無料で使えるFCSS_EFW_AD-7.4試験ブレーン問題集認定ガイド問題と解答 [Q51-Q69]

Share

無料で使えるFCSS_EFW_AD-7.4試験ブレーン問題集認定ガイド問題と解答

FCSS_EFW_AD-7.4認定概要最新のFCSS_EFW_AD-7.4のPDF問題集

質問 # 51
What action does FortiSwitch take when it receives a loop guard data packet (LGDP) that was sent by itself?

  • A. The sending port is moved to the STP blocking state
  • B. The receiving port is shut down
  • C. The receiving port is moved to the STP blocking state
  • D. The sending port is shut down

正解:D


質問 # 52
When investigating FortiGuard connectivity issues, which action is a valid troubleshooting step?

  • A. Verify that DNS requests are being proxied, if auto-update tunneling is enabled.
  • B. Verify management VDOM internet access.
  • C. Use the FortiGuard real-time debug command to verify rating requests.
  • D. Configure a virtual IP to forward port 443 to the FortiGate external IP.

正解:B


質問 # 53
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.

An administrator would like to test session failover between the two service provider connections.
What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

  • A. Configure set snat-route-change enable.
  • B. Change the priority of the port2 static route to 5.
  • C. unset snat-route-change to return it to the default setting.
  • D. Change the priority of the port1 static route to 11.

正解:A、D


質問 # 54
View the following FortiGate configuration.

All traffic to the Internet currently egresses from port1.
The exhibit shows partial session information for Internet traffic from a user on the internal network:

If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user's session?

  • A. The session would be deleted, so the client would need to start a new session.
  • B. The session would remain the session table, but its traffic would now egress from both port 1and port2
  • C. The session would remain the session table, and its traffic would still egress from port 1.
  • D. The session would remain the session table, and its traffic would start to egress from port2.

正解:C


質問 # 55
View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.

The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel.
To diagnose, the administrator enters these CLI commands:

However, the IKE real time debug does not show any output.
Why?

  • A. The debug shows only error messages. If there is no output, then the tunnel is operating normally.
  • B. The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
  • C. The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.
  • D. The log-filter setting was set incorrectly. The VPN's traffic does not match this filter.

正解:D


質問 # 56
Which layer of the FortiOS architecture does an application process or daemon run on?

  • A. Configuration layer
  • B. Hardware
  • C. User space
  • D. Kernel

正解:C


質問 # 57
A FortiGate device has the following LDAP configuration:

The LDAP user student cannot authenticate.
The exhibit shows the output of the authentication real time debug while testing the student account:

Based on the above output, what FortiGate LDAP settings must the administer check? (Choose two.)

  • A. cnid.
  • B. password.
  • C. dn.
  • D. username.

正解:B、D


質問 # 58
Refer to the exhibit, which contains the output of the diagnose vpn tunnel list.


Which command will capture ESP traffic for the VPN named DialUp_0?

  • A. diagnose sniffer packet any 'esp and host 10.200.3.2'
  • B. diagnose sniffer packet any 'host 10.0.10.10'
  • C. diagnose sniffer packet any 'port 4500'
  • D. diagnose sniffer packet any 'ip proto 50'

正解:C


質問 # 59
Which troubleshooting step is applicable when investigating antivirus and IPS update issues on FortiGate?

  • A. Use the diagnose debug rating command to check active servers.
  • B. Use the alternate service port 8888.
  • C. Verify outbound ICMP connectivity.
  • D. Validate DNS resolution for update.fortiguard.net.

正解:D


質問 # 60
Examine the output of the 'get router info ospf neighbor' command shown in the exhibit; then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. The OSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the wan1 network.
  • B. The interface ToRemote is OSPF network type point-to-point.
  • C. The OSPF router with the ID 0.0.0.2 is the designated router for the ToRemote network.
  • D. The local FortiGate is the backup designated router for the wan1 network.

正解:B、D


質問 # 61
Refer to the exhibit, which contains the output of a debug command.

If the default settings are in place, what can be concluded about the conserve mode shown in the exhibit?

  • A. FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings due to high memory use.
  • B. FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection.
  • C. FortiGate is currently blocking new sessions that require flow-based or proxy-based content inspection.
  • D. FortiGate is currently allowing new sessions that require flow-based or proxy-based content inspection but is not performing inspection on those sessions.

正解:C


質問 # 62
Which of the following tasks are part of the manual registration process for adding a FortiGate to a FortiManager for central management? (Choose three.)

  • A. Import the policy package from the managed FortiGate.
  • B. In the FortiManager, add the unregistered FortiGate.
  • C. Start the rating services on FortiManager.
  • D. Wait for the rating databases to download on FortiManager.
  • E. Add the FortiManager IP address to the FortiGate's central management configuration.

正解:A、B、E


質問 # 63
Examine the following traffic log; then answer the question below.
date-20xx-02-01 time=19:52:01 devname=masterdevice_id="xxxxxxx" log_id=0100020007 type=event subtype=system pri critical vd=root service=kemel status=failure msg="NAT port is exhausted." What does the log mean?

  • A. The limit for the maximum number of simultaneous sessions sharing the same NAT port has been reached.
  • B. FortiGate does not have any available NAT port for a new connection.
  • C. The limit for the maximum number of entries in the NAT port table has been reached.
  • D. There is not enough available memory in the system to create a new entry in the NAT port table.

正解:A


質問 # 64
What does hyperscale capability in data center firewalls typically support?

  • A. Application layer operations such as intrusion prevention
  • B. Network speeds ranging from 10 Gbps to 1000 Gbps
  • C. Enhanced encryption and decryption processes only
  • D. Bundling of multiple physical interfaces for a single logical interface

正解:B


質問 # 65
An administrator has decreased all the TCP session timers to optimize the FortiGate memory usage.
However, after the changes, one network application started to have problems.
During the troubleshooting, the administrator noticed that the FortiGate deletes the sessions after the clients send the SYN packets, and before the arrival of the SYN/ACKs.
When the SYN/ACK packets arrive to the FortiGate, the unit has already deleted the respective sessions.
Which TCP session timer must be increased to fix this problem?

  • A. TCP time wait.
  • B. TCP half open.
  • C. TCP half close.
  • D. TCP session time to live.

正解:B


質問 # 66
Which three tasks are part of the manual registration process for adding a FortiGate device to FortiManager for central management? (Choose three.)

  • A. Add the FortiManager IP address to the FortiGate central management configuration.
  • B. Start the rating services on FortiManager.
  • C. In FortiManager, add the unregistered FortiGate device.
  • D. Wait for the rating databases to download on FortiManager.
  • E. Import the policy package from the managed FortiGate device.

正解:A、C、E


質問 # 67
Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network.
What HA setting must be changed in one of the HA clusters to fix the problem?

  • A. Group ID.
  • B. Gratuitous ARPs.
  • C. Session pickup.
  • D. Group name.

正解:A


質問 # 68
View the exhibit, which contains a session entry, and then answer the question below.

Which statement is correct regarding this session?

  • A. This session is offloaded to the NPU.
  • B. Further packets for this session will be blocked.
  • C. This traffic is using the VIP and central NAT tables.
  • D. This session was successfully authenticated.

正解:D


質問 # 69
......

ベストなFortinet FCSS_EFW_AD-7.4学習ガイドと問題集には2025:https://www.passtest.jp/Fortinet/FCSS_EFW_AD-7.4-shiken.html

トップクラスFortinet FCSS_EFW_AD-7.4試験材料で学習ガイド!練習問題バージョンで挑もう:https://drive.google.com/open?id=1wgwN4aITRTiHpZnDpDNux47boq7u6kWB