Free NSE7-NST-7-2 Fortinet NSE7-NST-7-2 Practice Test Question

Loading demo links...

Showing 1–3 of 7 questions

Question 1 (Topic 1)

Refer to the exhibit, which shows the output of diagnose sys session list. If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

Select an option, then click Submit answer.

  • The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.
  • The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.
  • Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.
  • The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.
Question 2 (Topic 1)

Refer to the exhibit, which shows the output of get router info ospf neighbor. What can you conclude from the command output?

Select an option, then click Submit answer.

  • The local FortiGate is not a DROther.
  • All neighbors are in area 0.0.0.0.
  • The local FortiGate is the BDR.
  • The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.
Question 3 (Topic 1)

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command. What two conclusions can you draw from the output? (Choose two.)

Select an option, then click Submit answer.

  • FSSO is using agentless polling mode to detect logon events.
  • The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.
  • The logon event can be seen on the collector agent installed on Windows.
  • FSSO is using DC agent mode to detect logon events.