Fortinet NSE7_LED-7.0 Practice Test - Questions Answers, Page 6

List of questions
Question 51

Refer to the exhibits.
Examine the debug output and the SSL VPN configuration shown in the exhibits.
An administrator has configured SSL VPN on FortiGate. To improve security, the administrator enabled Required Client Certificate on the SSL VPN configuration page. However, a user is unable to successfully authenticate to SSL VPN.
Which configuration change should the administrator make to fix the problem?
Question 52

Refer to the exhibits.
Examine the VAP configuration and the Wi-Fi zones table shown in the exhibits.
Which two statements describe the FortiGate behavior regarding assignment of VLANs to wireless clients? (Choose two.)
Question 53

Which three FortiOS tools can you use to troubleshoot RADIUS authentication issues? (Choose three.)
Question 54

Refer to the exhibit.
An administrator wants to telnet into the S224EPTF19005867 switch over the FortiGate FortiLink interface.
Which configuration change should the administrator make?
Question 55

Refer to the exhibits.
An administrator has configured FortiGate with an SSID (Corp) with dynamic VLAN assignment, and also configured a RADIUS server to send IETF 64, IETF 65, and IETF 81 VSAs.
The administrator has verified that the RADIUS server is sending all the required information to FortiGate. However, FortiGate is not assigning correct VLANs to the wireless clients.
What is causing the problem?
Question 56

Refer to the exhibit.
Examine the FortiSwitch port configuration and the FortiGate interface configuration shown in the exhibit.
Based on the configuration shown in the exhibit, which two statements about how port2 handles tagged and untagged traffic are true? (Choose two.)
Question 57

Which CLI command should an administrator use on FortiGate to view the RSSO authentication process in real time?
Question 58

Refer to the exhibit.
Examine the FortiSwitch security policy shown in the exhibit.
A device that does not support 802.1X authentication is connected to a port using the Port-Security security policy.
What action does the FortiSwitch take on the port?
Question 59

Refer to the exhibit.
Examine the FortiGate RSSO configuration shown in the exhibit.
FortiGate is configured to receive RADIUS accounting messages on port3 to authenticate RSSO users. The incoming RADIUS accounting messages contain the username and group membership information in the User-Name and Class RADIUS attributes, respectively.
Which three settings must you configure on FortiGate to successfully authenticate RSSO users and match them to the existing RSSO user groups? (Choose three)
Question 60

Refer to the exhibits.
Examine the LDAP server configuration and output shown in the exhibits.
Note that the Distinguished Name and Username settings on the LDAP server configuration have been expanded to display their full contents.
An LDAP user named student cannot authenticate. While testing the student account, the administrator gets the CLI output shown in the exhibit.
According to the output, which FortiGate LDAP server settings must the administrator check?
Question