Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.0 Questions and answers with ValidTests

Exam NSE7_EFW-7.0 All Questions
Exam NSE7_EFW-7.0 Premium Access

View all detail and faqs for the NSE7_EFW-7.0 exam

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which two configuration commands change the default behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

Options:

A.

set av-failopen off

B.

set av-failopen pass

C.

set fail-open enable

D.

set ips fail-open disable

Expert Solution
Questions # 32:

View the exhibit, which contains the output of a diagnose command, and then answer the question below.

Question # 32

What statements are correct regarding the output? (Choose two.)

Options:

A.

This is an expected session created by a session helper.

B.

Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.0.1.10.

C.

Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.200.1.1.

D.

This is an expected session created by an application control profile.

Expert Solution
Questions # 33:

Which two statements about OCVPN are true? (Choose two.)

Options:

A.

Only root vdom supports OCVPN.

B.

OCVPN supports static and dynamic IPs in WAN interface.

C.

OCVPN offers only Hub-Spoke VPNs.

D.

FortiGate devices under different FortiCare accounts can be used to form OCVPN.

Expert Solution
Questions # 34:

A FortiGate is configured as an explicit web proxy. Clients using this web proxy are reposting DNS errors when accessing any website. The administrator executes the following debug commands and observes that the n-dns-timeout counter is increasing:

Question # 34

What should the administrator check to fix the problem?

Options:

A.

The connectivity between the FortiGate unit and the DNS server.

B.

The connectivity between the client workstations and the DNS server.

C.

That DNS traffic from client workstations is allowed by the explicit web proxy policies.

D.

That DNS service is enabled in the explicit web proxy interface.

Expert Solution
Questions # 35:

Refer to the exhibit, which shows the output of a diagnose command.

Question # 35

What can you conclude from the output shown in the exhibit? (Choose two.)

Options:

A.

This is a pinhole session created to allow traffic for a protocol that requires additional sessions to operate through FortiGate.

B.

This is an expected session created by the IPS engine.

C.

Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next-hop IP address 10.200.1.1.

D.

Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next-hop IP address 10.0.1.10.

Expert Solution
Questions # 36:

Which two statements about application-layer test commands are true? (Choose two.)

Options:

A.

Some of them display real-time application debugs.

B.

Some of them can be used to restart an application.

C.

Some of them display statistics and configuration information about a feature or process.

D.

Some of them only display output, after you run the diagnose debug console enable command.

Expert Solution
Questions # 37:

View the exhibit, which contains the partial output of a diagnose command, and then answer the question below.

Question # 37

Based on the output, which of the following statements is correct?

Options:

A.

Anti-reply is enabled.

B.

DPD is disabled.

C.

Quick mode selectors are disabled.

D.

Remote gateway IP is 10.200.5.1.

Expert Solution
Questions # 38:

Which statement about protocol options is true?

Options:

A.

Protocol options allows administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.

B.

Protocol options allows administrators the ability to configure the Any setting for all enabled protocols which provides the most efficient use of system resources.

C.

Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.

D.

Protocol options allows administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.

Expert Solution
Questions # 39:

Refer to the exhibit, which shows the output of diagnose sys session list.

Question # 39

If the HA ID for the primary device is 0, what will happen if the primary fails and the secondary becomes the primary?

Options:

A.

Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.

B.

The secondary device has this session synchronized; however, because application control is applied, the session will be marked dirty and have to be re-evaluated after failover.

C.

The session state will be preserved but the kernel will need to re-evaluate the session due to NAT being applied.

D.

The session will be removed from the session table of the secondary device due to the presence of allowed error packets, which will force the client to restart the session with the server.

Expert Solution
Questions # 40:

Refer to the exhibit, which shows a partial routing table.

Question # 40

Assuming all the appropriate firewall policies are configured, what two changes would an administrator need to make if they wanted to send traffic from a client directly connected to port3, to a server directly connected to port4? (Choose two.)

Options:

A.

Configure route leaking between VRF 12 and VRF 21.

B.

Disable auto-asic-offload as this is not supported between VRF instances.

C.

Configure RIPv2 to exchange route information between the VRF instances.

D.

Configure route leaking between port3 and port4.

E.

Enable SNAT on the relevant firewall policies to prevent RPF check drops.

Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions