Latest NSE7_EFW-7.0 Practice Tests with Actual Questions

Get Complete pool of questions with Premium PDF and Test Engine

Exam Code : NSE7_EFW-7.0
Exam Name : Fortinet NSE 7 - Enterprise Firewall 7.0
Vendor Name : "Fortinet"







Fortinet


NSE7_EFW-7.0


Fortinet NSE 7 - Enterprise Firewall 7.0


https://killexams.com/pass4sure/exam-detail/NSE7_EFW-7.0


Question: 1



tatements are true regarding the output in the exhibit? (Choose two.) iGate will probe 121.111.236.179 every fifteen minutes for a response. ers with the D flag are considered to be down.

ers with a negative TZ value are experiencing a service outage. iGate used 209.222.147.3 as the initial server to validate its contract.


r: A,D


ation:


cause flag is Failed so fortigate will check if server is available every 15 minD-state is I , contact to vali info


on: 2

View the exhibit, which contains the output of a diagnose command, and then answer the question below.


Which s

  1. Fort

  2. Serv

  3. Serv

  4. Fort


Answe


Explan


A C be date

contract


Questi


Refer to the exhibit, which contains partial output from an IKE real-time debug.



wo statements about this debug output are correct? (Choose two.) emote gateway IP address is 10.0.0.1.

nitiator provided remote as its IPsec peer ID. ows a phase 1 negotiation.

egotiation is using AES128 encryption with CBC hash.


r: B,C


on: 3


Gate has two default routes:

Which t

  1. The r

  2. The i

  3. It sh

  4. The n


Answe Questi A Forti



ernet traffic is currently using port1. The exhibit shows partial information for one sample session of Inte rom an internal user:


ould happen with the traffic matching the above session if the priority on the first default route (IDd1) w from 5 to 20?

ession would be deleted, and the client would need to start a new session.

ession would remain in the session table, and its traffic would start to egress from port2. ession would remain in the session table, but its traffic would now egress from

rt1 and port2.

ession would remain in the session table, and its traffic would still egress from port1.

All Int rnet

traffic f


What w ere

changed

  1. The s

  2. The s

  3. The s both po

  4. The s




Answer: D



Question: 4


Examine the output of the ‘get router info bgp summary’ command shown in the exhibit; then answer the question below.



tatements are true regarding the output in the exhibit? (Choose two.) state of the peer 10.125.0.60 is Established.

peer 10.200.3.1 has never been down since the BGP counters were cleared. BGP peer has not received an OpenConfirm from 10.200.3.1.

ocal BGP peer has received a total of 3 BGP prefixes.


r: A,C


on: 5


ministrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the admin that some of the switches in the network continue to send traffic to the former primary device. The strator decides to enable the setting link-failed-signal to fix the problem.


tatement about this setting is true?

nds an ARP packet to all connected devices, indicating that the HA virtual MAC address is reachable thr aster after a failover.

nds a link failed signal to all connected devices.

sabled all the non-heartbeat interfaces in all HA members for two seconds after a failover.

rces the former primary device to shut down all its non-heartbeat interfaces for one second, while the fai


r: D

Which s

  1. BGP

  2. BGP

  3. Local

  4. The l


Answe


Questi


An ad istrator

notices admini


Which s

  1. It se ough a

    new m

  2. It se

  3. It di

  4. It fo lover

occurs.


Answe



Explanation:


Reference: https://kb.fortinet.com/kb/viewContent.do?externalId=FD40860&sliceId=1



Question: 6


Examine the output from the BGP real time debug shown in the exhibit, then the answer the question below:



tatements are true regarding the output in the exhibit? (Choose two.) peers have successfully interchanged Open and Keepalive messages. BGP peer received a prefix for a default route.

tate of the remote BGP peer is OpenConfirm.

tate of the remote BGP peer will go to Connect after it confirms the received prefixes.


r: A,B


on: 7


he exhibit, which contains the output of a diagnose command, and then answer the question below.

Which s

  1. BGP

  2. Local

  3. The s

  4. The s


Answe Questi View t


What statements are correct regarding the output? (Choose two.)

  1. This is an expected session created by a session helper.

  2. Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.0.1.10.

  3. Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.200.1.1.

  4. This is an expected session created by an application control profile.



Answer: A,C



Question: 8


View the exhibit, which contains a partial web filter profile configuration, and then answer the question below.



Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

  1. FortiGate will exempt the connection based on the Web Content Filter configuration.

  2. FortiGate will block the connection based on the URL Filter configuration.

  3. FortiGate will allow the connection based on the FortiGuard category based filter configuration.

  4. FortiGate will block the connection as an invalid URL.




Answer: B
Explanation:

fortigate does it in order Static URL -> FortiGuard C > Content -> Advanced (java, cookie removal..)so block it in first step


on: 9


he central management configuration shown in the exhibit, and then answer the question below.

Questi


View t


Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an outage? A. 10.0.1.240

B. One of the public FortiGuard distribution servers C. 10.0.1.244

D. 10.0.1.242




Answer: B



Question: 10


utbound interface will FortiGate use to route web traffic from internal users to the Internet? port1 and port2


r: C


on: 11


vents are recorded in the crashlogs of a FortiGate device? (Choose two.) ocess crash.

figuration changes.

nges in the status of any of the FortiGuard licenses.

em entering to and leaving from the proxy conserve mode.


r: A,D


ation:


diagnose debug crashlog read

View these partial outputs from two routing debug commands:


Which o

  1. Both

  2. port3

  3. port1

  4. port2


Answe


Questi


What e

  1. A pr

  2. Con

  3. Cha

  4. Syst


Answe


Explan


275: 2014-08-05 13:03:53 proxy=acceptor service=imap session fail mode=activated276: 2014-08-05 13:03:53 proxy=acceptor service=ftp session fail mode=activated277: 2014-08-05 13:03:53 proxy=acceptor service=nntp session fail mode=activated278: 2014-08-06 11:05:47 service=kernel conserve=on free=”45034 pages” red=”45874 pages” msg=”Kernel279: 2014-08-06 11:05:47 enters conserve mode”280: 2014-08-06 13:07:16 service=kernel conserve=exit free=”86704 pages”

green=”68811 pages”281: 2014-08-06 13:07:16 msg=”Kernel leaves conserve mode”282: 2014-08-06 13:07:16 proxy=imd sysconserve=exited total=1008 free=349 marginenter=201283: 2014-08-06 13:07:16 marginexit=302


Question: 12


An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration.



diagnose debug application ike-1 diagnose debug enable

which order is each step and phase displayed in the debug output each time a new dial-up user is connecting


se1; IKE mode configuration; XAuth; phase 2. e1; XAuth; IKE mode configuration; phase2. e1; XAuth; phase 2; IKE mode configuration. se1; IKE mode configuration; phase 2; XAuth.


r: B ation:

help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-ipsecvpn- c_VPN_Concepts/IKE_Packet_Processing.htm


on: 13


dependent FortiGate HA clusters are connected to the same broadcast domain. The administrator has rep both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem

.


A setting must be changed in one of the HA clusters to fix the problem? up ID.

The administrator has also enabled the IKE real time debug:


In to the

VPN?

  1. Pha

  2. Phas

  3. Phas

  4. Pha


Answe Explan https://

54/IPse


Questi


Two in orted

that in the

network


What H

  1. Gro

  2. Group name.

  3. Session pickup.

  4. Gratuitous ARPs.




Answer: A
Explanation:

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_failoverVMAC.htm


Question: 14



f the following statements is true regarding this configuration? ill scan every byte in every session.

iGate will spawn IPS engine instances based on the system load.

packets will be passed through without inspection if the IPS socket buffer runs out of memory.

ill use the faster matching algorithm which is only available for units with more than 4 GB memory.


r: A


on: 15


Examine the following partial outputs from two routing debug commands; then answer the question below:


default route using port2 is not displayed in the output of the second command? a lower priority than the default route using port1.

a higher priority than the default route using port1. a higher distance than the default route using port1. isabled in the FortiGate configuration.

View the global IPS configuration, and then answer the question below.


Which o

  1. IPS w

  2. Fort

  3. New

  4. IPS w


Answe


Questi


Why the

  1. It has

  2. It has

  3. It has

  4. It is d




Answer: C
Explanation:

https://kb.fortinet.com/kb/viewContent.do?externalId=FD32103



Question: 16


Which real time debug should an administrator enable to troubleshoot RADIUS authentication problems?

  1. Diagnose debug application radius -1.

  2. Diagnose debug application fnbamd -1.

  3. Diagnose authd console Clog enable.

  4. Diagnose radius console Clog enable.




Answer: B
Explanation:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD32838



Question: 17


he exhibit, which contains the output of a debug command, and then answer the question below.


ne of the following statements about this FortiGate is correct? urrently in system conserve mode because of high CPU usage. urrently in extreme conserve mode because of high memory usage. urrently in proxy conserve mode because of high memory usage. urrently in memory conserve mode because of high memory usage.


r: D


on: 18


tatement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-acce is true?

iGate first checks the OSPF ID to elect a DR.

DR and non-BDR routers will form full adjacencies to DR and BDR only.

is responsible for forwarding link state information from one router to another. the DR receives link state information from non-DR routers.

View t


Which o

  1. It is c

  2. It is c

  3. It is c

  4. It is c


Answe


Questi


Which s ss

network

  1. Fort

  2. Non-

  3. BDR

  4. Only




Answer: B



Question: 19


Refer to the exhibit, which shows a partial routing table.



ng all the appropriate firewall policies are configured, which two pings will FortiGate route? (Choose t rce IP address: 10.1.0.10. Destination IP address: 10.64.1.52

ce IPaddress: 10.72.3.52. Destination IP address: 10.1.0.254 ce IPaddress: 10.10.4.24, Destination IPaddress: 10.72.3.20

rce IPaddress: 10.73.9.10, Destination IPaddress: 10.72.3.15


r: A,B


on: 20


the exhibit, which contains partial output from an IKE real-time debug.

Assumi wo.)

  1. Sou

  2. Sour

  3. Sour

  4. Sou


Answe Questi Refer to


Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?

  1. auto-discovery-shortcut

  2. auto-discovery-forwarder

  3. auto-discovery-sender

  4. auto-discovery-receiver




Answer: D
Explanation:

Reference: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/320160/example-advpn-configuration First the Spoke receives SHORTCUT_OFFER, it respondes with sending shortcut-query.

AT the end it receives SHORTCUT_REPLY and creates new dynamic tunnel (H2S_0_0).



Question: 21



dn’t the tunnel come up?

re-shared keys do not match.

emote gateway’s phase 2 configuration does not match the local gateway’s phase 2 configuration. emote gateway’s phase 1 configuration does not match the local gateway’s phase 1 configuration. emote gateway is using aggressive mode and the local gateway is configured to use man mode.

View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.


Why di

  1. The p

  2. The r

  3. The r

  4. The r




Answer: C



Question: 22


View the exhibit, which contains the output of a diagnose command, and the answer the question below.



tatements are true regarding the Weight value?

nitial value is calculated based on the round trip delay (RTT). nitial value is statically set to 10.

alue is incremented with each packet lost.

termines which FortiGuard server is used for license validation.


r: C


on: 23


he exhibit, which contains the output of a BGP debug command, and then answer the question below.

Which s

  1. Its i

  2. Its i

  3. Its v

  4. It de


Answe Questi View t


Which of the following statements about the exhibit are true? (Choose two.)

  1. For the peer 10.125.0.60, the BGP state of is Established.

  2. The local BGP peer has received a total of three BGP prefixes.

  3. Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.

  4. The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.




Answer: A,D


Question: 24


Which statement about memory conserve mode is true?

  1. A FortiGate exits conserve mode when the configured memory use threshold reaches yellow.

  2. A FortiGate starts dropping all the new and old sessions when the configured memory use threshold reaches extreme.

  3. A FortiGate starts dropping new sessions when the configured memory use threshold reaches red

  4. A FortiGate enters conserve mode when the configured memory use threshold reaches red




Answer: D


on: 25


wo configuration settings change the behavior for content-inspected traffic while FortiGate is in conser Choose two.)

ailopen failopen ailopen failopen


r: A,C


on: 26


the exhibit, which shows a FortiGate configuration.

Questi


Which t ve

mode? (

  1. IPS f

  2. mem

  3. AV f

  4. UTM


Answe Questi Refer to



ministrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filt nd applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the


ust the administrator change to fix the issue? dministrator must increase webfilter-timeout. dministrator must disable webfilter-force-off. dministrator must change protocol to TCP. dministrator must enable fortiguard-anycast.

An ad er

profile a policy.


What m

  1. The a

  2. The a

  3. The a

  4. The a




Answer: D
Explanation:

Reference: https://docs.fortinet.com/document/fortigate/6.4.5/cli-reference/109620/config-system-fortiguard



Question: 27


Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router. The second unit is elected as the backup designated router.

Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?

  1. 1

  2. 2

  3. 3

  4. 4


he exhibit, which contains a partial routing table, and then answer the question below.


ng all the appropriate firewall policies are configured, which of the following pings will FortiGate route two.)

rce IP address 10.1.0.24, Destination IP address 10.72.3.20. ce IP address 10.72.3.27, Destination IP address 10.1.0.52. ce IP address 10.72.3.52, Destination IP address 10.1.0.254. rce IP address 10.73.9.10, Destination IP address 10.72.3.15.


r: B,C


on: 29


ministrator has configured a FortiGate device with two VDOMs: root and internal. The administrator has



Answer:
B
Question: 28
View t


Assumi ?

(Choose

  1. Sou

  2. Sour

  3. Sour

  4. Sou


Answe


Questi


An ad also

created and inter-VDOM link that connects both VDOMs. The objective is to have each VDOM advertise some routes to the other VDOM via OSPF through the inter-VDOM link .


What OSPF configuration settings must match in both VDOMs to have the OSPF adjacency successfully forming? (Choose three.)

  1. Router ID.

  2. OSPF interface area.

  3. OSPF interface cost.

  4. OSPF interface MTU.

  5. Interface subnet mask.



Answer: B,D,E



Question: 30



dn’t the script make any changes to the managed device? mmands that start with the # sign are not executed.

cripts will add objects only if they are referenced by policies. mplete commands are ignored in CLI scripts.

Static routes can only be added using TCL scripts.


r: A ation:

help.fortinet.com/fmgr/50hlp/56/5-6- Manager_Admin_Guide/1000_Device%20Manager/2400_Scripts/1000_Script%20sa 0200_CLI%20scripts+.htm#Error_Messages


ence of FortiGate CLI commands, as you would type them at the command line. A comment line starts w sign (#). A comment line will not be executed.


on: 31


Examine the output of the ‘diagnose ips anomaly list’ command shown in the exhibit; then answer the question

An administrator has configured the following CLI script on FortiManager, which failed to apply any changes to the managed device after being executed.


Why di

  1. Co

  2. CLI s

  3. Inco D.


Answe Explan https://

2/Forti mples/


A sequ ith the

number


Questi


below.


Which I

  1. Tho

  2. Tho

  3. Tho

  4. Tho


Answe


Questi


What is

  1. Nu


    P addresses are included in the output of this command? se whose traffic matches a DoS policy.

    se whose traffic matches an IPS sensor.

    se whose traffic exceeded a threshold of a matching DoS policy. se whose traffic was detected as an anomaly by an IPS sensor.


    r: A


    on: 32


    Examine the following partial output from a sniffer command; then answer the question below.


    the meaning of the packets dropped counter at the end of the sniffer? mber of packets that didn’t match the sniffer filter.

  2. Number of total packets dropped by the FortiGate.

  3. Number of packets that matched the sniffer filter and were dropped by the FortiGate.

  4. Number of packets that matched the sniffer filter but could not be captured by the sniffer.




Answer: D
Explanation:

https://kb.fortinet.com/kb/documentLink.do?externalID=11655

Examine the following traffic log; then answer the question below.


date-20xx-02-01 time=19:52:01 devname=master device_id="xxxxxxx"


log_id=0100020007 type=event subtype=system pri critical vd=root service=kemel status=failure msg="NAT port is exhausted."


What does the log mean?

  1. There is not enough available memory in the system to create a new entry in the NAT port table.

  2. The limit for the maximum number of simultaneous sessions sharing the same NAT port has been reached.

    imit for the maximum number of entries in the NAT port table has been reached.


    r: B


    on: 34


    f the following statements are correct regarding application layer test commands? (Choose two.) are used to filter real-time debugs.

    display real-time application debugs.

    of them display statistics and configuration information about a feature or process. Some of them can be used to restart an application.


    r: C,D


    ation:


    ation layer test commands don’t display info in real time, but they do show statistics and configuration i feature or process. You can also use some of these commands to restart a process or execute a change i on.


    on: 35


    which two states is a given session categorized as ephemeral? (Choose two.) CP session waiting to complete the three-way handshake.

    CP session waiting for FIN ACK.

  3. FortiGate does not have any available NAT port for a new connection.

  4. The l


Answe


Questi


Which o

  1. They

  2. They

  3. Some D.


Answe


Explan


Applic nfo

about a n its

operati


Questi


In

  1. A T

  2. A T

  3. A UDP session with packets sent and received.

  4. A UDP session with only one packet received.




Answer: A,D



Question: 36


Which two statements about the Security Fabric are true? (Choose two.)

  1. Only the root FortiGate collects network information and forwards it to FortiAnalyzer.

  2. FortiGate uses FortiTelemetry protocol to communicate with FortiAnalyzer.

  3. All FortiGate devices in the Security Fabric must have bidirectional FortiTelemetry connectivity.

  4. Branch FortiGate devices must be configured first.




Answer: B,C
Explanation:

Reference: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/327890/deploying-security-fabric



Question: 37


ministrator wants to capture ESP traffic between two FortiGates using the built-in sniffer.


dministrator knows that there is no NAT device located between both FortiGates, what command should strator execute?

nose sniffer packet any ‘udp port 500’ nose sniffer packet any ‘udp port 4500’ nose sniffer packet any ‘esp’

nose sniffer packet any ‘udp port 500 or udp port 4500’


r: C ation:

IKE Traffic without NAT:diagnose sniffer packet ‘host and udp port

――――――――――――――――――――――――――――――――――――-Capture ESP T NAT:diagnose sniffer packet any ‘host and

――――――――――――――――――――――――――――――――――――-Capture IKE a AT-T:diagnose sniffer packet any ‘host and (udp port 500 or udp port 4500)’


on: 38


he exhibit, which contains the output of get sys ha status, and then answer the question below.

An ad


If the a the

admini

  1. diag

  2. diag

  3. diag

  4. diag


Answe Explan Capture

500’― raffic

without

esp’― nd ESP

with N


Questi


View t


tatements are correct regarding the output? (Choose two.) lave configuration is not synchronized with the master.

A management IP is 169.254.0.2.

ter is selected because it is the only device in the cluster. 7 is used the HA heartbeat on all devices in the cluster.


r: A,D


on: 39


Examine the IPsec configuration shown in the exhibit; then answer the question below.


Which s

  1. The s

  2. The H

  3. Mas

  4. port


Answe


Questi


An ad



ministrator wants to monitor the VPN by enabling the IKE real time debug using these commands: diagnose vpn ike log-filter src-addr4 10.0.10.1

diagnose debug application ike -1 diagnose debug enable

N is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged betwee ateways. However, the IKE real time debug does NOT show any output .

The VP n both

IPsec g


Why isn’t there any output?

  1. The IKE real time shows the phases 1 and 2 negotiations only. It does not show any more output once the tunnel is up.

  2. The log-filter setting is set incorrectly. The VPN’s traffic does not match this filter.

  3. The IKE real time debug shows the phase 1 negotiation only. For information after that, the administrator must use the IPsec real time debug instead: diagnose debug application ipsec -1.

  4. The IKE real time debug shows error messages only. If it does not provide any output, it indicates that the tunnel is operating normally.




Answer: B

Which statement about NGFW policy-based application filtering is true?

  1. After the application has been identified, the kernel uses only the Layer 4 header to match the traffic.

  2. The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT.

  3. After IPS identifies the application, it adds an entry to a dynamic ISDB table.

  4. FortiGate will drop all packets until the application can be identified.




Answer: D