Fortinet NSE7_EFW-7.0 - NSE 7 - Enterprise Firewall 7.0 Exam

Question #6 (Topic: Exam A)
What are two functions of automation stitches? (Choose two.)
A. Automation stitches can be configured on any FortiGate device in a Security Fabric environment. B. An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action. C. Automation stitches can be created to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds. D. An automation stitch configured to execute actions in parallel can be set to insert a specific delay between actions.
Answer: BC
Question #7 (Topic: Exam A)
Refer to the exhibit, which shows a partial web filter profile configuration.

Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?
A. FortiGate will block the connection, based on the FortiGuard category based filter configuration. B. FortiGate will block the connection as an invalid URL. C. FortiGate will exempt the connection, based on the Web Content Filter configuration. D. FortiGate will allow the connection, based onthe URL Filter configuration.
Answer: A
Question #8 (Topic: Exam A)
Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command.

Based on the output, which two statements are correct? (Choose two.)
A. The npu_flag for this tunnel is 03. B. Different SPI values are a result of auto-negotiation being disabled for phase 2 selectors. C. Anti-replay is enabled. D. The npu_flag for this tunnel is 02.
Answer: AC
Question #9 (Topic: Exam A)
Refer to the exhibit, which shows a session table entry.

Which statement about FortiGate behavior relating to this session is true?
A. FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made. B. FortiGate forwarded this session without any inspection. C. FortiGate is performing security profile inspection using the CPU. D. FortiGate applied only IPS inspection to this session.
Answer: B
Question #10 (Topic: Exam A)
Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate.


An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovered that FortiGate is not matching the user-2 VPN for members of the Users-2 group.
Which two changes must the administrator make to fix the issue? (Choose two.)
A. Use different pre-shared keys on both VPNs. B. Enable XAuth on both VPNs. C. Set up specific peer IDs on both VPNs. D. Change to aggressive mode on both VPNs.
Answer: BC
Download Exam
Page: 2 / 12
Total 60 questions