Fortinet FCSS - Enterprise Firewall 7.6 Administrator - FCSS_EFW_AD-7.6무료 덤프문제 풀어보기
Refer to the exhibits.



The configuration of a user's Windows PC, which has a default MTU of 1500 bytes, along with FortiGate interfaces set to an MTU of 1000 bytes, and the results of PC1 pinging server
172.16.0.254 are shown.
Why is the user in Windows PC1 unable to ping server 172.16.0.254 and is seeing the message:
Packet needs to be fragmented but DF set?



The configuration of a user's Windows PC, which has a default MTU of 1500 bytes, along with FortiGate interfaces set to an MTU of 1000 bytes, and the results of PC1 pinging server
172.16.0.254 are shown.
Why is the user in Windows PC1 unable to ping server 172.16.0.254 and is seeing the message:
Packet needs to be fragmented but DF set?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
What does the command set forward-domain <domain_ID> in a transparent VDOM interface do?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Refer to the exhibit, which contains the partial output of an OSPF command.

An administrator is checking the OSPF status of a FortiGate device and receives the output shown in the exhibit.
Which statement on this FortiGate device is correct?

An administrator is checking the OSPF status of a FortiGate device and receives the output shown in the exhibit.
Which statement on this FortiGate device is correct?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
What must be done for RIP routes to propagate into OSPF?
정답: B
Refer to the exhibit.

The network diagram shows the addition of Site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and Site 1.
Which IPsec phase 2 configuration must you make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?

The network diagram shows the addition of Site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and Site 1.
Which IPsec phase 2 configuration must you make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?
정답: D
설명: (Fast2test 회원만 볼 수 있음)
Which two statements about IKEv2 are true if an administrator decides to implement IKEv2 in the VPN topology? (Choose two.)
정답: A,D
설명: (Fast2test 회원만 볼 수 있음)
Refer to the exhibit.

A normalized interface LAN on FortiManager is shown.
Which two statements about this interface configuration are correct? (Choose two.)

A normalized interface LAN on FortiManager is shown.
Which two statements about this interface configuration are correct? (Choose two.)
정답: B,C
설명: (Fast2test 회원만 볼 수 있음)
In which two ways does FortiGate utlize the Internet Service Database (ISDB) within firewall policies and SD-WAN rules? (Choose two.)
정답: C,D
설명: (Fast2test 회원만 볼 수 있음)
Which parameter should be configured to scale iBGP sessions?
정답: A
Refer to the exhibit.

The packet capture output of a client hello message is shown.
You are updating a firewall policy that includes SSL certificate inspection. You are capturing packets from the traffic passing through this firewall policy.
Which two statements about the packet capture are correct? (Choose two.)

The packet capture output of a client hello message is shown.
You are updating a firewall policy that includes SSL certificate inspection. You are capturing packets from the traffic passing through this firewall policy.
Which two statements about the packet capture are correct? (Choose two.)
정답: A,C
설명: (Fast2test 회원만 볼 수 있음)
A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server.
What can the firewall administrator do to block all outdated SSL/TLS versions on any HTTPS web server to prevent possible attacks on user traffic?
What can the firewall administrator do to block all outdated SSL/TLS versions on any HTTPS web server to prevent possible attacks on user traffic?
정답: A
설명: (Fast2test 회원만 볼 수 있음)