ExamGecko
Home / Fortinet / NSE7_EFW-7.2 / List of questions
Ask Question

Fortinet NSE7_EFW-7.2 Practice Test - Questions Answers, Page 3

Add to Whishlist

List of questions

Question 21

Report Export Collapse

Refer to the exhibit, which shows a network diagram.

Fortinet NSE7_EFW-7.2 image Question 21 26973 09182024190732000000

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

Set route-overlap to allow.
Set route-overlap to allow.
Set single-source to enable
Set single-source to enable
Set route-overlap to either use---new or use-old
Set route-overlap to either use---new or use-old
Set net-device to enable
Set net-device to enable
Suggested answer: C
Explanation:

To ensure that only one remote site is connected at any given time in an IPsec VPN scenario, you should use route-overlap with the option to either use-new or use-old. This setting dictates which routes are preferred and how overlaps in routes are handled, allowing for one connection to take precedence over the other (C).

FortiOS Handbook - IPsec VPN

asked 18/09/2024
Ken Wilson
48 questions

Question 22

Report Export Collapse

Exhibit.

Fortinet NSE7_EFW-7.2 image Question 22 26974 09182024190732000000

Fortinet NSE7_EFW-7.2 image Question 22 26974 09182024190732000000

Refer to the exhibit, which contains an ADVPN network diagram and a partial BGP con figuration Which two parameters Should you configure in config neighbor range? (Choose two.)

set prefix 172.16.1.0 255.255.255.0
set prefix 172.16.1.0 255.255.255.0
set route reflector-client enable
set route reflector-client enable
set neighbor-group advpn
set neighbor-group advpn
set prefix 10.1.0 255.255.255.0
set prefix 10.1.0 255.255.255.0
Suggested answer: A, C
Explanation:

In the ADVPN configuration for BGP, you should specify the prefix that the neighbors can advertise. Option A is correct as you would configure the BGP network prefix that should be advertised to the neighbors, which matches the BGP network in the diagram. Option C is also correct since you should reference the neighbor group configured for the ADVPN setup within the BGP configuration.

asked 18/09/2024
Lionel CHOLEZ
37 questions

Question 23

Report Export Collapse

You want to configure faster failure detection for BGP

Which parameter should you enable on both connected FortiGate devices?

Ebgp-enforce-multihop
Ebgp-enforce-multihop
bfd
bfd
Distribute-list-in
Distribute-list-in
Graceful-restart
Graceful-restart
Suggested answer: B
Explanation:

BFD (Bidirectional Forwarding Detection) is a protocol that provides fast failure detection for BGP by sending periodic messages to verify the connectivity between two peers1.BFD can be enabled on both connected FortiGate devices by using the commandset bfd enableunder the BGP configuration2.Reference: =Technical Tip : FortiGate BFD implementation and examples ...,Configure BGP | FortiGate / FortiOS 7.0.2 - Fortinet Documentation

asked 18/09/2024
Khoi Le
43 questions

Question 24

Report Export Collapse

Which two statements about metadata variables are true? (Choose two.)

You create them on FortiGate
You create them on FortiGate
They apply only to non-firewall objects.
They apply only to non-firewall objects.
The metadata format is $<metadata_variabie_name>.
The metadata format is $<metadata_variabie_name>.
They can be used as variables in scripts
They can be used as variables in scripts
Suggested answer: A, D
Explanation:

Metadata variables in FortiGate are created to store metadata associated with different FortiGate features. These variables can be used in various configurations and scripts to dynamically replace the variable with its actual value during processing. A: You create metadata variables on FortiGate. They are used to store metadata for FortiGate features and can be called upon in different configurations. D: They can be used as variables in scripts. Metadata variables are utilized within the scripts to dynamically insert values as per the context when the script runs.

Fortinet FortiOS Handbook: CLI Reference

asked 18/09/2024
gdgd gdgd
27 questions

Question 25

Report Export Collapse

Refer to the exhibit, which contains a partial BGP combination.

Fortinet NSE7_EFW-7.2 image Question 25 26977 09182024190732000000

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

ebgp-enforce-multihop
ebgp-enforce-multihop
recursive-next-hop
recursive-next-hop
ibgp-enfoce-multihop
ibgp-enfoce-multihop
update-source
update-source
Suggested answer: A, D
Explanation:

To configure a loopback as the BGP source, you need to set the ''ebgp-enforce-multihop'' and ''update-source'' parameters in the BGP configuration.The ''ebgp-enforce-multihop'' allows EBGP connections to neighbor routers that are not directly connected, while ''update-source'' specifies the IP address that should be used for the BGP session1.Reference:=BGP on loopback,Loopback interface,Technical Tip: Configuring EBGP Multihop Load-Balancing,Technical Tip: BGP routes are not installed in routing table with loopback as update source

asked 18/09/2024
Marek Broadstock
39 questions

Question 26

Report Export Collapse

Exhibit.

Fortinet NSE7_EFW-7.2 image Question 26 26978 09182024190732000000

Refer to the exhibit, which shows a partial web filter profile conjuration

What can you cone udo from this configuration about access to www.facebook.com, which is categorized as Social Networking?

The access is blocked based on the Content Filter configuration
The access is blocked based on the Content Filter configuration
The access is allowed based on the FortiGuard Category Based Filter configuration
The access is allowed based on the FortiGuard Category Based Filter configuration
The access is blocked based on the URL Filter configuration
The access is blocked based on the URL Filter configuration
The access is hocked if the local or the public FortiGuard server does not reply
The access is hocked if the local or the public FortiGuard server does not reply
Suggested answer: C
Explanation:

The access to www.facebook.com is blocked based on the URL Filter configuration.In the exhibit, it shows that the URL ''www.facebook.com'' is specifically set to ''Block'' under the URL Filter section1.Reference:=Fortigate: How to configure Web Filter function on Fortigate,Web filter | FortiGate / FortiOS 7.0.2 | Fortinet Document Library,FortiGate HTTPS web URL filtering ... - Fortinet ... - Fortinet Community

asked 18/09/2024
Vijay Khara
50 questions

Question 27

Report Export Collapse

An administrator has configured two fortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device What can the administrator do to fix this problem?

Verify that the speed and duplex settings match between me FortiGate interfaces and the connected switch ports
Verify that the speed and duplex settings match between me FortiGate interfaces and the connected switch ports
Configure set link -failed signal enable under-config system ha on both Cluster members
Configure set link -failed signal enable under-config system ha on both Cluster members
Configure remote Iink monitoring to detect an issue in the forwarding path
Configure remote Iink monitoring to detect an issue in the forwarding path
Configure set send-garp-on-failover enables under config system ha on both cluster members
Configure set send-garp-on-failover enables under config system ha on both cluster members
Suggested answer: B
Explanation:

Virtual MAC Address and Failover

- The new primary broadcasts Gratuitous ARP packets to notify the network that each virtual MAC is now reachable through a different switch port.

- Some high-end switches might not clear their MAC table correctly after a failover - Solution: Force former primary to shut down all its interfaces for one second when the failover happens (excluding heartbeat and reserved management interfaces):

#Config system ha

set link-failed-signal enable

end

- This simulates a link failure that clears the related entries from MAC table of the switches.

asked 18/09/2024
Chukwuebuka Ogbonna
46 questions

Question 28

Report Export Collapse

Exhibit.

Fortinet NSE7_EFW-7.2 image Question 28 26980 09182024190732000000

Refer to the exhibit, which shows information about an OSPF interlace

What two conclusions can you draw from this command output? (Choose two.)

The port3 network has more man one OSPF router
The port3 network has more man one OSPF router
The OSPF routers are in the area ID of 0.0.0.1.
The OSPF routers are in the area ID of 0.0.0.1.
The interfaces of the OSPF routers match the MTU value that is configured as 1500.
The interfaces of the OSPF routers match the MTU value that is configured as 1500.
NGFW-1 is the designated router
NGFW-1 is the designated router
Suggested answer: A, C
Explanation:

From the OSPF interface command output, we can conclude that the port3 network has more than one OSPF router because the Neighbor Count is 2, indicating the presence of another OSPF router besides NGFW-1. Additionally, we can deduce that the interfaces of the OSPF routers match the MTU value configured as 1500, which is necessary for OSPF neighbors to form adjacencies. The MTU mismatch would prevent OSPF from forming a neighbor relationship.

Fortinet FortiOS Handbook: OSPF Configuration

asked 18/09/2024
Eduardo Rives
43 questions

Question 29

Report Export Collapse

In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)

lt can be configured as an update server a rating server or both
lt can be configured as an update server a rating server or both
It provides VM license validation services
It provides VM license validation services
It supports rating requests from non-FortiGate devices.
It supports rating requests from non-FortiGate devices.
It caches available firmware updates for unmanaged devices
It caches available firmware updates for unmanaged devices
Suggested answer: A, B
Explanation:

When deployed as a local FortiGuard Distribution Server (FDS), FortiManager functions in several capacities. It can act as an update server, a rating server, or both, providing firmware updates and FortiGuard database updates. Additionally, it plays a crucial role in VM license validation services, ensuring that the connected FortiGate devices are operating with valid licenses. However, it does not support rating requests from non-FortiGate devices nor cache firmware updates for unmanaged devices.

Fortinet FortiOS Handbook: FortiManager as a Local FDS Configuration

asked 18/09/2024
Sullivan Dabireau
44 questions

Question 30

Report Export Collapse

Refer to the exhibit.

Fortinet NSE7_EFW-7.2 image Question 30 26982 09182024190732000000

which contains a partial configuration of the global system. What can you conclude from this output?

NPs and CPs are enabled
NPs and CPs are enabled
Only CPs arc disabled
Only CPs arc disabled
Only NPs are disabled
Only NPs are disabled
NPs and CPs arc disabled
NPs and CPs arc disabled
Suggested answer: D
Explanation:

The configuration output shows various global settings for a FortiGate device. The terms NP (Network Processor) and CP (Content Processor) relate to FortiGate's hardware acceleration features. However, the provided configuration output does not directly mention the status (enabled or disabled) of NPs and CPs. Typically, the command to disable or enable hardware acceleration features would specifically mention NP or CP in the command syntax. Therefore, based on the output provided, we cannot conclusively determine the status of NPs and CPs, hence option D is the closest answer since the output does not confirm that they are enabled.

FortiOS Handbook - CLI Reference for FortiOS 5.2

asked 18/09/2024
alvaro Vasconcelos
40 questions
Total 64 questions
Go to page: of 7
Search

Related questions