Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.0 Questions and answers with ValidTests

Exam NSE7_EFW-7.0 All Questions
Exam NSE7_EFW-7.0 Premium Access

View all detail and faqs for the NSE7_EFW-7.0 exam

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as a local FDS?

Options:

A.

FortiManager can download and maintain local copies of FortiGuard databases.

B.

FortiManager supports only FortiGuard push to managed devices.

C.

FortiManager will respond to update requests only if they originate from a managed device.

D.

FortiManager does not support rating requests.

Expert Solution
Questions # 22:

You have configured FortiManager as a local FDS to provide FortiGate AV and IPS updates, but FortiGate devices are not receiving updates to their AV signature databases, IPS engines, or IPS signature databases.

Which two settings need to be verified for these features to function? (Choose two.)

Options:

A.

FortiGate needs to have the server list entry for FortiManager set to server-type update under config system central-management.

B.

FortiManager needs to be the license validation server for FortiGate devices trying to retrieve updated AV and IPS packages.

C.

Service access needs to be enabled on FortiManager under System Settings > Network.

D.

FortiGate needs to have include-default-servers disabled under config system central-management.

Expert Solution
Questions # 23:

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Question # 23

Which two statements about this debug output are correct? (Choose two.)

Options:

A.

The remote gateway IP address is 10.0.0.1.

B.

The initiator provided remote as its IPsec peer ID.

C.

It shows a phase 1 negotiation.

D.

The negotiation is using AES128 encryption with CBC hash.

Expert Solution
Questions # 24:

Refer to the exhibit, which contains the partial output of a diagnose command.

Question # 24

Based on the output, which two statements are correct? (Choose two.)

Options:

A.

Anti-replay is enabled.

B.

DPD is disabled.

C.

Remote gateway IP is 10.200.4.1.

D.

Quick mode selectors are disabled.

Expert Solution
Questions # 25:

Refer to the exhibit, which shows a session entry. Which statement about this session is true?

Question # 25

Options:

A.

It is an ICMP session from 10.1.10.10 to 10.200.5. 1.

B.

It is a TCP session in close_wait state, from 10. l. 10.10 to 10.200.1.1.

C.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.

D.

It is a TCP session in the established state, from 10.1.10.10 to 10.200.5.1.

Expert Solution
Questions # 26:

What does the dirty flag mean in a FortiGate session configured for NGFW policy mode?

Options:

A.

The existing session table entry has been updated with the app_id and the firewall policy table needs to be checked for a match.

B.

The application or URL category is unknown and needs to be rescanned by the IPS engine to try to identify the Layer 7 details.

C.

The URL category for this session has been updated by FortiGuard and the session needs to be checked against the policy again to ensure proper web filtering is applied.

D.

Traffic has been identified as coming from an application that is not allowed and the relevant replacement message needs to be displayed to the user, if configured.

Expert Solution
Questions # 27:

Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.

Question # 27

Which statement are true regarding the output in the exhibit? (Choose two.)

Options:

A.

There are three FortiGuard servers that are not responding to the queries sent by the FortiGate.

B.

The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone.

C.

FortiGate will send the FortiGuard queries to the server with highest weight.

D.

A server's round trip delay (RTT) is not used to calculate its weight.

Expert Solution
Questions # 28:

An administrator has created a VPN community within VPN Manager on FortiManager. They also added gateways to the VPN community and are now trying to create firewall policies to permit traffic over the tunnel; however, the VPN interfaces are not listed as available options.

What step must the administrator take to resolve this issue?

Options:

A.

Install the VPN community and gateway configuration to the FortiGate devices, in order for the interfaces to be displayed within Policy & Objects on FortiManager

B.

Set up all of the phase 1 settings in the VPN community that they neglected to set up initially. The interfaces will be automatically generated after the administrator configures all of the required settings.

C.

Refresh the device status from the Device Manager so that FortiGate will populate the IPsec interfaces.

D.

Create interface mappings for the IPsec VPN interfaces, before they can be used in a policy.

Expert Solution
Questions # 29:

Which of the following statements is true regarding a FortiGate configured as an explicit web proxy?

Options:

A.

FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT be modified by the administrator.

B.

FortiGate limits the total number of simultaneous explicit web proxy users.

C.

FortiGate limits the number of simultaneous sessions per explicit web proxy user The limit CAN be modified by the administrator

D.

FortiGate limits the number of workstations that authenticate using the same web proxy user credentials. This limit CANNOT be modified by the administrator.

Expert Solution
Questions # 30:

Examine the partial output from two web filter debug commands; then answer the question below:

Question # 30

Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99.com?

Options:

A.

Finance and banking

B.

General organization.

C.

Business.

D.

Information technology.

Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions