Free FCSS-EFW-AD-7-6 Fortinet FCSS-EFW-AD-7-6 Practice Test Question

Loading demo links...

Showing 1–3 of 7 questions

Question 1 (Topic 1)

Refer to the exhibit. An enterprise network connected to an ISP is shown. You must configure a loopback as a BGP source to connect to the ISP. Which two commands must you use to establish the connection? (Choose two.)

Select an option, then click Submit answer.

  • ibgp-enfогсе-multihop
  • ebgp-enfоrce-multihop
  • recursive-next-hop
  • update-source
Question 2 (Topic 1)

You need to install a new intrusion prevention system (IPS) profile without triggering false positives that can impact applications and disrupt normal traffic flow. How can you prevent false positives on IPS analysis?

Select an option, then click Submit answer.

  • Use an IPS profile with action default and analyze the applications.
  • Use the IPS profile extension to select an OS, protocol, and application for all the network internal services and users to prevent false positives.
  • Use an IPS profile with Scan Outgoing Connections to block botnets, which can create false positives.
  • Use an IPS profile with action monitor; however, you must be aware that this can compromise network integrity.
Question 3 (Topic 1)

You configured the FortiGate devices in an enterprise network to join the Fortinet Security Fabric. You have a list of IP addresses that must be blocked by the data center firewall. The list is updated daily. How can you automate updates to the firewall policy to add the IP addresses from the daily updated list?

Select an option, then click Submit answer.

  • With an external connector from External Feeds
  • With metadata variables in FortiManager
  • With a CLI script in FortiManager
  • With a Security Fabric automation