FCSS - Network Security 7.6 Support Engineer Questions and Answers
An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.
If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?
Refer to the exhibit, which shows the output of get router info ospf neighbor.
What can you conclude from the command output?
In IKEv2, which exchange establishes the first CHILD_SA?
Refer to the exhibit, which shows a partial web filter profile configuration.
The URL is categorized as File Sharing and Storage.
Which action does FortiGate take if a user attempts to access
In the SAML negotiation process, which section does the Identity Provider (IdP) provide the SAML attributes utilized in the authentication process to the Service Provider (SP)?
Refer to the exhibit, which shows a partial output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
Refer to the exhibit, which shows the output of a BGP debug command.
What can you conclude about the router in this scenario?
Refer to the exhibit, which shows the omitted output of a session table entry.
Which two statements are true? (Choose two.)
Refer to the exhibits.
An administrator Is expecting to receive advertised route 8.8.8.8/32 from FGT-A. On FGT-B, they confirm that the route is being advertised and received, however, the route is not being injected into the routing table. What is the most likely cause of this issue?
Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.
Which action will FortiGate take when using the default settings for SSL certificate inspection?
Refer to the exhibit, which shows the output o! the BGP database.
Which two statements are correct? (Choose two.)
Which authentication option can you not configure under config user radius on FortiOS?
Which statement about IKEv2 is true?
Refer to the exhibit, which shows the partial output of a real-time OSPF debug.
Why are the two FortiGate devices unable to form an adjacency?
Refer to the exhibit showing a debug output.
An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is deployed is successful.
The administrator then produces the debug output shown in the exhibit.
What could be causing this error message?
Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real-time debug? (Choose three.)
Refer to the exhibit, which contains partial output from an IKE real-time debug.
The administrator does not have access to the remote gateway.
Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?
Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
Which two statements about conserve mode are true? (Choose two.)