A partial output of a diagnose command is displayed. Which two conclusions can you draw from the output in the exhibit?
Choose two
AFortiGate will drop the expected traffic if it does not arrive within 23 seconds.
BThe packets that belong to this session are checked against firewall policy ID 25.
CThe TCP session is not established.
DThis is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.
Which two protocol states show that traffic is bidirectional?
Choose two
Aproto_state=05 for a TCP session.
Bproto_state=01 for a TCP session.
Cproto_state=01 for a UDP session.
Dproto_state=00 for an ICMP session.
Refer to the exhibits.
Exhibit 1 –
Exhibit 2 –
The FortiGate configuration and partial Internet-session information for a user on the internal network are displayed.
An administrator wants to test session failover between the two service-provider connections. Which two changes must the administrator make to force this existing session to immediately begin using the other interface?
Choose two
AModify the distance of the port1 route to 1.
BChange the priority of the port1 static route to 11.
CConfigure set snat-route-change enable.
DChange the priority of the port2 static route to 5.
Refer to the exhibits.
An administrator is trying to advertise the network configured on port3, but FGT-A is not receiving the prefix.
Which two actions can the administrator perform to resolve this issue?
Choose two
AModify the prefix using the network command and specify le 16 to include the 172.16.54.0/24 subnet.
BModify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.
CUse the set network-import-check disable command.
DRestart BGP using a soft reset to force both peers to exchange their complete BGP routing tables.
QuestionQ6
VPN
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
VPN
QuestionQ8
System troubleshooting
QuestionQ9
System troubleshooting
QuestionQ10
Authentication
QuestionQ11
VPN
QuestionQ12
Routing
QuestionQ13
System troubleshooting
QuestionQ14
Security profiles
QuestionQ15
Security profiles
QuestionQ16
System troubleshooting
QuestionQ17
Routing
QuestionQ18
System troubleshooting
QuestionQ19
System troubleshooting
QuestionQ20
System troubleshooting
QuestionQ21
Authentication
QuestionQ22
Routing
QuestionQ23
Routing
QuestionQ24
Security profiles
QuestionQ25
System troubleshooting
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit.
An IPsec VPN tunnel is dropping, as indicated in the debug output.
Based on the debug output, what could be causing the tunnel to go down?
AThe local FortiGate is dropping the incoming IKE packets from the peer.
BThe NAT-T negotiation was unsuccessful.
CDead Peer Detection is not receiving its acknowledge packet.
DThere is no active route to the remote peer.
Refer to the exhibit.
The output from the diagnose vpn tunnel list command is displayed.
Which two statements correctly describe the tunnel's status?
Choose two
APhase 1 is down.
BBoth Phase 1 and Phase 2 were negotiated successfully.
CPhase 2 is down.
DThere is currently no traffic traversing the tunnel.
Refer to the exhibit.
Partial FortiOS kernel-slab output is displayed.
Which statement about the total slab size is correct?
AThe total slab size of the ip6_session slab is 1472 kB and is associated with the kernel.
BThe total slab size of the ip_session slab is 14080 kB and is associated with the user space.
CThe total slab size of the UDPv6 slab is 14080 kB and is associated with the user space.
DThe total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.
Which two troubleshooting steps should you take if you experience intermittent web-filter behavior?
Choose two
ACheck that the correct port is mapped to HTTP in the Protocol Options.
BCheck that the communication between FortiGate and FortiGuard is stable.
CCheck that the inspection mode configured for the web filter profile matches that of the firewall policy where it is applied.
DCheck that FortiGate is not entering conserve mode.
Refer to the exhibit.
A partial output from the real-time LDAP debug is displayed.
Which two actions can the administrator perform to resolve this problem?
Choose two
AEnsure the account is active.
BEnsure the user is providing the correct user credentials.
CEnsure the user is a member of at least one AD group to ensure that step 4 of the LDAP authentication process is successful.
DEnsure the user logs in using ‘John Smith’ not ‘jsmith’.
Refer to the exhibit.
Debug output:
A partial IKE real-time debug output is displayed. The administrator cannot access the remote gateway. Based on the debug output, which two conclusions can be drawn?
Choose two
AThere is a Diffie-Hellman group mismatch.
BThis is a phase1 negotiation.
CThe remote peer is the initiating peer.
DThis is a phase2 negotiation.
Refer to the exhibit.
The output from a BGP debug command is displayed.
What is the most likely reason the local FortiGate is not receiving any prefixes from its neighbors?
AThe RIB-OUT configuration for router 10.127.0.75 prevents any route advertisement lo the local router.
BThe router 100.64.3.1 is waiting for the OPEN message from the local router.
CThe local router is waiting for the keepalive message from the router 10.125.0.60.
DNone of the three neighbors has successfully established the TCP three-way handshake with the local router.
Refer to the exhibit.
A partial output from diagnose npu np6 port-list on a FortiGate 2000E is displayed.
An administrator cannot analyze traffic passing between port1 and port17 with the diagnose sniffer command.
Which two commands enable the administrator to view the traffic?
Which two actions does FortiGate perform after an administrator enables the auxiliary-session setting?
Choose two
AFortiGates creates a new auxiliary session for each packet it receives.
BFortiGate only offloads auxiliary sessions.
CFortiGate creates two sessions in case of a routing change.
DFortiGate accelerates all ECMP traffic to the NP6 processor.
While investigating a FortiGate web-filtering problem, users state that they cannot reach any websites, although those sites are not explicitly denied by any web-filter profiles applied to firewall policies.
What are the three most likely causes of this behavior?
Choose three
AThe webfilter-force-off setting has been enabled under config system fortiguard.
BThe FortiGuard Web Filtering license has expired, causing FortiGate to apply the default block action.
CThe SSL/TLS deep inspection was configured but the browsers do not have the FortiGate certificate installed.
DThe web filter cache has been cleared causing all websites to take longer to be rated.
EThe DNS server is unreachable, preventing URL resolution.
Refer to the exhibit.
Debug output –
Which two statements regarding FortiGate behavior for this session are correct?
Choose two
AFortiGate either initiated the session or the session terminates at FortiGate.
BFortiGate redirected the client to the captive portal to authenticate so that a correct policy match could be made.
CFortiGate forwarded this session without any inspection.
DFortiGate is performing a security profile inspection using the CPU.
Refer to the exhibit.
The exhibit displays the port1 interface configuration on FortiGate and partial session details for ICMP traffic.
Which two events occur to the session information when a routing change affects this session?
Choose two
AThe session information will not change even when the active route has been removed from the routing table.
BThe session information will not change unless the current route has been removed from the routing table.
CThe session will be flagged as dirty but no route lookups will be performed.
DThis session will be unaffected by routing changes. The routing changes will apply only to new sessions.
Refer to the exhibit.
Partial output from the diagnose hardware sysinfo memory command is displayed.
Which two memory allocations can help troubleshoot a possible resource issue?
Choose two
AThe user space, which has 708880 kB of physical memory that is not used by the system.
BThe 98908 kB of memory that will never be used.
CThe I/O cache, which has 641364 kB of memory allocated to it.
DThe unused cache page, which is represented by the value indicated next to the Inactive heading.
Refer to the exhibit.
FortiGate is experiencing continuous high CPU utilization. During a maintenance window, the CLI command diagnose sys top shows the output in the exhibit.
The CLI command diagnose test application ipsmonitor 5 was executed, but CPU use by the ipsengine daemon did not decrease.
Which immediate action can be taken to reduce CPU usage effectively?
AReduce the number of IPS signatures enabled on the active IPS profiles.
BBypass all IPS engines.
CExecute diagnose test application ipsmonitor 2 instead.
DDisable IPS on all firewall policies.
Refer to the exhibit.
The displayed output is from the diagnose automation test command.
Which two observations can be made from this output?
Choose two
AThe test was unsuccessful.
BThe automation stitch test is not being logged.
CA high availability (HA) failover occurred.
DThe configuration was backed up.
Refer to the exhibits.
Network topology —
OSPF database —
FGT-1 is an area border router (ABR) with interfaces in OSPF areas 0.0.0.0 and 0.0.0.5. FGT-3 operates as an autonomous system border router (ASBR), importing static routes into OSPF. FGT-2 is an internal router, with all of its interfaces in area 0.0.0.5. FGT-1 is receiving every route advertised by FGT-2; however, FGT-3 is not receiving any routes advertised by FGT-1.
What is the most likely cause?
AArea 0.0.0.5 is configured not to propagate type 5 LSAs.
BFGT-2 is configured with a distribution list to block all advertised routes from FGT-3.
CFGT-3 and FGT-2 have not formed an OSPF adjacency yet.
DIP protocol 89 is blocked between FGT-1 and FGT-3.
Refer to the exhibit. The output of the get router info bgp summary command is displayed.
Which statement about the adjacencies between the local router and its neighbors is correct?
AThe local router and neighbor 100.64.2.254 are unable to establish adjacency because AS 100 is already used by neighbor 100.64.1.254.
BThe local router and neighbor 100.64.2.254 are unable to establish adjacency until the adjacency with neighbor 100.64.1.254 ceases.
CThe local router and neighbor 100.64.2.254 are unable to establish adjacency because the TCP session could not be established.
DThe local router and neighbor 100.64.1.254 established adjacency because the priority of 100.64.1.254 is higher than that of 100.64.2.254.
Refer to the exhibits.
An OSPF peer advertises route 172.16.52.0/24. The local FortiGate has an inbound distribution list configured to allow the 172.16.0.0/16 network into its routing table. However, the 172.16.52.0/24 subnet is not visible in the FIB.
Which two actions can the local FortiGate administrator take to ensure the advertised 172.16.52.0/24 subnet is injected into the routing table?
Choose two
AChange the le value to 16.
BAdd another entry to the prefix list to specifically allow the 172.16.52.0/24 network.
CModify the default prefix-list behavior from implicit deny to implicit allow.
DChange the ge value to 17.
Refer to the exhibit. The partial output of a session-table entry is displayed.
Which two statements regarding the output displayed in the exhibit are correct?
Choose two
AThe traffic is tagged for a VLAN interface.
BNP7 is handling offloading of this session.
CThe session has been offloaded.
DThe traffic matches Policy ID 1.
Refer to the exhibit. The partial output from the diagnose sys session stat command is displayed.
Which statement about the output displayed in the exhibit is correct?
A27 sessions have expired but are still in the session table in case any out-of-order packets arrive.
B562 TCP sessions have their proto_state set to 01 if there is no inspection.
CThere have been 131072 recorded ephemeral sessions but there are no current ones.
D113 sessions have been dropped because of memory page exhaustion.
Community Discussion