Fortinet FCSS_NST_SE-7.4 Übungsprüfungen
Zuletzt aktualisiert am 09.12.2025- Prüfungscode: FCSS_NST_SE-7.4
- Prüfungsname: FCSS - Network Security 7.4 Support Engineer
- Zertifizierungsanbieter: Fortinet
- Zuletzt aktualisiert am: 09.12.2025
Refer to the exhibit, which shows the omitted output of a session table entry.

Which two statements are true? (Choose two.)
- A . The traffic has been tagged for VLAN 0000.
- B . NP7 is handling offloading of this session.
- C . The traffic matches Policy ID 1.
- D . The session has been offloaded.
Exhibit.

Refer to the exhibit, which shows the output of a diagnose command.
What can you conclude about the debug output in this scenario?
- A . The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.
- B . There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.
- C . FortiGate used 64.26.151.37 as the initial server to validate its contract.
- D . Servers with a negative TZ value are less preferred for rating requests.
Exhibit.

Refer to the exhibit, which shows a partial output of diagnose hardware aysinfo memory.
Which two statements about the output are true? (Choose two.)
- A . There are 98908 kB o! memory that will never be used.
- B . The user space has 708880 kB of physical memory that is not used by the system.
- C . The I/O cache, which has 641364 kB of memory allocated to it.
- D . The value indicated next to the inactive heading represents the currently unused cache page.
Which authentication option can you not configure under config user radius on FortiOS?
- A . mschap
- B . pap
- C . mschap2
- D . eap
Which statement about parallel path processing is correct (PPP)?
- A . PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.
- B . Only FortiGate hardware configurations affect the path that a packet takes.
- C . PPP does not apply to packets that are part of an already established session.
- D . Software configuration has no impact on PPP.
Refer to the exhibit.

Which three pieces of information does the diagnose sys top command provide? (Choose three.)
- A . The miglogd daemon is running on CPU core ID 0.
- B . The diagnose sys top command has been running for 18 minutes.
- C . The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.
- D . The cmdbsvr process is occupying 2.4% of the total user memory space.
- E . If the neweli daemon continues to be in the R state, it will need to be manually restarted.
Refer to the exhibit, which shows the output of get router info bgp summary.

Which two statements are true? (Choose two.)
- A . The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.
- B . The TCP connection with BGP neighbor 100.64.2.254 was successful.
- C . The local FortiGate has received 18 packets from a BGP neighbor.
- D . The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264
Which two statements about Security Fabric communications are true? (Choose two.)
- A . FortiTelemetry and Neighbor Discovery both operate using TCP.
- B . The default port for Neighbor Discovery can be modified.
- C . FortiTelemetry must be manually enabled on the FortiGate interface.
- D . By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.
Refer to the exhibit, which shows the output of a BGP debug command.

What can you conclude about the router in this scenario?
- A . The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the 8GP session with the local router.
- B . An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.
- C . All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.
- D . The BGP session with peer 10.127.0.75 is up.
Exhibit.
![]()
Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.
What three conclusions can you draw from these log entries? {Choose three.)
- A . Remote registry is not running on the workstation.
- B . The user’s status shows as "not verified" in the collector agent.
- C . DNS resolution is unable to resolve the workstation name.
- D . The FortiGate firmware version is not compatible with that of the collector agent.
- E . A firewall is blocking traffic to port 139 and 445.