Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.2 Questions and answers with ValidTests

Exam NSE7_EFW-7.2 All Questions
Exam NSE7_EFW-7.2 Premium Access

View all detail and faqs for the NSE7_EFW-7.2 exam

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

While configuring the BGP protocol, an administrator applies the set netuork-inport-check disable command under config network.

What will FortiGate do as a result of this command?

Options:

A.

FortiGate will advertise only the corresponding prefixes in the BGP network table to its BGP neighbor, even if itis not in the routing table.

B.

FortiGate will advertise all the prefixes in the BGP network table to its BGP neighbor, even f itis not in the routing table.

C.

FortiGate will not advertise any imported routes received from one BGP neighbor to another.

D.

FortiGate will not advertise the prefixes, if it is not in the routing table.

Expert Solution
Questions # 12:

Refer to the exhibit, which contains information about an IPsec VPN tunnel.

Question # 12

What two conclusions can you draw from the command output? (Choose two.)

Options:

A.

Dead peer detection is set to enable.

B.

The IKE version is 2.

C.

Both IPsec SAs are loaded on the kernel.

D.

Forward error correction in phase 2 is set to enable.

Expert Solution
Questions # 13:

Exhibit.

Question # 13

Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.

Which two conclusions can you draw from this con figuration? (Choose two)

Options:

A.

10.1.5.254 is the default gateway of the internal network

B.

On failover new primary device uses the same MAC address as the old primary

C.

The VRRP domain uses the physical MAC address of the primary FortiGate

D.

By default FortiGate B is the primary virtual router

Expert Solution
Questions # 14:

Which two statements about bfd are true? (Choose two)

Options:

A.

It can support neighbor only over the next hop in BGP

B.

You can disable it at the protocol level

C.

It works for OSPF and BGP

D.

You must configure n globally only

Expert Solution
Questions # 15:

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

Options:

A.

fec-ingress and fec-egress

B.

Odpd and dpd-retryinterval

C.

fragmentation and fragmentation-mtu

D.

keepalive and keylive

Expert Solution
Questions # 16:

Refer to the exhibits, which show the configurations of two address objects from the same FortiGate.

Question # 16

Why can you modify the Engineering address object, but not the Finance address object?

Options:

A.

You have read-only access.

B.

FortiGate joined the Security Fabric and the Finance address object was configured on the root FortiGate.

C.

FortiGate is registered on FortiManager.

D.

Another user is editing the Finance address object in workspace mode.

Expert Solution
Questions # 17:

Refer to the exhibit, which shows an ADVPN network.

Question # 17

Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

Options:

A.

set auto-discovery-forwarder enable

B.

set add-route enable

C.

set auto-discovery-receiver enable

D.

set auto-discovery-sender enable

Expert Solution
Questions # 18:

Which two statements about the Security fabric are true? (Choose two.)

Options:

A.

FortiGate uses the FortiTelemetry protocol to communicate with FortiAnatyzer.

B.

Only the root FortiGate sends logs to FortiAnalyzer

C.

Only FortiGate devices with configuration-sync receive and synchronize global CMDB objects that the toot FortiGate sends

D.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer

Expert Solution
Questions # 19:

Exhibit.

Question # 19

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

Options:

A.

IPSec Tunnel aggregation is configured

B.

net-device is enabled in the tunnel IPSec phase 1 configuration

C.

OSPI is configured to run over IPSec.

D.

add-route is disabled in the tunnel IPSec phase 1 configuration.

Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions