Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

Pass NSE7_NST-7.2 Exam Guide

Page: 2 / 2
Question 8

Which of the following regarding protocol states is true?

Options:

A.

proto_state=00 indicates that UDP traffic flows in both directions.

B.

proto_state-01 indicates an established TCP session.

C.

proto_state=10 indicates an established TCP session.

D.

proto state=01 indicates one-way ICMP traffic.

Question 9

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which action will FortiGate take when using the default settingsfor SSL certificate inspection?

Options:

A.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration

B.

FortiGate uses the 31 information from the Subject field in the server certificate.

C.

FortiGate uses the first entry listed in the SAN field in the server certificate.

D.

FortiGate uses the SNI from the user's web browser.

Question 10

Refer to the exhibit, which shows a session table entry.

Which statement about FortiGate behavior relating to this session is true?

Options:

A.

FortiGate forwarded this session without any inspection.

B.

FortiGate is performing a security profile inspection using the CPU.

C.

FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made.

D.

FortiGate applied only IPS inspection to this session.

Question 11

Exhibit.

Refer to the exhibit, which shows the output of diagnose syssessionlist.

If the HA ID for the primary device is0. what happens if the primary failsand the secondary becomes the primary?

Options:

A.

The session will be removed from the session table of the secondary device because of the presence of allowed errorpackets, which will force the client to restart the session with the server.

B.

The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.

C.

Traffic for this session continues to be permitted on the new primary device after failover. without requiring the client to restart the session with the server.

D.

The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.

Page: 2 / 2
Pass NSE7_NST-7.2 Exam Guide,
Exam Code: NSE7_NST-7.2
Exam Name: Fortinet NSE 7 - Network Security 7.2 Support Engineer
Last Update: Nov 24, 2024
Questions: 40
NSE7_NST-7.2 pdf

NSE7_NST-7.2 PDF

$25.5  $84.99
NSE7_NST-7.2 Engine

NSE7_NST-7.2 Testing Engine

$28.5  $94.99
NSE7_NST-7.2 PDF + Engine

NSE7_NST-7.2 PDF + Testing Engine

$40.5  $134.99