Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NSE7_FSN_AR-7.6 Fortinet NSE 7 - Secure Networking 7.6 Architect Questions and Answers

Questions 4

Refer to the exhibit showing a debug output.

NSE7_FSN_AR-7.6 Question 4

An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is deployed is successful.

The administrator then produces the debug output shown in the exhibit.

What could be causing this error message?

Options:

A.

The TCP port 445 is blocked between FortiGate and collector agent.

B.

The collector agent preshared password is mismatched.

C.

The FortiGate cannot resolve the active directory server name.

D.

The FortiGate and the collector agent are using different TCP ports.

Buy Now
Questions 5

Refer to the exhibit, which shows the partial output of a real-time OSPF debug.

NSE7_FSN_AR-7.6 Question 5

Why are the two FortiGate devices unable to form an adjacency?

Options:

A.

The Hello packet is being sent from an OSPF router with ID 0.0.0.112.

B.

The two FortiGate devices attempting adjacency are in area 0.0.0.0.

C.

One FortiGate device is configured to require authentication, while the other is not.

D.

The passwords on the FortiGate devices do not match.

Buy Now
Questions 6

A VPN tunnel is up. To monitor traffic flow, the administrator enters the following CLI commands on an SSH session on FortiGate:

# diagnose debug enable

# diagnose sniffer packet any ' udp and port 500 ' 4

However, the sniffer does not show any output. Assuming default configuration values, what are two possible reasons there is no output? (Choose two answers)

Options:

A.

The filter should be modified to also capture packets for TCP port 443 or UDP port 4500 .

B.

NAT Traversal is enabled.

C.

The sniffer must be restricted to the remote peer IP address.

D.

The sniffer output will be ignored because running diagnose debug enable shows only application real-time debugs.

Buy Now
Questions 7

Refer to the exhibit, which shows the output o! the BGP database.

NSE7_FSN_AR-7.6 Question 7

Which two statements are correct? (Choose two.)

Options:

A.

The advertised prefix of 10.20.30.0/24 was configured using the network command.

B.

The first four prefixes are being advertised using a legacy route advertisement.

C.

The advertised prefix of 10.20.30.0/24 is being advertised through the redistribution of another routing protocol.

D.

The output shows all prefixes advertised by all neighbors as well as the local router.

Buy Now
Questions 8

A FortiGate administrator is troubleshooting a VPN that is failing to establish.

As a first step, the administrator is attempting to sniff the traffic using the command:

# diagnose sniffer packet any ‘’udp port 500 or udp port 4500 or esp’’ 4

After several minutes there is still no output. What is the most Likely reason for this?

Options:

A.

The VPN is configured to use IKE over TCP

B.

esp is not a valid sniffer argument.

C.

The ISP is blocking all VPN traffic.

D.

Mismatched IKE versions are detected on the VPN peers

Buy Now
Questions 9

Exhibit.

NSE7_FSN_AR-7.6 Question 9

Refer to the exhibit, which shows a partial web fillet profile configuration.

Which action does FortiGate lake if a user attempts to access www. dropbox. com, which is categorized as File Sharing and Storage?

Options:

A.

FortiGate allows the connection, based on the URL Filter configuration.

B.

FortiGate blocks the connection as an invalid URL.

C.

FortiGate exempts the connection, based on the Web Content Filter configuration.

D.

FortiGate blocks the connection, based on the FortiGuard category based filter configuration.

Buy Now
Questions 10

Which two protocol states indicate that traffic is bidirectional? (Choose two.)

Options:

A.

proto_state=01 for a TCP session.

B.

proto_state=01 for a UDP session.

C.

proto_state=05 for a TCP session.

D.

proto_state=00 for an ICMP session.

Buy Now
Questions 11

Refer to the exhibit, which shows the omitted output of a session table entry.

NSE7_FSN_AR-7.6 Question 11

Which two statements are true? (Choose two.)

Options:

A.

The traffic has been tagged for VLAN 0000.

B.

NP7 is handling offloading of this session.

C.

The traffic matches Policy ID 1.

D.

The session has been offloaded.

Buy Now
Questions 12

Refer to the exhibits.

NSE7_FSN_AR-7.6 Question 12

FGT-1 is an area border router (ABR) that has interfaces in OSPF areas 0.0.0.0 and 0.0.0.5. FGT-3 acts as an autonomous system border router (ASBR), importing static routes into OSPF. FGT-2 is an internal router with all its interfaces belonging to area 0.0.0.5. FGT-1 is receiving all advertised routes from FGT-2, however, FGT-3 is not receiving any of the advertised routes from FGT-1. What is the most likely reason for this? (Choose one answer)

Options:

A.

Area 0.0.0.5 is configured not to propagate type 5 LSAs.

B.

FGT-2 is configured with a distribution list to block all advertised routes from FGT-3.

C.

FGT-3 and FGT-2 have not formed an OSPF adjacency yet.

D.

IP protocol 89 is blocked between FGT-1 and FGT-3.

Buy Now
Questions 13

Refer to the exhibit.

The output of a BGO debug command is shown.

NSE7_FSN_AR-7.6 Question 13

What is the most likely reason that the local FortiGate is not receiving any prefixes from its neighbors?

Options:

A.

The local router is waiting for the keepalive message from the router 10.125.0.60.

B.

None of the three neighbors has successfully established the TCP three-way handshake with the local router.

C.

The router 100.64.3.1 is waiting for the OPEN message from the local router.

D.

The RIB-OUT configuration for router 10.127.0.75 prevents any route advertisement to the local router.

Buy Now
Questions 14

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 14

Partial output of the get vpn ipsec tunnel details command is shown. Based on the output, which two statements are correct? (Choose two.)

Options:

A.

The npu_flag for this tunnel is 02.

B.

Different SPI values are a result of auto-negotiation being disabled for phase2 selectors.

C.

The npu_flag for this tunnel is 03.

D.

Anti-replay is enabled.

Buy Now
Questions 15

Exhibit.

NSE7_FSN_AR-7.6 Question 15

Refer to the exhibit, which shows a FortiGate configuration.

An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.

What must the administrator do to fix the issue?

Options:

A.

Disable webfilter-force-off.

B.

Increase webfilter-timeout.

C.

Enable fortiguard-anycast.

D.

Change protocol to TCP.

Buy Now
Questions 16

Which statement about parallel path processing is correct (PPP)?

Options:

A.

PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.

B.

Only FortiGate hardware configurations affect the path that a packet takes.

C.

PPP does not apply to packets that are part of an already established session.

D.

Software configuration has no impact on PPP.

Buy Now
Questions 17

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 17

A network topology and the routing table of a FortiGate device are shown.

What must the administrator configure in the BGP section to add only the subnet 100.64.2.0/24 to the routing table of FortiGate_A? (Choose one answer.)

Options:

A.

The administrator must configure route-map-in on FortiGate_A.

B.

The administrator must configure connected-route redistribution on FortiGate_C.

C.

The administrator must configure the 100.64.2.0/24 network on FortiGate_C.

D.

The administrator must configure BGP route redistribution on FortiGate_B.

Buy Now
Questions 18

What is the diagnose test application ipsmonitor 5 command used for? (Choose one answer)

Options:

A.

To disable the IPS engine

B.

To provide information regarding IPS sessions

C.

To restart all IPS engines and monitors

D.

To enable IPS bypass mode

Buy Now
Questions 19

Which authentication option can you not configure under config user radius on FortiOS?

Options:

A.

mschap

B.

pap

C.

mschap2

D.

eap

Buy Now
Questions 20

Refer to the exhibit, which shows the output of the command get router info bgp neighbors 100.64.2.254 advertised-routes.

NSE7_FSN_AR-7.6 Question 20

What can you conclude from the output?

Options:

A.

The BGP state of the two BGP participants is OpenConfirm.

B.

The router ID of the neighbor is 100.64.2.254.

C.

The BGP neighbor is advertising the 10.20.30.40/24 network to the local router.

D.

The local router is advertising the 10.20.30.40/24 network to its BGP neighbor.

Buy Now
Questions 21

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 21

The exhibit shows the output of a session. Which two statements are correct? (Choose two.)

Options:

A.

The session did not match a firewall policy.

B.

The gateway to the destination is 10.1.10.1.

C.

The session was initiated from an authenticated user.

D.

The TCP session has been successfully established.

Buy Now
Questions 22

An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.

If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?

Options:

A.

diagnose sniffer packet any ' udp port 500 '

B.

diagnose sniffer packet any ' lp proto 50 '

C.

diagnose sniffer packet any ' udp port 4500 '

D.

diagnose sniffer packet any ' ah '

Buy Now
Questions 23

Refer to the exhibits.

NSE7_FSN_AR-7.6 Question 23

An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix.

Which two actions can the administrator take to fix this problem? (Choose two.)

Options:

A.

Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.

B.

Manually add the BGP route on FGT-A.

C.

Restart BGP using a soft reset to force both peers to exchange their complete BGP routing tables.

D.

Use the set network-import-check disable command.

Buy Now
Questions 24

You use the FortiManager SD-WAN overlay orchestrator to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, FortiManager creates templates that are ready to install on the spoke and hub devices.

Which three templates are created by the SD-WAN overlay orchestrator for a spoke device? (Choose three answers.)

Options:

A.

Rules template

B.

CLI template

C.

IPsec tunnel template

D.

BGP template

E.

Static route template

Buy Now
Questions 25

Exhibit.

NSE7_FSN_AR-7.6 Question 25

Refer to the exhibit, which shows a partial output of diagnose hardware aysinfo memory.

Which two statements about the output are true? (Choose two.)

Options:

A.

There are 98908 kB of memory that will never be used.

B.

The user space has 708880 kB of physical memory that is not used by the system.

C.

The I/O cache, which has 641364 kB of memory allocated to it.

D.

The value indicated next to the inactive heading represents the currently unused cache page.

Buy Now
Questions 26

In a Security Fabric environment which three actions must you take to ensure successful communication among the nodes? (Choose three.)

Options:

A.

You must ensure that TCP port 8013 is not blocked along the way.

B.

You must ensure that the port for Neighbor Discovery has been changed.

C.

You must configure FortiGate in transparent mode.

D.

You must authorize the downstream FortiGate on the root FortiGate.

E.

You must enable FortiTelemetry on the receiving interlace of the upstream FortiGate.

Buy Now
Questions 27

Refer to the exhibit, which shows the output of a diagnose command. What can you conclude from the RTT value?

NSE7_FSN_AR-7.6 Question 27

Options:

A.

Its value represents the time it takes to receive a response after a rating request is sent to a particular server.

B.

Its value is incremented with each packet lost.

C.

It determines which FortiGuard server is used for license validation.

D.

Its initial value is statically set to 10.

Buy Now
Questions 28

Which two statements about conserve mode are true? (Choose two.)

Options:

A.

FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.

B.

FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.

C.

FortiGate exits conserve mode when the system memory goes below the configured green threshold.

D.

FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.

Buy Now
Questions 29

Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.

NSE7_FSN_AR-7.6 Question 29

What happens to the session information if a routing change occurs that affects this session?

Options:

A.

Only the interface and gateway information for dev=7 will be removed.

B.

The session information will not change unless the current route has been removed from the routing table.

C.

The session will be flagged as dirty but no route lookups will be performed.

D.

Sessions involving port7 or port19 will not have their routing information flushed.

Buy Now
Questions 30

What is the correct order of the IKEv2 request-and-response protocol?

Options:

A.

Create_Child_SA, IKEAUTH, IKESAJNIT

B.

Create_Child_SA, IKE_SA_INIT. IKE_AUTH

C.

IKE SA INIT, IKE AUTH. Create Child SA OIKE AUTH.

D.

IKE_AUTH_IKE_SA_INIT, Create_Child_SA

Buy Now
Questions 31

Refer to the exhibit, which contains partial output from an IKE real-time debug.

NSE7_FSN_AR-7.6 Question 31

The administrator does not have access to the remote gateway.

Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?

Options:

A.

In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.

B.

In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.

C.

In the phase 1 network configuration, set the IKE version to 2.

D.

In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.

Buy Now
Questions 32

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 32

Partial output of the fssod daemon real-time debug command is shown. Which two conclusions can you draw from the output? (Choose two answers)

Options:

A.

FSSO cannot verify if the user is still logged in.

B.

Fortinet Single Sign-On (FSSO) is using DC Agent mode to detect logon events.

C.

FortiGate is frequently polling the workstation in case the user has logged out.

D.

FSSO is using agentless polling mode to detect logon events.

E.

FortiGate polled this event through TCP port 8000.

Buy Now
Questions 33

Exhibit.

NSE7_FSN_AR-7.6 Question 33

Refer to the exhibit, which shows the output of diagnose automation test.

What can you observe from the output? (Choose two.)

Options:

A.

The automation stitch test is not being logged.

B.

The automation stitch test failed but the HA failover was successful.

C.

An HA failover occurred.

D.

The test was unsuccessful.

Buy Now
Questions 34

Refer to the exhibits.

NSE7_FSN_AR-7.6 Question 34

An OSPF peer is advertising route 172.16.52.0/24. The local FortiGate is configured with an inbound distribution list that allows the 172.16.0.0/16 network to be injected into its routing table. However, the 1 ' 2.16.52.0/24 subnet cannot be seen in the FIB.

Which two stops can the administrator of the local FortiGate take to ensure that the advertised 172.16. 52.0/24 subnet will be injected into the routing table? (Choose two.)

Options:

A.

Add another entry to the prefix list to specifically allow the 172.16.52.0/24 network.

B.

Change the ge value to 17.

C.

Change the R- value lo 16.

D.

Modify the default prefix-list behavior from implicit deny to implicit allow.

Buy Now
Questions 35

Refer to the exhibit, which shows a session entry.

NSE7_FSN_AR-7.6 Question 35

Which statement about this session is true?

Options:

A.

Return traffic to the initiator is sent to 10.1.0.1.

B.

Return traffic to the initiator is sent lo 10.200.1.254.

C.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

D.

It is an ICMP session from 10.1.10.1 to 10.200.5.1.

Buy Now
Questions 36

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 36

The partial output of a session table entry is shown.

Which two statements about the output shown in the exhibit are correct? (Choose two.)

Options:

A.

NP7 is handling offloading of this session.

B.

The traffic matches Policy ID 1.

C.

The session has been offloaded.

D.

The traffic is tagged for a VLAN interface.

Buy Now
Questions 37

Exhibit.

NSE7_FSN_AR-7.6 Question 37

Refer to the exhibit, which contains a screenshot of some phase 1 settings.

The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands on an SSH session on FortiGate:

NSE7_FSN_AR-7.6 Question 37

However, the IKE real-time debug does not show any output. Why?

Options:

A.

The administrator must also run the command diagnose debug enable.

B.

The debug shows only error messages. If there is no output, then the phase 1 and phase 2 configurations match.

C.

The log-filter setting is incorrect. The VPN traffic does not match this filter.

D.

Replace diagnose debug application ike -1 with diagnose debug application ipsec -1.

Buy Now
Questions 38

Refer to the exhibit, which shows a partial output from the get router info routing-table database command.

NSE7_FSN_AR-7.6 Question 38

The administrator wants to configure a default static route for port3 and assign a distance of 50 and a priority of 0.

What will happen to the port1 and port2 default static routes after the port3 default static route is created?

Options:

A.

The port2 default static route will be injected into the forwarding information base (FIB).

B.

The port1 default static route will be injected into the FIB.

C.

Neither of the routes shown in the output will be injected into the FIB.

D.

Both default static routes shown in the output will be injected into the FIB.

Buy Now
Questions 39

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 39

The VDOM configuration on a FortiGate device is shown. You discover that web filtering stopped working in Core1 and Core2 after a maintenance window.

What are two reasons why web filtering stopped working? (Choose two answers.)

Options:

A.

The root VDOM does not have access to FortiManager in a closed network.

B.

The root VDOM does not have access to any valid public Fortinet Distribution Network (FDN) server.

C.

The Core1 and Core2 VDOMs must also be enabled as management VDOMs to receive FortiGuard updates.

D.

The root VDOM does not use a VDOM link to connect with the Core1 and Core2 VDOMs.

Buy Now
Questions 40

What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?

Options:

A.

A mismatched proposal was detected during the IKE_AUTH exchange.

B.

A mismatched Diffie-Hellman group was detected during the IKE_SA_INIT exchange.

C.

A mismatched pre-shared key was detected during the IKE_AUTH exchange.

D.

Mismatched quick-mode selectors were detected during the CREATE_CHILD_SA exchange.

Buy Now
Questions 41

You configure the overlay tunnels for an SD-WAN hub-and-spoke topology defined with IPsec tunnels, BGP on loopback, and dynamic BGP.

Which two are recommended IPsec settings for this topology? (Choose two answers.)

Options:

A.

On the hub, set the tunnel type to static.

B.

On the hub, set the parameter mode-cfg to enable.

C.

On the spoke, set the parameter net-device to enable.

D.

On the spoke, configure the parameter localid.

Buy Now
Questions 42

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 42

A partial output of diagnose npu up6 port-list on FortiGate 2000E is shown.

An administrator is unable to analyze traffic flowing between port1 and port17 using the diagnose sniffer command.

Which two commands allow the administrator to view the traffic? (Choose two.)

A)

NSE7_FSN_AR-7.6 Question 42

B)

NSE7_FSN_AR-7.6 Question 42

C)

NSE7_FSN_AR-7.6 Question 42

D)

NSE7_FSN_AR-7.6 Question 42

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 43

Refer to the exhibit.

NSE7_FSN_AR-7.6 Question 43

Which route will traffic take to get to the 100.65.0.0/24 network considering the routes are all configured with the same distance?

Options:

A.

The BGP route

B.

The policy route

C.

The static route

D.

The OS PF route

Buy Now
Exam Code: NSE7_FSN_AR-7.6
Exam Name: Fortinet NSE 7 - Secure Networking 7.6 Architect
Last Update: Aug 26, 2026
Questions: 172

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99