全面的FCSS_NST_SE-7.4認證考試解析,最新的考試資料幫助妳壹次性通過FCSS_NST_SE-7.4考試如果你選擇了報名參加Fortinet FCSS_NST_SE-7.4 認證考試,你就應該馬上選擇一份好的學習資料或培訓課程來準備考試。因為Fortinet FCSS_NST_SE-7.4 是一個很難通過的認證考試,要想通過考試必須為考試做好充分的準備。 最新的 Fortinet Certified Solution Specialist FCSS_NST_SE-7.4 免費考試真題 (Q38-Q43):問題 #38
Refer to the exhibit, which shows a partial output from the get router info routing-table database command.
The administrator wants to configure a default static route for port3 and assign a distance of 50 and a priority of 0.
What will happen to the port1 and port2 default static routes after the port3 default static route is created?
A. Both default static routes shown in the output will be injected into the FIB.
B. The port1 default static route will be injected into the FIB.
C. Neither of the routes shown in the output will be injected into the FIB.
D. The port2 default static route will be injected into the forwarding information base (FIB).
答案:D
問題 #39
Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs. What three conclusions can you draw from these log entries? (Choose three.)
A. DNS resolution is unable to resolve the workstation name.
B. Remote registry is not running on the workstation.
C. The FortiGate firmware version is not compatible with that of the collector agent.
D. The user's status shows as "not verified" in the collector agent.
E. A firewall is blocking traffic to port 139 and 445.
答案:B,D,E
解題說明:
Because the collector can't reach the workstation's registry, that host will remain in a "not verified" state in the FSSO collector agent.
A failure to connect to the remote registry almost always means the Remote Registry service on the Windows box is stopped or disabled.
Alternatively (or additionally), a host based or network firewall blocking SMB/RPC ports 139 or 445 will produce exactly this "failed to connect" error.
問題 #40
Refer to the exhibit, which shows the modified output of the routing kernel.
Which statement is true?
A. The default static route through 10.200.1.254 is not in the forwarding information base.
B. The BGP route to 10.0.4.0/24 is not in the forwarding information base.
C. The egress interface associated with static route 8.8.8.8/32 is administratively up.
D. The default static route through port2 is in the forwarding information base.
答案:B
問題 #41
Which two statements about an auxiliary session ate true? (Choose two.)
A. With the auxiliary session selling disabled, only auxiliary sessions are offloaded.
B. With the auxiliary session setting disabled, for each traffic path, FortiGate uses the same auxiliary session.
C. With the auxiliary session setting enabled, ECMP traffic is accelerated to the NP6 processor.
D. With the auxiliary session setting enabled, two sessions are created in case of routing change.
答案:C,D
問題 #42
Exhibit.
Refer to the exhibit, which shows the output of get system ha status.
NGFW-1 and NGFW-2 have been up for a week.
Which two statements about the output are true? (Choose two.)
A. If no action is taken, the primary FortiGate will leave the cluster because of the current sync status.
B. If port 7 becomes disconnected on the secondary, both FortiGate devices will elect itself as primary.
C. If FGVM...649 is rebooted. FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.
D. If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.