FCSS_NST_SE-7.4認定ガイドPDFは100%カバー率でリアル試験問題が使える
合格させるFCSS_NST_SE-7.4試験にはリアル問題解答
Fortinet FCSS_NST_SE-7.4 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
質問 # 12
In IKEv2, which exchange establishes the first CHILD_SA?
- A. IKE_Auth
- B. CREATE_CHILD_SA
- C. IKE_SA_INIT
- D. INFORMATIONAL
正解:B
質問 # 13
Exhibit.
Refer to the exhibit, which shows the output of a session. Which two statements are true? (Choose Iwo.)
- A. The session was initiated from an authenticated user.
- B. The session is being inspected using flow inspection.
- C. The TCP session has been successfully established.
- D. The session is being offloaded.
正解:A、C
質問 # 14
Which authentication option can you not configure under config user radius on FortiOS?
- A. mschap2
- B. mschap
- C. pap
- D. eap
正解:D
質問 # 15
Exhibit.
Refer to the exhibit, which shows the output of diagnose automation test.
What can you observe from the output? (Choose two.)
- A. The test was unsuccessful.
- B. An HA failover occurred.
- C. The automation stitch test failed but the HA failover was successful.
- D. The automation stitch test is not being logged.
正解:A、D
質問 # 16
Which statement about parallel path processing is correct (PPP)?
- A. Only FortiGate hardware configurations affect the path that a packet takes.
- B. PPP chooses froma group of parallel options lo identity the optimal path tor processing a packet.
- C. Software configuration has no impact on PPP.
- D. PPP does not apply to packets that are part of an already established session.
正解:B
質問 # 17
Refer to the exhibit, which contains the output ofdiagnose vpn tunnellist.
Which command will capture ESP traffic for the VPN named DialUp_0?
- A. diagnose sniffer packet any 'port 4500'
- B. diagnose sniffer packet any 'host 10.0.10.10'
- C. diagnose sniffer packet any 'esp and host 10.200.3.2'
- D. diagnose sniffer packet any 'ip proto 50'
正解:A
質問 # 18
Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
- A. The user is authenticating using CN=John Smith.
- B. The name of the configured LDAP server is Lab.
- C. FortiOS is performing the second step (Search Request) in the LDAP authentication process.
- D. FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.
正解:A、C
質問 # 19
Which two statements about an auxiliary session ate true? (Choose two.)
- A. With the auxiliary session setting enabled. Iwo sessions are created in case of routing change.
- B. With the auxiliary session selling disabled, only auxiliary sessions are offloaded.
- C. With the auxiliary session setting enabled. ECMP traffic is accelerated to the NP6 processor.
- D. With the auxiliary session setting disabled, for each traffic path. FortiGate uses the same auxiliary session.
正解:A、C
質問 # 20
Which two statements about Security Fabric communications are true? (Choose two.)
- A. The default port for Neighbor Discovery can be modified.
- B. FortiTelemetry must be manually enabled on the FortiGate interface.
- C. By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.
- D. FortiTelemetry and Neighbor Discovery both operate using TCP.
正解:B、C
質問 # 21
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.
What two conclusions can you draw Itom the output? (Choose two.)
- A. FSSO is using agentless polling mode to detect logon events.
- B. FSSO is using DC agent mode to detect logon events.
- C. The logon event can be seen on the collector agent installed on Windows.
- D. The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.
正解:A、D
質問 # 22
Exhibit.
Refer to theexhibit,which shows the output of getsystem ha status.
NGFW-1 and NGFW-2 have been up for a week.
Which two statements about the output are true? (Choose two.)
- A. If port 7 becomes disconnected on the secondary, both FortiGate devices will elect itself as primary.
- B. If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.
- C. If no action is taken, the primary FortiGate will leave the cluster because of the current sync status.
- D. If FGVM...649 is rebooted. FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.
正解:A、D
質問 # 23
Exhibit.
Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator do to fix the issue?
- A. Disable webfilter-force-off.
- B. Increase webfilter-timeout.
- C. Enable fortiguard-anycast.
- D. Change protocol to TCP.
正解:A
質問 # 24
Refer to the exhibit, which shows the output ofa debug command.
Which two statements about the output are true? (Choose two.)
- A. In the network connected to port4, two OSPF routers are down.
- B. One of the neighbors has a router ID of 0.0.0.4.
- C. The interlace is part of the OSPF backbone area.
- D. There are a total of five OSPF routers attached to the vorz4 network segment
正解:A、C
質問 # 25
Refer to the exhibit, which shows a session entry.
Which statement about this session is true?
- A. It is an ICMP session from 10.1.10.10 to 10.200.1.1.
- B. Return traffic to the initiator is sent lo 10.200.1.254.
- C. Return traffic to the initiator is sent to 10.1.0.1.
- D. It is an ICMP session from 10.1.10.1 to 10.200.5.1.
正解:D
質問 # 26
Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.
Which action will FortiGate take when using the default settings for SSL certificate inspection?
- A. FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
- B. FortiGate uses the first entry listed in the SAN field in the server certificate.
- C. FortiGate uses the SNI from the user's web browser.
- D. FortiGate uses the ZN information from the Subject field in the server certificate.
正解:B
質問 # 27
Exhibit 1.
Exhibit 2.
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.
An administrator would like to lest session failover between the two service provider connections.
Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)
- A. Change the priority of the port! static route to 11.
- B. Configure unsetsnat-route-change to return it to the default setting.
- C. Configure setsnat-route-change enable.
- D. Change the priority of the port2 static route to 5.
正解:A、C
質問 # 28
......
100%無料FCSS_NST_SE-7.4日常練習試験には42問があります:https://www.passtest.jp/Fortinet/FCSS_NST_SE-7.4-shiken.html
合格させるFCSS_NST_SE-7.4レビューガイド、信頼され続けるFCSS_NST_SE-7.4テストエンジン:https://drive.google.com/open?id=12R9qugzLOdmEE3buS0F_YpD72kpa2rJ6