Refer to the exhibit.

The partial output of an OSPF command is shown.
While checking the OSPF status of FortiGate, you receive the output shown in the exhibit.
Based on the output, which two statements about FortiGate are correct? (Choose two.)
A. FortiGate has OSPF ECMP enabled.
B. FortiGate injects external routing information.
C. FortiGate is connected to multiple areas.
D. FortiGate is a backup designated router.
正解:A,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Exhibit.

Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator do to fix the issue?
A. Change protocol to TCP.
B. Disable webfilter-force-off.
C. Increase webfilter-timeout.
D. Enable fortiguard-anycast.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Refer to the exhibit, which shows the output of a diagnose command.

What two conclusions can you draw from the output shown in the exhibit? (Choose two answers)
A. Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next- hop IP address 10.200.1.1.
B. This is an expected session created by the IPS engine.
C. This is a pinhole session created to allow traffic for a protocol that requires additional sessions to operate through FortiGate.
D. Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next- hop IP address 10.0.1.10.
正解:C,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Refer to the exhibits.

The system administrator settings configured on the root FortiGate and the Security Fabric settings configured on a downstream FortiGate are shown.
When prompted to sign in with Security Fabric to the downstream FortiGate, a user enters the single sign-on (SSO) provider credentials.
What happens next for the user?
A. The user receives an authentication failure message.
B. The user accesses the downstream FortiGate with super_admin_readonly privileges.
C. The user accesses the root FortiGate with AdminSSO privileges.
D. The user is redirected to the root FortiGate.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Refer to the exhibit.

Which two observations can you make about the web filter traffic captured using the flow tool? (Choose two.)
A. The web filter profile is configured with proxy-based inspection mode.
B. The session is offloaded to the NPU.
C. The firewall policy is configured with proxy-based inspection mode.
D. The HTTPS port is mapped to 443 in the SSL/SSH Inspection Profile
正解:A,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
During the SAML negotiation process, in which section does the Identity Provider (IdP) provide the SAML attributes used in the authentication process to the Service Provider (SP)?
A. Bindings HTTP post
B. Authentication request
C. Authentication response
D. Assertion dump
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Exhibit.

Refer to the exhibit, which shows the output of a session. Which two statements are true? (Choose Iwo.)
A. The TCP session has been successfully established.
B. The session is being inspected using flow inspection.
C. The session is being offloaded.
D. The session was initiated from an authenticated user.
正解:A,D
質問 8:
You are checking an enterprise network and see a suspicious packet with the MAC address 00:09:0f:09:18:81.
Which two statements about the suspicious packet are correct? (Choose two.)
A. The suspicious packet corresponds to a port with a physical index equal to 2.
B. The suspicious packet is related to a cluster with a group-id value lower than 255.
C. The suspicious packet is related to a cluster configured with the FortiGate Session Life Support Protocol (FGSP).
D. The suspicious packet is related to a cluster that has VDOMs enabled.
正解:B,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 9:
Refer to the exhibit.

Partial output of the fssod daemon real-time debug command is shown. Which two conclusions can you draw from the output? (Choose two answers)
A. FSSO is using agentless polling mode to detect logon events.
B. FortiGate polled this event through TCP port 8000.
C. FSSO cannot verify if the user is still logged in.
D. FortiGate is frequently polling the workstation in case the user has logged out.
E. Fortinet Single Sign-On (FSSO) is using DC Agent mode to detect logon events.
正解:A,D
解説: (Pass4Test メンバーにのみ表示されます)
1242 お客様のコメント








Makimura -
仕事で使うようになり勉強開始。
偏差値真ん中くらいの自分でも、内容もわかりやすくて助かります!試験は受けないので、NSE7_FSN_AR-7.6勉強にいいかも。