Fortinet FCSS - Enterprise Firewall 7.6 Administrator - FCSS_EFW_AD-7.6 Exam Practice Test

You applied a block-all intrusion prevention system (IPS) profile for client and server targets to secure the server, but the database team reported that applications stopped working immediately after. How can you apply IPS in a way that ensures it does not disrupt existing applications in the network?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Users in your organization who are on an IPsec VPN between FortiGate A and FortiGate B are experiencing intermittent issues since implementing VXLAN. You suspect that packets exceeding the 1500-byte default maximum transmission unit (MTU) are causing the problems. How would you adjust the interface MTU value help resolve issues caused by protocols that add extra headers to IP packets?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Refer to the exhibit.

FortiGate_A and FortiGate_B are members of a FortiGate Session Life Support Protocol (FGSP) cluster in an enterprise network.
While testing the cluster using the ping command, you monitor packet loss and on FortiGate_B, you see the session list output is shown in the exhibit.
What is causing this output on FortiGate_B?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
You must enable direct communication between multiple spokes in a organization's network.
Each spoke has more than one internet connection. Each spoke must connect directly without passing through the hub and the links must automatically switch to the best available connection.
How can you achieve automatic detection and optimal link utilization between spokes?

Correct Answer: A Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A company that acquired multiple branches across different countries needs to install new FortiGate devices on each of those branches. However, the IT staff lacks sufficient knowledge to implement the initial configuration on the FortiGate devices.
Which three approaches can the company take to successfully deploy advanced initial configurations on remote branches? (Choose three.)

Correct Answer: C,D,E Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration.


Why is FortiGate unable to detect HTTPS attacks on firewall policy ID 3 targeting the Linux server?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Refer to the exhibit, which shows an ADVPN network.

An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2.
What must the administrator configure in the phase 1 VPN IPSEC configuration of the Hub2Hub tunnels?

Correct Answer: B Vote an answer
A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server.
What can the firewall administrator do to block all outdated SSL/TLS versions on any HTTPS web server to prevent possible attacks on user traffic?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday

Support: Contact now 

日本語 Deutsch 繁体中文 한국어