identity Provider (IdP) provide the SAML attributes utilized in the authentication process to the Service Provider (SP)?
- A. SP Login dump
- B. Assertion dump
- C. Authentication Request
- D. Authentication Response
正解:B
質問 # 21
Refer to the exhibit.
An IPsec VPN tunnel is dropping, as shown by the debug output.
Analyzing the debug output, what could be causing the tunnel to go down?
- A. The tunnel drops during rekey negotiation.
- B. Dead Peer Detection is not receiving its acknowledge packet.
- C. The tunnel drops after the timer expires.
- D. Phase 2 drops but Phase 1 is up.
正解:B
質問 # 22
Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
- A. FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.
- B. The name of the configured LDAP server is Lab.
- C. The user is authenticating using CN=John Smith.
- D. FortiOS is performing the second step (Search Request) in the LDAP authentication process.
正解:C、D
質問 # 23
Refer to the exhibit, which shows the output of get router info ospf neighbor.
What can you conclude from the command output?
- A. The local FortiGate is the BDR.
- B. The local FortiGate is not a DROther.
- C. All neighbors are in area 0.0.0.0.
- D. The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.
正解:D
質問 # 24
Refer to the exhibit, which shows the output of a debug command.
Which two statements about the output are true? (Choose two.)
- A. In the network connected to port4, two OSPF routers are down.
- B. The interlace is part of the OSPF backbone area.
- C. There are a total of five OSPF routers attached to the vorz4 network segment
- D. One of the neighbors has a router ID of 0.0.0.4.
正解:A、B
質問 # 25
The local OSPF router is unable to establish adjacency with a peer.
Which two things should the administrator do to troubleshoot the issue? (Choose two.)
- A. Check whether both peers have an IP address within the same subnet.
- B. Check if IP protocol 89 is blocked.
- C. Check if there is an active static route to the peer.
- D. Check whether TCP port 179 is blocked.
正解:A、B
質問 # 26
Exhibit.
Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.
What three conclusions can you draw from these log entries? {Choose three.)
- A. Remote registry is not running on the workstation.
- B. DNS resolution is unable to resolve the workstation name.
- C. The user's status shows as "not verified" in the collector agent.
- D. The FortiGate firmware version is not compatible with that of the collector agent.
- E. A firewall is blocking traffic to port 139 and 445.
正解:A、C、E
質問 # 27
Which two statements about conserve mode are true? (Choose two.)
- A. FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.
- B. FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.
- C. FortiGate exits conserve mode when the system memory goes below the configured green threshold.
- D. FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.
正解:A、C
質問 # 28
Exhibit.
Refer to the exhibit, which shows a partial output of diagnose hardware aysinfo memory.
Which two statements about the output are true? (Choose two.)
- A. The I/O cache, which has 641364 kB of memory allocated to it.
- B. The user space has 708880 kB of physical memory that is not used by the system.
- C. There are 98908 kB o! memory that will never be used.
- D. The value indicated next to the inactive heading represents the currently unused cache page.
正解:C、D
質問 # 29
Refer to the exhibit, which a network topology and a partial routing table.
FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.
Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?
- A. Modify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
- B. A firewall policy that allows all ICMP traffic from port3 to port1.
- C. Enable asymmetric routing under config system settings.
- D. Change the configuration from strict RPF check mode to feasible RPF check mode.
正解:C
質問 # 30
Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real- time debug? (Choose three.)
- A. Inability to reach IP address of the collector agent.
- B. Refused connection. Potential mismatch of TCP port.
- C. Log is full on the collector agent.
- D. Mismatched pre-shared password.
- E. Incompatible collector agent software version.
正解:A、B、D
質問 # 31
Refer to the exhibit, which shows a partial output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
- A. The user was found in the LDAP tree, whose root is TAC.ottawa.fortinet.com.
- B. FortiOS performs a bind to the LDAP server using the user's credentials.
- C. FortiOS collects the user group information.
- D. FortiOS is performing the second step (Search Request) in the LDAP authentication process.
正解:A、D
質問 # 32
Refer to the exhibit, which shows the partial output of FortiOS kernel slabs.
Which statement is true?
- A. The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.
- B. The total slab size of the ip_session slab is 3600 kB and is associated with the user space.
- C. The total slab size of the sctp_session slab is 0 kB and is associated with the user space.
- D. The total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.
正解:D
質問 # 33
Refer to the exhibit.
The exhibit shows the output from using the command diagnose debug application samld -1 to diagnose a SAML connection.
Based on this output, what can you conclude?
- A. The IdP IP address is 10.1.10.254.
- B. Active Directory is used for authentication.
- C. The authentication request is for an SSL VPN connection.
- D. The IdP IP address is 10.1.10.2.
正解:D
質問 # 34
Refer to the exhibit, which shows the output o! the BGP database.
Which two statements are correct? (Choose two.)
- A. The advertised prefix of 10.20.30.0'24 is being advertised through the redistribution of another routing protocol.
- B. The output shows all prefixes advertised by all neighbors as well as the local router.
- C. The advertised prefix of 10.20.30.0'24 was configured using the network command.
- D. The first four prefixes are being advertised using a legacy route advertisement.
正解:B、C
質問 # 35
Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate.
An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovers that FortiGate is not matching the user-2 VPN for members of the Users-2 group.
Which two changes must the administrator make to fix the issue? (Choose two.)
- A. Set up specific peer IDs on both VPNs.
- B. Enable XAuth on both VPNs.
- C. Use different pre-shared keys on both VPNs.
- D. Change to aggressive mode on both VPNs.
正解:A、D
質問 # 36
Exhibit.
Refer to the exhibit, which contains partial output from an IKE real-time debug.
Which two statements about this debug output are correct? (Choose two.)
- A. It shows a phase 2 negotiation.
- B. Perfect Forward Secrecy (PFS) is enabled in the configuration.
- C. The initiator provided remote as its IPsec peer ID.
- D. The local gateway IP address is 10.0.0.1.
正解:A、C
質問 # 37
Refer to the exhibit showing a debug output.
An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is deployed is successful.
The administrator then produces the debug output shown in the exhibit.
What could be causing this error message?
- A. The collector agent preshared password is mismatched.
- B. The FortiGate and the collector agent are using different TCP ports.
- C. The TCP port 445 is blocked between FortiGate and collector agent.
- D. The FortiGate cannot resolve the active directory server name.
正解:B
質問 # 38
Refer to the exhibit, which shows a partial web filter profile configuration.
The URL www.dropbox.com is categorized as File Sharing and Storage.
Which action does FortiGate take if a user attempts to access www.dropbox.com?
- A. Based on the URL Filter configuration, FortiGate allows the connection.
- B. FortiGate blocks the connection as an invalid URL.
- C. FortiGate blocks the connection, based on the FortiGuard category-based filter configuration.
- D. Based on the Web Content filter configuration, access to www.dropbox.com would be exempted.
正解:A
質問 # 39
Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.
What happens to the session information if a routing change occurs that affects this session?
- A. The session information will not change unless the current route has been removed from the routing table.
- B. Sessions involving port7 or port19 will not have their routing information flushed.
- C. The session will be flagged as dirty but no route lookups will be performed.
- D. Only the interface and gateway information for dev=7 will be removed.
正解:A
質問 # 40
Refer to the exhibit, which shows the partial output of a diagnose command.
Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)
- A. The session is checked against firewall policy ID 25.
- B. FortiGate will drop the expected traffic if it does not arrive within 23 seconds.
- C. This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.
- D. Clearing the master session has no impact on the expectation session.
正解:B、C
質問 # 41
Refer to the exhibit, which shows the partial output of command diagnose debug rating.
In this exhibit, which FDS server will the FortiGate algorithm choose?
- A. 208.91.112.194
- B. 209.22.147.36
- C. 64.26.151.37
- D. 66.117.56.37
正解:C
質問 # 42
......
Fortinet FCSS_NST_SE-7.6事前試験練習テストはPassTest:https://www.passtest.jp/Fortinet/FCSS_NST_SE-7.6-shiken.html
FCSS_NST_SE-7.6練習テスト問題、解答、解釈:https://drive.google.com/open?id=1Mv-0bWfMCwgAwBfGWCLBxyokuICHstf7