ExamGecko
Home / Fortinet / NSE7_LED-7.0 / List of questions
Ask Question

Fortinet NSE7_LED-7.0 Practice Test - Questions Answers, Page 3

List of questions

Question 21

Report Export Collapse

Refer to the exhibit.

Fortinet NSE7_LED-7.0 image Question 21 27023 09182024190743000000

Examine the FortiManager configuration and FortiGate CLI output shown in the exhibit

An administrator is testing the NAC feature The test device is connected to a managed FortiSwitch device {S224EPTF19'537)onpOrt2

After applying the NAC policy on port2 and generating traffic on the test device the test device is not matching the NAC policy therefore the test device remains m the onboarding VLAN

Based on the information shown in the exhibit which two scenarios are likely to cause this issue? (Choose two.)

Management communication between FortiGate and FortiSwitch is down
Management communication between FortiGate and FortiSwitch is down
The MAC address configured on the NAC policy is incorrect
The MAC address configured on the NAC policy is incorrect
The device operating system detected by FortiGate is not Linux
The device operating system detected by FortiGate is not Linux
Device detection is not enabled on VLAN 4089
Device detection is not enabled on VLAN 4089
Suggested answer: A, B
Explanation:

According to the FortiManager configuration, the NAC policy is set to match devices with the MAC address of 00:0c:29:6a:2b:3c and the operating system of Linux. However, according to the FortiGate CLI output, the test device has a different MAC address of 00:0c:29:6a:2b:3d. Therefore, option B is true. Option A is also true because the FortiSwitch device status is shown as down, which means that the management communication between FortiGate and FortiSwitch is not working properly. This could prevent the NAC policy from being applied correctly. Option C is false because the device operating system detected by FortiGate is Linux, which matches the NAC policy. Option D is false because device detection is enabled on VLAN 4089, as shown by the command ''config switch-controller vlan''.

asked 18/09/2024
Juan Pablo Mateos Ornelas
52 questions

Question 22

Report Export Collapse

Refer to the exhibit.

Fortinet NSE7_LED-7.0 image Question 22 27024 09182024190743000000

Examine the FortiManager information shown in the exhibit

Which two statements about the FortiManager status are true'' (Choose two)

Become a Premium Member for full access
  Unlock Premium Member

Question 23

Report Export Collapse

An administrator has configured an SSID in bridge mode for corporate employees All APs are online and provisioned using default AP profiles Employees are unable to locate the SSID to conned

Which two configurations can the administrator verify? (Choose two)

Become a Premium Member for full access
  Unlock Premium Member

Question 24

Report Export Collapse

What is the purpose of enabling Windows Active Directory Domain Authentication on FortiAuthenticator?

Become a Premium Member for full access
  Unlock Premium Member

Question 25

Report Export Collapse

Refer to the exhibit.

Fortinet NSE7_LED-7.0 image Question 25 27027 09182024190743000000

Examine the FortiGate configuration FortiAnalyzer logs and FortiGate widget shown in the exhibit

An administrator is testing the Security Fabric quarantine automation The administrator added FortiAnalyzer to the Security Fabric and configured an automation stitch to automatically quarantine compromised devices The test device (::.:.:.!) s connected to a managed Fort Switch dev :e

After trying to access a malicious website from the test device, the administrator verifies that FortiAnalyzer has a log (or the test connection However the device is not getting quarantined by FortiGate as shown in the quarantine widget

Which two scenarios are likely to cause this issue? (Choose two)

Become a Premium Member for full access
  Unlock Premium Member

Question 26

Report Export Collapse

Which FortiSwitch VLANs are automatically created on FortGate when the first FortiSwitch device is discovered1?

Become a Premium Member for full access
  Unlock Premium Member

Question 27

Report Export Collapse

Refer to the exhibit.

Fortinet NSE7_LED-7.0 image Question 27 27029 09182024190743000000

Examine the network diagram and packet capture shown in the exhibit

The packet capture was taken between FortiGate and FortiAuthenticator and shows a RADIUS Access-Request packet sent by FortiSwitch to FortiAuthenticator through FortiGate

Why does the User-Name attribute in the RADIUS Access-Request packet contain the client MAC address?

Become a Premium Member for full access
  Unlock Premium Member

Question 28

Report Export Collapse

Refer to the exhibit.

Fortinet NSE7_LED-7.0 image Question 28 27030 09182024190743000000

Examine the RADIUS server configuration shown in the exhibit

An administrator has configured a RADIUS server on FortiGate that points to FortiAuthenticator FortiAuthenticator is acting as an authentication proxy and is configured to relay all authentication requests to a remote Windows AD server using LDAP

While testing the configuration the administrator noticed that the diagnose test authserver command worked with PAP, however authentication requests failed when using MSCHAP2

Which two solutions can the administrator implement to get MSCHAP2 authentication to work'' (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 29

Report Export Collapse

Which CLI command should an administrator use to view the certificate verification process in real time?

Become a Premium Member for full access
  Unlock Premium Member

Question 30

Report Export Collapse

Refer to the exhibits.

Fortinet NSE7_LED-7.0 image Question 30 27032 09182024190743000000

Firewall Policy

Fortinet NSE7_LED-7.0 image Question 30 27032 09182024190743000000

Examine the firewall policy configuration and SSID settings

An administrator has configured a guest wireless network on FortiGate using the external captive portal The administrator has verified that the external captive portal URL is correct However wireless users are not able to see the captive portal login page

Given the configuration shown in the exhibit and the SSID settings which configuration change should the administrator make to fix the problem?

Become a Premium Member for full access
  Unlock Premium Member
Total 37 questions
Go to page: of 4
Search

Related questions