Free FCSS_NST_SE-7.4 Exam Braindumps (page: 2)

Page 1 of 11

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.
Which action will FortiGate take when using the default settings for SSL certificate inspection?

  1. FortiGate uses the SNI from the user's web browser.
  2. FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
  3. FortiGate uses the first entry listed in the SAN field in the server certificate.
  4. FortiGate uses the ZN information from the Subject field in the server certificate.

Answer(s): C



Exhibit.



Refer to the exhibit, which contains partial output from an IKE real-time debug.
Which two statements about this debug output are correct? (Choose two.)

  1. Perfect Forward Secrecy (PFS) is enabled in the configuration.
  2. The local gateway IP address is 10.0.0.1.
  3. It shows a phase 2 negotiation.
  4. The initiator provided remote as its IPsec peer I

Answer(s): C,D



Exhibit.



Refer to the exhibit, which shows the output of a diagnose command.
What can you conclude about the debug output in this scenario?

  1. The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.
  2. There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.
  3. FortiGate used 64.26.151.37 as the initial server to validate its contract.
  4. Servers with a negative TZ value are less preferred for rating requests.

Answer(s): B



Refer to the exhibit, which shows the output of a policy route table entry.



Which type of policy route does the output show?

  1. An ISDB route
  2. A regular policy route
  3. A regular policy route, which is associated with an active static route in the FIB
  4. An SD-WAN rule

Answer(s): A






Post your Comments and Discuss Fortinet FCSS_NST_SE-7.4 exam with other Community members:

FCSS_NST_SE-7.4 Exam Discussions & Posts