Fortinet

FCSS_NST_SE-7.4 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 59-question bank.

Provider
Fortinet
Question bank
59
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for FCSS_NST_SE-7.4, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic. What happens to the session information if a routing change occurs that affects this session?

    Choose one answer.

    Question illustration 1
    • Only the interface and gateway information for dev=7 will be removed.
    • The session information will not change unless the current route has been removed from the routing table.
    • The session will be flagged as dirty but no route lookups will be performed.
    • Sessions involving port7 or port19 will not have their routing information flushed.
  2. Question 2 · 1

    Refer to the exhibit, which contains the partial configuration of an IPsec VPN configuration. After reviewing the configuration, what can you conclude about the IPsec VPN Phase 1 setup?

    Choose one answer.

    Question illustration 1
    • The VPN is configured using IKEv2.
    • Dead Peer Detection is disabled.
    • The VPN is configured with DHCP over IPsec.
    • The tunnel is configured as a route-based VPN.
  3. Question 3 · 1

    Refer to the exhibit, which shows the output of diagnose sys session list. If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

    Choose one answer.

    Question illustration 1
    • The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.
    • Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.
    • The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.
    • The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.
  4. Question 4 · 1

    Refer to the exhibit, which shows the partial output of a diagnose command. Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • FortiGate will drop the expected traffic if it does not arrive within 23 seconds.
    • Clearing the master session has no impact on the expectation session.
    • This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.
    • The session is checked against firewall policy ID 25.
  5. Question 5 · 1

    Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which action will FortiGate take when using the default settings for SSL certificate inspection?

    Choose one answer.

    • FortiGate uses the CN information from the Subject field in the server certificate.
    • FortiGate uses the SNI from the user's web browser.
    • FortiGate will establish a connection without SSL/TLS inspection.
    • The web filter will automatically bypass SSL inspection for this connection.
  6. Question 6 · 1

    Refer to the exhibits. An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix. Which two actions can the administrator take to fix this problem? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.
    • Manually add the BGP route on FGT-A.
    • Restart BGP using a soft reset to force both peers to exchange their complete BGP routing tables.
    • Use the set network-import-check disable command.
  7. Question 7 · 1

    Refer to the exhibit, which shows a partial output of a real-time LDAP debug. What two conclusions can you draw from the output? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The user was found in the LDAP tree, whose root is TAC.ottawa.fortinet.com.
    • FortiOS performs a bind to the LDAP server using the user's credentials.
    • FortiOS collects the user group information.
    • FortiOS is performing the second step (Search Request) in the LDAP authentication process.
  8. Question 8 · 1

    During which phase of IKEv2 does the Diffie-Helman key exchange take place?

    Choose one answer.

    • IKE_Req_INIT
    • Create_CHILD_SA
    • IKE_Auth
    • IKE_SA_INIT
  9. Question 9 · 1

    In the SAML negotiation process, which section does the Identity Provider (IdP) provide the SAML attributes utilized in the authentication process to the Service Provider (SP)?

    Choose one answer.

    • SP Login dump
    • Authentication Response
    • Authentication Request
    • Assertion dump
  10. Question 10 · 1

    Refer to the exhibit, which shows the partial output of diagnose sys session stat. Which statement about the output shown in the exhibit is correct?

    Choose one answer.

    Question illustration 1
    • 27 sessions have expired but are still in the session table in case any out-of-order packets arrive.
    • 15 sessions have been categorized as ephemeral.
    • 113 sessions have been dropped because of memory page exhaustion.
    • 562 TCP sessions have their proto_state set to 01 if there is no inspection.
  11. Question 11 · 1

    Refer to the exhibit, which shows the partial output of command diagnose debug rating. In this exhibit, which FDS server will the FortiGate algorithm choose?

    Choose one answer.

    Question illustration 1
    • 66.117.56.37
    • 208.91.112.194
    • 209.22.147.36
    • 64.26.151.37
  12. Question 12 · 1

    Refer to the exhibit, which shows the modified output of the routing kernel. Which statement is true?

    Choose one answer.

    Question illustration 1
    • The egress interface associated with static route 8.8.8.8/32 is administratively up.
    • The default static route through 10.200.1.254 is not in the forwarding information base.
    • The default static route through port2 is in the forwarding information base.
    • The BGP route to 10.0.4.0/24 is not in the forwarding information base.
  13. Question 13 · 1

    Refer to the exhibit, which shows the output of the command get router info ospf neighbor. To what extent does FortiGate operate when looking at its OSPF neighbors? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The local FortiGate has at least one interface that participates in a broadcast network.
    • The local FortiGate has at least one interface that participates in a point-to-point network.
    • The local FortiGate is the DR.
    • Neighbor 0.0.0.18 is the designated router (DR).
  14. Question 14 · 1

    FortiGate performs different actions when in conserve mode depending on the configured memory thresholds. Which actions correlates to which thresholds? (Choose two.)

    Choose all answers that apply.

    • FortiGate exits conserve mode when the system memory goes below the configured green threshold.
    • FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.
    • FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.
    • FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.
  15. Question 15 · 1

    Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate. An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovers that FortiGate is not matching the user-2 VPN for members of the Users-2 group. Which two changes must the administrator make to fix the issue? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Change to aggressive mode on both VPNs.
    • Enable XAuth on both VPNs.
    • Use different pre-shared keys on both VPNs.
    • Set up specific peer IDs on both VPNs.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free