Fortinet FCSS_NST_SE-7.6 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Fortinet FCSS_NST_SE-7.6 Exam Dumps and Practice Test Dumps

 

Q281. What is the primary purpose of BFD when used with dynamic routing protocols?

1) Provide rapid failure detection
2) Encrypt routing updates
3) Create VLAN interfaces
4) Replace the routing table

Correct Answer: 1)

Explanation:

Bidirectional Forwarding Detection (BFD) provides a fast mechanism for detecting failures between network devices. Routing protocols can use BFD information to react more quickly than they might when relying only on their own timers. This can improve convergence when a forwarding path becomes unavailable. BFD operates independently of the routing protocol and can be associated with supported protocols such as BGP. It does not replace routing protocols, encrypt routing information, or create interfaces. When troubleshooting fast failover behavior, administrators should verify BFD configuration, timers, neighbor status, and whether the routing protocol is correctly using BFD events.

Q282. What can happen if BFD detection timers are configured too aggressively?

1) Routing becomes permanently disabled
2) Temporary network variations may trigger unnecessary failures
3) All routes are automatically summarized
4) BGP changes to UDP

Correct Answer: 2)

Explanation:

BFD is designed for rapid failure detection, but extremely aggressive timers can make a network overly sensitive to short-lived packet loss or processing delays. This may cause the device to incorrectly consider a healthy path unavailable, resulting in unnecessary routing changes or session resets. Administrators should select BFD timers that provide sufficiently fast detection without reacting to normal transient conditions. Testing should consider the stability of the underlying network and device capabilities. Proper BFD configuration balances rapid convergence with operational stability and helps prevent repeated route changes caused by brief, nonpersistent connectivity problems.

Q283. Which feature can help a FortiGate detect whether a static route’s associated path is still available?

1) Static route tracking or link monitoring
2) Antivirus scanning
3) DNS filtering
4) Application Control

Correct Answer: 1)

Explanation:

Static route tracking or link-monitoring mechanisms can help determine whether a path associated with a static route remains usable. Instead of relying only on the physical interface status, monitoring can test reachability to a configured destination. If the monitored path fails, the device can take appropriate action, such as removing or deactivating the associated route so that another route can be selected. This is useful for primary and backup WAN designs. Administrators should ensure that the monitored destination accurately represents the desired path and that backup routing is configured correctly.

Q284. Why is route tracking useful in a primary and backup WAN design?

1) It can remove an unusable primary path from routing decisions
2) It increases the MTU automatically
3) It disables firewall inspection
4) It creates additional BGP autonomous systems

Correct Answer: 1)

Explanation:

Route tracking helps ensure that routing decisions reflect actual path availability rather than simply the administrative state of an interface. A WAN interface may remain physically up even when the upstream Internet connection is unavailable. By monitoring a reliable destination, the FortiGate can detect this condition and remove or deactivate the affected primary route when appropriate. A backup route can then become active. This provides more reliable failover than checking only whether the local interface is operational. Proper monitoring targets and route priorities are essential for predictable failover behavior.

Q285. What is a common ECMP behavior for traffic distribution?

1) Use a hashing mechanism to distribute flows across equal-cost paths
2) Send every packet through every path simultaneously
3) Disable all backup routes
4) Randomly change the destination IP address

Correct Answer: 1)

Explanation:

ECMP commonly uses a hashing mechanism based on characteristics of the traffic flow to distribute sessions across multiple equal-cost paths. This approach helps maintain consistency so packets belonging to the same flow generally use the same path rather than being randomly distributed packet by packet. The exact hashing inputs and behavior depend on the platform and configuration. ECMP can improve utilization and provide redundancy, but administrators should consider how multiple paths affect stateful security inspection, asymmetric routing, and troubleshooting. Properly designed ECMP provides efficient use of available paths while maintaining predictable session forwarding.

Q286. What is a potential concern when ECMP causes traffic to take different forward and return paths through stateful firewalls?

1) Asymmetric routing may interfere with session processing
2) DNS records are automatically deleted
3) All interfaces become VLANs
4) BGP stops using TCP

Correct Answer: 1)

Explanation:

Stateful firewalls maintain information about active sessions and may expect packets belonging to a session to follow an appropriate path through the security device. ECMP can create asymmetric routing where the forward direction uses one path while the return direction uses another. Depending on the topology and security design, this may cause sessions to fail or require additional configuration. Administrators should investigate routing symmetry, session synchronization, and firewall forwarding behavior when ECMP is deployed. Understanding path selection is particularly important when multiple WAN links or redundant security devices are involved.

Q287. What should an administrator verify if an SD-WAN health check reports a WAN member as unavailable?

1) The health-check destination and connectivity through that member
2) Only the administrator’s password
3) The number of firewall objects
4) The device serial number

Correct Answer: 1)

Explanation:

When an SD-WAN health check reports a member as unavailable, the administrator should verify whether the configured health-check destination is reachable through that specific WAN member. The physical interface may be operational while upstream connectivity is unavailable. Administrators should inspect routing, health-check configuration, packet loss, latency, and the selected probe destination. They should also confirm that security policies or upstream devices are not blocking the health-check traffic. Reviewing these elements helps determine whether the failure represents a genuine WAN problem or an incorrectly configured monitoring destination.

Q288. Which factor should be considered when selecting an SD-WAN health-check destination?

1) The destination should reliably represent the availability of the desired WAN path
2) It should always be the firewall’s management IP
3) It should never respond to probes
4) It should be an unreachable private address

Correct Answer: 1)

Explanation:

An SD-WAN health-check destination should provide a meaningful indication of whether the associated WAN path is usable. If the destination is unstable, unavailable, or unrelated to the service being evaluated, the health-check results may not accurately represent actual WAN performance. Administrators should select reliable destinations and consider how routing and Internet connectivity reach those destinations through each WAN member. Multiple monitoring targets may sometimes provide a more representative assessment. A carefully selected health-check target helps SD-WAN make better path-selection decisions and reduces unnecessary failover caused by misleading monitoring results.

Q289. Which SD-WAN configuration can determine whether a WAN member is preferred when multiple members satisfy the required SLA?

1) Member priority or preference
2) Antivirus profile
3) DNS cache
4) User authentication timeout

Correct Answer: 1)

Explanation:

When multiple SD-WAN members satisfy the required performance SLA, configured member preference or priority can influence which path is selected. This allows administrators to express business requirements such as preferring a private connection over a backup Internet link when both provide acceptable performance. SLA compliance alone does not necessarily mean every path should be treated equally. Administrators should therefore review member priorities, SD-WAN rules, and performance measurements together. Correct configuration ensures that the preferred path is used under normal conditions while another suitable member can take over when the preferred path becomes unsuitable.

Q290. What is an important difference between physical interface status and SD-WAN SLA status?

1) An interface can be physically up while failing performance requirements
2) They are always identical
3) SLA status only checks cable connectivity
4) Physical status measures application performance

Correct Answer: 1)

Explanation:

A physical interface can remain operational even when the WAN path has poor performance or cannot reach important destinations. Interface status typically indicates whether the local link is operational, while an SD-WAN SLA can evaluate conditions such as latency, jitter, packet loss, and reachability. This distinction is important because SD-WAN decisions may need to react to degraded performance even though the interface itself remains up. Administrators should therefore avoid assuming that an operational interface automatically represents a healthy WAN path. Both interface status and SLA measurements should be reviewed during troubleshooting.

Q291. What is the primary purpose of BGP route filtering at an external network boundary?

1) Control which prefixes are accepted or advertised
2) Increase CPU temperature
3) Disable TCP
4) Replace all routing protocols

Correct Answer: 1)

Explanation:

BGP route filtering controls which network prefixes are accepted from or advertised to external neighbors. This is an important security and routing-management practice because it prevents accidental advertisement of unintended networks and limits the routes accepted from external autonomous systems. Prefix lists, route maps, and related routing policies can be used to implement these controls. Without appropriate filtering, a configuration mistake can potentially cause incorrect route propagation or routing instability. Administrators should define expected prefixes clearly and regularly review external BGP policies to ensure that only authorized routes are exchanged.

Q292. What can happen if a route map unintentionally denies a BGP prefix?

1) The prefix may not be advertised or accepted as intended
2) The firewall automatically reboots
3) The WAN interface changes its MAC address
4) The BGP router creates a new VLAN

Correct Answer: 1)

Explanation:

A route map can explicitly permit or deny routes based on configured matching conditions. If a route unintentionally matches a deny sequence, the prefix may not be advertised to a neighbor or may be rejected when received, depending on where the policy is applied. This is a common troubleshooting consideration when a route exists locally but does not appear in the neighbor’s routing table. Administrators should inspect route-map sequence order, match conditions, prefix lists, and policy direction. Reviewing the complete routing policy helps identify whether filtering is responsible for the missing prefix.

Q293. Which command output or information is most useful for determining why a BGP route was not selected as the best path?

1) BGP routing information showing available paths and attributes
2) Web-filter category names
3) Antivirus signature version only
4) Administrator login history

Correct Answer: 1)

Explanation:

To understand why a BGP route was not selected as the best path, administrators should examine the available BGP paths and their attributes. Important information can include Local Preference, weight where applicable, locally originated status, AS Path length, origin, MED, and other selection factors. The next-hop reachability should also be confirmed because an otherwise attractive route may not be usable if its next hop cannot be resolved. Reviewing the BGP routing information provides a much clearer explanation than looking only at the general routing table or unrelated security configuration.

Q294. What is the purpose of checking the routing table after receiving a BGP route?

1) Confirm whether the route is eligible for installation and forwarding
2) Determine the antivirus version
3) Identify the administrator’s password
4) Configure DNS filtering

Correct Answer: 1)

Explanation:

Receiving a BGP route does not necessarily mean that the route will be installed in the active routing table. The device may compare it with routes learned from other sources, evaluate administrative distance and route preference, and verify next-hop reachability. Checking the routing table helps determine whether the BGP route became the active route used for forwarding. If it is absent, administrators should compare BGP information with the routing table and investigate competing routes, invalid next hops, policy filtering, or other conditions. This distinction is essential when troubleshooting why traffic is not following a BGP-learned path.

Q295. What is the purpose of a blackhole route in a routing design?

1) Intentionally discard traffic matching a specific destination
2) Encrypt all Internet traffic
3) Increase WAN bandwidth
4) Establish BGP sessions

Correct Answer: 1)

Explanation:

A blackhole route intentionally directs matching traffic to a discard interface or null destination rather than forwarding it toward a normal next hop. Blackhole routes can be useful for preventing routing loops, protecting against unwanted traffic, or supporting certain route-summarization designs. For example, a summary route may be accompanied by a discard route so that traffic for unused addresses within the summarized range does not circulate indefinitely. Administrators must use blackhole routes carefully because legitimate traffic can also be discarded if the prefix is too broad or incorrectly configured.

Q296. What is recursive routing resolution used for?

1) Resolve a route’s next hop through another routing entry
2) Encrypt route advertisements
3) Replace BGP with DNS
4) Create security profiles

Correct Answer: 1)

Explanation:

Recursive routing resolution occurs when the next-hop address of a route is not directly connected and the router must use another routing-table entry to determine how to reach that next hop. This allows a route to reference a logical or remote next-hop address rather than requiring the next hop to be directly connected. Recursive resolution is common in dynamic routing and certain static-route designs. If the recursive lookup fails, the route may become unusable. Troubleshooting should therefore verify both the original route and the routing information required to resolve its next-hop address.

Q297. What is a common reason a static route may not be installed as expected?

1) Its next hop cannot be resolved or the route has lower preference than another route
2) The hostname contains uppercase letters
3) Antivirus scanning is enabled
4) DNS filtering is disabled

Correct Answer: 1)

Explanation:

A static route may fail to become active if its next hop is unreachable or cannot be resolved through the routing table. Another possibility is that a different route to the same destination has a more preferred administrative distance or routing preference. Administrators should inspect the configured next hop, interface status, routing table, and competing routes when troubleshooting. A static route does not automatically override every other route simply because it was manually configured. Understanding route preference and next-hop resolution is therefore important for predicting which path the FortiGate will actually use.

Q298. Which routing behavior selects the most specific matching prefix?

1) Longest-prefix match
2) Random path selection
3) Lowest interface number
4) DNS priority

Correct Answer: 1)

Explanation:

Longest-prefix match is a fundamental IP routing principle in which the route with the most specific matching network prefix is preferred for forwarding traffic. For example, a route for a specific subnet is generally preferred over a broader route covering the entire larger network. This behavior allows administrators to create more precise routing decisions while retaining broader summary routes as fallbacks. When troubleshooting unexpected forwarding, checking for more-specific routes is essential because the presence of a broad preferred route does not necessarily mean it will be used if a longer matching prefix exists.

Q299. What should an administrator examine if traffic unexpectedly follows a more specific route instead of a summary route?

1) The routing table and longest-prefix match entries
2) The antivirus database only
3) The administrator profile
4) The DNS filter categories

Correct Answer: 1)

Explanation:

When traffic follows an unexpected path, administrators should inspect the routing table for more-specific entries that match the destination. Longest-prefix match means that a specific route can take precedence over a broader summary route. The administrator should compare destination prefixes, next hops, administrative distances, and route sources. If the specific route was learned dynamically, its origin and policy should also be investigated. This method helps determine whether the behavior is expected according to routing rules or caused by an unintended route advertisement or configuration. It is especially useful when troubleshooting complex BGP and SD-WAN environments.

Q300. Which approach provides the most reliable troubleshooting sequence for a FortiGate forwarding problem involving BGP and SD-WAN?

1) Change random settings until traffic works
2) Check only the physical interface
3) Verify policy matching, route selection, BGP information, SD-WAN rules, and member health
4) Disable all routing protocols

Correct Answer: 3)

Explanation:

A structured troubleshooting sequence is the most reliable way to diagnose forwarding problems involving BGP and SD-WAN. First, confirm that the traffic matches the intended firewall policy. Next, inspect the routing table and determine the selected route and next hop. Then examine BGP information to understand learned routes and attributes. After that, review SD-WAN rules, member priorities, and SLA results to determine the selected WAN path. Finally, verify interface and health-check status. Following the actual forwarding decision process prevents unnecessary configuration changes and makes it easier to isolate whether the problem is caused by policy, routing, or SD-WAN.