FCSS_NST_SE-7.6: FCSS - Network Security 7.6 Support Engineer Fortigate Practice Questions
The free FCSS_NST_SE-7.6: FCSS - Network Security 7.6 Support Engineer questions that deal with fortigate, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
Exhibit 1. Exhibit 2. Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network. An administrator would like to lest session failover between the two service provider connections. Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)


Select 2 answers.
Correct answer: A, D
Question #4
Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which action will FortiGate take when using the default settings for SSL certificate inspection?
Correct answer: D
Explanation
When FortiGate performs SSL certificate inspection with default settings, it checks if the Server Name Indication (SNI) matches either the Common Name (CN) or any Subject Alternative Name (SAN) in the server certificate. If there is no match, FortiGatedoes not block the connection; instead, it uses the CN value from the certificate's subject field to continue web filtering and categorization. This behavior is described in the official Fortinet 7.6.4 Administration Guide: "Check the SNI in the hello message with the CN or SAN field in the returned server certificate: Enable: If it is mismatched, use the CN in the server certificate." This is the default (Enable) mode, which differs from the Strict mode that would block the mismatched connection. By default, this policy ensures service continuity and prevents disruptions due to certificate mismatches, allowing FortiGate to log and inspect based on the CN even when the requested SNI does not match. It provides a balance between connection reliability and the accuracy of filtering by certificate identity, allowing security policies to remain functional without unnecessary blocks. This approach is recommended by Fortinet to maintain usability for end-users while still supporting granular inspection. [References:, FortiGate 7.6.4 Administration Guide: Certificate Inspection?, SSL/SSH Inspection Profile Configuration, ]
Question #9
Refer to the exhibit, which shows one way communication of the downstream FortiGate with the upstream FortiGate within a Security Fabric. What three actions must you take to ensure successful communication? (Choose three.)

Select 3 answers.
Correct answer: A, C, D
Explanation
One way communication means the downstream device is not authorized on the root FortiGate, Security Fabric/FortiTelemetry is not enabled on the upstream receiving interface, or TCP port 8013 is blocked in between.
Continue with FCSS_NST_SE-7.6: FCSS - Network Security 7.6 Support Engineer
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in FCSS_NST_SE-7.6: FCSS - Network Security 7.6 Support Engineer, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All FCSS_NST_SE-7.6: FCSS - Network Security 7.6 Support Engineer practice questions →
