Easter Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

NSE7_EFW-7.2 Sample Questions Answers

Questions 4

An administrator has configured two fortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device What can the administrator do to fix this problem?

Options:

A.

Verify that the speed and duplex settings match between me FortiGate interfaces and the connected switch ports

B.

Configure set link -failed signal enable under-config system ha on both Cluster members

C.

Configure remote Iink monitoring to detect an issue in the forwarding path

D.

Configure set send-garp-on-failover enables under config system ha on both cluster members

Buy Now
Questions 5

Refer to the exhibit, which shows a custom signature.

Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Choose two.)

Options:

A.

Add severity.

B.

Add attack_id.

C.

Ensure that the header syntax is F-SBID.

D.

Start options with --.

Buy Now
Questions 6

Which configuration can be used to reduce the number of BGP sessions in on IBGP network?

Options:

A.

Route-reflector-peer enable

B.

Route-reflector-client enable

C.

Route-reflector enable

D.

Route-reflector-server enable

Buy Now
Questions 7

Exhibit.

Refer to the exhibit, which contains an ADVPN network diagram and a partial BGP con figuration Which two parameters Should you configure in config neighbor range? (Choose two.)

Options:

A.

set prefix 172.16.1.0 255.255.255.0

B.

set route reflector-client enable

C.

set neighbor-group advpn

D.

set prefix 10.1.0 255.255.255.0

Buy Now
Questions 8

Which two statements about IKE version 2 fragmentation are true? (Choose two.)

Options:

A.

Only some IKE version 2 packets are considered fragmentable.

B.

The reassembly timeout default value is 30 seconds.

C.

It is performed at the IP layer.

D.

The maximum number of IKE version 2 fragments is 128.

Buy Now
Questions 9

You contoured an address object on the tool fortiGate in a Security Fabric. This object is not synchronized with a downstream device. Which two reasons could be the cause? (Choose two)

Options:

A.

The address object on the tool FortiGate has fabric-object set to disable

B.

The root FortiGate has configuration-sync set to enable

C.

The downstream TortiGate has fabric-object-unification set to local

D.

The downstream FortiGate has configuration-sync set to local

Buy Now
Questions 10

Exhibit.

Refer to the exhibit, which provides information on BGP neighbors.

Which can you conclude from this command output?

Options:

A.

The router are in the number to match the remote peer.

B.

You must change the AS number to match the remote peer.

C.

BGP is attempting to establish a TCP connection with the BGP peer.

D.

The bfd configuration to set to enable.

Buy Now
Questions 11

Exhibit.

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

Options:

A.

FortiGate creates separate virtual interfaces for each dial up client.

B.

The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.

C.

Dead peer detection s disabled.

D.

The routing table shows a single IPSec virtual interface.

Buy Now
Questions 12

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

Options:

A.

FortiManager provides FortiGuard.

B.

fortiguard-anycast is set to enable.

C.

You do not have the corresponding write access.

D.

udp is not a protocol option.

Buy Now
Questions 13

Which FortiGate in a Security I auric sends togs to FortiAnalyzer?

Options:

A.

Only the root FortiGate.

B.

Each FortiGate in the Security fabric.

C.

The FortiGate devices performing network address translation (NAT) or unified threat management (UTM). if configured.

D.

Only the last FortiGate that handled a session in the Security Fabric

Buy Now
Questions 14

You want to configure faster failure detection for BGP

Which parameter should you enable on both connected FortiGate devices?

Options:

A.

Ebgp-enforce-multihop

B.

bfd

C.

Distribute-list-in

D.

Graceful-restart

Buy Now
Questions 15

Which statement about network processor (NP) offloading is true?

Options:

A.

For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP

B.

The NP provides IPS signature matching

C.

You can disable the NP for each firewall policy using the command np-acceleration st to loose.

D.

The NP checks the session key or IPSec SA

Buy Now
Exam Code: NSE7_EFW-7.2
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.2
Last Update: May 14, 2024
Questions: 50
$64  $159.99
$48  $119.99
$40  $99.99
buy now NSE7_EFW-7.2