exam questions

Exam FCSS_EFW_AD-7.4 All Questions

View all questions & answers for the FCSS_EFW_AD-7.4 exam

Exam FCSS_EFW_AD-7.4 topic 1 question 22 discussion

Actual exam question from Fortinet's FCSS_EFW_AD-7.4
Question #: 22
Topic #: 1
[All FCSS_EFW_AD-7.4 Questions]

Refer to the exhibit, which shows a partial troubleshooting command output.

An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit.
What can the administrator conclude?

  • A. IPsec SAs cannot be offloaded.
  • B. The two IPsec SAs, inbound and outbound, are copied to the NPU.
  • C. Only the outbound IPsec SA is copied to the NPU.
  • D. Only the inbound IPsec SA is copied to the NPU.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Maria21
1 month ago
Selected Answer: A
00 = Both IPsec SAs loaded to the kernel 01 = Outbound IPsec SA copied to NPU 02 = Inbound IPsec SA copied to NPU 03 = Both outbound and inbound IPsec SA copied to NPU 20 = Unsupported cipher or HMAC, IPsec SA cannot be offloaded
upvoted 1 times
...
Yaghu
3 months, 3 weeks ago
Selected Answer: A
A is the answer.
upvoted 1 times
...
Tweefo
3 months, 3 weeks ago
Selected Answer: A
A is correct. npu_flag=20 -> Unsupported cipher or HMAC, IPSec SA cannot be offloaded Source : Study Guide P298
upvoted 2 times
...
Poskgraff
4 months ago
Selected Answer: A
El valor 20 en el campo npu_flag indica que la descarga de hardware no está disponible debido a un cifrado no compatible o un algoritmo HMAC.
upvoted 1 times
...
79cab4d
4 months ago
Selected Answer: A
Correct answer A. npu_flag=20 means unsupported cipher or HMAC. IPsec SA cannot be offloaded. Source: Network_Security_Support_Engineer_7.4_Study_Guide, p. 328
upvoted 1 times
...
Adonisthewise22
4 months ago
Selected Answer: A
npu_flag=03 Means that both ingress & egress ESP packets will be offloaded. npu_flag=20 Unsupported cipher or HMAC, IPsec SA cannot be offloaded.
upvoted 1 times
...
Adonisthewise22
4 months ago
npu_flag=03 Means that both ingress & egress ESP packets will be offloaded. npu_flag=20 Unsupported cipher or HMAC, IPsec SA cannot be offloaded.
upvoted 1 times
...
djekson
4 months ago
Selected Answer: A
npu_flag=20 means unsupported cipher or HMAC. IPsec SA cannot be offloaded. If both inbound and outbound IPsec SAs would be offloaded to NPU the flag would be npc_flag=03
upvoted 3 times
Adonisthewise22
4 months ago
npu_flag=03 Means that both ingress & egress ESP packets will be offloaded. npu_flag=20 Unsupported cipher or HMAC, IPsec SA cannot be offloaded.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...