Font size
WorksheetsFCSS-NST_SE-7.6 Network Security Suport Enginer English
Total questions: 73
Worksheet time: 42mins
Consider a scenario where the server name indication (SNI) does not match the common name (CN) or any of the subject alternative names (SAN) in the server certificate. What action will FortiGate take when using the default settings for SSL certificate inspection?
FortiGate uses the SNI from the user's web browser.
FortiGate closes the connection because this is an invalid SSL/TLS configuration.
FortiGate uses the first entry listed in the SAN field of the server certificate.
FortiGate uses the CN information from the Subject field in the server certificate.
Refer to the exhibit, which contains partial output from an IKE real-time debug. Which two statements about this debug output are correct? (Choose two.)
Perfect Forward Secrecy (PFS) is enabled in the configuration.
The local gateway IP address is 10.0.0.1.
This indicates phase 2 negotiation.
The initiator provides remote as its IPsec peer ID.
Refer to the exhibit, which shows the output of a diagnose command. What can you conclude about the debug output in this scenario?
The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.
There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.
FortiGate used 64.26.151.37 as the initial server to validate its contract.
Servers with negative TZ values are less preferred for rating requests.
What type of policy route is indicated by the output?
An ISDB route
A Regular policy route
A Regular policy route, associated with an active static route in the FIB
An SD-WAN rule
Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator do to fix the issue?
Disable webfilter-force-off.
Increase webfilter-timeout.
Enable fortiguard-anycast.
Change protocol to TCP.
Which statement about IKEv2 is true?
Both IKEv1 and IKEv2 share the feature of asymmetric authentication.
IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.
IKEv1 and IKEv2 use same TCP port but run on different UDP ports.
IKEv1 and IKEv2 share the concept of phase1 and phase2.
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.
An administrator would like to lest session failover between the two service provider connections.
Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)
Change the priority of the port1 static route to 11.
Change the priority of the port2 static route to 5.
Configure unset snat-route-change to return it to the default setting.
Configure set snat-route-change enable.
Refer to the exhibit, which shows the output of a debug command.
Which two statements about the output are true? (Choose two.)
The interlace is part of the OSPF backbone area.
There are a total of five OSPF routers attached to the port4 network segment.
One of the neighbors has a router ID of 0.0.0.4.
In the network connected to port4, two OSPF routers are down.
Which three pieces of information does the diagnose sys top command provide? (Choose three.)
The miglogd daemon is running on CPU core ID 0.
The diagnose sys top command has been running for 18 minutes.
The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.
The cmdbsvr process is occupying 2.4% of the total user memory space.
If the newcli daemon continues to be in the R state, it will need to be manually restarted.
Refer to the exhibit, which shows the output o! the BGP database.
Which two statements are correct? (Choose two.)
The advertised prefix of 10.20.30.0'24 was configured using the network command.
The first four prefixes are being advertised using a legacy route advertisement.
The advertised prefix of 10.20.30.0'24 is being advertised through the redistribution of another routing protocol.
The output shows all prefixes advertised by all neighbors as well as the local router.
In which two slates is a given session categorized as ephemeral? (Choose two.)
A UDP session with only one packet received
A UDP session with packets sent and received
A TCP session waiting for the SYN ACK
A TCP session waiting for FIN ACK
Refer to the exhibit, which shows the output of get router info bgp summary.
Which two statements are true? (Choose two.)
The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.
The TCP connection with BGP neighbor 100.64.2.254 was successful.
The local FortiGate has received 18 packets from a BGP neighbor.
The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264
Which exchange lakes care of DoS protection in IKEv2?
Create_CHILD_SA
IKE_Auth
IKE_Req_INIT
IKE_SA_NIT
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.
What two conclusions can you draw Itom the output? (Choose two.)
The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.
The logon event can be seen on the collector agent installed on Windows.
FSSO uses DC agent mode to detect logon events.
FSSO uses agentless polling mode to detect logon events.
An administrator wants to capture encrypted phase 2 traffic between two FortiGate devices using the built-in sniffer.
If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?
diagnose sniffer packet any 'udp port 500'
diagnose sniffer packet any 'ip proto 50'
diagnose sniffer packet any 'udp port 4500'
diagnose sniffer packet any 'ah'
An administrator Is expecting to receive advertised route 8.8.8.8/32 from FGT-A. On FGT-B, they confirm that the route is being advertised and received, however, the route is not being injected into the routing table.
What is the most likely cause of this issue?
A better route to the 8.8.8.8/32 network exists in the routing table.
FGT-B is configured with a prefix list denying the 8.8.8.8/32 network to be injected into the routing table.
The administrator has misconfigured redistribution of routes on FGT-A.
FGT-B is configured with a distribution list denying the 8.8.8.8/32 network to be injected into the routing table.
What can you conclude about the router in this scenario?
The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the BGP session with the local router.
An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.
All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.
The BGP session with peer 10.127.0.75 is up.
Which two statements about an auxiliary session ate true? (Choose two.)
With the auxiliary session setting disabled, only auxiliary sessions are offloaded.
With the auxiliary session setting enabled, ECMP traffic is accelerated to the NP6 processor.
With the auxiliary session setting enabled, two sessions are created if there is a routing change.
With the auxiliary session setting disabled, for each traffic path, FortiGate uses the same auxiliary session.
Refer to the exhibit, which contains a screenshot of some phase 1 settings.
The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands on an SSH session on FortiGate:
However, the IKE real-time debug does not show any output. Why?
The administrator must also run the command diagnose debug enable.
The debug shows only error messages. If there is no output, then the phase 1 and phase 2 configurations match
The log-filter setting is incorrect. The VPN traffic does not match this filter.
A. Replace diagnose debug application ike -1 with diagnose debug application ipsec -1.
Which two statements are true regarding heartbeat messages sent from an FSSO collector agent to FortiGate? (Choose two.)
The heartbeat messages can be seen using the command diagnose debug authd fsso list.
The heartbeat messages can be seen in the collector agent logs.
The heartbeat messages can be seen on FortiGate using the real-lime FSSO debug.
The heartbeat messages must be manually enabled on FortiGate.
Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
The name of the configured LDAP server is Lab.
The user is authenticating using CN=John Smith.
FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.
FortiOS is performing the second step (Search Request) in the LDAP authentication process.
Refer to the exhibit, which shows a session entry.
Which statement about this session is true?
Return traffic to the initiator is sent to 10.1.0.1.
Return traffic to the initiator is sent lo 10.200.1.254.
It is an ICMP session from 10.1.10.10 to 10.200.1.1.
It is an ICMP session from 10.1.10.1 to 10.200.5.1.
Which statement about parallel path processing (PPP) is correct?
PPP selects from a group of parallel options to identify the optimal path for processing packets.
Only FortiGate hardware configuration affects the path taken by packets.
PPP does not apply to packets that are part of an already established session.
Software configuration has no impact on PPP.
In IKEv2, which exchange establishes the first CHILD_SA?
IKE_SA_INIT
INFORMATIONAL
CREATE_CHILD_SA
IKE_Auth
Which authentication option can you not configure under user radius config on FortiOS?
mschap
pap
mschap2
eap
Refer to the exhibit, which shows a partial output of diagnose hardware aysinfo memory. Which two statements about the output are true? (Choose two.)
There are 98908 kB of memory that will never be used.
The user space has 708880 kB of physical memory that is not used by the system.
The I/O cache, which has 641364 kB of memory allocated to it.
The value indicated next to the inactive heading represents the currently unused cache page.
Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week.
Which two statements about the output are true? (Choose two.)
If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.
If port 7 becomes disconnected on the secondary, both FortiGate devices will elect itself as primary.
If FGVM...649 is rebooted. FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.
If no action is taken, the primary FortiGate will leave the cluster because of the current sync status.
Refer to the exhibit, which shows a partial web fillet profile configuration.
Which action does FortiGate lake if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?
FortiGate allows the connection, based on the URL Filter configuration.
FortiGate blocks the connection as an invalid URL.
FortiGate exempts the connection, based on the Web Content Filter configuration.
FortiGate blocks the connection, based on the FortiGuard category based filter configuration.
Which two statements are true?
A. The traffic has been tagged for VLAN 0000.
B. NP7 is handling offloading of this session.
C. The traffic matches Policy ID 1.
D. The session has been offloaded.
Assuming a default configuration, which three statements are true?
Strict RPF is enabled by default.
User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table.
User A: Pass. The default static route through wan1 passes the RPF check regardless of the source IP address.
User B: Pass. FortiGate will use asymmetric routing using wan1 to reply to traffic for 95.56.234.24.
User C: Fail. There is no route to 10.0.4.63 using port1 in the routing table.
Which two statements about Security Fabric communications are true? (Choose two.)
FortiTelemetry and Neighbor Discovery both operate using TCP.
The default port for Neighbor Discovery can be modified
FortiTelemetry must be manually enabled on the FortiGate interface.
By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.
Refer to the exhibit, which contains the output of diagnose vpn tunnel list.
Which command will capture ESP traffic for the VPN named DialUp_0?
diagnose sniffer packet any 'ip proto 50'
diagnose sniffer packet any 'host 10.0.10.10'
diagnose sniffer packet any 'esp and host 10.200.3.2'
diagnose sniffer packet any 'port 4500'
Refer to the exhibit, which shows the output of diagnose automation test. What can you observe from the output? (Choose two.)
The automation stitch test is not being logged.
The automation stitch test failed but the HA failover was successful.
An HA failover occurred
The test was unsuccessful.
Refer to the exhibit, which shows partial outputs from two routing debug commands.
Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?
Set snat-route-change to enable.
Set the priority of the static default route using port2 to 1.
Set preserve-session-route to enable.
Set the priority of the static default route using port1 to 10.
What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two.)
Packet was dropped because of policy route misconfiguration.
Packet was dropped because of traffic shaping.
Trusted host list misconfiguration.
VIP or IP pool misconfiguration.
Refer to the exhibit, which shows the output of a session. Which two statements are true? (Choose Two.)
The TCP session has been successfully established.
The session was initiated from an authenticated user.
The session is being inspected using flow inspection.
The session is being offloaded.
Refer to the exhibit, which shows the output of get router info ospf neighbor.
What can you conclude from the command output?
The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.
All neighbors are in area 0.0.0.0.
The local FortiGate is the BDR.
The local FortiGate is not a DROther.
Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.
What three conclusions can you draw from these log entries? {Choose three.)
Remote registry is not running on the workstation.
The user's status shows as "not verified" in the collector agent.
DNS resolution is unable to resolve the workstation name.
The FortiGate firmware version is not compatible with that of the collector agent.
A firewall is blocking traffic to port 139 and 445.
Which statement about protocol options is true?
Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.
Protocol options give administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.
Protocol options allow administrators to configure the Any setting for all enabled protocols, which provides the most efficient use of system resources.
Protocol options allow administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.
Which two statements about conserve mode are true? (Choose two.)
FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.
FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.
FortiGate exits conserve mode when the system memory goes below the configured green threshold.
FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.
Refer to the exhibit, which contains partial output from an IKE real-time debug.
The administrator does not have access to the remote gateway.
Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?
In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
In the phase 1 network configuration, set the IKE version to 2.
In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
Which three common FortiGate-to-collector-agent connectivity issues can you identify using the
FSSO real-time debug? (Choose three.)
Log is full on the collector agent.
Inability to reach IP address of the collector agent.
Refused connection. Potential mismatch of TCP port.
Mismatched pre-shared password.
Incompatible collector agent software version
The administrator wants to configure a default static route for port3 and assign a distance of 50 and a
priority of 0.
What will happen to the port1 and port2 default static routes after the port3 default static route is
created?
The port2 default static route will be injected into the forwarding information base (FIB).
The port1 default static route will be injected into the FIB.
Neither of the routes shown in the output will be injected into the FIB.
Both default static routes shown in the output will be injected into the FIB.
The local OSPF router is unable to establish adjacency with a peer.
Which two things should the administrator do to troubleshoot the issue? (Choose two.)
Check whether TCP port 179 is blocked.Check whether TCP port 179 is blocked.
Check if there is an active static route to the peer.
Check whether both peers have an IP address within the same subnet.
Check if IP protocol 89 is blocked.
An IPsec VPN tunnel is dropping, as shown by the debug output.
Analyzing the debug output, what could be causing the tunnel to go down?
hase 2 drops but Phase 1 is up.
Dead Peer Detection is not receiving its acknowledge packet.
The tunnel drops during rekey negotiation.
he tunnel drops after the timer expires.
Refer to the exhibit, which shows the partial output of command diagnose debug rating. In this exhibit, which FDS server will the FortiGate algorithm choose?
66.117.56.37
208.91.112.194
209.22.147.36
64.26.151.37
Refer to the exhibit, which shows the output of the command get router info ospf neighbor.
To what extent does FortiGate operate when looking at its OSPF neighbors? (Choose two.)
The local FortiGate has at least one interface that participates in a broadcast network.
The local FortiGate has at least one interface that participates in a point-to-point network.
The local FortiGate is the DR.
Neighbor 0.0.0.18 is the designated router (DR).
Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate.
An administrator has configured two VPNs for two different user groups. Users who are in the Users-2
group are not able to connect to the VPN. After running a diagnostics command, the administrator
discovers that FortiGate is not matching the user-2 VPN for members of the Users-2 group.
Which two changes must the administrator make to fix the issue? (Choose two.)
Change to aggressive mode on both VPNs.
Enable XAuth on both VPNs.
Use different pre-shared keys on both VPNs.
Set up specific peer IDs on both VPNs.
In the SAML negotiation process, which section does the Identity Provider (IdP) provide the SAML
attributes utilized in the authentication process to the Service Provider (SP)?
SP Login dump
Authentication Response
Authentication Request
Assertion dump
he URL www.dropbox.com is categorized as File Sharing and Storage.
Which action does FortiGate take if a user attempts to access www.dropbox.com?
FortiGate blocks the connection as an invalid URL.
Based on the URL Filter configuration, FortiGate allows the connection.
FortiGate blocks the connection, based on the FortiGuard category-based filter configuration.
Based on the Web Content filter configuration, access to www.dropbox.com would be exempted
During which phase of IKEv2 does the Diffie-Helman key exchange take place?
IKE_Req_INIT
Create_CHILD_SA
IKE_Auth
IKE_SA_INIT
What two actions can the administrator take to resolve this issue? (Choose two.)
Ensure the user logs in using 'John Smith' not 'jsmith'.
Ensure the user is providing the correct user credentials.
Ensure the user is a member of at least one AD group to ensure step 4 of the LDAP authentication
process is successful.
Ensure the account is active.
What two conclusions can you draw from the output? (Choose two.)
The user was found in the LDAP tree, whose root is TAC.ottawa.fortinet.com.
FortiOS performs a bind to the LDAP server using the user's credentials.
FortiOS collects the user group information.
FortiOS is performing the second step (Search Request) in the LDAP authentication process
Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)
FortiGate will drop the expected traffic if it does not arrive within 23 seconds.
Clearing the master session has no impact on the expectation session
This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.
The session is checked against firewall policy ID 25.
An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate
from where the collector agent is deployed is successful.
The administrator then produces the debug output shown in the exhibit.
What could be causing this error message?
The TCP port 445 is blocked between FortiGate and collector agent.
The collector agent preshared password is mismatched.
The FortiGate cannot resolve the active directory server name.
The FortiGate and the collector agent are using different TCP ports.
An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix.
Which two actions can the administrator take to fix this problem? (Choose two.)
Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.
Manually add the BGP route on FGT-A.
Restart BGP using a soft reset to force both peers to exchange their complete BGP routing tables.
Use the set network-import-check disable command
Refer to the exhibit, which shows the output of diagnose sys session list.If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the
Primary?
The secondary device has this session synchronized; however, because application control is applied,
the session is marked dirty and has to be re-evaluated after failover.
Traffic for this session continues to be permitted on the new primary device after failover, without
requiring the client to restart the session with the server.
The session will be removed from the session table of the secondary device because of the presence
of allowed error packets, which will force the client to restart the session with the server.
The session state is preserved but the kernel will need to re-evaluate the session because NAT was
applied
What are two functions of automation stitches? (Choose two.)
You can configure automation stitches on any FortiGate device in a Security Fabric environment.
You can configure automation stitches to execute actions sequentially by taking parameters from
previous actions as input for the current action.
You can set an automation stitch configured to execute actions in parallel to insert a specific delay
between actions.
You can create automation stitches to run diagnostic commands and attach the results to an email
message when CPU or memory usage exceeds specified thresholds.
Refer to the exhibit, which a network topology and a partial routing table.
FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3. Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?
Enable asymmetric routing under config system settings.
Change the configuration from strict RPF check mode to feasible RPF check mode.
A firewall policy that allows all ICMP traffic from port3 to port1.
Modify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
Refer to the exhibit, which shows the partial output of FortiOS kernel slabs. Which statement is true?
The total slab size of the sctp_session slab is 0 kB and is associated with the user space.
The total slab size of the ip_session slab is 3600 kB and is associated with the user space.
The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.
The total slab size of the tcp_session slab is 7500 kB and is associated with the kernel
Refer to the exhibit, which shows one way communication of the downstream FortiGate with the
upstream FortiGate within a Security Fabric.
What three actions must you take to ensure successful communication? (Choose three.)
You must authorize the downstream FortiGate on the root FortiGate
FortiGate must not be in NAT mode.
Ensure TCP port 8013 is not blocked along the way.
You must enable Security Fabric/Fortitelemetry on the receiving interface of the upstream FortiGate.
Ensure the port for Neighbor Discovery has been changed
Refer to the exhibit, which shows the partial output of a real-time OSPF debug. Why are the two FortiGate devices unable to form an adjacency?
The Hello packet is being sent from an OSPF router with ID 0.0.0.112.
The two FortiGate devices attempting adjacency are in area 0.0.0.0.
One FortiGate device is configured to require authentication, while the other is not.
The passwords on the FortiGate devices do not match.
Refer to the exhibit, which shows the output of the command get router info bgp neighbors
100.64.2.254 advertised-routes.
What can you conclude from the output?
The BGP state of the two BGP participants is OpenConfirm.
The router ID of the neighbor is 100.64.2.254
The BGP neighbor is advertising the 10.20.30.40/24 network to the local router.
The local router is advertising the 10.20.30.40/24 network to its BGP neighbor
Refer to the exhibit.
The exhibit shows the output from using the command diagnose debug application samld -1 to diagnose
a SAML connection. Based on this output, what can you conclude?
Active Directory is used for authentication.
The authentication request is for an SSL VPN connection.
The IdP IP address is 10.1.10.254.
The IdP IP address is 10.1.10.2.
Refer to the exhibit, which shows the modified output of the routing kernel.
Which statement is true?
The egress interface associated with static route 8.8.8.8/32 is administratively up.
The default static route through 10.200.1.254 is not in the forwarding information base.
The default static route through port2 is in the forwarding information base.
The BGP route to 10.0.4.0/24 is not in the forwarding information base.
Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session
information for ICMP traffic.
What happens to the session information if a routing change occurs that affects this session?
Only the interface and gateway information for dev=7 will be removed.
The session information will not change unless the current route has been removed from the routing table.
The session will be flagged as dirty but no route lookups will be performed.
Sessions involving port7 or port19 will not have their routing information flushed.
Refer to the exhibit.
Partial output of the get vpn ipsec tunnel details command is shown.
Based on the output, which two statements are correct? (Choose two answers)
Different SPI values are a result of auto-negotiation being disabled for phase2 selectors.
The npu_flag for this tunnel is 03.
Anti-replay is enabled.
The npu_flag for this tunnel is 02
Refer to the exhibit.
An IPsec VPN tunnel using IKEv2 was brought up successfully, but when the tunnel rekey takes place the tunnel goes down.
The debug command for IKE was enabled and, in the exhibit, you can review the partial output of the debug IKE while attempting to bring the tunnel up.
What is causing the tunnel to be down? (Choose one answer)
A mismatch in the Phase 2 negotiations
Blocked traffic on UDP port 500
A Diffie-Hellman mismatch
A mismatch in the Phase 1 negotiations
Refer to the exhibit.
The output from using the command diagnose debug application samld -l to diagnose a SAML connection is shown.
Based on this output, which two conclusions can you draw? (Choose two answers)
The IdP IP address is 10.1.10.254
The SP IP address is 10.1.10.254
The SP IP address is 10.1.10.2
The IdP IP address is 10.1.10.2
Refer to the exhibit.
The output of the command diagnose vpn tunnel list is shown.
Reviewing the debug command, what is the current status of the traffic flowing through the tunnel? (Choose one answer)
NP6 is handling the offloading.
The inbound IPsec SA was copied to the NPU.
The inbound and outbound IPsec SAs were copied to the NPU.
The outbound IPsec SA was copied to the NPU
Refer to the exhibit.
Which two statements about FortiGate behavior relating to this session are correct? (Choose two answers)
FortiGate redirected the client to the captive portal to authenticate so that a correct policy match could be made.
FortiGate either initiated the session or the session terminates at FortiGate.
FortiGate forwarded this session without any inspection.
FortiGate is performing a security profile inspection using the CPU
Refer to the exhibit.
Partial output of a real-time OSPF debug is shown.
Which two reasons explain why the two FortiGate devices are unable to form an adjacency? (Choose two answers)
The remote peer has either OSPF cleartext or MD5 authentication configured.
There is an OSPF authentication configuration mismatch.
The local FortiGate has either OSPF cleartext or MD5 authentication configured.
The local FortiGate does not have OSPF authentication configured
Refer to the exhibit.
A partial output from an IKE real-time debug is shown.
The administrator does not have access to the remote gateway.
Based on the debug output, which two conclusions can you draw? (Choose two answers)
There is a Diffie-Hellman group mismatch.
This is a phase 1 negotiation.
The remote peer is the initiating peer.
This is a phase 2 negotiation.
