Fortinet
NSE7_NST-7.2
Q1:
What are two functions of automation stitches? (Choose two.)
☐
A
You can configure automation stitches on any FortiGate device in a Security Fabric environment.☐
B
You can create automation stitches to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds.☐
C
An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action.☐
D
You can set an automation stitch configured to execute actions in parallel to insert a specific delay between actions.
Fortinet
NSE7_NST-7.2
Q2:
Refer to the exhibit, which shows the output of diagnose sys session stat. Which statement about the output shown in the exhibit is correct?
○
A
AII the sessions in the session table are TCP sessions.○
B
162 sessions have been deleted because of memory page exhaustion.○
C
There are 166 TCP sessions waiting to complete the three-way handshake.○
D
There are two sessions that have not been removed in case of any out-of-order packets that arrive.
Fortinet
NSE7_NST-7.2
Q3:
Refer to the exhibit, which shows the omitted output of FortiOS kernel slabs.

Which statement is true?
○
A
The total slab size of the tcp_sessior. slab Is 7500 kB and is associated with the kernel.○
B
The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.○
C
The total slab size of the sctp_session slab is 0 kB and is associated with the user space○
D
The total slab size of the ip_session slab is 3600 kB and is associated with the user space.
Fortinet
NSE7_NST-7.2
Q4:
Exhibit.

Refer to the exhibit, which shows the output of diagnose sys session list.
If the HA ID for the primary device is 0. what happens if the primary fails and the secondary becomes the primary?
○
A
The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.○
B
The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.○
C
Traffic for this session continues to be permitted on the new primary device after failover. without requiring the client to restart the session with the server.○
D
The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.
Fortinet
NSE7_NST-7.2
Q5:
There are four exchanges during IKEv2 negotiation.
Which sequence is correct?
○
A
IKE_Proposal, ID_Auth, PiggyBack_CHILD and Informational○
B
lnit_Req, Wait_lnit_Req, ID_Auth_Req and Create_CHILD_SA○
C
INIT_Re, INIT_Auth, ID_Child and SET_Nonce○
D
IKE_SAJNIT, IKE_Auth, Create_CHILD_SA and Informational