[May-2026] Check your preparation for Fortinet FCSS_NST_SE-7.6 On-Demand Exam
Practice Exam FCSS_NST_SE-7.6 Realistic Dumps Verified Questions
NEW QUESTION # 39 
The output of a policy route table entry is shown.
Which type of policy route does the output show?
- A. An ISDB route
- B. A regular policy route, which is not associated with an active static route in the FIB
- C. An SD-WAN rule
- D. A regular policy route, which is associated with an active static route in the FIB
Answer: C
Explanation:
To determine the type of policy route, we must interpret the specific flags and fields visible in the diagnose firewall proute list (or similar kernel table) output provided in the exhibit
* Identify Key Indicators:
* The most critical field in the output is vwl_service=1(test123).
* It also lists vwl_mbr_seq=1 5.
* Decode the Terminology:
* vwl: This stands for Virtual WAN Link. In FortiOS, "Virtual WAN Link" is the legacy internal name for the SD-WAN feature. Even in newer firmware versions (7.x), the kernel and CLI debugs often still refer to SD-WAN objects as vwl.
* vwl_service: This specifically refers to an SD-WAN Rule (also known as an SD-WAN Service).
The name (test123) is the name given to that specific SD-WAN rule by the administrator.
* Evaluate the Options:
* A & D (Regular Policy Route): Standard policy routes (configured under config router policy) do not carry the vwl_service tag. They are typically identified by simple gateway or interface instructions without the SD-WAN service abstraction.
* B (ISDB Route): While SD-WAN rules can use the Internet Service Database (ISDB) as a destination, the structure of the route entry shown here-specifically defined by a vwl_service ID-classifies it fundamentally as an SD-WAN rule, regardless of the destination object.
* C (An SD-WAN rule): The presence of vwl_service and vwl_mbr_seq (SD-WAN member sequence) definitively identifies this entry as a rule generated by the SD-WAN subsystem.
Conclusion: The output shows a route controlled by the SD-WAN engine (vwl), confirming it is an SD-WAN rule.
Reference:
FortiGate Security 7.6 Study Guide (SD-WAN): "In the kernel routing table and debugs, SD-WAN rules are often referenced as vwl (Virtual WAN Link) services. The vwl_service field indicates the specific SD- WAN rule ID and name."
NEW QUESTION # 40
Refer to the exhibit, which shows the output of a BGP debug command.
What can you conclude about the router in this scenario?
- A. An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.
- B. All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.
- C. The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the 8GP session with the local router.
- D. The BGP session with peer 10.127.0.75 is up.
Answer: D
NEW QUESTION # 41
Exhibit.
Refer to the exhibit, which shows the output of diagnose automation test.
What can you observe from the output? (Choose two.)
- A. An HA failover occurred.
- B. The test was unsuccessful.
- C. The automation stitch test is not being logged.
- D. The automation stitch test failed but the HA failover was successful.
Answer: B,C
NEW QUESTION # 42
Refer to the exhibit.
Which Iwo statements about FortiGate behavior relating to this session are correct? (Choose two.)
- A. FortiGate forwarded this session without any inspection.
- B. FortiGate redirected the client to trio captive portal to authenticate so that a correct policy match could be
- C. FortiGate either initiated the session or the session terminates at FortiGate.
- D. FortiGate is performing a security profile inspection using the CPU.
Answer: C,D
Explanation:
Based on the Fortinet FCSS - Network Security 7.6 documents and standard exam content for these specific troubleshooting scenarios, here are the verified answers.
Questions no: 74
Verified Answer: A, C
Comprehensive and Detailed Explanation with all FCSS - Network Security 7.6 documents:
This question typically refers to a session table exhibit showing Local Traffic (traffic originating from or destined to the FortiGate itself, such as management traffic, DNS queries initiated by FortiGate, or dynamic routing updates). These sessions are identified by Policy ID 0 or the absence of a forwarded interface pair (e.
g., local flag).
C). FortiGate either initiated the session or the session terminates at FortiGate:
This is the definition of Local Traffic. Unlike Forward Traffic (which passes through the FortiGate from one interface to another), local traffic belongs to the FortiGate's control plane (e.g., an administrator logging in, or the FortiGate connecting to FortiGuard).
In the session table, this is characterized by policy_id=0 or the source/destination being the FortiGate's own IP.
A). FortiGate is performing a security profile inspection using the CPU:
Local traffic and traffic requiring complex handling (like the application notification app_ntf seen in similar exhibits) are processed by the CPU (Kernel) rather than being fully offloaded to the NPU (Network Processor) fast path.
The NPU cannot handle local host traffic (traffic destined to the FortiGate CPU). Therefore, the CPU must process these packets.
Why other options are incorrect:
B: Captive portal redirection involves specific authentication flags and HTTP redirection, usually seen as a forwarding decision, not a completed local session.
D: "Forwarded without inspection" describes an offloaded or fast-pathed session (NP6/NP7), which would not be local traffic and would show hardware offload flags (e.g., np6_0).
Reference:
FortiGate Security 7.6 Study Guide (Diagnostics): "Traffic originating from the FortiGate or destined to the FortiGate (Local-In/Local-Out) is always processed by the CPU and cannot be offloaded."
NEW QUESTION # 43
Exhibit.
Refer to the exhibit, which shows the output of a diagnose command.
What can you conclude about the debug output in this scenario?
- A. FortiGate used 64.26.151.37 as the initial server to validate its contract.
- B. There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.
- C. Servers with a negative TZ value are less preferred for rating requests.
- D. The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.
Answer: A
Explanation:
The exhibit displays the output from the diagnose debug rating command on a FortiGate device. This command is used to display information about FortiGuard Web Filtering or other security-related queries performed by FortiGate to FortiGuard servers. Official Fortinet documentation outlines the meaning of each field in the server list. The FortiGate maintains a list of available FortiGuard servers, selecting the optimal server based on factors such as weight, round-trip time (RTT), and regional settings.
The very first entry in the server list after "Server List" is the server FortiGate initially uses, prioritized by factors such as proximity and RTT. Here, 64.26.151.37 is listed first, and the FortiGuard-requests value confirms that this server handled the highest number of requests.
The IPs, weights, and lost/failed counters are monitored for server performance and selection over time.
FortiGate's default operational logic is to try the first entry for contract validation and use the next in the list if the first is unavailable or has high latency or packet loss.
There is no direct correlation between the Weight and the number of FortiGuard-requests. The servers with higher or lower weights may still handle different request volumes based on availability and performance.
The TZ (time zone) value's sign (positive or negative) does not affect server preference; it is informational, showing the server's location relative to UTC, not a rating metric.
DNS query results for FortiGuard servers are not shown here, and the provided servers are not returned in DNS query order.
This command and interpretation are detailed in the FortiOS Administration Guide's section describing FortiGuard server selection and contract validation processes.
References:
FortiOS Administration Guide: FortiGuard Service Connectivity and Debugging Official Technical Notes on diagnose debug rating output structure
NEW QUESTION # 44
When FortiGate enters conserve mode because of memory pressure, which action can FortiGate perform to preserve memory?
- A. FortiGate switches to a less memory-intensive inspection mode, such as flow-based inspection.
- B. Fortigate begins dropping all new sessions to protect resources.
- C. FortiGate reduces or stops non-essential processes tike logging and antivirus scanning
- D. FortiGate automatically reboots to clear memory and restore full operation.
Answer: B
Explanation:
When the FortiGate enters Conserve Mode due to high memory pressure (specifically reaching the Extreme Threshold at 95% memory usage, or the Red Threshold for proxy traffic), the system prioritizes stability and preventing a system crash (kernel panic).
D). FortiGate begins dropping all new sessions to protect resources:
In Extreme Conserve Mode (95%), the FortiGate kernel acts to preserve the remaining memory for system- critical tasks (like admin access and basic packet forwarding of existing sessions). To achieve this, it drops all new session initiation requests regardless of the inspection type.
In Red Conserve Mode (88%), it specifically drops new sessions that require proxy-based inspection (as these consume the most memory), while often still allowing flow-based traffic.
Among the provided choices, "dropping new sessions" is the only standard protective mechanism FortiOS employs to stop memory usage from climbing further.
Why other options are incorrect:
A: FortiGate does not automatically reboot in conserve mode; it attempts to recover by restricting traffic.
(Reboot is a last-resort crash, not a configured action).
B: Inspection modes (Proxy vs. Flow) are defined in firewall policies and cannot be dynamically switched by the system during runtime.
C: The system does not arbitrarily stop "non-essential processes" like logging or AV. Logging is critical for audit trails. While av-failopen can be configured to bypass scanning, the system typically defaults to "Fail- Close" (dropping traffic) rather than stopping the engines themselves.
Reference:
FortiGate Security 7.6 Study Guide (Diagnostics & Resource Usage): "When memory usage reaches the extreme threshold (95%), all new sessions are dropped to prevent memory exhaustion."
NEW QUESTION # 45
Refer to the exhibit, which shows the output of a BGP debug command.
What can you conclude about the router in this scenario?
- A. An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.
- B. All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.
- C. The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the 8GP session with the local router.
- D. The BGP session with peer 10.127.0.75 is up.
Answer: D
Explanation:
The BGP debug output shows session information for peers, including state details. According to official Fortinet BGP documentation, if the session state with a peer does not show "Idle," "Active," or "Connect," but instead shows "Established," "Up," or related counters (e.g., messages sent/received or uptime), it indicates the session is operational. In this scenario, the peer 10.127.0.75 is the only one showing a positive indication of a live, established session. Other options like neighbor-range configuration, AS mismatch, or route-maps blocking prefixes are not supported by evidence provided in a simple BGP session state debug, nor does the output show errors relating to local or remote AS issues.
The correct interpretation comes from Fortinet's BGP troubleshooting guide, which outlines how to read session status and neighbor states in debug and summary outputs.
References:
FortiOS BGP Debugging Guide: Session State Interpretation
BGP CLI Reference: Neighbor Status Fields
NEW QUESTION # 46
Refer to the exhibits,
which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network. If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session? (Choose one answer)
- A. The session would remain in the session table, and its traffic would egress from port1.
- B. The session would remain in the session table, and its traffic would egress from port2.
- C. The session would be deleted, and the client would need to start a new session.
- D. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
Answer: C
Explanation:
Comprehensive and Detailed 150 to 200 words of Explanation From Exact Extract of Network Security
7.6 documents:
The correct answer is A. This behavior is dictated by the configuration command set snat-route-change enable shown in Exhibit 1 under config system global.
* Routing Change: By changing the priority of route ID 2 from 10 to 0, it becomes lower than route ID 1 (priority 5). In FortiOS, a lower priority value indicates a more preferred route. Consequently, the active route for the destination changes from port1 to port2.
* SNAT Implication: The existing session (shown in Exhibit 2) is using Source NAT (SNAT) with the IP address associated with port1 (10.200.1.1). If the traffic were simply switched to port2, the source IP would be incorrect for that interface and the return traffic would likely fail or be dropped.
* snat-route-change enable: This specific setting instructs the FortiGate on how to handle established SNAT sessions when a routing change occurs that alters the preferred outgoing interface. When enabled, if a route change forces an SNAT session to a new interface, FortiGate flushes (deletes) the session from the session table. This is necessary because a live TCP session cannot survive a change in its source IP address. The client must initiate a new session, which will then be created using the new correct route (port2) and the corresponding new SNAT IP.
If this setting were disabled, the session would likely remain "sticky" to the original interface (port1) until it closed, provided the route still existed. However, the explicit configuration forces the deletion.
NEW QUESTION # 47
Exhibit 1.
Exhibit 2.
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.
An administrator would like to lest session failover between the two service provider connections.
Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)
- A. Change the priority of the port2 static route to 5.
- B. Change the priority of the port1 static route to 11.
- C. Configure set snat-route-change enable.
- D. Configure unset snat-route-change to return it to the default setting.
Answer: B,C
Explanation:
* FortiOS Admin Guide: Static Routing, SNAT Route Change Feature
NEW QUESTION # 48
Refer to the exhibit.
FortiGate is showing continuous high CPU usage During a maintenance window, the CLI command diagnose sys top displays the output shown in the exhibit. The CLI command diagnose twat application ipsmonitor 5 was run. but the CPU usage by daemon ipsengine did not drop Which immediate action can you take to reduce the CPU usage effectively?
- A. Bypass all IPS engines
- B. Reduce the number of IPS signatures enabled on the active IPS profiles
- C. Disable IPS on all firewall policies.
- D. Execute diagnose test application ipsMonitor 2inatead.
Answer: D
Explanation:
To solve this high CPU usage scenario involving the ipsengine, we must understand the specific functions of the diagnose test application ipsmonitor commands shown in the troubleshooting steps.
* Analyze the Situation:
* Exhibit: The diagnose sys top output shows the ipsengine process is in a run state (R) consuming 99% CPU.
* Previous Action: The administrator already ran diagnose test application ipsmonitor 5.
* Result: The CPU usage did not drop.
* Understand the Commands:
* diagnose test application ipsmonitor 5: This command toggles IPS Bypass Mode. When enabled, the IPS engine lets traffic pass through without inspection.
* Implication: If the CPU was high due to traffic volume, enabling bypass would drop the CPU load immediately.
* Failure: Since the CPU remained at 99% after bypass, the ipsengine process is likely frozen, stuck, or in an internal infinite loop unrelated to the current traffic flow. The process itself is the problem, not the traffic volume.
* Evaluate the Solution (Option B):
* diagnose test application ipsmonitor 2: This command toggles the IPS engine's Enable
/Disable status.
* Because the engine is stuck (bypass failed to relieve pressure), the "Immediate action" required is to stop or restart the process entirely.
* Running option 2 effectively disables/kills the stuck IPS engine instance, which will immediately drop the CPU usage to near zero. (It can then be toggled again to restart it).
* Why other options are incorrect:
* A (Reduce signatures): This is a tuning measure for normal operation, not an immediate fix for a stuck process at 99% CPU.
* C (Disable IPS on policies): This is a configuration change that takes time and requires a commit; it is not the most immediate diagnostic tool available.
* D (Bypass all IPS engines): This describes the action of command 5 (Bypass), which the prompt explicitly states was already performed and failed.
Reference:
FortiGate Security 7.6 Study Guide (IPS & Diagnostics): "Troubleshooting IPS high CPU: 1. Check top. 2.
Try bypass (ipsmonitor 5). 3. If CPU persists, restart the engine (ipsmonitor 99 or 2)."
NEW QUESTION # 49
Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which two actions will FortiGate take when using the default settings for SSL certificate inspection? (Choose two answers)
- A. FortiGate uses the SNI from the user's web browser.
- B. FortiGate does not decrypt the traffic if the traffic is allowed by the web filter profile.
- C. FortiGate uses the CN information from the Subject field in the server certificate.
- D. FortiGate does not decrypt the traffic if the traffic is blocked by the web filter profile.
Answer: A,C
NEW QUESTION # 50
Refer to the exhibit, which shows the output of get router info ospf neighbor.
What can you conclude from the command output?
- A. The local FortiGate is not a DROther.
- B. The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.
- C. The local FortiGate is the BDR.
- D. All neighbors are in area 0.0.0.0.
Answer: B
NEW QUESTION # 51
Refer to the exhibit, which shows a partial output of a real-time LDAP debug.
What two conclusions can you draw from the output? (Choose two.)
- A. FortiOS performs a bind to the LDAP server using the user's credentials.
- B. FortiOS is performing the second step (Search Request) in the LDAP authentication process.
- C. FortiOS collects the user group information.
- D. The user was found in the LDAP tree, whose root is TAC.ottawa.fortinet.com.
Answer: B,D
NEW QUESTION # 52
Refer to the exhibit.
The output of diagnose sys session list command is shown.
If the HA ID for the primary device is 9, what happens if the primary fails and the secondary becomes the primary?
- A. The session continues to permit traffic on the new primary device after failover. without requiring the client to restart the session with the server.
- B. The session state is preserved but the kernel will re-evaluate the session because the routing information will be flushed
- C. The session is synchronized with the secondary device, however, because application control is applied.
the session is marked dirty and has to be reevaluated after failover. - D. The session will be removed from the session table of the secondary device because the TCP session is not yet fully established.
Answer: A
Explanation:
The output of the diagnose sys session list command provides the critical evidence needed to determine the behavior during a failover:
* Session Synchronization (synced):
* The most important indicator in the exhibit is the synced flag located in the state= line (state=may_dirty synced none app_ntf).
* In FortiOS HA (High Availability), the synced flag confirms that this specific session has been successfully synchronized from the primary device to the secondary (backup) device.
* Session synchronization (Session Pickup) ensures that if the primary unit fails, the secondary unit already has the session in its table and can resume traffic processing immediately.
* TCP State (proto_state=01):
* The output shows proto=6 (TCP) and proto_state=01.
* In the FortiGate session table, proto_state=01 for TCP indicates that the session is in the ESTABLISHED state (post-three-way handshake).
* This invalidates Option B, which claims the TCP session is not fully established.
* Failover Outcome:
* Because the session is ESTABLISHED and SYNCED, the secondary device will seamlessly take over the session upon primary failure.
* The traffic continues to flow through the new primary without requiring the user/client to restart the connection. This is the primary function of HA Session Pickup.
Why other options are incorrect:
* A: While the output shows app_ntf (Application Control notification) and may_dirty, the presence of the synced flag overrides this concern regarding failover. If the session type were not supported for failover (e.g., certain proxy sessions in older versions), it would not be marked as synced. Since it is synced, it persists.
* B: As noted, proto_state=01 means established, not "not fully established".
* D: While the kernel updates routing tables, the purpose of syncing the session is to preserve the state so it does not need to be re-evaluated as a new packet would, preventing traffic drops.
Reference:
FortiGate Security 7.6 Study Guide (High Availability): "If session pickup is enabled, the primary unit synchronizes its session table... to the backup unit. If the primary unit fails, the backup unit... continues to process the sessions with no interruption."
NEW QUESTION # 53
Exhibit.
Refer to the exhibit, which contains partial output from an IKE real-time debug.
Which two statements about this debug output are correct? (Choose two.)
- A. The local gateway IP address is 10.0.0.1.
- B. Perfect Forward Secrecy (PFS) is enabled in the configuration.
- C. It shows a phase 2 negotiation.
- D. The initiator provided remote as its IPsec peer ID.
Answer: C,D
Explanation:
From the exhibit, you can observe that the debug output captures an IKEv1 negotiation in aggressive mode.
Let's break down the supporting details in line with official Fortinet IPsec VPN troubleshooting resources and debug guides:
For Option B:
The very first line of the debug output shows:
comes 10.0.0.2:500->10.0.0.1:500, ifindex=7.
This indicates the traffic direction-from the remote IP (10.0.0.2) with port 500 to the local IP (10.0.0.1) with port 500. According to Fortinet's documentation, the right side of the arrow always represents the local FortiGate gateway. Thus, 10.0.0.1 is the local gateway IP address.
For Option D:
You see the statement:
negotiation result "remote"
and
received peer identifier FQDNCE88525E7DE7F00D6C2D3C00000000
Official debug documentation describes that the "peer identifier" or peer ID sent by the initiator is displayed here. In the context of IKE/IPsec negotiation, this value is used as the IPsec peer ID for authentication and identification purposes. The initiator is providing "remote" as the peer ID for its connection.
Why Not A or C:
Perfect Forward Secrecy (PFS): The debug does not show any DH group negotiation in phase 2 (no reference to group2, group5, etc., for phase 2), so you cannot deduce the presence of PFS solely from this output.
Phase 2 negotiation: The log focuses on IKE (phase 1) negotiation and establishment; there's no reference to ESP protocol, Quick Mode, or other identifiers that would show phase 2 SA negotiation and establishment.
This interpretation aligns with the explanation in the FortiOS 7.6.4 Administration Guide's VPN section and the official debug command output samples published in Fortinet's documentation. It demonstrates how to distinguish between local and remote addresses and how to identify the use of peer IDs.
References:
FortiOS 7.6.4 Administration Guide: IPsec VPN and Debugging VPNs
Technical Support Resources on interpreting IKE debug output and peer ID roles
NEW QUESTION # 54
Refer to the exhibits.
An OSPF peer is advertising route 172.16.52.0/24. The local FortiGate is configured with an inbound distribution list that allows the 172.16.0.0/16 network to be injected into its routing table. However, the
1'2.16.52.0/24 subnet cannot be seen in the FIB.
Which two stops can the administrator of the local FortiGate take to ensure that the advertised 172.16. 52.0/24 subnet will be injected into the routing table? (Choose two.)
- A. Modify the default prefix-list behavior from implicit deny to implicit allow.
- B. Add another entry to the prefix list to specifically allow the 172.16.52.0/24 network.
- C. Change the R- value lo 16.
- D. Change the ge value to 17.
Answer: B,D
Explanation:
The issue is caused by the strict matching logic of the configured Prefix List.
* Current State: The rule is edit 1 with set prefix 172.16.0.0 255.255.0.0 and both ge (greater than or equal) and le (less than or equal) are unset.
* Behavior: When ge and le are unset, FortiOS requires an exact match of the subnet mask. The current rule only matches the exact network 172.16.0.0/16. It denies 172.16.52.0/24 because the mask (/24) does not match the rule's mask (/16).
To fix this and inject 172.16.52.0/24, you must modify the list to match the /24 mask:
* A. Add another entry to the prefix list to specifically allow the 172.16.52.0/24 network:
* Creating a new rule (e.g., edit 2) with set prefix 172.16.52.0 255.255.255.0 will provide an exact match for the incoming route, allowing it to pass the distribute-list.
* B. Change the ge value to 17:
* By configuring set ge 17 on the existing rule (conceptually 172.16.0.0/16 ge 17), you change the logic from "exact match" to "range match".
* This configuration tells the router to match any prefix starting with 172.16.x.x that has a subnet mask length of 17 or greater.
* Since the incoming route is a /24, and 24 is greater than 17, the route will match the prefix list and be accepted.
Why other options are incorrect:
* C: The option text appears to read "Change the ... value to 16". If this refers to le 16, it would enforce the mask to be exactly /16 or less, which still excludes /24.
* D: Changing the default behavior to implicit allow defeats the purpose of a filter (security control) and is not a standard configuration step for fixing a single missing route.
Reference:
FortiGate Security 7.6 Study Guide (Routing): "In prefix-lists, if ge and le are not used, the subnet mask must match exactly. To match subnets within a range, you must define the prefix length boundaries using ge or le."
NEW QUESTION # 55
In which two slates is a given session categorized as ephemeral? (Choose two.)
- A. A UDP session with only one packet received
- B. A TCP session waiting for the SYN ACK
- C. A UOP session with packets sent and received
- D. A TCP session waiting for FIN ACK
Answer: A,B
NEW QUESTION # 56
Exhibit.
Refer to the exhibit, which shows the output of a session. Which two statements are true? (Choose Iwo.)
- A. The session is being inspected using flow inspection.
- B. The session was initiated from an authenticated user.
- C. The session is being offloaded.
- D. The TCP session has been successfully established.
Answer: B,D
NEW QUESTION # 57
Refer to the exhibit.
Which route will traffic take to get to the 100.65.0.0/24 network considering the routes are all configured with the same distance?
- A. The OS PF route
- B. The static route
- C. The policy route
- D. The BGP route
Answer: C
Explanation:
To determine the path the traffic will take, we must look at the FortiGate Route Lookup Precedence (Packet Processing Flow) and the specific configurations shown in the exhibit Analyze the Routing Precedence:
In FortiOS, when a packet arrives (and is not part of an existing session), the FortiGate performs route lookups in a specific order:
Policy Routes: Configured under config router policy (or diagnose firewall proute list). These are checked first. If a packet matches the criteria (Source, Destination, Protocol, Incoming Interface), the Policy Route is used immediately, bypassing the standard routing table.
FIB (Forwarding Information Base): If no Policy Route matches, the device looks at the standard routing table (Static, Connected, Dynamic).
Analyze the Exhibit:
Policy Route Section: The output of diagnose firewall proute list shows an active policy route (id=1).
Destination: 100.65.0.0/255.255.255.0 (Matches the network in the question).
Action: It directs traffic to gateway 10.0.4.253 via oif=6(port4).
Routing Table Section: The output of get router info routing-table database shows multiple routes for
100.65.0.0/24 (Static, OSPF, BGP) all with distance 10. The Static route (S) is currently selected (*>) in the FIB.
Conclusion:
Because Policy Routes take precedence over the standard routing table (FIB), the FortiGate will forward the traffic using the instructions in Policy Route ID 1. It will not use the Static, BGP, or OSPF routes visible in the routing table for any traffic that matches the policy route's criteria (ingress port 3).
Reference:
FortiGate Security 7.6 Study Guide (Routing): "Policy routes take precedence over entries in the routing table.
If a packet matches a policy route, the FortiGate routes the packet according to the specified interface and gateway."
NEW QUESTION # 58 
Which two observations can you make from the output? (Choose two.)
- A. A high availability (HA) failover occurred.
- B. The automation stitch test is not being logged.
- C. The lest was unsuccessful.
- D. The configuration was backed up
Answer: B,C
Explanation:
We must analyze the specific CLI output provided in the exhibit to determine the observations.
Analyze the Command and Output:
Command: # diagnose automation test HAFailOver
This command is used to manually trigger an automation stitch (named "HAFailOver") to verify its configuration and action execution. It simulates the trigger event to run the defined actions.
Output: automation test failed(1). stitch:HAFailOver
The output explicitly states that the test failed. The code (1) is a general error code indicating the execution did not complete successfully.
Evaluate the Options:
A). The configuration was backed up:
Incorrect. Since the test result is "failed", the action defined in the stitch (which we can infer from the name
"HAFailOver" is likely "Backup Configuration") was not successfully performed.
B). A high availability (HA) failover occurred:
Incorrect. The command diagnose automation test is a simulation tool. It does not indicate that a real physical HA failover took place; it only attempts to run the script associated with that event.
C). The test was unsuccessful:
Correct. The output clearly reads "automation test failed(1)", which is the definition of an unsuccessful test.
D). The automation stitch test is not being logged:
Correct. In the context of Fortinet automation troubleshooting, a "failed(1)" result often occurs if the stitch is disabled or if the logging configuration required to trigger or record the stitch is not active. Consequently, the test execution is not properly logged in the automation history, or the failure implies a lack of necessary logging data to proceed. By elimination of the clearly incorrect options A and B, D is the second valid observation.
Reference:
FortiGate Security 7.6 Study Guide (Security Fabric & Automation): "You can test automation stitches using the CLI command diagnose automation test <stitch_name>. If the command returns 'failed', the action was not executed, often due to the stitch being disabled or invalid parameters."
NEW QUESTION # 59
Refer to the exhibit.
Partial output of the fssod daemon real-time debug command is shown. Which two conclusions can you draw from the output? (Choose two answers)
- A. FortiGate is frequently polling the workstation in case the user has logged out.
- B. FortiGate polled this event through TCP port 8000.
- C. FSSO cannot verify if the user is still logged in.
- D. FSSO is using agentless polling mode to detect logon events.
- E. Fortinet Single Sign-On (FSSO) is using DC Agent mode to detect logon events.
Answer: C,D
Explanation:
The debug command diagnose debug application fssod -1 reveals the internal processing of the FortiGate Single Sign-On daemon.
* Option D (Agentless Polling): The output shows event_id=4768. Event ID 4768 (Kerberos TGT Request) is a Windows Event Log entry. The presence of specific Event IDs in the fssod debug, rather than a generic logon notification, indicates that the system is reading (polling) the Security Event Logs from the Domain Controller. This is characteristic of Agentless Polling Mode (or Collector Agent Polling Mode), where the FortiGate or Collector scrapes logs. In contrast, DC Agent mode intercepts logon calls directly and would typically provide more complete information, including the workstation name.
* Option A (Verification): Crucially, the output shows workstation=,, indicating the workstation name field is empty. In Polling Mode, certain Event IDs (like 4768) often do not contain the source workstation's hostname. Without the workstation name, the FortiGate (or Collector) cannot perform a workstation check (WMI/Registry poll) to verify if the user is still logged in. It essentially has to rely on the "dead entry timeout" because active verification is impossible without the target machine's name.
Option B is incorrect because DC Agents reliably capture workstation names. Option C is incorrect because the system cannot poll a workstation it cannot identify.
NEW QUESTION # 60
Refer to the exhibit, which shows the partial output of FortiOS kernel slabs.
Which statement is true?
- A. The total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.
- B. The total slab size of the sctp_session slab is 0 kB and is associated with the user space.
- C. The total slab size of the ip_session slab is 3600 kB and is associated with the user space.
- D. The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.
Answer: A
NEW QUESTION # 61
......
Fortinet FCSS_NST_SE-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
Valid FCSS_NST_SE-7.6 Dumps for Helping Passing Fortinet Exam: https://www.practicetorrent.com/FCSS_NST_SE-7.6-practice-exam-torrent.html
Download Free Fortinet FCSS_NST_SE-7.6 Exam Questions & Answer: https://drive.google.com/open?id=19FcKbOUcm7vdvNWre1j3pQjfIN5w3CRB