Labour Day Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

NSE7_EFW-7.0 Sample Questions Answers

Questions 4

Refer to the exhibit, which shows the output of a debug command.

What can be concluded from the debug command output?

Options:

A.

The OSPF router with the ID 0.0.0.69 has its OSPF priority set to 0.

B.

The local FortiGate has a different MTU value from the OSPF router with ID 0.0.0.2, based on the state information.

C.

There are more than two OSPF routers on the wan2 network.

D.

The interface ToRemote is a broadcast OSPF network.

Buy Now
Questions 5

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Which two statements about this debug output are correct? (Choose two.)

Options:

A.

The initiator provided remote as its IPsec peer ID.

B.

It shows a phase 2 negotiation.

C.

Perfect Forward Secrecy (PFS) is enabled in the configuration.

D.

The local gateway IP address is 10.0.0.1.

Buy Now
Questions 6

Refer to the exhibit, which contains a TCL script configuration on FortiManager.

An administrator has configured the TCL script on FortiManager, but failed to apply any changes to the managed device after being executed.

Why did the TCL script fail to make any changes to the managed device?

Options:

A.

Changes in an interface configuration can only be done by CLI script.

B.

The TCL script must start with #include <>.

C.

Incomplete commands are ignored in TCL scripts.

D.

The TCL command run_cmd has not been created.

Buy Now
Questions 7

Which two statements about the Security Fabric are true? (Choose two.)

Options:

A.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer.

B.

Only the root FortiGate sends logs to FortiAnalyzer.

C.

Only FortiGate devices with fabric-object-unification set to default will receive and synchronize global CMDB objects sent by the root FortiGate.

D.

FortiGate uses FortiTelemetry protocol to communicate with FortiAnalyzer.

Buy Now
Questions 8

An administrator is running the following sniffer in a FortiGate:

diagnose sniffer packet any “host 10.0.2.10” 2

What information is included in the output of the sniffer? (Choose two.)

Options:

A.

Ethernet headers.

B.

IP payload.

C.

IP headers.

D.

Port names.

Buy Now
Questions 9

Refer to the exhibit, which contains the partial output of a diagnose command.

Based on the output, which two statements are correct? (Choose two.)

Options:

A.

Anti-replay is enabled

B.

The remote gateway IP is 10.200.4.1.

C.

DPD is disabled.

D.

Quick mode selectors are disabled.

Buy Now
Questions 10

View the exhibit, which contains a partial web filter profile configuration, and then answer the question below.

Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

Options:

A.

FortiGate will exempt the connection based on the Web Content Filter configuration.

B.

FortiGate will block the connection based on the URL Filter configuration.

C.

FortiGate will allow the connection based on the FortiGuard category based filter configuration.

D.

FortiGate will block the connection as an invalid URL.

Buy Now
Questions 11

View the exhibit, which contains the partial output of a diagnose command, and then answer the question below.

Based on the output, which of the following statements is correct?

Options:

A.

Anti-reply is enabled.

B.

DPD is disabled.

C.

Quick mode selectors are disabled.

D.

Remote gateway IP is 10.200.5.1.

Buy Now
Questions 12

Refer to exhibit, which contains the output of a BGP debug command.

Which statement explains why the state of the 10.200.3.1 peer is Connect?

Options:

A.

The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the OpenConfirm yet.

B.

The TCP session to 10.200.3.1 has not completed the three-way handshake.

C.

The local router is receiving the BGP keepalives from the peer, but it has not received a BGP prefix yet.

D.

The local router has received the BGP prefixes from the remote peer.

Buy Now
Questions 13

How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as a local FDS?

Options:

A.

FortiManager can download and maintain local copies of FortiGuard databases.

B.

FortiManager supports only FortiGuard push to managed devices.

C.

FortiManager will respond to update requests only if they originate from a managed device.

D.

FortiManager does not support rating requests.

Buy Now
Questions 14

Exhibits:

Refer to the exhibits, which contain the network topology and BGP configuration for a hub.

An administrator is trying to configure ADVPN with a hub-spoke VPN setup using iBGP. All the VPNs are up and connected to the hub. The hub is receiving route information from both spokes over iBGP; however, the spokes are not receiving route information from each other.

What change must the administrator make to the hub BGP configuration so that the routes learned by one spoke are forwarded to the other spokes?

Options:

A.

Configure an individual neighbor and remove neighbor-range configuration.

B.

Configure the hub as a route reflector client.

C.

Change the router id to 10.1.0.254.

D.

Make the configuration of remote-as different from the configuration of local-as.

Buy Now
Questions 15

Refer to the exhibit, which shows partial outputs from two routing debug commands.

Why is the port2 default route not in the second command output?

Options:

A.

The port2 interface is disabled in the FortiGate configuration.

B.

The port1 default route has a lower distance than the default route using port2.

C.

The port1 default route has a higher priority value than the default route using port2.

D.

The port1 default route has a lower priority value than the default route using port2.

Buy Now
Questions 16

Examine the following partial output from a sniffer command; then answer the question below.

What is the meaning of the packets dropped counter at the end of the sniffer?

Options:

A.

Number of packets that didn’t match the sniffer filter.

B.

Number of total packets dropped by the FortiGate.

C.

Number of packets that matched the sniffer filter and were dropped by the FortiGate.

D.

Number of packets that matched the sniffer filter but could not be captured by the sniffer.

Buy Now
Questions 17

Refer to the exhibit, which shows the output of a web filtering diagnose command.

Which configuration change would result in non-zero results in the cache statistics section?

Options:

A.

set server-type rating under config system central-management

B.

set webfilter-cache enable under config system fortiguard

C.

set webfilter-force-off disable under config system fortiguard

D.

set ngfw-mode policy-based under config system settings

Buy Now
Questions 18

Which action will FortiGate take when using the default settings for SSL certificate inspection, where the server name indication (SNI) does not match either the common name (CN) or any of the subject altemative names (SAN) in the server certificate?

Options:

A.

FortiGate uses the CN information from the Subject field in the server certificate.

B.

FortiGate uses the first entry listed in the SAN field in the server certificate.

C.

FortiGate uses the SNI from the user's web browser.

D.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.

Buy Now
Questions 19

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?

Options:

A.

auto-discovery-shortcut

B.

auto-discovery-forwarder

C.

auto-discovery-sender

D.

auto-discovery-receiver

Buy Now
Questions 20

Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.

Which statement are true regarding the output in the exhibit? (Choose two.)

Options:

A.

There are three FortiGuard servers that are not responding to the queries sent by the FortiGate.

B.

The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone.

C.

FortiGate will send the FortiGuard queries to the server with highest weight.

D.

A server's round trip delay (RTT) is not used to calculate its weight.

Buy Now
Questions 21

A FortiGate is configured as an explicit web proxy. Clients using this web proxy are reposting DNS errors when accessing any website. The administrator executes the following debug commands and observes that the n-dns-timeout counter is increasing:

What should the administrator check to fix the problem?

Options:

A.

The connectivity between the FortiGate unit and the DNS server.

B.

The connectivity between the client workstations and the DNS server.

C.

That DNS traffic from client workstations is allowed by the explicit web proxy policies.

D.

That DNS service is enabled in the explicit web proxy interface.

Buy Now
Questions 22

Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

Options:

A.

IPS failopen

B.

mem failopen

C.

AV failopen

D.

UTM failopen

Buy Now
Questions 23

Refer to the exhibit, which shows a session table entry.

Which statement about FortiGate behavior relating to this session is true?

Options:

A.

FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made.

B.

FortiGate forwarded this session without any inspection.

C.

FortiGate is performing security profile inspection using the CPU. Most Voted

D.

FortiGate applied only IPS inspection to this session.

Buy Now
Questions 24

Which two tasks are automated using the Import Configuration wizard on FortiManager? (Choose two.)

Options:

A.

Importing firewall address objects from managed devices

B.

Importing interface mappings from managed devices

C.

Importing static and dynamic route configurations from managed devices

D.

Importing devices to FortiManager

Exam Code: NSE7_EFW-7.0
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.0
Last Update: May 4, 2024
Questions: 163
$64  $159.99
$48  $119.99
$40  $99.99
buy now NSE7_EFW-7.0