Fortinet NSE7_FSN_AR-7.6 Exam Prep
Fortinet NSE 7 - Secure Networking 7.6 Architect (Page 5 )

Updated On: 7-Oct-2026

MULTIPLE CHOICE
In which two slates is a given session categorized as ephemeral? (Choose two.)

  1. A UDP session with only one packet received
  2. A UOP session with packets sent and received
  3. A TCP session waiting for the SYN ACK
  4. A TCP session waiting for FIN ACK

Answer(s): A,C

Explanation:

The study guide states:
''FortiGate categorizes an entry in the session table as an ephemeral session when it is a TCP session that is not fully established (three-way handshake not completed), or when it is a UDP session with only one packet received.''
This directly proves:
A is correct because a UDP session with only one packet received is ephemeral.
C is correct because a TCP session waiting for the SYN/ACK is not fully established, so it is ephemeral. The study guide's TCP state table shows that the handshake is only completed when the session reaches ESTABLISHED
Why the other options are wrong:
B is wrong because once UDP traffic has been seen in both directions, it is no longer the ''single packet received'' condition described for ephemeral sessions. The study guide says for UDP: 00 = one way, 01 = both ways
D is wrong because a TCP session waiting for FIN/ACK is already in the closing stage after establishment, not in the ''not fully established'' stage. The study guide explains that after both sides close the session, FortiGate can keep it briefly in the table in state value 5 for out-of-order packets after FIN/ACK



MULTIPLE CHOICE
Refer to the exhibit, which shows the output of get router info bgp summary.

Which two statements are true? (Choose two.)

  1. The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.
  2. The TCP connection with BGP neighbor 100.64.2.254 was successful.
  3. The local FortiGate has received 18 packets from a BGP neighbor.
  4. The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264

Answer(s): A,C

Explanation:

The get router info bgp summary output lists BGP neighbor status:
Prefix Reception: The 'State/PfxRcd' column shows the number of prefixes received from the neighbor---neighbor 100.64.1.254 has '1', confirming option A.
Received Message Count: Under 'MsgRcvd', 18 packets have been received from neighbor 100.64.1.254. This matches option C.
The second neighbor 100.64.2.254 is in 'Active' state and has received/sent 0 packets, indicating that its TCP connection is NOT established, disproving option B.
There is no indication anywhere that the router is 'still calculating' prefixes; 'Active' just means no session is established, so option D is incorrect.
FortiOS BGP Command Reference: BGP Neighbor States, PfxRcd, and Counters



Which exchange lakes care of DoS protection in IKEv2?

  1. Create_CHILD_SA
  2. IKE_Auth
  3. IKE_Req_INIT
  4. IKE_SA_NIT

Answer(s): C

Explanation:

TheIKE_SA_INITexchange in IKEv2 is responsible for DoS protection measures. During IKE_SA_INIT, before authentication and further exchange, the responder can use cookie challenges (per RFC 7296 and Fortinet VPN documentation). If a DoS attack is suspected (many requests from the same source), the responder replies with a cookie. Only after the initiator returns the correct cookie does the exchange proceed, protecting the responder from state exhaustion and certain forms of DoS traffic at the handshake stage.
FortiOS VPN Manual: IKEv2 Exchange Process and DoS Protections
IKEv2 RFC 7296: Description of IKE_SA_INIT and DoS Cookie Mechanism



MULTIPLE CHOICE
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.

What two conclusions can you draw from the output? (Choose two.)

  1. The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.
  2. The logon event can be seen on the collector agent installed on Windows.
  3. FSSO is using DC agent mode to detect logon events.
  4. FSSO is using agentless polling mode to detect logon events.

Answer(s): A,D

Explanation:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-FSSO-age-tless-polling/ta-p/214349
From the snippet we can see that FortiGate (via the fssod daemon) is directly detecting the user logon rather than relying on a separate ''collector'' or ''DC agent.'' This indicates agentless polling---FortiGate polls the DC's event logs over TCP 445 to discover logons. So: - FSSO is using agentless polling mode to detect logon events -In agentless mode, FortiGate will periodically poll the same IP (the DC) on port 445 to see if the user is still logged on



Your organization is deploying a multi-region SD-WAN topology with two hub sites in different geographic locations and 50 branch offices. You want to minimize WAN bandwidth consumption while maintaining sub-second failover capabilities if one hub becomes unavailable.
Which combination of technologies should you implement to achieve this objective?

  1. Configure ADVPN 2.0 with dual-hub topology using EBGP on loopback interfaces and enable SD-WAN self-healing with dependent shortcuts
  2. Deploy FortiGate clustering in active-active mode at each hub with FGCP and configure standard hub-and-spoke IPsec tunnels without ADVPN shortcuts
  3. Implement OSPF equal-cost multi-path routing with dual hub redundancy but disable ADVPN shortcut negotiation to reduce complexity
  4. Use ADVPN 1.0 with route reflectors at the hub sites and configure independent shortcuts without dependent shortcut relationships

Answer(s): A

Explanation:

ADVPN 2.0 with dual-hub topology and EBGP on loopback interfaces is the correct modern approach for large multi-region deployments. ADVPN 2.0 addresses ADVPN 1.0 challenges by enabling efficient shortcut negotiation between branches without hub traversal, reducing bandwidth. Dependent shortcuts ensure that if one hub fails, the branch automatically falls back to the other hub without administrator intervention—this is the sub-second failover mechanism. Using EBGP on loopback interfaces provides dynamic routing convergence and self-healing capabilities.
Option B (FGCP clustering without ADVPN) works only for local hub redundancy, not multi-region optimization. Option C (OSPF with disabled shortcuts) wastes bandwidth by forcing all branch-to-branch traffic through hubs. Option D (ADVPN 1.0 without dependent shortcuts) lacks the self-healing and rapid failover properties that ADVPN 2.0 provides.



Viewing page 5 of 34
Viewing questions 21 - 25 out of 164 questions


Post your Comments and Discuss Fortinet NSE7_FSN_AR-7.6 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!