Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet NSE 7 Network Security Architect NSE7_NST-7.2 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE7_NST-7.2 Premium Access

View all detail and faqs for the NSE7_NST-7.2 exam


393 Students Passed

84% Average Score

97% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Question # 1

Refer to the exhibit, which shows the modified output of the routing kernel.

Which statement is true?

Options:

A.

The BGP route to 10.0.4.0/24 is not in the forwarding information base.

B.

The default static route through port2 is in the forwarding information base.

C.

The default static route through 10.200.1.254 is not in the forwarding information base.

D.

The egress interface associated with static route 8.8.8.8/32 is administratively up.

Questions # 2:

Refer to the exhibit, which shows the omitted output of FortiOS kernel slabs.

Question # 2

Which statement is true?

Options:

A.

The total slab size of the tcp_sessior. slab Is 7500 kB and is associated with the kernel.

B.

The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.

C.

The total slab size of the sctp_session slab is 0 kB and is associated with the user space

D.

The total slab size of the ip_session slab is 3600 kB and is associated with the user space.

Questions # 3:

Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.

Question # 3

What three conclusions can you draw from these log entries? (Choose three.)

Options:

A.

Remote registry is not running on the workstation.

B.

The FortiGate firmware version is not compatible with that of the collector agent

C.

DNS resolution is unable to resolve the workstation name.

D.

The user's status shows as "not verified" in the collector agent

E.

A firewall is blocking traffic to port 139 and 445.

Questions # 4:

Which of the following regarding protocol states is true?

Options:

A.

proto_state=00 indicates that UDP traffic flows in both directions.

B.

proto_state-01 indicates an established TCP session.

C.

proto_state=10 indicates an established TCP session.

D.

proto state=01 indicates one-way ICMP traffic.

Questions # 5:

Which two statements about conserve mode are true? (Choose two.)

Options:

A.

FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.

B.

FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.

C.

FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.

D.

FortiGate exits conserve mode when the system memory goes below the configured green threshold

Questions # 6:

What is the diagnosetest applicationipsmonitor 5 command used for?

Options:

A.

To disable the IPS engine

B.

To provide information regarding IPS sessions

C.

To restart all IPS engines and monitors

D.

To enable IPS bypass mode

Questions # 7:

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which action will FortiGate take when using the default settingsfor SSL certificate inspection?

Options:

A.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration

B.

FortiGate uses the 31 information from the Subject field in the server certificate.

C.

FortiGate uses the first entry listed in the SAN field in the server certificate.

D.

FortiGate uses the SNI from the user's web browser.

Questions # 8:

Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)

Options:

A.

OSPF link costs match.

B.

OSPF interface priority settings are unique

C.

OSPF interface network types match

D.

Authentication settings match.

E.

OSPF router IDs are unique.

Questions # 9:

Question # 9

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command

What two conclusions can you draw from the output? (Choose two.)

Options:

A.

FSSO is using agentless polling mode to detect logon events.

B.

The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on

C.

The logon event can be seen on the collector agent installed on Windows.

D.

FSSO is using DC agent mode to detect logon events.

Questions # 10:

Which statement about IKE and IKE NAT-T is true?

Options:

A.

IKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface.

B.

IKE is the standard implementation for IKEv1and IKE NAT-T is an extension added in IKEv2.

C.

They each use their own IP protocol number.

D.

They both use UDP as their transport protocol and the port number is configurable.

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.