Fortinet NSE 7 - Enterprise Firewall 6.2 v1.0 (NSE7-EFW-6.2)

Page:    1 / 2   
Total 30 questions

Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

  • A. IPS failopen
  • B. mem failopen
  • C. AV failopen
  • D. UTM failopen


Answer : AC

Refer to the exhibit, which contains the partial output of a diagnose command.


Based on the output, which two statements are correct? (Choose two.)

  • A. Anti-replay is enabled.
  • B. DPD is disabled.
  • C. Remote gateway IP is 10.200.4.1.
  • D. Quick mode selectors are disabled.


Answer : AC

Refer to the exhibit, which contains the output of a diagnose command.


Which two statements regarding the output in the exhibit are true? (Choose two.)

  • A. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
  • B. Servers with a negative TZ value are experiencing a service outage.
  • C. Servers with the D flag are considered to be down.
  • D. FortiGate used 209.222.147.36 as the initial server to validate its contract.


Answer : AD

Which two statements about application layer test commands are true? (Choose two.)

  • A. They are used to filter real-time debugs.
  • B. They display real-time application debugs.
  • C. Some of them can be used to restart an application.
  • D. Some of them display statistics and configuration information about a feature or process.


Answer : CD

Refer to the exhibits, which contain configuration on FortiGate and partial session information.



All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network.
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user’s session?

  • A. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
  • B. The session would remain in the session table, and its traffic would still egress from port1.
  • C. The session would remain in the session table, and its traffic would start to egress from port2.
  • D. The session would be deleted, so the client would need to start a new session.


Answer : B

Which three conditions are required for two FortiGate devices to form an OSP adjacency? (Choose three.)

  • A. OSPF costs match
  • B. OSPF peer IDs match
  • C. Hello and dead intervals match
  • D. OSPF IP MTUs match
  • E. IP addresses are in the same subnet


Answer : CDE

Which two statements about bulk configuration changes using FortiManager CLI scripts are correct? (Choose two.)

  • A. When executed on the Device Database, you must use the installation wizard to apply the changes to the managed FortiGate.
  • B. When executed on the Policy Package, ADOM database, changes are applied directly to the managed FortiGate.
  • C. When executed on the All FortiGate in ADOM, changes are automatically installed without creating a new revision history.
  • D. When executed on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.


Answer : AD

Refer to the exhibit, which contains a partial output of an IKE real-time debug.


Based on the debug output, which phase-1 setting is enabled in the configuration of this VPN?

  • A. auto-discovery-receiver
  • B. auto-discovery-forwarder
  • C. auto-discovery-sender
  • D. auto-discovery-shortcut


Answer : C

What is the diagnose test application ipsmonitor 99 command used for?

  • A. To enable IPS bypass mode
  • B. To provide information regarding IPS sessions
  • C. To disable the IPS engine
  • D. To restart all IPS engines and monitors


Answer : D

Refer to the exhibit, which contains a session table entry.


Which statement about FortiGate inspection of this session is true?

  • A. FortiGate applied proxy-based inspection.
  • B. FortiGate applied flow-based NGFW policy-based inspection.
  • C. FortiGate applied flow-based inspection.
  • D. FortiGate forwarded this session without any inspection.


Answer : A

Refer to the exhibit, which contains the output of a debug command.


Which two statements about the exhibit are true? (Choose two.)

  • A. The local FortiGate OSPF router ID is 0.0.0.4.
  • B. The local FortiGate is the backup designated router.
  • C. In the network connected to port4, two OSPF routers are down.
  • D. Port4 is connected to the OSPF backbone area.


Answer : AD

Refer to the exhibit, which contains the output of diagnose sys session stat.


Which two statements about the output shown are correct? (Choose two.)

  • A. No sessions have been deleted because of memory pages exhaustion.
  • B. There are 0 ephemeral sessions.
  • C. There are 168 TCP sessions waiting to complete the three-way handshake.
  • D. All the sessions in the session table are TCP sessions.


Answer : AB

Refer to the exhibit, which contains central management configuration.


Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an outage?

  • A. 10.0.1.242
  • B. 10.0.1.244
  • C. Public FortiGuard servers
  • D. 10.0.1.240


Answer : C

Refer to the exhibit, which contains the output of diagnose sys session list.


If the HA ID for the primary unit is zero (0), which statement about the output is true?

  • A. This session cannot be synced with the slave unit.
  • B. The inspection of this session has been offloaded to the slave unit.
  • C. The master unit is processing this traffic.
  • D. This session is for HA heartbeat traffic.


Answer : C

Refer to the exhibit, which contains the partial output of an IKE real-time debug.


Why did the tunnel not come up?

  • A. The pre-shared keys do not match
  • B. The remote gateway phase 1 configuration does not match the local gateway phase 1 configuration.
  • C. The remote gateway phase 2 configuration does not match the local gateway phase 2 configuration.
  • D. The remote gateway is using aggressive mode and the local gateway is configured to use main mode.


Answer : B

Page:    1 / 2   
Total 30 questions