Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Fortinet FCSS_NST_SE-7.6 Practice Exam with Questions & Answers

Questions 1

The local OSPF router is unable to establish adjacency with a peer.

Which two things should the administrator do to troubleshoot the issue? (Choose two.)

Options:
A.

Check if both peers have an IP address within the same subnet.

B.

Check if IP protocol 89 is blocked.

C.

Check if TCP port 179 is blocked.

D.

Check if there is an active static route to the peer.

Fortinet FCSS_NST_SE-7.6 Premium Access
Questions 2

Refer to the exhibit, which shows a truncated output of a real-time RADIUS debug.

FCSS_NST_SE-7.6 Question 2

Which two statements are true? (Choose two answers)

Options:
A.

The RADIUS server queried for authentication is located at IP address 172.25.188.164.

B.

Authentication was unsuccessful.

C.

The authentication scheme used was pop3.

D.

Authentication was successful.

E.

Two-factor authentication was required.

Questions 3

Refer to the exhibit, which shows the output of get router info bgp summary.

FCSS_NST_SE-7.6 Question 3

Which two statements are true? (Choose two.)

Options:
A.

The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.

B.

The TCP connection with BGP neighbor 100.64.2.254 was successful.

C.

The local FortiGate has received 18 packets from a BGP neighbor.

D.

The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264

Questions 4

Refer to the exhibit, which shows partial outputs from two routing debug commands.

FCSS_NST_SE-7.6 Question 4

Why is the port2 default route not in the second command output?

Options:
A.

The port2 interface is disabled in the FortiGate configuration.

B.

The port1 default route has a higher priority value than the default route using port2.

C.

The port1 default route has a lower priority value than the default route using port2.

D.

The port1 default route has a lower distance than the default route using port2.

Questions 5

Refer to the exhibit.

Partial output of a real-time OSPF debug is shown.

FCSS_NST_SE-7.6 Question 5

Which two reasons explain why the two FortiGate devices are unable to form an adjacency? (Choose two.)

Options:
A.

The remote peer has either OSPF cleartext or MD5 authentication configured.

B.

There is an OSPF authentication configuration mismatch.

C.

The local FortiGate does not have OSPF authentication configured

D.

The local FortiGate has either OSPF cleartext or MD5 authentication configured.

Questions 6

Refer to the exhibit.

FCSS_NST_SE-7.6 Question 6

Which route will traffic take to get to the 100.65.0.0/24 network considering the routes are all configured with the same distance?

Options:
A.

The BGP route

B.

The policy route

C.

The static route

D.

The OS PF route

Questions 7

Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.

FCSS_NST_SE-7.6 Question 7

What happens to the session information if a routing change occurs that affects this session?

Options:
A.

Only the interface and gateway information for dev=7 will be removed.

B.

The session information will not change unless the current route has been removed from the routing table.

C.

The session will be flagged as dirty but no route lookups will be performed.

D.

Sessions involving port7 or port19 will not have their routing information flushed.

Questions 8

What are two reasons that an OSPF router does not have any type 5 tank-state advertisements (LSAs) In its link-stale database (LSD6)? (Choose two.)

Options:
A.

There is no autonomous system border router (ASBR) in the network,

B.

The peer of the local router is using a prefix-list-out. configuration to prevent all type 5 LSAs to be advertised.

C.

The local router is located in a stub area

D.

IP protocol 89 is blocked between the local router and its peer.

Questions 9

Refer to the exhibit, which shows the output of diagnose sys session list.

FCSS_NST_SE-7.6 Question 9

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

Options:
A.

The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.

B.

Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.

C.

The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.

D.

The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.

Questions 10

Refer to the exhibit.

FCSS_NST_SE-7.6 Question 10

The partial output of diagnose sys session stat command is shown.

Which statement about the output shown in the exhibit is correct?

Options:
A.

113 sessions have been dropped because of memory page exhaustion.

B.

There have been 131072 recorded ephemeral sessions but there are no current ones.

C.

562 TCP sessions have their proto_state set to 01 if there is no inspection.

D.

27 sessions have expired but are still in the session table in case any out-of-order packets arrive.

Exam Code: FCSS_NST_SE-7.6
Certification Provider: Fortinet
Exam Name: Fortinet NSE 6 - Network Security 7.6 Support Engineer
Last Update: Aug 1, 2026
Questions: 134

Fortinet Free Exams

Fortinet Free Exams
Access free Fortinet exam study guides and practice tests at Examstrack. Ensure your success with top-notch preparation resources at Examstrack.