5/5 - (1 vote)

FCSS_EFW_AD-7.4 Tested & Approved Fortinet Certified Solution Specialist Study Materials

Validate your Skills with Updated Fortinet Certified Solution Specialist Exam Questions & Answers and Test Engine

QUESTION 45
Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?

 
 
 
 

QUESTION 46
Which statement about NGFW policy-based application filtering is true?

 
 
 
 

QUESTION 47
An administrator wants to simplify a new hub-and-spoke network deployment with the BGP recommended configuration.
Which two sections on FortiManager must the administrator use? (Choose two.)

 
 
 
 

QUESTION 48
What are two functions of automation stitches? (Choose two.)

 
 
 
 

QUESTION 49
Which two statements about an auxiliary session are true? (Choose two.)

 
 
 
 

QUESTION 50
Which three conditions are required for two FortiGate devices to form an OSP adjacency? (Choose three.)

 
 
 
 
 

QUESTION 51
Which two events can trigger an HA failover? (Choose two.)

 
 
 
 

QUESTION 52
Refer to the exhibit, which contains the output of a web filtering diagnose command.


Which statement explains why the cache statistics are all zeros?

 
 
 
 

QUESTION 53
Examine the following traffic log; then answer the question below.
date-20xx-02-01 time=19:52:01 devname=masterdevice_id=”xxxxxxx” log_id=0100020007 type=event subtype=system pri critical vd=root service=kemel status=failure msg=”NAT port is exhausted.” What does the log mean?

 
 
 
 

QUESTION 54
Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)

 
 
 
 
 

QUESTION 55
An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device.
What can the administrator do to fix this problem?

 
 
 
 

QUESTION 56
Which of the following conditions must be met for a static route to be active in the routing table?
(Choose three.)

 
 
 
 
 

QUESTION 57
An administrator is deploying APs that are connecting over an IPsec network. All APs have been configured to connect to FortiGate manually. FortiGate can discover the APs and authorize them.
However, FortiGate is unable to establish CAPWAP tunnels to manage the APs.
Which configuration setting can the administrator perform to resolve the problem?

 
 
 
 

QUESTION 58
A FortiGate’s port1 is connected to a private network. Its port2 is connected to the Internet. Explicit web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP.
Which statements are true regarding the two entries in the FortiGate session table related with this traffic? (Choose two.)

 
 
 
 

QUESTION 59
View the following exhibit, which contains the sniffer output for a passive mode FTP request.

An administrator has created the following custom IPS signature to block all FTP requests for passive mode: F-SBID (–attack_id 1002; –name “Block.FTP “; –protocol tcp; –flow from_client; –pattern
“PASV”; –no_case;) Soon after the signature is enabled in an active IPS sensor, some false positive detections are generated.
Which option and value pair will allow more specific detection?

 
 
 
 

QUESTION 60
View the IPS exit log, and then answer the question below.

What is the status of IPS on this FortiGate?

 
 
 
 

QUESTION 61
View the exhibit, which contains the output of a diagnose command, and then answer the question below.

What statements are correct regarding the output? (Choose two.)

 
 
 
 

QUESTION 62
Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router.
The second unit is elected as the backup designated router.
Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?

 
 
 
 

QUESTION 63
Exhibits:



Refer to the exhibits, which contain the network topology and BGP configuration for a hub.
An administrator is trying to configure ADVPN with a hub-spoke VPN setup using iBGP. All the VPNs are up and connected to the hub. The hub is receiving route information from both spokes over iBGP; however, the spokes are not receiving route information from each other.
What change must the administrator make to the hub BGP configuration so that the routes learned by one spoke are forwarded to the other spokes?

 
 
 
 

QUESTION 64
View the exhibit, which contains the sniffer output for a passive mode FTP request, and then answer the question below.

An administrator has created the following custom IPS signature to block all FTP requests for passive mode:
F-SBID (–attack_id 1002; –name “Block.FTP “; –protocol tcp; –flow from_client; –pattern “PASV”; — no_case;) Soon after the signature is enabled in an active IPS sensor, some false positive detections are generated.
Which of the following option and value pairs will allow more specific detection?

 
 
 
 

QUESTION 65
Which layer of the FortiOS architecture does an application process or daemon run on?

 
 
 
 

FCSS_EFW_AD-7.4 [Jan-2025] Newly Released] FCSS_EFW_AD-7.4 Exam Questions For You To Pass: https://www.actualcollection.com/FCSS_EFW_AD-7.4-exam-questions.html

Related Links: myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt www.stes.tyc.edu.tw