Free FCSS_NST_SE-7.4 Exam Braindumps (page: 5)

Page 4 of 11

Which exchange lakes care of DoS protection in IKEv2?

  1. Create_CHILD_SA
  2. IKE_Auth
  3. IKE_Req_INIT
  4. IKE_SA_NIT

Answer(s): C



Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.



What two conclusions can you draw Itom the output? (Choose two.)

  1. The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.
  2. The logon event can be seen on the collector agent installed on Windows.
  3. FSSO is using DC agent mode to detect logon events.
  4. FSSO is using agentless polling mode to detect logon events.

Answer(s): A,D



An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.
If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?

  1. diagnose sniffer packet any 'udp port 500'
  2. diagnose sniffer packet any 'lp proto 50'
  3. diagnose sniffer packet any 'udp port 4500'
  4. diagnose sniffer packet any 'ah'

Answer(s): B



Refer to the exhibits.



An administrator Is expecting to receive advertised route 8.8.8.8/32 from FGT-

  1. On FGT-B, they confirm that the route is being advertised and received, however, the route is not being injected into the routing table.
    What is the most likely cause of this issue?
  2. A batter route to the 8.8.8.8/32 network exists in the routing table.
  3. FGT-B is configured with a prefix list denying the 8.8.8.8/32 network to be injected into the routing table.
  4. The administrator has misconfigured redistribution of routes on FGT-A.
  5. FGT-8 is configured with a distribution list denying the 8.8.8.8/32 network to be injected into the routing table.

Answer(s): B






Post your Comments and Discuss Fortinet FCSS_NST_SE-7.4 exam with other Community members:

FCSS_NST_SE-7.4 Exam Discussions & Posts