Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.2 Questions and answers with ValidTests

Exam NSE7_EFW-7.2 All Questions
Exam NSE7_EFW-7.2 Premium Access

View all detail and faqs for the NSE7_EFW-7.2 exam

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit, which shows a network diagram.

Question # 1

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

Options:

A.

Set route-overlap to allow.

B.

Set single-source to enable

C.

Set route-overlap to either use—new or use-old

D.

Set net-device to enable

Expert Solution
Questions # 2:

Exhibit.

Question # 2

Refer to the exhibit, which contains a partial policy configuration.

Which setting must you configure to allow SSH?

Options:

A.

Specify SSH in the Service field

B.

Configure pot 22 in the Protocol Options field.

C.

Include SSH in the Application field

D.

Select an application control profile corresponding to SSH in the Security Profiles section

Expert Solution
Questions # 3:

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel however, the VPN interfaces do not appear as available options.

Options:

A.

Create interface mappings for the IPsec VPN interfaces before you use them in a policy.

B.

Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces

C.

Configure the phase 1 settings in the VPN community that you didnt initially configure. FortiGate automatically generates the interfaces after you configure the required settings

D.

install the VPN community and gateway configuration on the fortiGate devices so that the VPN interfaces appear on the Policy Objects on fortiManager.

Expert Solution
Questions # 4:

Refer to the exhibit, which shows device registration on FortiManager.

Question # 4

What can you conclude about the Spoke-1 and Spoke-2 configurations with respect to the information cond: Modified (recent auto-updated)?

Options:

A.

Based on the policy configuration on NGFW-1, the configuration on both spokes is modified and automatically updated.

B.

On NGFW-A, the configuration was changed and spokes are wailing for an autoupdate.

C.

On both Spoke-1 and Spoke-2, the configuration was changed directly on the FortiGate device, and the changes were automatically retrieved by the device database.

D.

Spoke-1 and Spoke-2 are sharing the same security policy configuration and the same policy package.

Expert Solution
Questions # 5:

Refer to the exhibit, which shows config system central-management information.

Question # 5

Which setting must you configure for the web filtering feature to function?

Options:

A.

Add server. fortiguard. net to the server list.

B.

Configure securewf.fortiguard. net on the default servers.

C.

Set update-server-location to automatic.

D.

Configure server-type with the rating option.

Expert Solution
Questions # 6:

An administrator is configuring two FortiGate devices in an HA cluster. While configuring the devices, the administrator issues the following commands on both HA cluster members:

Question # 6

In which two ways do these commands impact the HA cluster? (Choose two.)

Options:

A.

They force the former primary to send gratuitous ARP packets when the failover happens to indicate that the virtual MAC address is now using a different device.

B.

They force the former primary to shut down all ts interfaces for one second when failover happens, excluding the heartbeat and reserved management interfaces.

C.

They force both HA devices for remote link monitoring to detect an issue in the forwarding path.

D.

They force the switches to update their MAC forwarding tables, when failover happens.

Expert Solution
Questions # 7:

Refer to the exhibit, which contains a TCL script configuration on FortiManager.

Question # 7

An administrator has configured the TCL script on FortiManager, but the TCL script failed

to apply any changes to the managed device after being run.

Why did the TCL script fail to make any changes to the managed device?

Options:

A.

The TCL procedure run_cmd has not been created.

B.

The TCL script must start with #include.

C.

There is no corresponding #! to signify the end of the script.

D.

The TCL procedure lacks the required loop statements to iterate through the changes.

Expert Solution
Questions # 8:

In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)

Options:

A.

lt can be configured as an update server a rating server or both

B.

It provides VM license validation services

C.

It supports rating requests from non-FortiGate devices.

D.

It caches available firmware updates for unmanaged devices

Expert Solution
Questions # 9:

Refer to the exhibit, which contains a partial BGP combination.

Question # 9

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

Options:

A.

ebgp-enforce-multihop

B.

recursive-next-hop

C.

ibgp-enfoce-multihop

D.

update-source

Expert Solution
Questions # 10:

Exhibit.

Question # 10

Refer to the exhibit, which provides information on BGP neighbors.

Which can you conclude from this command output?

Options:

A.

The router are in the number to match the remote peer.

B.

You must change the AS number to match the remote peer.

C.

BGP is attempting to establish a TCP connection with the BGP peer.

D.

The bfd configuration to set to enable.

Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions