QuestionQ1
System troubleshootingRefer to the exhibit.

Which three items of information are provided by the diagnose sys top command?
- A The miglogd daemon is running on CPU core ID 0.
- B The cmdbsvr process is occupying 2.4% of the total user memory space.
- C The diagnose sys top command has been running for 18 minutes.
- D If the newcli daemon continues to be in the R state, it will need to be manually restarted.
- E The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.
QuestionQ2
System troubleshootingRefer to the exhibit.
Partial output from a diagnose command

A partial output of a diagnose command is displayed. Which two conclusions can you draw from the output in the exhibit?
- A FortiGate will drop the expected traffic if it does not arrive within 23 seconds.
- B The packets that belong to this session are checked against firewall policy ID 25.
- C The TCP session is not established.
- D This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.
Community Discussion
QuestionQ3
RoutingWhich two protocol states show that traffic is bidirectional?
- A proto_state=05 for a TCP session.
- B proto_state=01 for a TCP session.
- C proto_state=01 for a UDP session.
- D proto_state=00 for an ICMP session.
Community Discussion
QuestionQ4
RoutingRefer to the exhibits.
Exhibit 1 –

Exhibit 2 –

The FortiGate configuration and partial Internet-session information for a user on the internal network are displayed.
An administrator wants to test session failover between the two service-provider connections. Which two changes must the administrator make to force this existing session to immediately begin using the other interface?
- A Modify the distance of the port1 route to 1.
- B Change the priority of the port1 static route to 11.
- C Configure set snat-route-change enable.
- D Change the priority of the port2 static route to 5.
Community Discussion
QuestionQ5
RoutingRefer to the exhibits.

An administrator is trying to advertise the network configured on port3, but FGT-A is not receiving the prefix.
Which two actions can the administrator perform to resolve this issue?
- A Modify the prefix using the network command and specify le 16 to include the 172.16.54.0/24 subnet.
- B Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.
- C Use the set network-import-check disable command.
- D Restart BGP using a soft reset to force both peers to exchange their complete BGP routing tables.


















Community Discussion