Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Fortinet NSE7_EFW-7.2 Dumps

Fortinet NSE 7 - Enterprise Firewall 7.2 Questions and Answers

Question 1

Refer to the exhibit, which shows a network diagram.

as

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

Options:

A.

Set route-overlap to allow.

B.

Set single-source to enable

C.

Set route-overlap to either use—new or use-old

D.

Set net-device to enable

Question 2

Which two statements about the Security fabric are true? (Choose two.)

Options:

A.

FortiGate uses the FortiTelemetry protocol to communicate with FortiAnatyzer.

B.

Only the root FortiGate sends logs to FortiAnalyzer

C.

Only FortiGate devices with configuration-sync receive and synchronize global CMDB objects that the toot FortiGate sends

D.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer

Question 3

Refer to the exhibit, which shows an ADVPN network.

as

Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

Options:

A.

set auto-discovery-forwarder enable

B.

set add-route enable

C.

set auto-discovery-receiver enable

D.

set auto-discovery-sender enable

Question 4

Exhibit.

as

Refer to the exhibit, which shows a partial web filter profile conjuration

What can you cone udo from this configuration about access to , com, which is categorized as Social Networking?

Options:

A.

The access is blocked based on the Content Filter configuration

B.

The access is allowed based on the FortiGuard Category Based Filter configuration

C.

The access is blocked based on the URL Filter configuration

D.

The access is hocked if the local or the public FortiGuard server does not reply

Question 5

Exhibit.

as

Refer to the exhibit, which contains a CLI script configuration on fortiManager. An administrator configured the CLI script on FortiManager rut the script tailed to apply any changes to the managed

device after being executed.

What are two reasons why the script did not make any changes to the managed device? (Choose two)

Options:

A.

The commands that start with the # sign did not run.

B.

Incomplete commands can cause CLI scripts to fail.

C.

Static routes can be added using only TCI scripts.

D.

CLI scripts must start with #!.

Question 6

Exhibit.

as

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

Options:

A.

IPSec Tunnel aggregation is configured

B.

net-device is enabled in the tunnel IPSec phase 1 configuration

C.

OSPI is configured to run over IPSec.

D.

add-route is disabled in the tunnel IPSec phase 1 configuration.

Question 7

Which FortiGate in a Security I auric sends togs to FortiAnalyzer?

Options:

A.

Only the root FortiGate.

B.

Each FortiGate in the Security fabric.

C.

The FortiGate devices performing network address translation (NAT) or unified threat management (UTM). if configured.

D.

Only the last FortiGate that handled a session in the Security Fabric

Question 8

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 9

Refer to the exhibit, which shows config system central-management information.

as

Which setting must you configure for the web filtering feature to function?

Options:

A.

Add server. fortiguard. net to the server list.

B.

Configure securewf.fortiguard. net on the default servers.

C.

Set update-server-location to automatic.

D.

Configure server-type with the rating option.

Question 10

Exhibit.

as

Refer to exhibit, which shows a central management configuration

Which server will FortiGate choose for web filler rating requests if 10.0.1.240 is experiencing an outage?

Options:

A.

Public FortiGuard servers

B.

10.0.1.242

C.

10.0.1.244

D.

10.0.1.243

Question 11

Exhibit.

as

Refer to the exhibit, which contains a partial policy configuration.

Which setting must you configure to allow SSH?

Options:

A.

Specify SSH in the Service field

B.

Configure pot 22 in the Protocol Options field.

C.

Include SSH in the Application field

D.

Select an application control profile corresponding to SSH in the Security Profiles section

Question 12

Exhibit.

as

Refer to the exhibit, which provides information on BGP neighbors.

Which can you conclude from this command output?

Options:

A.

The router are in the number to match the remote peer.

B.

You must change the AS number to match the remote peer.

C.

BGP is attempting to establish a TCP connection with the BGP peer.

D.

The bfd configuration to set to enable.

Question 13

Winch two statements about ADVPN are true? (Choose two)

Options:

A.

auto-discovery receiver must be set to enable on the Spokes.

B.

Spoke to-spoke traffic never goes through the hub

C.

lt supports NAI for on-demand tunnels

D.

Routing is configured by enabling add-advpn-route

Question 14

After enabling IPS you receive feedback about traffic being dropped.

What could be the reason?

Options:

A.

Np-accel-mode is set to enable

B.

Traffic-submit is set to disable

C.

IPS is configured to monitor

D.

Fail-open is set to disable

Question 15

Which statement about network processor (NP) offloading is true?

Options:

A.

For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP

B.

The NP provides IPS signature matching

C.

You can disable the NP for each firewall policy using the command np-acceleration st to loose.

D.

The NP checks the session key or IPSec SA

Page: 1 / 5
Total 50 questions