質問 1:An administrator logs into a FortiGate unit using an account which has been assigned a super_admin profile. Which of the following operations can this administrator perform?
A. They can delete logged-in users who are also assigned the super_admin access profile.
B. They can view all the system configuration settings but can not make changes.
C. They can access configuration options for only the VDOMs to which they have been assigned.
D. They can make changes to the super_admin profile.
E. They can delete the admin account if the default admin user is not logged in.
正解:E
質問 2:Examine the following log message for IPS and identify the valid responses below. (Select all that apply.)
2012-07-01 09:54:28 oid=2 log_id=18433 type=ips subtype=anomaly pri=alert vd=root severity="critical" src="192.168.3.168" dst="192.168.3.170" src_int="port2" serial=0 status="detected" proto=1 service="icmp" count=1 attack_name="icmp_flood" icmp_id="0xa8a4" icmp_type="0x08" icmp_code="0x00" attack_id=16777316 sensor="1" ref="http://www.fortinet.com/ids/VID16777316" msg="anomaly: icmp_flood, 51 > threshold 50"
A. The target is 192.168.3.168.
B. The target is 192.168.3.170.
C. The attack was TCP based.
D. The attack was detected only.
E. The attack was detected and blocked.
正解:B,D
質問 3:Which of the following statements are TRUE for Port Pairing and Forwarding Domains? (Select all that apply.)
A. They may contain physical and/or virtual interfaces.
B. They are only available in high-end models.
C. Port Pairing works only for physical interfaces.
D. They both create separate broadcast domains.
E. Forwarding Domains only apply to virtual interfaces.
正解:A,D
解説: (Topexam メンバーにのみ表示されます)
質問 4:Examine the Exhibit shown below; then answer the question following it.

The Vancouver FortiGate unit initially had the following information in its routing table:
S 172.20.0.0/16 [10/0] via 172.21.1.2, port2 C 172.21.0.0/16 is directly connected, port2 C 172.11.11.0/24 is directly connected, port1
Afterwards, the following static route was added:
config router static edit 6 set dst 172.20.1.0 255.255.255.0 set pririoty 0 set device port1 set gateway 172.11.12.1
next end
Since this change, the new static route is NOT showing up in the routing table. Given the information provided, which of the following describes the cause of this problem?
A. The subnet 172.20.1.0/24 is overlapped with the subnet of one static route that is already in the routing table (172.20.0.0/16), so, we need to enable allow-subnet-overlap first.
B. The 'gateway' IP address is NOT in the same subnet as the IP address of port1.
C. The static route configuration is missing the distance setting.
D. The priority is 0, which means that the route will remain inactive.
正解:B
質問 5:An administrator is examining the attack logs and notices the following entry:
device_id=FG100A3907508962 log_id=18432 subtype=anomaly type=ips timestamp=1270017358 pri=alert itime=1270017893 severity=critical src=192.168.1.52 dst=64.64.64.64 src_int=internal serial=0 status=clear_session proto=6 service=http vd=root count=1 src_port=35094 dst_port=80 attack_id=100663402 sensor=protect-servers ref=http://www.fortinet.com/ids/VID100663402 msg="anomaly: tcp_src_session, 2 > threshold 1" policyid=0 carrier_ep=N/A profile=N/A dst_int=N/A user=N/A group=N/A
Based solely upon this log message, which of the following statements is correct?
A. This attack was caught by the DoS sensor "protect-servers".
B. The number of concurrent connections to destination IP address 64.64.64.64 has exceeded the configured threshold.
C. This attack was launched against the FortiGate unit itself rather than a host behind the FortiGate unit.
D. This attack was blocked by the HTTP protocol decoder.
正解:A
質問 6:Based on the web filtering configuration illustrated in the exhibit, which one of the following statements is not a reasonable conclusion?
A. Users can access both the www.google.com site and the www.fortinet.com site.
B. Downloaded content from www.google.com will be scanned for viruses if antivirus is enabled.
C. When a user attempts to access the www.google.com site, the FortiGate unit will not perform web filtering on the content of that site.
D. When a user attempts to access the www.fortinet.com site, any remaining web filtering will be bypassed.
正解:C
安全的な支払方式を利用しています
Credit Cardは今まで全世界の一番安全の支払方式です。少数の手続きの費用かかる必要がありますとはいえ、保障があります。お客様の利益を保障するために、弊社のFCNSP問題集は全部Credit Cardで支払われることができます。
領収書について:社名入りの領収書が必要な場合、メールで社名に記入していただき送信してください。弊社はPDF版の領収書を提供いたします。
弊社は失敗したら全額で返金することを承諾します
我々は弊社のFCNSP問題集に自信を持っていますから、試験に失敗したら返金する承諾をします。我々のFortinet FCNSPを利用して君は試験に合格できると信じています。もし試験に失敗したら、我々は君の支払ったお金を君に全額で返して、君の試験の失敗する経済損失を減少します。
弊社のFortinet FCNSPを利用すれば試験に合格できます
弊社のFortinet FCNSPは専門家たちが長年の経験を通して最新のシラバスに従って研究し出した勉強資料です。弊社はFCNSP問題集の質問と答えが間違いないのを保証いたします。

この問題集は過去のデータから分析して作成されて、カバー率が高くて、受験者としてのあなたを助けて時間とお金を節約して試験に合格する通過率を高めます。我々の問題集は的中率が高くて、100%の合格率を保証します。我々の高質量のFortinet FCNSPを利用すれば、君は一回で試験に合格できます。
弊社は無料Fortinet FCNSPサンプルを提供します
お客様は問題集を購入する時、問題集の質量を心配するかもしれませんが、我々はこのことを解決するために、お客様に無料FCNSPサンプルを提供いたします。そうすると、お客様は購入する前にサンプルをダウンロードしてやってみることができます。君はこのFCNSP問題集は自分に適するかどうか判断して購入を決めることができます。
FCNSP試験ツール:あなたの訓練に便利をもたらすために、あなたは自分のペースによって複数のパソコンで設置できます。
TopExamは君にFCNSPの問題集を提供して、あなたの試験への復習にヘルプを提供して、君に難しい専門知識を楽に勉強させます。TopExamは君の試験への合格を期待しています。
一年間の無料更新サービスを提供します
君が弊社のFortinet FCNSPをご購入になってから、我々の承諾する一年間の更新サービスが無料で得られています。弊社の専門家たちは毎日更新状態を検査していますから、この一年間、更新されたら、弊社は更新されたFortinet FCNSPをお客様のメールアドレスにお送りいたします。だから、お客様はいつもタイムリーに更新の通知を受けることができます。我々は購入した一年間でお客様がずっと最新版のFortinet FCNSPを持っていることを保証します。
Fortinet Certified Network Security Professional (FCNSP v4.2) 認定 FCNSP 試験問題:
1. Review the IKE debug output for IPsec shown in the Exhibit below.

Which one of the following statements is correct regarding this output?
A) The output captures the Dead Gateway Detection packets.
B) The output captures the Dead Peer Detection messages.
C) The output is a Phase 1 negotiation.
D) The output is a Phase 2 negotiation.
2. The FortiGate Server Authentication Extensions (FSAE) provide a single sign on solution to authenticate users transparently to a FortiGate unit using credentials stored in Windows Active Directory.
Which of the following statements are correct regarding FSAE in a Windows domain environment when NTLM is not used? (Select all that apply.)
A) An FSAE Collector Agent must be installed on every domain controller.
B) For non-domain computers, an FSAE client must be installed on the computer to allow FSAE authentication.
C) The FSAE Domain Controller Agent will regularly update user logon information on the FortiGate unit.
D) An FSAE Domain Controller Agent must be installed on every domain controller.
E) The FSAE Collector Agent will retrieve user information from the Domain Controller Agent and will send the user logon information to the FortiGate unit.
3. A DLP rule with an action of Exempt has been matched against traffic passing through the FortiGate unit. Which of the following statements is correct regarding how this transaction will be handled by the FortiGate unit?
A) The client IP address will be added to a white list.
B) Future files whose characteristics match this file will bypass DLP scanning.
C) Any other matched DLP rules will be ignored with the exception of Archiving.
D) The traffic matching the DLP rule will bypass antivirus scanning.
4. Which of the following items is NOT a packet characteristic matched by a firewall service object?
A) IP protocol number
B) TCP/UDP source and destination ports
C) TCP sequence number
D) ICMP type and code
5. What advantages are there in using a fully Meshed IPSec VPN configuration instead of a hub and spoke set of IPSec tunnels?
A) Full mesh topology is the most fault-tolerant configuration.
B) Using a full mesh topology simplifies configuration.
C) Using a full mesh topology provides stronger encryption.
D) Using a hub and spoke topology is required to achieve full redundancy.
質問と回答:
質問 # 1 正解: B | 質問 # 2 正解: D、E | 質問 # 3 正解: C | 質問 # 4 正解: C | 質問 # 5 正解: A |