wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Preguntas NS7 - Test No. 2

Total questions: 17

Worksheet time: 26mins

Name
Class
Date
1.

Refer to the exhibit, which contains the output of a BGP debug command. Which statement about the exhibit is true?

a)

The local router has received a total of three BGP prefixes from all peers.

b)

The local router has not established a TCP session with 100.64.3.1.

c)

Since the counters were last reset, the 10.200.3.1 peer has never been down.

d)

The local router BGP state is OpenConfirm with the 10.127.0.75 peer.

2.

Which action will FortiGate take when using the default settings for SSL certificate inspection, where the server name indication (SNI) does not match either the common name (CN) or any of the subject altemative names (SAN) in the server certificate?

a)

FortiGate uses the CN information from the Subject field in the server certificate.

b)

FortiGate uses the first entry listed in the SAN field in the server certificate.

c)

FortiGate uses the SNI from the user's web browser.

d)

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.

3.

Which two conditions must be met for a statistic route to be active in the routing table? (Choose two.)

a)

The link health monitor (if configured) is up.

b)

There is no other route, to the same destination, with a higher distance.

c)

The outgoing interface is up.

d)

The next-hop IP address is up.

4.

Refer to the exhibit, which contains the output of diagnose sys session list.

a)

This session cannot be synced with the slave unit.

b)

The inspection of this session has been offloaded to the slave unit.

c)

The master unit is processing this traffic.

d)

This session is for HA heartbeat traffic.

5.

What is the diagnose test application ipsmonitor 99 command used for?

a)

To enable IPS bypass mode

b)

To provide information regarding IPS sessions

c)

To disable the IPS engine

d)

To restart all IPS engines and monitors

6.

View the exhibit, which contains the output of a debug command, and then answer the question below. Which one of the following statements about this FortiGate is correct?

a)

It is currently in system conserve mode because of high CPU usage.

b)

It is currently in extreme conserve mode because of high memory usage.

c)

It is currently in proxy conserve mode because of high memory usage.

d)

It is currently in memory conserve mode because of high memory usage.

7.

Refer to the exhibit, which contains partial outputs from two routing debug commands. Why is the port2 default route not in the second command's output?

a)

It has a higher priority value than the default route using port1.

b)

It is disabled in the FortiGate configuration.

c)

It has a lower priority value than the default route using port1.

d)

It has a higher distance than the default route using port1.

8.

Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?

a)

In the phase 1 network configuration, set the IKE version to 2.

b)

In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.

c)

In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.

d)

In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.

9.

Refer to the exhibit, which shows the output of a web filtering diagnose command. Which configuration change would result in non-zero results in the cache statistics section?

a)

set server-type rating under config system central-management

b)

set webfilter-cache enable under config system fortiguard

c)

set webfilter-force-off disable under config system fortiguard

d)

set ngfw-mode policy-based under config system settings

10.

Refer to the exhibits, which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network. If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?

a)

The session would remain in the session table, but its traffic would now egress from both port1 and port2.

b)

The session would remain in the session table, and its traffic would egress from port2.

c)

The session would be deleted, and the client would need to start a new session.

d)

The session would remain in the session table, and its traffic would egress from port1.

11.

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network. An administrator would like to test session failover between the two service provider connections. What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

a)

Configure set snat-route-change enable.

b)

Change the priority of the port2 static route to 5.

c)

Change the priority of the port1 static route to 11.

d)

unset snat-route-change to return it to the default setting.

12.

What are two functions of automation stitches? (Choose two.)

a)

Automation stitches can be configured on any FortiGate device in a Security Fabric environment.

b)

An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action.

c)

Automation stitches can be created to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds.

d)

An automation stitch configured to execute actions in parallel can be set to insert a specific delay between actions.

13.

Refer to the exhibit, which contains a TCL script configuration on FortiManager. An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any changes to the managed device after being run. Why did the TCL script fail to make any changes to the managed device?

a)

The TCL command run_cmd has not been created.

b)

The TCL script must start with tinclude <>.

c)

Incomplete commands are ignored in TCL scripts.

d)

Changes to an interface configuration can be made only by a CLI script.

14.

Refer to the exhibit, which shows a session entry. Which statement about this session is true?

a)

It is an ICMP session from 10.1.10.10 to 10.200.5. 1.

b)

It is a TCP session in close_wait state, from 10. l. 10.10 to 10.200.1.1.

c)

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

d)

It is a TCP session in the established state, from 10.1.10.10 to 10.200.5.1.

15.

Exhibits: Refer to the exhibits, which contain the network topology and BGP configuration for a hub. An administrator is trying to configure ADVPN with a hub-spoke VPN setup using iBGP. All the VPNs are up and connected to the hub. The hub is receiving route information from both spokes over iBGP; however, the spokes are not receiving route information from each other. What change must the administrator make to the hub BGP configuration so that the routes learned by one spoke are forwarded to the other spokes?

a)

Configure an individual neighbor and remove neighbor-range configuration.

b)

Configure the hub as a route reflector client.

c)

Change the router id to 10.1.0.254.

d)

Make the configuration of remote-as different from the configuration of local-as.

16.

Refer to the exhibit, which shows a partial routing table. Assuming all the appropriate firewall policies are configured, which two pings will FortiGate route? (Choose two.)

a)

Source IP address: 10.1.0.10. Destination IP address: 10.64.1.52

b)

Source IPaddress: 10.72.3.52. Destination IP address: 10.1.0.254

c)

Source IPaddress: 10.10.4.24, Destination IPaddress: 10.72.3.20

d)

Source IPaddress: 10.73.9.10, Destination IPaddress: 10.72.3.15

17.

Refer to the exhibits. Which contain the partial configurations of two VPNs on FortiGate.

An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovered that FortiGate is not matching the user-2 VPN for members of the Users-2 group. Which two changes must administrator make to fix the issue? (Choose two.)

a)

Use different pre-shared keys on both VPNs

b)

Enable Mode Config on both VPNs.

c)

Set up specific peer IDs on both VPNs.

d)

Change to aggressive mode on both VPNs.