Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Fortinet NSE7_EFW-7.2 Dumps

Fortinet NSE 7 - Enterprise Firewall 7.2 Questions and Answers

Question 1

An administrator has configured two fortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device What can the administrator do to fix this problem?

Options:

A.

Verify that the speed and duplex settings match between me FortiGate interfaces and the connected switch ports

B.

Configure set link -failed signal enable under-config system ha on both Cluster members

C.

Configure remote Iink monitoring to detect an issue in the forwarding path

D.

Configure set send-garp-on-failover enables under config system ha on both cluster members

Question 2

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel however, the VPN interfaces do not appear as available options.

Options:

A.

Create interface mappings for the IPsec VPN interfaces before you use them in a policy.

B.

Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces

C.

Configure the phase 1 settings in the VPN community that you didnt initially configure. FortiGate automatically generates the interfaces after you configure the required settings

D.

install the VPN community and gateway configuration on the fortiGate devices so that the VPN interfaces appear on the Policy Objects on fortiManager.

Question 3

Exhibit.

Refer to exhibit, which shows a central management configuration

Which server will FortiGate choose for web filler rating requests if 10.0.1.240 is experiencing an outage?

Options:

A.

Public FortiGuard servers

B.

10.0.1.242

C.

10.0.1.244

D.

10.0.1.243

Question 4

In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)

Options:

A.

lt can be configured as an update server a rating server or both

B.

It provides VM license validation services

C.

It supports rating requests from non-FortiGate devices.

D.

It caches available firmware updates for unmanaged devices

Question 5

Which two statements about the neighbor-group command are true? (Choose two.)

Options:

A.

You can configure it on the GUI.

B.

It applies common settings in an OSPF area.

C.

It is combined with the neighbor-range parameter.

D.

You can apply it in Internal BGP (IBGP) and External BGP (EBGP).

Question 6

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

Options:

A.

FortiManager provides FortiGuard.

B.

fortiguard-anycast is set to enable.

C.

You do not have the corresponding write access.

D.

udp is not a protocol option.

Question 7

Refer to the exhibits, which show the configurations of two address objects from the same FortiGate.

Why can you modify the Engineering address object, but not the Finance address object?

Options:

A.

You have read-only access.

B.

FortiGate joined the Security Fabric and the Finance address object was configured on the root FortiGate.

C.

FortiGate is registered on FortiManager.

D.

Another user is editing the Finance address object in workspace mode.

Question 8

Which FortiGate in a Security I auric sends togs to FortiAnalyzer?

Options:

A.

Only the root FortiGate.

B.

Each FortiGate in the Security fabric.

C.

The FortiGate devices performing network address translation (NAT) or unified threat management (UTM). if configured.

D.

Only the last FortiGate that handled a session in the Security Fabric

Question 9

Which two statements about ADVPN are true? (Choose two.)

Options:

A.

You must disable add-route in the hub.

B.

AllFortiGate devices must be in the same autonomous system (AS).

C.

The hub adds routes based on IKE negotiations.

D.

You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0.

Question 10

Exhibit.

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

Options:

A.

FortiGate creates separate virtual interfaces for each dial up client.

B.

The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.

C.

Dead peer detection s disabled.

D.

The routing table shows a single IPSec virtual interface.

Question 11

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 12

Refer to the exhibit, which shows a custom signature.

Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Choose two.)

Options:

A.

Add severity.

B.

Add attack_id.

C.

Ensure that the header syntax is F-SBID.

D.

Start options with --.

Question 13

You want to configure faster failure detection for BGP

Which parameter should you enable on both connected FortiGate devices?

Options:

A.

Ebgp-enforce-multihop

B.

bfd

C.

Distribute-list-in

D.

Graceful-restart

Question 14

Which two statements about IKE version 2 fragmentation are true? (Choose two.)

Options:

A.

Only some IKE version 2 packets are considered fragmentable.

B.

The reassembly timeout default value is 30 seconds.

C.

It is performed at the IP layer.

D.

The maximum number of IKE version 2 fragments is 128.

Question 15

Exhibit.

Refer to the exhibit, which contains a partial policy configuration.

Which setting must you configure to allow SSH?

Options:

A.

Specify SSH in the Service field

B.

Configure pot 22 in the Protocol Options field.

C.

Include SSH in the Application field

D.

Select an application control profile corresponding to SSH in the Security Profiles section