Winter Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

NSE7_EFW-7.0 Fortinet NSE 7 - Enterprise Firewall 7.0 Questions and Answers

Questions 4

Examine the following partial output from two system debug commands; then answer the question below.

NSE7_EFW-7.0 Question 4

NSE7_EFW-7.0 Question 4

Which of the following statements are true regarding the above outputs? (Choose two.)

Options:

A.

The unit is running a 32-bit FortiOS

B.

The unit is in kernel conserve mode

C.

The Cached value is always the Active value plus the Inactive value

D.

Kernel indirectly accesses the low memory (LowTotal) through memory paging

Buy Now
Questions 5

View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.

NSE7_EFW-7.0 Question 5

The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:

NSE7_EFW-7.0 Question 5

However, the IKE real time debug does not show any output. Why?

Options:

A.

The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.

B.

The log-filter setting was set incorrectly. The VPN’s traffic does not match this filter.

C.

The debug shows only error messages. If there is no output, then the tunnel is operating normally.

D.

The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.

Buy Now
Questions 6

View the exhibit, which contains the output of a diagnose command, and then answer the question below.

NSE7_EFW-7.0 Question 6

Which statements are true regarding the output in the exhibit? (Choose two.)

Options:

A.

FortiGate will probe 121.111.236.179 every fifteen minutes for a response.

B.

Servers with the D flag are considered to be down.

C.

Servers with a negative TZ value are experiencing a service outage.

D.

FortiGate used 209.222.147.3 as the initial server to validate its contract.

Buy Now
Questions 7

View the exhibit, which contains the output of a debug command, and then answer the question below.

NSE7_EFW-7.0 Question 7

Which of the following statements about the exhibit are true? (Choose two.)

Options:

A.

In the network on port4, two OSPF routers are down.

B.

Port4 is connected to the OSPF backbone area.

C.

The local FortiGate’s OSPF router ID is 0.0.0.4

D.

The local FortiGate has been elected as the OSPF backup designated router.

Buy Now
Questions 8

Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week.

NSE7_EFW-7.0 Question 8

Which two statements about the output are true? (Choose two.)

Options:

A.

If FGVM...649 is rebooted, FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.

B.

If no action is taken, the primary FortiGate will leave the cluster due to the current sync status.

C.

If port7 becomes disconnected on the secondary, both FortiGate devices will elect itself the primary.

D.

If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.

Buy Now
Questions 9

Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)

Options:

A.

Preview pending configuration changes for managed devices.

B.

Add devices to FortiManager.

C.

Import policy packages from managed devices.

D.

Install configuration changes to managed devices.

E.

Import interface mappings from managed devices.

Buy Now
Questions 10

The logs in a FSSO collector agent (CA) are showing the following error:

failed to connect to registry: PIKA1026 (192.168.12.232)

What can be the reason for this error?

Options:

A.

The CA cannot resolve the name of the workstation.

B.

The FortiGate cannot resolve the name of the workstation.

C.

The remote registry service is not running in the workstation 192.168.12.232.

D.

The CA cannot reach the FortiGate with the IP address 192.168.12.232.

Buy Now
Questions 11

An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device.

What can the administrator do to fix this problem?

Options:

A.

Configure remote link monitoring to detect an issue in the forwarding path.

B.

Configure set send-garp-on-failover enable under config system ha on both cluster members.

C.

Verify that the speed and duplex settings match between the FortiGate interfaces and the connected switch ports.

D.

Configure set link-failed-signal enable under config system ha on both cluster members.

Buy Now
Questions 12

Refer to the exhibit, which contains the debug output of diagnose dvm device list.

NSE7_EFW-7.0 Question 12

Which two statements about the output shown in the exhibit are correct? (Choose two.)

Options:

A.

ADOMs are disabled on the FortiManager

B.

The FortiGate configuration is in sync with latest running revision history.

C.

There are pending device-level changes yet to be installed on Local-FortiGate.

D.

The policy package has been modified for Local-FortiGate.

Buy Now
Questions 13

View the exhibit, which contains the output of a debug command, and then answer the question below.

NSE7_EFW-7.0 Question 13

Which one of the following statements about this FortiGate is correct?

Options:

A.

It is currently in system conserve mode because of high CPU usage.

B.

It is currently in extreme conserve mode because of high memory usage.

C.

It is currently in proxy conserve mode because of high memory usage.

D.

It is currently in memory conserve mode because of high memory usage.

Buy Now
Questions 14

View the exhibit, which contains the output of get sys ha status, and then answer the question below.

NSE7_EFW-7.0 Question 14

Which statements are correct regarding the output? (Choose two.)

Options:

A.

The slave configuration is not synchronized with the master.

B.

The HA management IP is 169.254.0.2.

C.

Master is selected because it is the only device in the cluster.

D.

port 7 is used the HA heartbeat on all devices in the cluster.

Buy Now
Questions 15

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.

NSE7_EFW-7.0 Question 15

An administrator would like to test session failover between the two service provider connections.

What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

Options:

A.

Configure set snat-route-change enable.

B.

Change the priority of the port2 static route to 5.

C.

Change the priority of the port1 static route to 11.

D.

unset snat-route-change to return it to the default setting.

Buy Now
Questions 16

Refer to the exhibit, which contains partial output from an IKE real-time debug.

NSE7_EFW-7.0 Question 16

Which two statements about this debug output are correct? (Choose two.)

Options:

A.

The initiator provided remote as its IPsec peer ID.

B.

It shows a phase 2 negotiation.

C.

Perfect Forward Secrecy (PFS) is enabled in the configuration.

D.

The local gateway IP address is 10.0.0.1.

Buy Now
Questions 17

View the global IPS configuration, and then answer the question below.

NSE7_EFW-7.0 Question 17

Which of the following statements is true regarding this configuration?

Options:

A.

IPS will scan every byte in every session.

B.

FortiGate will spawn IPS engine instances based on the system load.

C.

New packets will be passed through without inspection if the IPS socket buffer runs out of memory.

D.

IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.

Buy Now
Questions 18

Examine the output of the ‘diagnose sys session list expectation’ command shown in the exhibit; than answer the question below.

NSE7_EFW-7.0 Question 18

Which statement is true regarding the session in the exhibit?

Options:

A.

It was created by the FortiGate kernel to allow push updates from FotiGuard.

B.

It is for management traffic terminating at the FortiGate.

C.

It is for traffic originated from the FortiGate.

D.

It was created by a session helper or ALG.

Buy Now
Questions 19

What does the dirty flag mean in a FortiGate session?

Options:

A.

Traffic has been blocked by the antivirus inspection.

B.

The next packet must be re-evaluated against the firewall policies.

C.

The session must be removed from the former primary unit after an HA failover.

D.

Traffic has been identified as from an application that is not allowed.

Buy Now
Questions 20

Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?

Options:

A.

Only the DR receives link state information from non-DR routers.

B.

Non-DR and non-BDR routers form full adjacencies to DR only.

C.

Non-DR and non-BDR routers send link state updates and acknowledgements to 224.0.0.6.

D.

FortiGate first checks the OSPF ID to elect a DR.

Buy Now
Questions 21

An administrator has enabled HA session synchronization in a HA cluster with two members. Which flag is added to a primary unit’s session to indicate that it has been synchronized to the secondary unit?

Options:

A.

redir.

B.

dirty.

C.

synced

D.

nds.

Buy Now
Questions 22

What is the diagnose test application ipsmonitor 99 command used for?

Options:

A.

To enable IPS bypass mode

B.

To provide information regarding IPS sessions

C.

To disable the IPS engine

D.

To restart all IPS engines and monitors

Buy Now
Questions 23

View the central management configuration shown in the exhibit, and then answer the question below.

NSE7_EFW-7.0 Question 23

Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an outage?

Options:

A.

10.0.1.240

B.

One of the public FortiGuard distribution servers

C.

10.0.1.244

D.

10.0.1.242

Buy Now
Questions 24

Refer to the exhibit, which contains the output of a debug command.

NSE7_EFW-7.0 Question 24

If the default settings are in place, what can be concluded about the conserve mode shown in the exhibit?

Options:

A.

FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings due to high memory use.

B.

FortiGate is currently allowing new sessions that require flow-based or proxy-based content inspection but is not performing inspection on those sessions.

C.

FortiGate is currently blocking new sessions that require flow-based or proxy-based content inspection.

D.

FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection.

Buy Now
Exam Code: NSE7_EFW-7.0
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.0
Last Update: Dec 2, 2024
Questions: 163

PDF + Testing Engine

$66  $164.99

Testing Engine

$50  $124.99
buy now NSE7_EFW-7.0 testing engine

PDF (Q&A)

$42  $104.99
buy now NSE7_EFW-7.0 pdf