Fortinet NSE7_EFW-6.4 - Fortinet NSE 7 - Enterprise Firewall 6.4 Exam

Question #11 (Topic: Single Topic)
Refer to the exhibit, which contains partial output from an IKE real-time debug.

Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?
A. auto-discovery-shortcut B. auto-discovery-forwarder C. auto-discovery-sender D. auto-discovery-receiver
Answer: C
Question #12 (Topic: Single Topic)
Which two statements about OCVPN are true? (Choose two.)
A. Only root vdom supports OCVPN. B. OCVPN supports static and dynamic IPs in WAN interface. C. OCVPN offers only Hub-Spoke VPNs. D. FortiGate devices under different FortiCare accounts can be used to form OCVPN.
Answer: AB
Question #13 (Topic: Single Topic)
Refer to the exhibit, which shows a central management configuration.

Which server will FortiGate choose for antivirus and IPS updates, if 10.0.1.243 is experiencing an outage?
A. 10.0.1.242 B. Public FortiGuard servers C. 10.0.1.240 D. 10.0.1.244
Answer: B
Question #14 (Topic: Single Topic)
Which two statements about application layer test commands are true? (Choose two.)
A. They display real-time application debugs. B. They are used to filter real-time debugs. C. Some of them can be used to restart an application. D. Some of them display statistics and configuration information about a feature or process.
Answer: CD
Question #15 (Topic: Single Topic)
Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)
A. mem failopen B. IPS failopen C. AV failopen D. UTM failopen
Answer: BC
Download Exam
Page: 3 / 7
Total 35 questions