Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet NSE 7 Network Security Architect NSE7_NST-7.2 Questions and answers with ValidTests

Exam NSE7_NST-7.2 All Questions
Exam NSE7_NST-7.2 Premium Access

View all detail and faqs for the NSE7_NST-7.2 exam

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.

Question # 1

What three conclusions can you draw from these log entries? (Choose three.)

Options:

A.

Remote registry is not running on the workstation.

B.

The FortiGate firmware version is not compatible with that of the collector agent

C.

DNS resolution is unable to resolve the workstation name.

D.

The user's status shows as "not verified" in the collector agent

E.

A firewall is blocking traffic to port 139 and 445.

Expert Solution
Questions # 2:

Which three common FortiGate-to-collector-agent connectivity issues can you identifyusing the FSSO real-time debug?(Choose three.)

Options:

A.

Refused connection. Potential mismatch of TCP port.

B.

Mismatched pre-shared password.

C.

Inability to reach IP address of the collector agent.

D.

Log is full on the collector agent.

E.

Incompatible collector agent software version.

Expert Solution
Questions # 3:

Exhibit.

Question # 3

Refer to the exhibit, which shows the output of getrouterinfo bgp neighbors100.64.2.254.

What can you conclude from the output?

Options:

A.

The BGP neighbor is advertising the 10.20.30.40/24 network to the local router.

B.

The router ID of the neighbor is 100.64.2.254.

C.

The BGP state of the two BGP participants is OpenConfirm.

D.

The local router is adverting the 10.20.30.40/24 network to its BGP neighbor.

Expert Solution
Questions # 4:

Refer to the exhibit, which shows the output of a real-time debug.

Question # 4

Which statement about this output is true?

Options:

A.

The server hostname was extracted from the SNI in the client request, or from the CN in the server certificate

B.

FortiGate found the requested URL in its local cache.

C.

This web request was inspected using the rtgd-allowweb filter profile.

D.

The requested URL belongs to category ID 255.

Expert Solution
Questions # 5:

Refer to the exhibit, which shows the omitted output of a real-time OSPF debug

Question # 5

Which statement is false?

Options:

A.

A password has been configured on the local OSPF router but is not shown in the output

B.

The Hello packet is being sent from an OSPF router with ID 0.0.0.112.

C.

The two FortiGate devices attempting adjacency are in area 0.0.0.0.

D.

One FortiGate device is configured to require authentication, while the other is not

Expert Solution
Questions # 6:

What is the diagnosetest applicationipsmonitor 5 command used for?

Options:

A.

To disable the IPS engine

B.

To provide information regarding IPS sessions

C.

To restart all IPS engines and monitors

D.

To enable IPS bypass mode

Expert Solution
Questions # 7:

There are four exchanges during IKEv2 negotiation.

Which sequence is correct?

Options:

A.

IKE_Proposal,ID_Auth, PiggyBack_CHILD and Informational

B.

lnit_Req, Wait_lnit_Req,ID_Auth_Req and Create_CHILD_SA

C.

INIT_Re, INIT_Auth,ID_Child and SET_Nonce

D.

IKE_SAJNIT, IKE_Auth, Create_CHILD_SA and Informational

Expert Solution
Questions # 8:

Exhibit.

Question # 8

Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command. Based on the output, which two statements are correct? (Choose two.)

Options:

A.

Anti-replay is enabled.

B.

The npu_flag for this tunnel is 03.

C.

The npu_flag for this tunnel is 02

D.

Different SPI values are a result of auto-negotiation being disabled for phase 2 selectors.

Expert Solution
Questions # 9:

Question # 9

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command

What two conclusions can you draw from the output? (Choose two.)

Options:

A.

FSSO is using agentless polling mode to detect logon events.

B.

The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on

C.

The logon event can be seen on the collector agent installed on Windows.

D.

FSSO is using DC agent mode to detect logon events.

Expert Solution
Questions # 10:

Refer to the exhibit, which shows the output of a BGP debug command.

Question # 10

Which statement explains why the state of the 10.200.3.1 peer is Connect?

Options:

A.

The local router initiated the BGP session to 10.200.3.1 but did not receive a response.

B.

The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the OpenConf inn yet.

C.

The router 10.200.3.1 has authentication configured for BGP and the local router does not.

D.

The local router has a different AS number than the remote peer.

Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions