Fortinet NSE7_FSN_AR-7.6 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: SD-WAN | - Deployment and troubleshooting - SD-WAN routing - Performance SLA - SD-WAN architecture - Application steering - Overlay VPN |
| Topic 2: Enterprise Firewall | - Security Fabric integration - Authentication and identity - Advanced firewall deployment - VPN technologies - Centralized management and analytics - Routing and advanced networking - Troubleshooting - High availability |
Fortinet NSE 7 - Secure Networking 7.6 Architect Sample Questions:
Question 1
Refer to the exhibit.
The network diagram shows the addition of Site 2 with an overlapping network segment to the existing IPsec VPN connection between the hub and Site 1.
Which IPsec phase 2 configuration must you make on the FortiGate hub to enable equal-cost multipath (ECMP) routing when multiple remote sites connect with overlapping subnets?
A. Set route-overlap to either use-new or use-old.
B. Set multipath to enable.
C. Set route-overlap to allow.
D. Set net-device to ecmp.
Question 2
Refer to the exhibits,
which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network. If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session? (Choose one answer)
A. The session would be deleted, and the client would need to start a new session.
B. The session would remain in the session table, and its traffic would egress from port2.
C. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
D. The session would remain in the session table, and its traffic would egress from port1.
Question 3
Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real- time debug? (Choose three.)
A. FortiGate cannot reach the IP address of the collector agent.
B. The group filters do not match.
C. The pro-shared key does not match
D. The SSL certificate used for FSSO over SSL has expired.
E. The connection was refused. There may be a mismatch of the TCP port.
Question 4
Refer to the exhibit.
The output of the command diagnose vpn tunnel list is shown.
Reviewing the debug command, what is the current status of the traffic flowing through the tunnel?
A. The inbound IPsec SA was copied to the NPU.
B. NP6 is handling the offloading.
C. The inbound and outbound IPsec SAs were copied to the NPU.
D. The outbound IPsec SA was copied to the NPU.
Question 5
Refer to the exhibit, which shows the partial output of a real-time OSPF debug.
Why are the two FortiGate devices unable to form an adjacency?
A. The two FortiGate devices attempting adjacency are in area 0.0.0.0.
B. The passwords on the FortiGate devices do not match.
C. One FortiGate device is configured to require authentication, while the other is not.
D. The Hello packet is being sent from an OSPF router with ID 0.0.0.112.
Solutions:
| Question 1 Answer: C | Question 2 Answer: A | Question 3 Answer: A,C,E | Question 4 Answer: A | Question 5 Answer: C |














654 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
