Refer to the exhibit. The output of diagnose sys session list command is shown. If the HA ID for the primary device is 9, what happens if the primary fails and the secondary becomes the primary?
Correct Answer: C
The output of the diagnose sys session list command provides the critical evidence needed to determine the behavior during a failover: Session Synchronization (synced): The most important indicator in the exhibit is the synced flag located in the state= line (state=may_dirty synced none app_ntf). In FortiOS HA (High Availability), the synced flag confirms that this specific session has been successfully synchronized from the primary device to the secondary (backup) device. Session synchronization (Session Pickup) ensures that if the primary unit fails, the secondary unit already has the session in its table and can resume traffic processing immediately. TCP State (proto_state=01): The output shows proto=6 (TCP) and proto_state=01. In the FortiGate session table, proto_state=01 for TCP indicates that the session is in the ESTABLISHED state (post-three-way handshake). This invalidates Option B, which claims the TCP session is not fully established. Failover Outcome: Because the session is ESTABLISHED and SYNCED, the secondary device will seamlessly take over the session upon primary failure. The traffic continues to flow through the new primary without requiring the user/client to restart the connection. This is the primary function of HA Session Pickup. Why other options are incorrect: A: While the output shows app_ntf (Application Control notification) and may_dirty, the presence of the synced flag overrides this concern regarding failover. If the session type were not supported for failover (e.g., certain proxy sessions in older versions), it would not be marked as synced. Since it is synced, it persists. B: As noted, proto_state=01 means established, not "not fully established". D: While the kernel updates routing tables, the purpose of syncing the session is to preserve the state so it does not need to be re-evaluated as a new packet would, preventing traffic drops. Reference: FortiGate Security 7.6 Study Guide (High Availability): "If session pickup is enabled, the primary unit synchronizes its session table... to the backup unit. If the primary unit fails, the backup unit... continues to process the sessions with no interruption."
Question 22
Refer to the exhibit. The output from a collector agent log is shown. The collector agent is showing the status of a workstation as Not Verified . What are two common causes for this message? (Choose two.)
Correct Answer: B,C
The correct answers are B and C . The study guide has a section titled "Not Verified Status on the Collector Agent" and states: "The collector agent cannot verify if the user is still logged in" and lists these common causes : * "A firewall is blocking traffic to port 139 and 445" * "The workstation remote registry service is not running" The guide also explains the verification method: "For WMI polling mode, the collector agent checks the WMI service. For all the other modes, the collector agent checks the HKEY_USERS hive through remote registry services." If the workstation does not respond to these checks, the status can become not verified An additional requirements slide in the same study guide confirms: * "TCP ports 139 and 445 must be open between the collector agent and all workstations" * "Remote registry service must be up and running on each workstation" Why the other options are wrong: * A is wrong because the study guide mentions a workstation coming out of hibernate mode under a different problem: "No Internet After IP Address Change" , not as a common cause of Not Verified status * D is wrong because DNS resolution issues are also discussed under the IP address change scenario, where the collector agent uses DNS to resolve the workstation name after an IP change. That is separate from the Not Verified causes listed for this log message So the verified answers are: B, C .
Question 23
Which statement about parallel path processing is correct (PPP)?
Correct Answer: A
Question 24
Which two statements about an auxiliary session ate true? (Choose two.)
Correct Answer: B,C
Auxiliary sessions in Fortinet are designed to support ECMP (Equal Cost Multi-Path) and SD-WAN scenarios, allowing sessions to be handled efficiently when traffic needs to be dynamically distributed across multiple links. With the auxiliary session setting enabled, FortiGate creates additional session table entries for each possible path in ECMP or SD-WAN-meaning that if the routing path changes (such as a link failover), a new session can be immediately activated and offloaded to the NP6 network processor for acceleration, ensuring minimal disruption. This greatly benefits high-throughput deployments. Official documentation specifies that when auxiliary sessions are enabled, FortiGate doesn't just rely on dynamically creating new sessions after a routing event, it proactively creates sessions for all potential paths. This means that in the event of a route change, two sessions exist and the traffic is quickly re-routed and offloaded, maximizing performance and reliability. Without this feature, multiple paths cannot be efficiently offloaded, and routing changes trigger a single session update, reducing failover performance. References: FortiOS Handbook: Session Table, ECMP, SD-WAN, and Auxiliary Sessions FortiGate NP6 Acceleration Guide: Auxiliary Session Behavior
Question 25
Refer to the exhibit, which contains the output of diagnose vpn tunnel list. Which command will capture ESP traffic for the VPN named DialUp_0?