Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Fortinet FCSS_NST_SE-7.6 Practice Exam with Questions & Answers | Set: 3

Questions 21

Refer to the exhibit.

FCSS_NST_SE-7.6 Question 21

Assuming a default configuration, which three statements are true? (Choose three.)

Options:
A.

Strict RPF is enabled by default.

B.

User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table.

C.

User A: Pass. The default static route through wan1 passes the RPF check regardless of the source IP address.

D.

User B: Pass. FortiGate will use asymmetric routing using wan1 to reply to traffic for 95.56.234.24.

E.

User C: Fail. There is no route to 10.0.4.63 using port1 in the touting table.

Fortinet FCSS_NST_SE-7.6 Premium Access
Questions 22

Refer to the exhibit.

FCSS_NST_SE-7.6 Question 22

The modified output of live routing kemel is shown

Which two statements about the output are (rue? (Choose two.)

Options:
A.

The BGP route to 10.0.4.0/24 is not in the forwarding information base.

B.

The default static route through 10.200.1 254 is in the forwarding information* base.

C.

FortiGate is performing ECMP using both default static routes.

D.

The local FortiGate is receiving only one LSA from one OSPF neighbor.

Questions 23

Refer to the exhibit, which shows the output of the command get router info ospf neighbor.

FCSS_NST_SE-7.6 Question 23

To what extent does FortiGate operate when looking at its OSPF neighbors? (Choose two.)

Options:
A.

The local FortiGate has at least one interface that participates in a broadcast network.

B.

The local FortiGate has at least one interface that participates in a point-to-point network.

C.

The local FortiGate is the DR.

D.

Neighbor 0.0.0.18 is the designated router (DR).

Questions 24

What is an accurate description of LDAP authentication using the regular bind type?

Options:
A.

The regular bind requires the client to send the full distinguished name (ON).

B.

The regular bind type is the easiest bind type to configure on ForbOS.

C.

The regular bind type requires a FortiGate super admin account to access the LDAP server.

D.

It is not often used as a bind type

Questions 25

Refer to the exhibit.

FCSS_NST_SE-7.6 Question 25

The sniffer log on two FortiGate devices are shown. Based on the information in the log, which two factors explain the output on FortiGate FGT-02? (Choose two answers)

Options:
A.

A third-party device is blocking protocol 50.

B.

The administrator has not yet configured the VPN tunnel on FGT-02.

C.

The administrator configured the wrong remote peer IP address on FGT-01.

D.

The administrator set the wrong sniffer filter on FGT-02.

Questions 26

Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.

FCSS_NST_SE-7.6 Question 26

What two conclusions can you draw from the output? (Choose two.)

Options:
A.

The name of the configured LDAP server is Lab.

B.

The user is authenticating using CN=John Smith.

C.

FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.

D.

FortiOS is performing the second step (Search Request) in the LDAP authentication process.

Questions 27

Refer to the exhibit, which contains the output of diagnose vpn tunnel list.

FCSS_NST_SE-7.6 Question 27

Which command will capture ESP traffic for the VPN named DialUp_0?

Options:
A.

diagnose sniffer packet any 'ip proto 50'

B.

diagnose sniffer packet any 'host 10.0.10.10'

C.

diagnose sniffer packet any 'esp and host 10.200.3.2'

D.

diagnose sniffer packet any 'port 4500'

Questions 28

Refer to the exhibits.

FCSS_NST_SE-7.6 Question 28

FGT-1 is an area border router (ABR) that has interfaces in OSPF areas 0.0.0.0 and 0.0.0.5. FGT-3 acts as an autonomous system border router (ASBR), importing static routes into OSPF. FGT-2 is an internal router with all its interfaces belonging to area 0.0.0.5. FGT-1 is receiving all advertised routes from FGT-2, however, FGT-3 is not receiving any of the advertised routes from FGT-1. What is the most likely reason for this? (Choose one answer)

Options:
A.

Area 0.0.0.5 is configured not to propagate type 5 LSAs.

B.

FGT-2 is configured with a distribution list to block all advertised routes from FGT-3.

C.

FGT-3 and FGT-2 have not formed an OSPF adjacency yet.

D.

IP protocol 89 is blocked between FGT-1 and FGT-3.

Questions 29

FCSS_NST_SE-7.6 Question 29

The output of a policy route table entry is shown.

Which type of policy route does the output show?

Options:
A.

A regular policy route, which is not associated with an active static route in the FIB

B.

An ISDB route

C.

An SD-WAN rule

D.

A regular policy route, which is associated with an active static route in the FIB

Questions 30

Refer to the exhibit, which shows the partial output of FortiOS kernel slabs.

FCSS_NST_SE-7.6 Question 30

Which statement is true?

Options:
A.

The total slab size of the sctp_session slab is 0 kB and is associated with the user space.

B.

The total slab size of the ip_session slab is 3600 kB and is associated with the user space.

C.

The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.

D.

The total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.

Exam Code: FCSS_NST_SE-7.6
Certification Provider: Fortinet
Exam Name: Fortinet NSE 6 - Network Security 7.6 Support Engineer
Last Update: Feb 21, 2026
Questions: 95

Fortinet Free Exams

Fortinet Free Exams
Access free Fortinet exam study guides and practice tests at Examstrack. Ensure your success with top-notch preparation resources at Examstrack.