How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as a local FDS?
A. FortiManager does not support rating requests.
B. FortiManager can download and maintain local copies of FortiGuard databases.
C. FortiManager supports only FortiGuard push to managed devices.
D. FortiManager will respond to update requests only if they originate from a managed device.
正解:B
質問 2:
View the IPS exit log, and then answer the question below.
# diagnose test application ipsmonitor 3
ipsengine exit log"
pid = 93 (cfg), duration = 5605322 (s) at Wed Apr 19 09:57:26 2017
code = 11, reason: manual
What is the status of IPS on this FortiGate?
A. All IPS-related features have been disabled in FortiGate's configuration.
B. There are communication problems between the IPS engine and the management database.
C. IPS daemon experienced a crash.
D. IPS engine memory consumption has exceeded the model-specific predefined value.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which action will FortiGate take when using the default settings for SSL certificate inspection, where the server name indication (SNI) does not match either the common name (CN) or any of the subject altemative names (SAN) in the server certificate?
A. FortiGate uses the SNI from the user's web browser.
B. FortiGate uses the CN information from the Subject field in the server certificate.
C. FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
D. FortiGate uses the first entry listed in the SAN field in the server certificate.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Examine the output from the BGP real time debug shown in the exhibit, then the answer the question below:

Which statements are true regarding the output in the exhibit? (Choose two.)
A. BGP peers have successfully interchanged Open and Keepalive messages.
B. Local BGP peer received a prefix for a default route.
C. The state of the remote BGP peer is OpenConfirm.
D. The state of the remote BGP peer will go to Connect after it confirms the received prefixes.
正解:A,B
質問 5:
Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network. What HA setting must be changed in one of the HA clusters to fix the problem?
A. Session pickup.
B. Group name.
C. Group ID.
D. Gratuitous ARPs.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Which configuration can be used to reduce the number of BGP sessions in an IBGP network?
A. Neighbor group
B. Next-hop-self
C. Neighbor range
D. Route reflector
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Refer to the exhibit, which shows the output of a BGP debug command.

Which statement explains why the state of the 10.200.3.1 peer is Connect?
A. The local router initiated the BGP session to 10.200.3.1 but did not receive a response.
B. The router 10.200.3.1 has authentication configured for BGP and the local router does not.
C. The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the openConfirm yet.
D. The local router has a different AS number than the remote peer.
正解:A
質問 8:
Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)
A. IPS failopen
B. mem failopen
C. AV failopen
D. UTM failopen
正解:A,C
森下** -
Fortinetさんの問題集は解説が丁寧で理解が助かります。NSE7_EFW-7.0本番試験に無事合格いたしました。