Nse7 - Efw-7.0 V9.02
Nse7 - Efw-7.0 V9.02
1. Refer to the exhibit, which contains partial output from an IKE real-time debug.
1 / 63
The safer , easier way to help you pass any IT exams.
Which two statements about this debug output are correct? (Choose two.)
A. The remote gateway IP address is 10.0.0.1.
B. The initiator provided remote as its IPsec peer ID.
C. It shows a phase 1 negotiation.
D. The negotiation is using AES128 encryption with CBC hash.
Answer: B,C
2 / 63
The safer , easier way to help you pass any IT exams.
All Internet traffic is currently using port1. The exhibit shows partial information for one sample session of
Internet traffic from an internal user:
What would happen with the traffic matching the above session if the priority on the first default route
(IDd1) were changed from 5 to 20?
A. The session would be deleted, and the client would need to start a new session.
B. The session would remain in the session table, and its traffic would start to egress from port2.
C. The session would remain in the session table, but its traffic would now egress from
both port1 and port2.
D. The session would remain in the session table, and its traffic would still egress from port1.
Answer: D
3. View the central management configuration shown in the exhibit, and then answer the question below.
3 / 63
The safer , easier way to help you pass any IT exams.
Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an
outage?
A. 10.0.1.240
B. One of the public FortiGuard distribution servers
C. 10.0.1.244
D. 10.0.1.242
Answer: B
4. Examine the following partial outputs from two routing debug commands; then answer the question
below:
Why the default route using port2 is not displayed in the output of the second command?
A. It has a lower priority than the default route using port1.
B. It has a higher priority than the default route using port1.
C. It has a higher distance than the default route using port1.
D. It is disabled in the FortiGate configuration.
Answer: C
Explanation:
4 / 63
The safer , easier way to help you pass any IT exams.
http://kb.fortinet.com/kb/viewContent.do?externalId=FD32103
5. An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication
(XAuth) and IKE mode configuration.
The administrator has also enabled the IKE real time debug:
diagnose debug application ike-1
diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dial-up user is
connecting to the VPN?
A. Phase1; IKE mode configuration; XAuth; phase 2.
B. Phase1; XAuth; IKE mode configuration; phase2.
C. Phase1; XAuth; phase 2; IKE mode configuration.
D. Phase1; IKE mode configuration; phase 2; XAuth.
Answer: B
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-ipsecvpn-
54/IPsec_VPN_Concepts/IKE_Packet_Processing.htm
6. View the exhibit, which contains a partial web filter profile configuration, and then answer the question
below.
5 / 63
The safer , easier way to help you pass any IT exams.
Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as
File Sharing and Storage?
A. FortiGate will exempt the connection based on the Web Content Filter configuration.
B. FortiGate will block the connection based on the URL Filter configuration.
C. FortiGate will allow the connection based on the FortiGuard category based filter configuration.
6 / 63
The safer , easier way to help you pass any IT exams.
8. An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover,
the administrator notices that some of the switches in the network continue to send traffic to the former
primary device. The administrator decides to enable the setting link-failed-signal to fix the problem.
Which statement about this setting is true?
A. It sends an ARP packet to all connected devices, indicating that the HA virtual MAC address
is reachable through a new master after a failover.
B. It sends a link failed signal to all connected devices.
C. It disabled all the non-heartbeat interfaces in all HA members for two seconds after a failover.
D. It forces the former primary device to shut down all its non-heartbeat interfaces for one second, while
the failover occurs.
Answer: D
Explanation:
Reference: https://kb.fortinet.com/kb/viewContent.do?externalId=FD40860&sliceId=1
9. Examine the output from the BGP real time debug shown in the exhibit, then the answer the question
below:
Which statements are true regarding the output in the exhibit? (Choose two.)
7 / 63
The safer , easier way to help you pass any IT exams.
10. View the exhibit, which contains the output of a diagnose command, and the answer the question
below.
Which statements are true regarding the Weight value?
A. Its initial value is calculated based on the round trip delay (RTT).
B. Its initial value is statically set to 10.
C. Its value is incremented with each packet lost.
D. It determines which FortiGuard server is used for license validation.
Answer: C
8 / 63
The safer , easier way to help you pass any IT exams.
Assuming all the appropriate firewall policies are configured, which two pings will FortiGate route?
(Choose two.)
9 / 63
The safer , easier way to help you pass any IT exams.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a
web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is
passing through the policy.
What must the administrator change to fix the issue?
A. The administrator must increase webfilter-timeout.
B. The administrator must disable webfilter-force-off.
C. The administrator must change protocol to TCP.
D. The administrator must enable fortiguard-anycast.
Answer: D
10 / 63
The safer , easier way to help you pass any IT exams.
Explanation:
Reference: https://docs.fortinet.com/document/fortigate/6.4.5/cli-reference/109620/config-system-
fortiguard
13. View the exhibit, which contains the output of a diagnose command, and then answer the question
below.
14. Examine the output of the ‘get router info bgp summary’ command shown in the exhibit; then
11 / 63
The safer , easier way to help you pass any IT exams.
12 / 63
The safer , easier way to help you pass any IT exams.
B. BGP peer 10.200.3.1 has never been down since the BGP counters were cleared.
C. Local BGP peer has not received an OpenConfirm from 10.200.3.1.
D. The local BGP peer has received a total of 3 BGP prefixes.
Answer: A,C
15. Two independent FortiGate HA clusters are connected to the same broadcast domain. The
administrator has reported that both clusters are using the same HA virtual MAC address. This creates
a duplicated MAC address problem in the network.
What HA setting must be changed in one of the HA clusters to fix the problem?
A. Group ID.
B. Group name.
C. Session pickup.
D. Gratuitous ARPs.
Answer: A
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_failoverVMAC.htm
16. View the exhibit, which contains the output of a BGP debug command, and then answer the question
below.
Which of the following statements about the exhibit are true? (Choose two.)
A. For the peer 10.125.0.60, the BGP state of is Established.
B. The local BGP peer has received a total of three BGP prefixes.
C. Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.
D. The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.
Answer: A,D
17. Examine the IPsec configuration shown in the exhibit; then answer the question below.
13 / 63
The safer , easier way to help you pass any IT exams.
An administrator wants to monitor the VPN by enabling the IKE real time debug using these commands:
diagnose vpn ike log-filter src-addr4 10.0.10.1
diagnose debug application ike -1
diagnose debug enable
The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged
between both IPsec gateways. However, the IKE real time debug does NOT show any output.
Why isn’t there any output?
A. The IKE real time shows the phases 1 and 2 negotiations only. It does not show any more output once
the tunnel is up.
B. The log-filter setting is set incorrectly. The VPN’s traffic does not match this filter.
C. The IKE real time debug shows the phase 1 negotiation only. For information after that, the
administrator must use the IPsec real time debug instead: diagnose debug application ipsec -1.
D. The IKE real time debug shows error messages only. If it does not provide any output, it indicates that
the tunnel is operating normally.
Answer: B
18. Which real time debug should an administrator enable to troubleshoot RADIUS authentication
problems?
14 / 63
The safer , easier way to help you pass any IT exams.
19. View the exhibit, which contains the output of get sys ha status, and then answer the question below.
20. What events are recorded in the crashlogs of a FortiGate device? (Choose two.)
A. A process crash.
B. Configuration changes.
C. Changes in the status of any of the FortiGuard licenses.
D. System entering to and leaving from the proxy conserve mode.
15 / 63
The safer , easier way to help you pass any IT exams.
Answer: A,D
Explanation:
diagnose debug crashlog read
275: 2014-08-05 13:03:53 proxy=acceptor service=imap session fail
mode=activated276: 2014-08-05 13:03:53 proxy=acceptor service=ftp session fail
mode=activated277: 2014-08-05 13:03:53 proxy=acceptor service=nntp session fail
mode=activated278: 2014-08-06 11:05:47 service=kernel conserve=on free=”45034
pages” red=”45874 pages” msg=”Kernel279: 2014-08-06 11:05:47 enters conserve
mode”280: 2014-08-06 13:07:16 service=kernel conserve=exit free=”86704 pages”
green=”68811 pages”281: 2014-08-06 13:07:16 msg=”Kernel leaves conserve
mode”282: 2014-08-06 13:07:16 proxy=imd sysconserve=exited total=1008 free=349
marginenter=201283: 2014-08-06 13:07:16 marginexit=302
21. View these partial outputs from two routing debug commands:
Which outbound interface will FortiGate use to route web traffic from internal users to the Internet?
A. Both port1 and port2
B. port3
C. port1
D. port2
Answer: C
16 / 63
The safer , easier way to help you pass any IT exams.
22. View the global IPS configuration, and then answer the question below.
17 / 63
The safer , easier way to help you pass any IT exams.
23. Refer to the exhibit, which contains partial output from an IKE real-time debug.
Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?
A. auto-discovery-shortcut
B. auto-discovery-forwarder
C. auto-discovery-sender
D. auto-discovery-receiver
Answer: D
Explanation:
Reference: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/320160/example-advpn-
configuration
First the Spoke receives SHORTCUT_OFFER, it respondes with sending shortcut-query.
AT the end it receives SHORTCUT_REPLY and creates new dynamic tunnel (H2S_0_0).
24. Examine the following partial output from a sniffer command; then answer the question below.
What is the meaning of the packets dropped counter at the end of the sniffer?
18 / 63
The safer , easier way to help you pass any IT exams.
19 / 63
The safer , easier way to help you pass any IT exams.
25. In which two states is a given session categorized as ephemeral? (Choose two.)
A. A TCP session waiting to complete the three-way handshake.
B. A TCP session waiting for FIN ACK.
C. A UDP session with packets sent and received.
D. A UDP session with only one packet received.
Answer: A,D
26. Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit
is elected as the designated router. The second unit is elected as the backup designated router.
Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?
A. 1
B. 2
C. 3
D. 4
Answer: B
27. An administrator has configured a FortiGate device with two VDOMs: root and internal. The
administrator has also created and inter-VDOM link that connects both VDOMs. The objective is to have
each VDOM advertise some routes to the other VDOM via OSPF through the inter-VDOM link.
What OSPF configuration settings must match in both VDOMs to have the OSPF adjacency successfully
forming? (Choose three.)
A. Router ID.
B. OSPF interface area.
C. OSPF interface cost.
D. OSPF interface MTU.
E. Interface subnet mask.
Answer: B,D,E
28. An administrator wants to capture ESP traffic between two FortiGates using the built-in sniffer.
If the administrator knows that there is no NAT device located between both FortiGates, what command
should the administrator execute?
A. diagnose sniffer packet any ‘udp port 500’
B. diagnose sniffer packet any ‘udp port 4500’
C. diagnose sniffer packet any ‘esp’
D. diagnose sniffer packet any ‘udp port 500 or udp port 4500’
Answer: C
Explanation:
20 / 63
The safer , easier way to help you pass any IT exams.
Capture IKE Traffic without NAT:diagnose sniffer packet ‘host and udp port 500’———————————
——————————————————————————-Capture ESP Traffic without NAT:diagnose
sniffer packet any ‘host and esp’————————————————————————————————
—————-Capture IKE and ESP with NAT-T:diagnose sniffer packet any ‘host and (udp port 500 or udp
port 4500)’
29. Which two statements about the Security Fabric are true? (Choose two.)
A. Only the root FortiGate collects network information and forwards it to FortiAnalyzer.
B. FortiGate uses FortiTelemetry protocol to communicate with FortiAnalyzer.
C. All FortiGate devices in the Security Fabric must have bidirectional FortiTelemetry connectivity.
D. Branch FortiGate devices must be configured first.
Answer: B,C
Explanation:
Reference: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/327890/deploying-security-fabric
30. Which two configuration settings change the behavior for content-inspected traffic while FortiGate is
in conserve mode? (Choose two.)
A. IPS failopen
B. mem failopen
C. AV failopen
D. UTM failopen
Answer: A,C
31. An administrator has configured the following CLI script on FortiManager, which failed to apply any
changes to the managed device after being executed.
Why didn’t the script make any changes to the managed device?
A. Commands that start with the # sign are not executed.
B. CLI scripts will add objects only if they are referenced by policies.
C. Incomplete commands are ignored in CLI scripts.
D. Static routes can only be added using TCL scripts.
Answer: A
Explanation:
https://help.fortinet.com/fmgr/50hlp/56/5-6-
2/FortiManager_Admin_Guide/1000_Device%20Manager/2400_Scripts/1000_Script%20sa mples/0200_CLI
%20scripts+.htm#Error_Messages
21 / 63
The safer , easier way to help you pass any IT exams.
A sequence of FortiGate CLI commands, as you would type them at the command line. A comment line
starts with the number sign (#). A comment line will not be executed.
32. View the exhibit, which contains the output of a debug command, and then answer the question
below.
33. Examine the output of the ‘diagnose ips anomaly list’ command shown in the exhibit; then answer
the question below.
34. View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the
question below.
22 / 63
The safer , easier way to help you pass any IT exams.
35. Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF
multi-access network is true?
A. FortiGate first checks the OSPF ID to elect a DR.
B. Non-DR and non-BDR routers will form full adjacencies to DR and BDR only.
C. BDR is responsible for forwarding link state information from one router to another.
D. Only the DR receives link state information from non-DR routers.
Answer: B
36. Examine the following traffic log; then answer the question below.
date-20xx-02-01 time=19:52:01 devname=master device_id="xxxxxxx"
log_id=0100020007 type=event subtype=system pri critical vd=root service=kemel status=failure
msg="NAT port is exhausted."
What does the log mean?
23 / 63
The safer , easier way to help you pass any IT exams.
A. There is not enough available memory in the system to create a new entry in the NAT port table.
B. The limit for the maximum number of simultaneous sessions sharing the same NAT port has been
reached.
C. FortiGate does not have any available NAT port for a new connection.
D. The limit for the maximum number of entries in the NAT port table has been reached.
Answer: B
37. View the exhibit, which contains a partial routing table, and then answer the question below.
Assuming all the appropriate firewall policies are configured, which of the following pings will FortiGate
route? (Choose two.)
A. Source IP address 10.1.0.24, Destination IP address 10.72.3.20.
B. Source IP address 10.72.3.27, Destination IP address 10.1.0.52.
C. Source IP address 10.72.3.52, Destination IP address 10.1.0.254.
D. Source IP address 10.73.9.10, Destination IP address 10.72.3.15.
Answer: B,C
38. View the exhibit, which contains the output of a diagnose command, and then answer the question
below.
24 / 63
The safer , easier way to help you pass any IT exams.
Which statements are true regarding the output in the exhibit? (Choose two.)
A. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
B. Servers with the D flag are considered to be down.
C. Servers with a negative TZ value are experiencing a service outage.
D. FortiGate used 209.222.147.3 as the initial server to validate its contract.
Answer: A,D
Explanation:
A – because flag is Failed so fortigate will check if server is available every 15 minD-state is I , contact to
validate contract info
39. Which of the following statements are correct regarding application layer test commands? (Choose
two.)
A. They are used to filter real-time debugs.
B. They display real-time application debugs.
C. Some of them display statistics and configuration information about a feature or process.
D. Some of them can be used to restart an application.
Answer: C,D
Explanation:
Application layer test commands don’t display info in real time, but they do show statistics and
configuration info about a feature or process. You can also use some of these commands to restart a
process or execute a change in its operation.
25 / 63
The safer , easier way to help you pass any IT exams.
reaches extreme.
C. A FortiGate starts dropping new sessions when the configured memory use threshold reaches red
D. A FortiGate enters conserve mode when the configured memory use threshold reaches red
Answer: D
41. Examine the partial output from two web filter debug commands; then answer the question below:
Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99.com?
A. Finance and banking
B. General organization.
C. Business.
D. Information technology.
Answer: C
26 / 63
The safer , easier way to help you pass any IT exams.
Based on the above output, what FortiGate LDAP settings must the administer check? (Choose two.)
A. cnid.
B. username.
C. password.
D. dn.
Answer: B,C
Explanation:
https://kb.fortinet.com/kb/viewContent.do?externalId=13141
43. Refer to the exhibit, which contains the output of diagnose sys session list.
If the HA ID for the primary unit is zero (0), which statement about the output is true?
A. This session cannot be synced with the slave unit.
B. The inspection of this session has been offloaded to the slave unit.
C. The master unit is processing this traffic.
27 / 63
The safer , easier way to help you pass any IT exams.
44. View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the
question below.
The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic
cannot pass through the tunnel.
To diagnose, the administrator enters these CLI commands:
However, the IKE real time debug does not show any output.
Why?
A. The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show
any more output.
B. The log-filter setting was set incorrectly. The VPN’s traffic does not match this filter.
C. The debug shows only error messages. If there is no output, then the tunnel is operating normally.
D. The debug output shows phase 1 negotiation only. After that, the administrator must enable
the following real time debug: diagnose debug application ipsec -1.
Answer: B
45. View the IPS exit log, and then answer the question below.
# diagnose test application ipsmonitor 3
ipsengine exit log”
28 / 63
The safer , easier way to help you pass any IT exams.
29 / 63
The safer , easier way to help you pass any IT exams.
46. What is the diagnose test application ipsmonitor 99 command used for?
A. To enable IPS bypass mode
B. To provide information regarding IPS sessions
C. To disable the IPS engine
D. To restart all IPS engines and monitors
Answer: D
47. What conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)
A. IP addresses are in the same subnet.
B. Hello and dead intervals match.
C. OSPF IP MTUs match.
D. OSPF peer IDs match.
E. OSPF costs match.
Answer: A,B,C
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-advanced-routing-
54/Routing_OSPF/OSPF_Background_Concepts.htm#Adjacenc
48. Refer to the exhibit, which contains partial outputs from two routing debug commands.
Why is the port2 default route not in the second command's output?
A. It has a higher priority value than the default route using port1.
30 / 63
The safer , easier way to help you pass any IT exams.
49. Which of the following conditions must be met for a static route to be active in the routing table?
(Choose three.)
A. The next-hop IP address is up.
B. There is no other route, to the same destination, with a higher distance.
C. The link health monitor (if configured) is up.
D. The next-hop IP address belongs to one of the outgoing interface subnets.
E. The outgoing interface is up.
Answer: C,D,E
Explanation:
A configured static route only goes to routing table from routing database when all the following are met:
✑ The outgoing interface is up
✑ There is no other matching route with a lower distance ✑ The link health monitor (if configured) is
successful
✑ The next-hop IP address belongs to one of the outgoing interface subnets
50. View the exhibit, which contains the output of a debug command, and then answer the question
below.
Which of the following statements about the exhibit are true? (Choose two.)
A. In the network on port4, two OSPF routers are down.
B. Port4 is connected to the OSPF backbone area.
C. The local FortiGate’s OSPF router ID is 0.0.0.4
D. The local FortiGate has been elected as the OSPF backup designated router.
Answer: B,C
51. How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as
a local FDS?
31 / 63
The safer , easier way to help you pass any IT exams.
52. Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)
A. Installing configuration changes to managed devices
B. Importing interface mappings from managed devices
C. Adding devices to FortiManager
D. Previewing pending configuration changes for managed devices
Answer: A,D
Explanation:
Reference: https://docs.fortinet.com/document/fortimanager/6.2.0/administration-guide/668612/using-
the-install-wizard-to-install-device-settings-only
53. Examine the output from the 'diagnose debug authd fsso list' command; then answer the question
below.
# diagnose debug authd fsso list —FSSO logons-IP: 192.168.3.1 User: STUDENT Groups:
TRAININGAD/USERS Workstation: INTERNAL2. TRAINING. LAB The IP address 192.168.3.1 is NOT
the one used by the workstation INTERNAL2. TRAINING. LAB.
What should the administrator check?
A. The IP address recorded in the logon event for the user STUDENT.
B. The DNS name resolution for the workstation name INTERNAL2. TRAINING. LAB.
C. The source IP address of the traffic arriving to the FortiGate from the workstation
INTERNAL2. TRAINING. LAB.
D. The reserve DNS lookup forthe IP address 192.168.3.1.
Answer: C
54. Which two statements about FortiManager is true when it is deployed as a local FDS? (Choose two.)
A. It caches available firmware updates for unmanaged devices.
B. It can be configured as an update server, or a rating server, but not both.
C. It supports rating requests from both managed and unmanaged devices.
D. It provides VM license validation services.
Answer: C,D
32 / 63
The safer , easier way to help you pass any IT exams.
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user’s
session?
A. The session would remain in the session table, and its traffic would still egress from port1.
33 / 63
The safer , easier way to help you pass any IT exams.
B. The session would remain in the session table, but its traffic would now egress from both port1 and
port2.
C. The session would remain in the session table, and its traffic would start to egress from port2.
D. The session would be deleted, so the client would need to start a new session.
Answer: A
Explanation:
http://kb.fortinet.com/kb/documentLink.do?externalID=FD40943
57. Examine the output of the ‘get router info ospf neighbor’ command shown in the exhibit; then
answer the question below.
34 / 63
The safer , easier way to help you pass any IT exams.
Which statements are true regarding the output in the exhibit? (Choose two.)
Refer to the exhibit, which shows the output of a debug command.
Which statement about the output is true?
A. The OSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the war. l
network.
B. The OSPF router with the ID 0.0.0.2 is the designated router for the ToRemote network.
C. The local FortiGate is the designated router for the wan1 network.
D. The interface ToRemote is a point-to-point OSPF network.
Answer: D
Explanation:
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html
58. What configuration changes can reduce the memory utilization in a FortiGate? (Choose two.)
A. Reduce the session time to live.
B. Increase the TCP session timers.
C. Increase the FortiGuard cache time to live.
D. Reduce the maximum file size to inspect.
Answer: A,D
59. An administrator has enabled HA session synchronization in a HA cluster with two members.
Which flag is added to a primary unit’s session to indicate that it has been synchronized to the secondary
unit?
A. redir.
B. dirty.
C. synced
D. nds.
Answer: C
Explanation:
The synced sessions have the ‘synced’ flag. The command ‘diag sys session list’ can be used to see the
sessions on the member, with the associated flags.
60. View the exhibit, which contains the output of a web diagnose command, and then answer the
question below.
35 / 63
The safer , easier way to help you pass any IT exams.
Which one of the following statements explains why the cache statistics are all zeros?
A. The administrator has reallocated the cache memory to a separate process.
B. There are no users making web requests.
C. The FortiGuard web filter cache is disabled in the FortiGate’s configuration.
D. FortiGate is using a flow-based web filter and the cache applies only to proxy-based inspection.
Answer: C
61. Refer to the exhibit, which contains the output of a BGP debug command.
36 / 63
The safer , easier way to help you pass any IT exams.
62. View the exhibit, which contains the output of a debug command, and then answer the question
below.
63. Which statement is true regarding File description (FD) conserve mode?
A. IPS inspection is affected when FortiGate enters FD conserve mode.
B. A FortiGate enters FD conserve mode when the amount of available description is less than 5%.
C. FD conserve mode affects all daemons running on the device.
D. Restarting the WAD process is required to leave FD conserve mode.
37 / 63
The safer , easier way to help you pass any IT exams.
Answer: B
64. An administrator has configured two FortiGate devices for an HA cluster. While testing the HA
failover, the administrator noticed that some of the switches in the network continue to send traffic to the
former primary unit. The administrator decides to enable the setting link-failed-signal to fix the problem.
Which statement is correct regarding this command?
A. Forces the former primary device to shut down all its non-heartbeat interfaces for one second while
the failover occurs.
B. Sends an ARP packet to all connected devices, indicating that the HA virtual MAC address
is reachable through a new master after a failover.
C. Sends a link failed signal to all connected devices.
D. Disables all the non-heartbeat interfaces in all the HA members for two seconds after a failover.
Answer: A
66. Refer to the exhibit, which contains the output of get system ha status.
38 / 63
The safer , easier way to help you pass any IT exams.
Which two statements about the output are true? (Choose two.)
A. The slave configuration is synchronized with the master.
B. port7 is used as the HA heartbeat on all devices in the cluster.
C. Primary is selected based on the priority configured under config system ha.
D. The HA management IP is 169.254.0.2.
Answer: B,C
67. Examine the output of the ‘get router info bgp summary’ command shown in the exhibit; then
prefix yet.
B. The TCP session for the BGP connection to 10.200.3.1 is down.
C. The local peer has received the BGP prefixed from the remote peer.
D. The local peer is receiving the BGP keepalives from the remote peer but it has not received the
OpenConfirm yet.
Answer: B
Explanation:
http://www.ciscopress.com/articles/article.asp?p=2756480&seqNum=4
68. View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the
question below.
40 / 63
The safer , easier way to help you pass any IT exams.
41 / 63
The safer , easier way to help you pass any IT exams.
69. Which of the following statements is true regarding a FortiGate configured as an explicit web proxy?
A. FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT
be modified by the administrator.
B. FortiGate limits the total number of simultaneous explicit web proxy users.
C. FortiGate limits the number of simultaneous sessions per explicit web proxy user The limit CAN be
modified by the administrator
D. FortiGate limits the number of workstations that authenticate using the same web proxy user
credentials. This limit CANNOT be modified by the administrator.
Answer: B
Explanation:
https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-WAN-opt-52/web_proxy.htm#Explicit2
The explicit proxy does not limit the number of active sessions for each user. As a result the actual
explicit proxy session count is usually much higher than the number of explicit web proxy users. If an
excessive number of explicit web proxy sessions is compromising system performance you can limit the
amount of users if the FortiGate unit is operating with multiple VDOMs.
70. Which statements about bulk configuration changes using FortiManager CLI scripts are correct?
(Choose two.)
A. When executed on the Policy Package, ADOM database, changes are applied directly to
the managed FortiGate.
B. When executed on the Device Database, you must use the installation wizard to apply the changes to
the managed FortiGate.
C. When executed on the All FortiGate in ADOM, changes are automatically installed without creating
a new revision history.
D. When executed on the Remote FortiGate directly, administrators do not have the option to review the
changes prior to installation.
Answer: B,D
Explanation:
CLI scripts can be run in three different ways:Device Database: By default, a script is executed on the
device database. It is recommend you run the changes on the device database (default setting), as this
allows you to check what configuration changes you will send to the managed device. Once scripts are
run on the device database, you can install these changes to a managed device using the installation
wizard.
Policy Package, ADOM database: If a script contains changes related to ADOM level objects
andpolicies, you can change the default selection to run on Policy Package, ADOM database and can
then be installed using the installation wizard.
Remote FortiGate directly (through CLI): A script can be executed directly on the device and you don’t
need to install these changes using the installation wizard. As the changes are directly installed on the
managed device, no option is provided to verify and check the configuration changes through
FortiManager prior to executing it.
71. Refer to the exhibit, which shows the output of a debug command.
42 / 63
The safer , easier way to help you pass any IT exams.
Which two statements about the output are true? (Choose two.)
A. The local FortiGate OSPF router ID is 0.0.0.4.
B. Port4 is connected to the OSPF backbone area.
C. In the network connected to port4, two OSPF routers are down.
D. The local FortiGate is the backup designated router.
Answer: A,B
Explanation:
Area 0.0.0.0 is the backbone area.
72. View the exhibit, which contains the output of diagnose sys session list, and then answer the question
below.
If the HA ID for the primary unit is zero (0), which statement is correct regarding the output?
A. This session is for HA heartbeat traffic.
B. This session is synced with the slave unit.
C. The inspection of this session has been offloaded to the slave unit.
D. This session cannot be synced with the slave unit.
Answer: B
73. View the exhibit, which contains the partial output of a diagnose command, and then answer the
question below.
43 / 63
The safer , easier way to help you pass any IT exams.
74. Which two statements about bulk configuration changes made using FortiManager CLI scripts are
correct? (Choose two.)
A. When run on the Device Database, you must use the installation wizard to apply the changes to the
managed FortiGate device.
B. When run on the Remote FortiGate directly, administrators do not have the option to review the
changes prior to installation.
C. When run on the All FortiGate in ADOM, changes are automatically installed without the creation of
a new revision history.
D. When run on the Policy Package, ADOM database, changes are applied directly to the
managed FortiGate device.
Answer: A,B
Explanation:
Reference: https://docs.fortinet.com/document/fortimanager/6.2.1/administration-guide/71780/cli-scripts
75. Examine the following partial outputs from two routing debug commands; then answer the question
below.
# get router info kernel
tab=254 vf=0 scope=0type=1 proto=11 prio=0 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0
gwy=10.200.1.254 dev=2(port1)
tab=254 vf=0 scope=0type=1 proto=11 prio=10 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0
gwy=10.200.2.254 dev=3(port2)
44 / 63
The safer , easier way to help you pass any IT exams.
76. Refer to exhibit, which contains the output of a BGP debug command.
Which statement explains why the state of the 10.200.3.1 peer is Connect?
A. The local router is receiving BGP keepalives from the remote peer, but the local peer has not received
the OpenConfirm yet.
B. The TCP session to 10.200.3.1 has not completed the three-way handshake.
C. The local router is receiving the BGP keepalives from the peer, but it has not received a BGP
prefix yet.
D. The local router has received the BGP prefixes from the remote peer.
Answer: B
77. Examine the partial output from the IKE real time debug shown in the exhibit; then answer the
question below.
45 / 63
The safer , easier way to help you pass any IT exams.
46 / 63
The safer , easier way to help you pass any IT exams.
C. The remote gateway’s Phase-1 configuration does not match the local gateway’s phase-1
configuration.
D. One IPsec gateway is using main mode, while the other IPsec gateway is using aggressive mode.
Answer: C
The administrator executed the ‘dsquery’ command in the Windows LDAp server 10.0.1.10, and got the
following output:
>dsquery user –samid administrator
“CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab”
Based on the output, what FortiGate LDAP setting is configured incorrectly?
A. cnid.
B. username.
C. password.
D. dn.
Answer: B
Explanation:
https://kb.fortinet.com/kb/viewContent.do?externalId=FD37516
79. Examine the output of the ‘diagnose sys session list expectation’ command shown in the exhibit;
than answer the question below.
47 / 63
The safer , easier way to help you pass any IT exams.
80. View the exhibit, which contains an entry in the session table, and then answer the question below.
Which one of the following statements is true regarding FortiGate’s inspection of this session?
48 / 63
The safer , easier way to help you pass any IT exams.
81. Which the following events can trigger the election of a new primary unit in a HA cluster?
(Choose two.)
A. Primary unit stops sending HA heartbeat keepalives.
B. The FortiGuard license for the primary unit is updated.
C. One of the monitored interfaces in the primary unit is disconnected.
D. A secondary unit is removed from the HA cluster.
Answer: A,C
82. View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the
question below.
Which statements about this debug output are correct? (Choose two.)
A. The remote gateway IP address is 10.0.0.1.
49 / 63
The safer , easier way to help you pass any IT exams.
83. What global configuration setting changes the behavior for content-inspected traffic while FortiGate is
in system conserve mode?
A. av-failopen
B. mem-failopen
C. utm-failopen
D. ips-failopen
Answer: A
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles-
54/Other_Profile_Considerations/Conserve%20mode.htm
84. Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command.
Based on the output, which two statements are correct? (Choose two.)
A. Phase 2 authentication is set to sha1 on both sides.
50 / 63
The safer , easier way to help you pass any IT exams.
B. Anti-replay is disabled.
C. Hub2Spoke1 is a policy-based VPN.
D. Hub2Spoke1 is configured on interface wan2.
Answer: A,D
85. View the exhibit, which contains the output of diagnose sys session stat, and then answer the
question below.
Which statements are correct regarding the output shown? (Choose two.)
A. There are 0 ephemeral sessions.
B. All the sessions in the session table are TCP sessions.
C. No sessions have been deleted because of memory pages exhaustion.
D. There are 166 TCP sessions waiting to complete the three-way handshake.
Answer: A,C
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD40578
86. View the exhibit, which contains the output of a BGP debug command, and then answer the question
51 / 63
The safer , easier way to help you pass any IT exams.
below.
Which of the following statements about the exhibit are true? (Choose two.)
A. The local router's BGP state is Established with the 10.125.0.60 peer.
B. Since the counters were last reset; the 10.200.3.1 peer has never been down.
C. The local router has received a total of three BGP prefixes from all peers.
D. The local router has not established a TCP session with 100.64.3.1.
Answer: A,D
87. Examine the following routing table and BGP configuration; then answer the question below.
The BGP connection is up, but the local peer is NOT advertising the prefix 192.168.1.0/24.
Which configuration change will make the local peer advertise this prefix?
A. Enable the redistribution of connected routers into BGP.
B. Enable the redistribution of static routers into BGP.
C. Disable the setting network-import-check.
D. Enable the setting ebgp-multipath.
Answer: C
89. Which configuration can be used to reduce the number of BGP sessions in an IBGP network?
A. Neighbor range
B. Route reflector
C. Next-hop-self
D. Neighbor group
Answer: B
Explanation:
Route reflectors help to reduce the number of IBGP sessions inside an AS. A route reflector forwards the
routers learned from one peer to the other peers. If you configure route reflectors, you dont’ need to
create a full mesh IBGP network. All clients in a cluster only talck to route reflector to get sync routing
updates. Route reflectors pass the routing updates to other route reflectors and border routers within the
AS.
90. An administrator has decreased all the TCP session timers to optimize the FortiGate memory
usage. However, after the changes, one network application started to have problems. During the
troubleshooting, the administrator noticed that the FortiGate deletes the sessions after the clients send
the SYN packets, and before the arrival of the SYN/ACKs. When the SYN/ACK packets arrive to the
FortiGate, the unit has already deleted the respective sessions.
Which TCP session timer must be increased to fix this problem?
A. TCP half open.
B. TCP half close.
C. TCP time wait.
D. TCP session time to live.
Answer: A
Explanation:
http://docs- legacy.fortinet.com/fos40hlp/43prev/wwhelp/wwhimpl/common/html/wwhelp.htm?
context=fgt&file=CLI_g et_Commands.58.25.html
The tcp-halfopen-timer controls for how long, after a SYN packet, a session without SYN/ACKremains in
the table.
The tcp-halfclose-timer controls for how long, after a FIN packet, a session without FIN/ACKremains in
the table.
The tcp-timewait-timer controls for how long, after a FIN/ACK packet, a session remains in thetable. A
closed session remains in the session table for a few seconds more to allow any out-of-sequence
packet.
91. The CLI command set intelligent-mode <enable | disable> controls the IPS engine’s adaptive
53 / 63
The safer , easier way to help you pass any IT exams.
scanning behavior.
Which of the following statements describes IPS adaptive scanning?
A. Determines the optimal number of IPS engines required based on system load.
B. Downloads signatures on demand from FDS based on scanning requirements.
C. Determines when it is secure enough to stop scanning session traffic.
D. Choose a matching algorithm based on available memory and the type of inspection being performed.
Answer: C
Explanation:
Configuring IPS intelligenceStarting with FortiOS 5.2, intelligent-mode is a new adaptive detection
method. This command is enabled the default and it means that the IPS engine will perform adaptive
scanning so that, for some traffic, the FortiGate can quickly finish scanning and offload the traffic to NPU
or kernel. It is a balanced method which could cover all known exploits. When disabled, the IPS engine
scans every single byte.
config ips globalset intelligent-mode {enable|disable}end
92. Refer to the exhibit, which contains the partial output of a diagnose command.
Based on the output, which two statements are correct? (Choose two.)
A. Anti-replay is enabled.
B. DPD is disabled.
C. Remote gateway IP is 10.200.4.1.
D. Quick mode selectors are disabled.
Answer: A,C
54 / 63
The safer , easier way to help you pass any IT exams.
94. When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate
filter web requests when the client browser does not provide the server name indication (SNI)
extension?
A. FortiGate uses the requested URL from the user’s web browser.
B. FortiGate uses the CN information from the Subject field in the server certificate.
C. FortiGate blocks the request without any further inspection.
D. FortiGate switches to the full SSL inspection method to decrypt the data.
Answer: B
95. Examine the following partial output from two system debug commands; then answer the question
below.
55 / 63
The safer , easier way to help you pass any IT exams.
Which of the following statements are true regarding the above outputs? (Choose two.)
A. The unit is running a 32-bit FortiOS
B. The unit is in kernel conserve mode
C. The Cached value is always the Active value plus the Inactive value
D. Kernel indirectly accesses the low memory (LowTotal) through memory paging
Answer: A,C
97. Refer to the exhibit, which contains a TCL script configuration on FortiManager.
56 / 63
The safer , easier way to help you pass any IT exams.
An administrator has configured the TCL script on FortiManager, but failed to apply any changes to the
managed device after being executed.
B. The TCL script must start with #include <>.
C. Incomplete commands are ignored in TCL scripts.
D. The TCL command run_cmd has not been created.
Answer: D
98. A FortiGate is configured as an explicit web proxy. Clients using this web proxy are reposting
DNS errors when accessing any website.
The administrator executes the following debug commands and observes that the n-dns-timeout counter
is increasing:
99. View the exhibit, which contains a partial output of an IKE real-time debug, and then answer the
question below.
57 / 63
The safer , easier way to help you pass any IT exams.
Based on the debug output, which phase-1 setting is enabled in the configuration of this VPN?
A. auto-discovery-sender
B. auto-discovery-forwarder
C. auto-discovery-shortcut
D. auto-discovery-receiver
Answer: B
100. Refer to the exhibit, which contains a TCL script configuration on FortiManager.
An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any
changes to the managed device after being run.
58 / 63
The safer , easier way to help you pass any IT exams.
Why did the TCL script fail to make any changes to the managed device?
A. The TCL command run_cmd has not been created.
B. The TCL script must start with tinclude <>.
C. Incomplete commands are ignored in TCL scripts.
D. Changes to an interface configuration can be made only by a CLI script.
Answer: A
101. Refer to the exhibit, which contains the debug output of diagnose dvm device list.
Which two statements about the output shown in the exhibit are correct? (Choose two.)
A. ADOMs are disabled on the FortiManager
B. The FortiGate configuration is in sync with latest running revision history.
C. There are pending device-level changes yet to be installed on Local-FortiGate.
D. The policy package has been modified for Local-FortiGate.
Answer: B,C
Explanation:
Reference: https://docs.fortinet.com/document/fortimanager/7.0.0/upgrade-guide/959309/cli-example-of-
diagnose-dvm-device-list
59 / 63
The safer , easier way to help you pass any IT exams.
103. Which two statements about OCVPN are true? (Choose two.)
A. Only root vdom supports OCVPN.
B. OCVPN supports static and dynamic IPs in WAN interface.
C. OCVPN offers only Hub-Spoke VPNs.
D. FortiGate devices under different FortiCare accounts can be used to form OCVPN.
Answer: A,B
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/977344/one-click-vpn-ocvpn
https://docs.fortinet.com/document/fortigate/6.2.9/cookbook/496884/overlay-controller-vpn-ocvpn
105. View the exhibit, which contains a session entry, and then answer the question below.
Which statement is correct regarding this session?
A. It is an ICMP session from 10.1.10.10 to 10.200.1.1.
B. It is an ICMP session from 10.1.10.10 to 10.200.5.1.
C. It is a TCP session in ESTABLISHED state from 10.1.10.10 to 10.200.5.1.
D. It is a TCP session in CLOSE_WAIT state from 10.1.10.10 to 10.200.1.1.
Answer: B
106. Which of the following statements are true regarding the SIP session helper and the SIP
application layer gateway (ALG)? (Choose three.)
60 / 63
The safer , easier way to help you pass any IT exams.
A. SIP session helper runs in the kernel; SIP ALG runs as a user space process.
B. SIP ALG supports SIP HA failover; SIP helper does not.
C. SIP ALG supports SIP over IPv6; SIP helper does not.
D. SIP ALG can create expected sessions for media traffic; SIP helper does not.
E. SIP helper supports SIP over TCP and UDP; SIP ALG supports only SIP over UDP.
Answer: B,C,D
107. Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the
question below.
Which statement are true regarding the output in the exhibit? (Choose two.)
A. There are three FortiGuard servers that are not responding to the queries sent by the FortiGate.
B. The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's
time zone.
C. FortiGate will send the FortiGuard queries to the server with highest weight.
D. A server's round trip delay (RTT) is not used to calculate its weight.
Answer: B,C
108. Examine the output of the ‘get router info ospf interface’ command shown in the exhibit; then
answer the question below.
61 / 63
The safer , easier way to help you pass any IT exams.
Which statements are true regarding the above output? (Choose two.)
A. The port4 interface is connected to the OSPF backbone area.
B. The local FortiGate has been elected as the OSPF backup designated router.
C. There are at least 5 OSPF routers connected to the port4 network.
D. Two OSPF routers are down in the port4 network.
Answer: A,C
Explanation:
on BROADCAST network there are 4 neighbors, among which 1*DR +1*BDR. So our FG has 4
neighbors, but create adjacency only with 2 (with DR and BDR). 2 neighbors DRother (not down).
109.Exhibits:
62 / 63
The safer , easier way to help you pass any IT exams.
Refer to the exhibits, which contain the network topology and BGP configuration for a hub.
An administrator is trying to configure ADVPN with a hub-spoke VPN setup using iBGP. All the VPNs are
up and connected to the hub. The hub is receiving route information from both spokes over iBGP;
however, the spokes are not receiving route information from each other.
What change must the administrator make to the hub BGP configuration so that the routes learned by
one spoke are forwarded to the other spokes?
A. Configure an individual neighbor and remove neighbor-range configuration.
B. Configure the hub as a route reflector client.
C. Change the router id to 10.1.0.254.
D. Make the configuration of remote-as different from the configuration of local-as.
Answer: B
63 / 63
The safer , easier way to help you pass any IT exams.
111. Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)
A. Preview pending configuration changes for managed devices.
B. Add devices to FortiManager.
C. Import policy packages from managed devices.
D. Install configuration changes to managed devices.
E. Import interface mappings from managed devices.
Answer: A,D
Explanation:
https://help.fortinet.com/fmgr/50hlp/56/5-6-
2/FortiManager_Admin_Guide/1000_Device%20Manager/1200_install_to%20devices/0400_Install%20w
izard-device%20settings.htm
There are 4 main wizards:Add Device: is used to add devices to central management and import their
configurations.
Install: is used to install configuration changes from Device Manager or Policies & Objects to the
managed devices. It allows you to preview the changes and, if the administrator doesn’t agree with the
changes, cancel and modify them.
Import policy: is used to import interface mapping, policy database, and objects associated with the
managed devices into a policy package under the Policy & Object tab. It runs with the Add Device wizard
by default and may be run at any time from the managed device list.
Re-install policy: is used to perform a quick install of the policy package. It doesn’t give the ability to
preview the changes that will be installed to the managed device.
112. View the exhibit, which contains the output of a real-time debug, Which statement about this output
is true?
64 / 63
The safer , easier way to help you pass any IT exams.
113. Examine the output from the ‘diagnose vpn tunnel list’ command shown in the exhibit; then
answer the question below.
Which command can be used to sniffer the ESP traffic for the VPN DialUP_0?
A. diagnose sniffer packet any ‘port 500’
B. diagnose sniffer packet any ‘esp’
C. diagnose sniffer packet any ‘host 10.0.10.10’
65 / 63
The safer , easier way to help you pass any IT exams.
114. Which two statements about an auxiliary session are true? (Choose two.)
A. With the auxiliary session setting enabled, ECMP traffic is accelerated to the NP6 processor.
B. With the auxiliary session setting enabled, two sessions will be created in case of routing change.
C. With the auxiliary session setting disabled, for each traffic path, FortiGate will use the same auxiliary
session.
D. With the auxiliary session disabled, only auxiliary sessions will be offloaded.
Answer: C,D
Explanation:
Reference: https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/14295/controlling-
return-path-with-auxiliary-session
Based on the output in the exhibit, what can cause this authentication problem?
A. User student is not found in the LDAP server.
B. User student is using a wrong password.
C. The FortiGate has been configured with the wrong password for the LDAP administrator.
D. The FortiGate has been configured with the wrong authentication schema.
Answer: A
116. Which two conditions must be met for a statistic route to be active in the routing table? (Choose
two.)
66 / 63
The safer , easier way to help you pass any IT exams.
117. A FortiGate's portl is connected to a private network. Its port2 is connected to the Internet. Explicit
web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is
NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP.
Which statements are true regarding the two entries in the FortiGate session table related with this
traffic? (Choose two.)
A. Both session have the local flag on.
B. The destination IP addresses of both sessions are IP addresses assigned to FortiGate's interfaces.
C. One session has the proxy flag on, the other one does not.
D. One of the sessions has the IP address of port2 as the source IP address.
Answer: A,D
118. Refer to the exhibit, which contains the partial output of a diagnose command.
Based on the output, which two statements are correct? (Choose two.)
A. Anti-replay is enabled
B. The remote gateway IP is 10.200.4.1.
C. DPD is disabled.
D. Quick mode selectors are disabled.
Answer: A,B
119. When using the SSL certificate inspection method for HTTPS traffic, how does FortiGate filter
web requests when the browser client does not provide the server name indication (SNI) extension?
A. FortiGate uses CN information from the Subject field in the server’s certificate.
B. FortiGate switches to the full SSL inspection method to decrypt the data.
C. FortiGate blocks the request without any further inspection.
D. FortiGate uses the requested URL from the user’s web browser.
67 / 63
The safer , easier way to help you pass any IT exams.
Answer: A
120. The logs in a FSSO collector agent (CA) are showing the following error:
failed to connect to registry: PIKA1026 (192.168.12.232)
What can be the reason for this error?
A. The CA cannot resolve the name of the workstation.
B. The FortiGate cannot resolve the name of the workstation.
C. The remote registry service is not running in the workstation 192.168.12.232.
D. The CA cannot reach the FortiGate with the IP address 192.168.12.232.
Answer: C
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD30548
121. An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254.
The administrator runs the debug flow while attempting the connection using HTTP.
122. A corporate network allows Internet Access to FSSO users only. The FSSO user student does not
have Internet access after successfully logged into the Windows AD network. The output of the
‘diagnose debug authd fsso list’ command does not show student as an active FSSO user. Other FSSO
users can access the Internet without problems.
What should the administrator check? (Choose two.)
A. The user student must not be listed in the CA’s ignore user list.
B. The user student must belong to one or more of the monitored user groups.
C. The student workstation’s IP subnet must be listed in the CA’s trusted list.
D. At least one of the student’s user groups must be allowed by a FortiGate firewall policy.
Answer: A,D
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD38828
68 / 63