ExamGecko
Home Home / Fortinet / NSE7_EFW-7.2

Fortinet NSE7_EFW-7.2 Practice Test - Questions Answers

Question list
Search
Search

List of questions

Search

Related questions











Exhibit.

Refer to the exhibit, which contains an active-active toad balancing scenario.

During the traffic flow the primary FortiGate forwards the SYN packet to the secondary FortiGate.

What is the destination MAC address or addresses when packets are forwarded from the primary FortiGate to the secondary FortiGate?

A.
Secondary physical MAC port1
A.
Secondary physical MAC port1
Answers
B.
Secondary virtual MAC port1
B.
Secondary virtual MAC port1
Answers
C.
Secondary virtual MAC port1 then physical MAC port1
C.
Secondary virtual MAC port1 then physical MAC port1
Answers
D.
Secondary physical MAC port2 then virtual MAC port2
D.
Secondary physical MAC port2 then virtual MAC port2
Answers
Suggested answer: A

Explanation:

In an active-active load balancing scenario, when the primary FortiGate forwards the SYN packet to the secondary FortiGate, the destination MAC address would be the secondary's physical MAC on port1, as the packet is being sent over the network and the physical MAC is used for layer 2 transmissions.

Which two statements about IKE vision 2 are true? (Choose two.)

A.
Phase 1 includes main mode
A.
Phase 1 includes main mode
Answers
B.
It supports the extensible authentication protocol (EAP)
B.
It supports the extensible authentication protocol (EAP)
Answers
C.
It supports the XAuth protocol.
C.
It supports the XAuth protocol.
Answers
D.
It exchanges a minimum of four messages to establish a secure tunnel
D.
It exchanges a minimum of four messages to establish a secure tunnel
Answers
Suggested answer: B, D

Explanation:

IKE version 2 supports the extensible authentication protocol (EAP), which allows for more flexible and secure authentication methods1.IKE version 2 also exchanges a minimum of four messages to establish a secure tunnel, which is more efficient than IKE version 12.Reference: =IKE settings | FortiClient 7.2.2 - Fortinet Documentation,Technical Tip: How to configure IKE version 1 or 2 ... - Fortinet Community

Which statement about network processor (NP) offloading is true?

A.
For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP
A.
For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP
Answers
B.
The NP provides IPS signature matching
B.
The NP provides IPS signature matching
Answers
C.
You can disable the NP for each firewall policy using the command np-acceleration st to loose.
C.
You can disable the NP for each firewall policy using the command np-acceleration st to loose.
Answers
D.
The NP checks the session key or IPSec SA
D.
The NP checks the session key or IPSec SA
Answers
Suggested answer: B

Explanation:

Network processors (NPs) are specialized hardware within FortiGate devices that accelerate certain security functions. One of the primary functions of NPs is to provide IPS signature matching (B), allowing for high-speed inspection of traffic against a database of known threat signatures.

Exhibit.

Refer to exhibit, which shows a central management configuration

Which server will FortiGate choose for web filler rating requests if 10.0.1.240 is experiencing an outage?

A.
Public FortiGuard servers
A.
Public FortiGuard servers
Answers
B.
10.0.1.242
B.
10.0.1.242
Answers
C.
10.0.1.244
C.
10.0.1.244
Answers
D.
10.0.1.243
D.
10.0.1.243
Answers
Suggested answer: C

Explanation:

In the event of an outage at 10.0.1.240, the FortiGate will choose the next server in the sequence for web filter rating requests, which is 10.0.1.244 according to the configuration shown in the exhibit. This is because the server list is ordered by priority, and the server with the lowest priority number is chosen first. If that server is unavailable, the next server with the next lowest priority number is chosen, and so on. The public FortiGuard servers are only used if the include-default-servers option is enabled and all the custom servers are unavailable.Reference:=Fortinet Enterprise Firewall Study Guide for FortiOS 7.2, page 132.

Exhibit.

Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.

Which two conclusions can you draw from this con figuration? (Choose two)

A.
10.1.5.254 is the default gateway of the internal network
A.
10.1.5.254 is the default gateway of the internal network
Answers
B.
On failover new primary device uses the same MAC address as the old primary
B.
On failover new primary device uses the same MAC address as the old primary
Answers
C.
The VRRP domain uses the physical MAC address of the primary FortiGate
C.
The VRRP domain uses the physical MAC address of the primary FortiGate
Answers
D.
By default FortiGate B is the primary virtual router
D.
By default FortiGate B is the primary virtual router
Answers
Suggested answer: A, B

Explanation:

The Virtual Router Redundancy Protocol (VRRP) configuration in the exhibit indicates that 10.1.5.254 is set as the virtual IP (VRIP), commonly serving as the default gateway for the internal network (A). With vrrp-virtual-mac enabled, both FortiGates would use the same virtual MAC address, ensuring a seamless transition during failover (B). The VRRP domain does not use the physical MAC address (C), and the priority settings indicate that FortiGate-A would be the primary router by default due to its higher priority (D).

Winch two statements about ADVPN are true? (Choose two)

A.
auto-discovery receiver must be set to enable on the Spokes.
A.
auto-discovery receiver must be set to enable on the Spokes.
Answers
B.
Spoke to-spoke traffic never goes through the hub
B.
Spoke to-spoke traffic never goes through the hub
Answers
C.
lt supports NAI for on-demand tunnels
C.
lt supports NAI for on-demand tunnels
Answers
D.
Routing is configured by enabling add-advpn-route
D.
Routing is configured by enabling add-advpn-route
Answers
Suggested answer: A, C

Explanation:

ADVPN (Auto Discovery VPN) is a feature that allows to dynamically establish direct tunnels (called shortcuts) between the spokes of a traditional Hub and Spoke architecture. The auto-discovery receiver must be set to enable on the spokes to allow them to receive NHRP messages from the hub and other spokes. NHRP (Next Hop Resolution Protocol) is used for on-demand tunnels, which are established when there is traffic between spokes. Routing is configured by enabling add-nhrp-route, not add-advpn-route.Reference:=ADVPN | FortiGate / FortiOS 7.2.0 | Fortinet Document Library,Technical Tip: Fortinet Auto Discovery VPN (ADVPN)

Refer to the exhibit, which shows an ADVPN network.

Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

A.
set auto-discovery-forwarder enable
A.
set auto-discovery-forwarder enable
Answers
B.
set add-route enable
B.
set add-route enable
Answers
C.
set auto-discovery-receiver enable
C.
set auto-discovery-receiver enable
Answers
D.
set auto-discovery-sender enable
D.
set auto-discovery-sender enable
Answers
Suggested answer: A, C

Explanation:

For the ADVPN feature to function properly on the hub, the following phase 1 parameters must be configured:

A) set auto-discovery-forwarder enable: This enables the hub to forward shortcut information to the spokes, which is essential for them to establish direct tunnels.

C) set auto-discovery-receiver enable: This allows the hub to receive shortcut offers from the spokes.

This information is corroborated by the Fortinet documentation, which explains that in an ADVPN setup, the hub must be able to both forward and receive shortcut information for dynamic tunnel creation between spokes.

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

A.
FortiManager provides FortiGuard.
A.
FortiManager provides FortiGuard.
Answers
B.
fortiguard-anycast is set to enable.
B.
fortiguard-anycast is set to enable.
Answers
C.
You do not have the corresponding write access.
C.
You do not have the corresponding write access.
Answers
D.
udp is not a protocol option.
D.
udp is not a protocol option.
Answers
Suggested answer: D

Explanation:

The reason for the command failure when trying to set the protocol to UDP in the config system fortiguard is likely that UDP is not a protocol option in this context. The command syntax might be incorrect or the option to set a protocol for FortiGuard updates might not exist in this manner. So the correct answer is D. udp is not a protocol option.

Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)

A.
Dead peer detection is set to enable.
A.
Dead peer detection is set to enable.
Answers
B.
The IKE version is 2.
B.
The IKE version is 2.
Answers
C.
Both IPsec SAs are loaded on the kernel.
C.
Both IPsec SAs are loaded on the kernel.
Answers
D.
Forward error correction in phase 2 is set to enable.
D.
Forward error correction in phase 2 is set to enable.
Answers
Suggested answer: B, C

Explanation:

From the command output shown in the exhibit:

B) The IKE version is 2: This can be deduced from the presence of 'ver=2' in the output, which indicates that IKEv2 is being used.

C) Both IPsec SAs are loaded on the kernel: This is indicated by the line 'npu flags=0x0/0', suggesting that no offload to NPU is occurring, and hence, both Security Associations are loaded onto the kernel for processing.

Fortinet documentation specifies that the version of IKE (Internet Key Exchange) used and the loading of IPsec Security Associations can be verified through the diagnostic commands related to VPN tunnels.

Refer to the exhibit, which contains a partial OSPF configuration.

What can you conclude from this output?

A.
Neighbors maintain communication with the restarting router.
A.
Neighbors maintain communication with the restarting router.
Answers
B.
The router sends grace LSAs before it restarts.
B.
The router sends grace LSAs before it restarts.
Answers
C.
FortiGate restarts if the topology changes.
C.
FortiGate restarts if the topology changes.
Answers
D.
The restarting router sends gratuitous ARP for 30 seconds.
D.
The restarting router sends gratuitous ARP for 30 seconds.
Answers
Suggested answer: B

Explanation:

From the partial OSPF (Open Shortest Path First) configuration output:

B) The router sends grace LSAs before it restarts: This is implied by the command 'set restart-mode graceful-restart'. When OSPF is configured with graceful restart, the router sends grace LSAs (Link State Advertisements) to inform its neighbors that it is restarting, allowing for a seamless transition without recalculating routes.

Fortinet documentation on OSPF configuration clearly states that enabling graceful restart mode allows the router to maintain its adjacencies and routes during a brief restart period.

Total 56 questions
Go to page: of 6