Fortinet FCSS_EFW_AD-7.6 - NSE 7 - Enterprise Firewall 7.6 Administrator Exam

Question #11 (Topic: Exam A)
Refer to the exhibits.

The system administrator settings configured on a root FortiGate and the Security Fabric settings
configured on a downstream FortiGate are shown.
When prompted to sign in with Security Fabric to the downstream FortiGate. a user enters the single sign-on (SSO) provider credentials.
What happens next for the user?
A. The user is redirected to the root FortiGate. B. The user accesses the downstream FortiGate with super_admin_readonly privileges. C. The user accesses the root FortiGate with AdminSSO privileges. D. The user receives an authentication failure message.
Answer: B
Question #12 (Topic: Exam A)
Refer to the exhibit.

The ADVPN IPsec interface represents the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub В to Spoke 3 and Spoke 4.
You must configure an ADVPN using IBGP and EBGP to connect Overlay 1 with Overlay 2.
Which parameters must you configure in the phase 1 VPN IPsec configuration of the ADVPN tunnels?
A. set auto-discovery-forwarder enable and set remote-as x B. set auto-discovery-crossover enable and set enforce-multihop enable C. set auto-discovery-sender enable and set network-id x D. set auto-discovery-receiver enable and set remote-ip x
Answer: C
Question #13 (Topic: Exam A)
Refer to the exhibit.
The partial output of an OSPF command is shown.

While checking the OSPF status of FortiGate. you receive the output shown in the exhibit.
Based on the output, which two statements about FortiGate are correct? (Choose two.)
A. FortiGate injects external routing information. B. FortiGate is a backup designated router. C. FortiGate is connected to multiple areas. D. FortiGate has OSPF ECMP enabled.
Answer: CD
Question #14 (Topic: Exam A)
Refer to the exhibit.

You are deploying a hub and spokes network and using OSPF as a dynamic protocol.
Which configuration is recommended for neighbor adjacency through the hub?
A. Set virtual-link enable in the OSPF configuration B. Set rfc1583-compatible enable in the router configuration C. Set network-type point-to-multipoint in the hub interface D. Set route-reflector-client enable in the router configuration
Answer: C
Question #15 (Topic: Exam A)
Refer to the exhibit.

A network diagram showing the corporate network and a new remote office network is shown.
You must integrate the new remote office network with the corporate enterprise network.
What must you do to allow routing between the two networks?
A. Implement BGP to inject the new remote office network into the corporate FortiGate device. B. Add the network 192.168.1.0/24 in the OSPF section on the corporate FortiGate device. C. Implement OSPF over IPsec on both FortiGate devices. D. Configure virtual links on both FortiGate devices.
Answer: C
Download Exam
Page: 3 / 14
Total 66 questions