00:00

QUESTION 1

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.
FCSS_NST_SE-7.6 dumps exhibit
What two conclusions can you draw from the output? (Choose two.)

Correct Answer: AD
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-FSSO-agentless-polling/ta-p/214349
From the snippet we can see that FortiGate (via the fssod daemon) is directly detecting the user logon rather than relying on a separate ??collector?? or ??DC agent.?? This indicates agentless polling—FortiGate polls the DC??s event logs over TCP 445 to discover logons. So: - FSSO is using agentless polling mode to detect logon events - In agentless mode, FortiGate will periodically poll the same IP (the DC) on port 445 to see if the user is still logged on

QUESTION 2

Refer to the exhibit, which shows the output of a policy route table entry.
FCSS_NST_SE-7.6 dumps exhibit
Which type of policy route does the output show?

Correct Answer: A

QUESTION 3

An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.
If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?

Correct Answer: B

QUESTION 4

Refer to the exhibit.
FCSS_NST_SE-7.6 dumps exhibit
The exhibit shows the output from using the command diagnose debug application samld -1 to diagnose a SAML connection.
Based on this output, what can you conclude?
FCSS_NST_SE-7.6 dumps exhibitA. Active Directory is used for authentication.
FCSS_NST_SE-7.6 dumps exhibitB. The authentication request is for an SSL VPN connection.
FCSS_NST_SE-7.6 dumps exhibitC. The IdP IP address is 10.1.10.254.
FCSS_NST_SE-7.6 dumps exhibitD. The IdP IP address is 10.1.10.2.

Correct Answer: D

QUESTION 5

Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.
FCSS_NST_SE-7.6 dumps exhibit
What happens to the session information if a routing change occurs that affects this session?
FCSS_NST_SE-7.6 dumps exhibitA. Only the interface and gateway information for dev=7 will be removed.
FCSS_NST_SE-7.6 dumps exhibitB. The session information will not change unless the current route has been removed from the routing table.
FCSS_NST_SE-7.6 dumps exhibitC. The session will be flagged as dirty but no route lookups will be performed.
FCSS_NST_SE-7.6 dumps exhibitD. Sessions involving port7 or port19 will not have their routing information flushed.

Correct Answer: B