Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Certification > NSE7_EFW-7.2

NSE7_EFW-7.2 Fortinet NSE 7 - Enterprise Firewall 7.2 Question and Answers

Question # 4

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

A.

FortiManager provides FortiGuard.

B.

fortiguard-anycast is set to enable.

C.

You do not have the corresponding write access.

D.

udp is not a protocol option.

Full Access
Question # 5

Exhibit.

Refer to the exhibit, which contains a CLI script configuration on fortiManager. An administrator configured the CLI script on FortiManager rut the script tailed to apply any changes to the managed

device after being executed.

What are two reasons why the script did not make any changes to the managed device? (Choose two)

A.

The commands that start with the # sign did not run.

B.

Incomplete commands can cause CLI scripts to fail.

C.

Static routes can be added using only TCI scripts.

D.

CLI scripts must start with #!.

Full Access
Question # 6

Which two statements about IKE vision 2 are true? (Choose two.)

A.

Phase 1 includes main mode

B.

It supports the extensible authentication protocol (EAP)

C.

It supports the XAuth protocol.

D.

It exchanges a minimum of four messages to establish a secure tunnel

Full Access
Question # 7

You want to configure faster failure detection for BGP

Which parameter should you enable on both connected FortiGate devices?

A.

Ebgp-enforce-multihop

B.

bfd

C.

Distribute-list-in

D.

Graceful-restart

Full Access
Question # 8

Refer to the exhibit, which shows the output of a BGP summary.

What two conclusions can you draw from this BGP summary? (Choose two.)

A.

External BGP (EBGP) exchanges routing information.

B.

The BGP session with peer 10. 127. 0. 75 is established.

C.

The router 100. 64. 3. 1 has the parameter bfd set to enable.

D.

The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.

Full Access
Question # 9

Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)

A.

Dead peer detection is set to enable.

B.

The IKE version is 2.

C.

Both IPsec SAs are loaded on the kernel.

D.

Forward error correction in phase 2 is set to enable.

Full Access
Question # 10

Exhibit.

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

A.

IPSec Tunnel aggregation is configured

B.

net-device is enabled in the tunnel IPSec phase 1 configuration

C.

OSPI is configured to run over IPSec.

D.

add-route is disabled in the tunnel IPSec phase 1 configuration.

Full Access
Question # 11

Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

A.

Enable AD-VPN in IPsec phase 1

B.

Disable add-route on hub

C.

Configure IP addresses on IPsec virtual interlaces

D.

Set protected network to all

Full Access
Question # 12

Exhibit.

Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.

Which two conclusions can you draw from this con figuration? (Choose two)

A.

10.1.5.254 is the default gateway of the internal network

B.

On failover new primary device uses the same MAC address as the old primary

C.

The VRRP domain uses the physical MAC address of the primary FortiGate

D.

By default FortiGate B is the primary virtual router

Full Access
Question # 13

Refer to the exhibit, which shows a network diagram.

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

A.

Set route-overlap to allow.

B.

Set single-source to enable

C.

Set route-overlap to either use—new or use-old

D.

Set net-device to enable

Full Access
Question # 14

Exhibit.

Refer to the exhibit, which contains a partial policy configuration.

Which setting must you configure to allow SSH?

A.

Specify SSH in the Service field

B.

Configure pot 22 in the Protocol Options field.

C.

Include SSH in the Application field

D.

Select an application control profile corresponding to SSH in the Security Profiles section

Full Access
Question # 15

An administrator has configured two fortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device What can the administrator do to fix this problem?

A.

Verify that the speed and duplex settings match between me FortiGate interfaces and the connected switch ports

B.

Configure set link -failed signal enable under-config system ha on both Cluster members

C.

Configure remote Iink monitoring to detect an issue in the forwarding path

D.

Configure set send-garp-on-failover enables under config system ha on both cluster members

Full Access