FCSS_EFW_AD-7.4リアルな試験問題FCSS_EFW_AD-7.4練習問題集 [Q112-Q131]

Share

FCSS_EFW_AD-7.4リアルな試験問題FCSS_EFW_AD-7.4練習問題集

厳密検証されたFCSS_EFW_AD-7.4試験問題集と解答で無料提供のFCSS_EFW_AD-7.4問題と正解付き

質問 # 112
Which layer of the FortiOS architecture does an application process or daemon run on?

  • A. Configuration layer
  • B. User space
  • C. Hardware
  • D. Kernel

正解:B


質問 # 113
Which three conditions are required for two FortiGate devices to form an OSP adjacency? (Choose three.)

  • A. OSPF IP MTUs match
  • B. OSPF peer IDs match
  • C. IP addresses are in the same subnet
  • D. OSPF costs match
  • E. Hello and dead intervals match

正解:A、C、E


質問 # 114
Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network.
What HA setting must be changed in one of the HA clusters to fix the problem?

  • A. Session pickup.
  • B. Group ID.
  • C. Gratuitous ARPs.
  • D. Group name.

正解:B


質問 # 115
An administrator wants to capture encrypted phase 2 traffic between two FortiGate devices using the built-in sniffer.
If the administrator knows that there is no NAT device located between both FortiGate devices, which command should the administrator run?

  • A. diagnose sniffer packet any 'ip proto 50'
  • B. diagnose sniffer packet any 'udp port 500'
  • C. diagnose sniffer packet any 'udp port 4500'
  • D. diagnose sniffer packet any 'ah'

正解:A


質問 # 116
Which setting must be enabled in an in a spoke IPsec phase 1 configuration, to indicate that it wants to participate in ADVPN?

  • A. auto-discovery-ipsec
  • B. auto-discovery-receiver
  • C. auto-discovery-forwarder
  • D. auto-discovery-sender

正解:B


質問 # 117
Refer to the exhibits, which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network.

If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?

  • A. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
  • B. The session would remain in the session table, and its traffic would egress from port1.
  • C. The session would be deleted, and the client would need to start a new session.
  • D. The session would remain in the session table, and its traffic would egress from port2.

正解:B


質問 # 118
What does hyperscale capability in data center firewalls typically support?

  • A. Application layer operations such as intrusion prevention
  • B. Enhanced encryption and decryption processes only
  • C. Network speeds ranging from 10 Gbps to 1000 Gbps
  • D. Bundling of multiple physical interfaces for a single logical interface

正解:C


質問 # 119
What are valid options for handling DNS requests sent directly to a FortiGates interface IP? (Choose three.)

  • A. Recursive.
  • B. Conditional-forward.
  • C. Iterative.
  • D. Non-recursive.
  • E. Forward-only.

正解:A、D、E


質問 # 120
When investigating FortiGuard connectivity issues, which of the following is a valid troubleshooting step?

  • A. Verify DNS requests are being proxied if auto-update tunneling is enabled.
  • B. Verify management VDOM's internet access.
  • C. Configure a virtual IP to forward port 443 to FortiGate's external IP.
  • D. Use the FortiGuard real-time debug command to verify rating requests.

正解:B


質問 # 121
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.


Which statements about this debug output are correct? (Choose two.)

  • A. The initiator has provided remote as its IPsec peer ID.
  • B. The remote gateway IP address is 10.0.0.1.
  • C. It shows a phase 1 negotiation.
  • D. The negotiation is using AES128 encryption with CBC hash.

正解:A、C


質問 # 122
Refer to the exhibit, which shows the device and policy layers for FortiGate key operations.

How can the administrator restore a previous FortiGate configuration, which had more policies than the current one, without the layer synchronization between the device and policy layers on FortiManager?

  • A. Find the configuration file by date and time in the provisioning templates, then reinstall the policy package to apply the configuration changes.
  • B. Use the global ADOM to access the previous configurations and install policies on ADOM devices to synchronize all layers.
  • C. Retrieve the configuration, import system templates, and reinstall the policy package on FortiGate.
  • D. Locate the configuration ID in the FortiGate revision history, click revert, install the device settings, and import policies to sync the policy package.

正解:D


質問 # 123
View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.

The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel.
To diagnose, the administrator enters these CLI commands:

However, the IKE real time debug does not show any output.
Why?

  • A. The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.
  • B. The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
  • C. The debug shows only error messages. If there is no output, then the tunnel is operating normally.
  • D. The log-filter setting was set incorrectly. The VPN's traffic does not match this filter.

正解:D


質問 # 124
Which statement about NGFW policy-based application filtering is true?

  • A. The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT.
  • B. After the application has been identified, the kernel uses only the Layer 4 header to match the traffic.
  • C. FortiGate will drop all packets until the application can be identified.
  • D. After IPS identifies the application, it adds an entry to a dynamic ISDB table.

正解:C


質問 # 125
An administrator wants to simplify a new hub-and-spoke network deployment with the BGP recommended configuration.
Which two sections on FortiManager must the administrator use? (Choose two.)

  • A. Provisioning Templates
  • B. Metadata Variables
  • C. Meta Fields
  • D. Automation Stitch

正解:A、B


質問 # 126
One firewall policy in an enterprise firewall is essentially used for IPS.
Which configuration must the administrator check in this firewall policy to validate optimum performance for IPS?

  • A. set offload enable
  • B. set cp-accel-mode enable
  • C. set np-acceleration enable
  • D. set inspection-mode proxy

正解:C


質問 # 127
What does the dirty flag mean in a FortiGate session?

  • A. The next packet must be re-evaluated against the firewall policies.
  • B. Traffic has been blocked by the antivirus inspection.
  • C. Traffic has been identified as from an application that is not allowed.
  • D. The session must be removed from the former primary unit after an HA failover.

正解:A


質問 # 128
What are two functions of automation stitches? (Choose two.)

  • A. Automation stitches can be configured on any FortiGate device in a Security Fabric environment.
  • B. An automation stitch configured to execute actions in parallel can be set to insert a specific delay between actions.
  • C. Automation stitches can be created to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds.
  • D. An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action.

正解:C、D


質問 # 129
An LDAP user cannot authenticate against a FortiGate device.
Examine the real time debug output shown in the exhibit when the user attempted the authentication; then answer the question below.


Based on the output in the exhibit, what can cause this authentication problem?

  • A. User student is not found in the LDAP server.
  • B. User student is using a wrong password.
  • C. The FortiGate has been configured with the wrong password for the LDAP administrator.
  • D. The FortiGate has been configured with the wrong authentication schema.

正解:A


質問 # 130
View the exhibit, which contains the output of get sys ha status, and then answer the question below.


Which statements are correct regarding the output? (Choose two.)

  • A. port 7 is used the HA heartbeat on all devices in the cluster.
  • B. The slave configuration is not synchronized with the master.
  • C. The HA management IP is 169.254.0.2.
  • D. Master is selected because it is the only device in the cluster.

正解:A、B


質問 # 131
......

無料でゲット!高評価Fortinet FCSS_EFW_AD-7.4試験問題集を今すぐダウンロード!:https://www.passtest.jp/Fortinet/FCSS_EFW_AD-7.4-shiken.html

あなたを合格させるFCSS_EFW_AD-7.4無料最新問題集でFortinet練習テストしよう:https://drive.google.com/open?id=1rK9QeZi6szWjSZT4yHYrwcrOBqHHyjEv