Fortinet FCSS_NST_SE-7.4 Exam Practice Questions (P. 2)
- Full Access (66 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Refer to the exhibit, which shows one way communication of the downstream FortiGate with the upstream FortiGate within a Security Fabric.

What three actions must you take to ensure successful communication? (Choose three.)

What three actions must you take to ensure successful communication? (Choose three.)
- AYou must authorize the downstream FortiGate on the root FortiGate.
- BFortiGate must not be in NAT mode.
- CEnsure TCP port 8013 is not blocked along the way.
- DYou must enable Security Fabric/Fortitelemetry on the receiving interface of the upstream FortiGate.
- EEnsure the port for Neighbor Discovery has been changed.
send
light_mode
delete
Question #7
Refer to the exhibit, which shows the partial output of FortiOS kernel slabs.

Which statement is true?

Which statement is true?
- AThe total slab size of the sctp_session slab is 0 kB and is associated with the user space.
- BThe total slab size of the ip_session slab is 3600 kB and is associated with the user space.
- CThe total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.
- DThe total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.
send
light_mode
delete
Question #8
Refer to the exhibit, which a network topology and a partial routing table.

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.
Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.
Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?
- AEnable asymmetric routing under config system settings.
- BChange the configuration from strict RPF check mode to feasible RPF check mode.
- CA firewall policy that allows all ICMP traffic from port3 to port1.
- DModify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
send
light_mode
delete
Question #9
What are two functions of automation stitches? (Choose two.)
- AYou can configure automation stitches on any FortiGate device in a Security Fabric environment.
- BYou can configure automation stitches to execute actions sequentially by taking parameters from previous actions as input for the current action.
- CYou can set an automation stitch configured to execute actions in parallel to insert a specific delay between actions.
- DYou can create automation stitches to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds.
send
light_mode
delete
Question #10
Refer to the exhibit, which contains the partial configuration of an IPsec VPN configuration.

After reviewing the configuration, what can you conclude about the IPsec VPN Phase 1 setup?

After reviewing the configuration, what can you conclude about the IPsec VPN Phase 1 setup?
- AThe VPN is configured using IKEv2.
- BDead Peer Detection is disabled.
- CThe VPN is configured with DHCP over IPsec.
- DThe tunnel is configured as a route-based VPN.
send
light_mode
delete
All Pages