NSE7_EFW-7.2 Exam Questions
102 real NSE7_EFW-7.2 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1
Refer to the exhibit, which contains a TCL script configuration on FortiManager. An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply...
- Question #2FortiGate Advanced Routing and VPN
You want to improve reliability over a lossy IPSec tunnel. Which combination of IPSec phase 1 parameters should you configure?
IPsec FECforward error correctionlossy tunnelphase 1 - Question #3
How are bulk configuration changes made using FortiManager CLI scripts? (Choose two.)
- Question #4Traffic Management and QoS
Refer to the exhibit, which contains a partial configuration of the global system. What can you conclude from this output?
NP offloadCP offloadhardware accelerationglobal settings - Question #5Advanced Security Features
Refer to the exhibits, which show the configurations of two address objects from the same FortiGate. Engineering address object Finance address object Why can you modify the Engine...
Security Fabricaddress objectFortiManagerworkspace mode - Question #6
Which two statements about the neighbor-group command are true? (Choose two.)
- Question #7FortiGate Advanced Routing and VPN
Refer to the exhibit, which contains information about an IPsec VPN tunnel. What two conclusions can you draw from the command output? (Choose two.)
IPsec SAIKEv2kernel SAVPN diagnostics - Question #8FortiGate Advanced Routing and VPN
Which two statements about IKE version 2 fragmentation are true? (Choose two.)
IKEv2 fragmentationIP fragmentationfragment reassemblyIKE packets - Question #9High Availability and Redundancy
An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to s...
HA failoverGARPlink-failed-signalswitch flooding - Question #10FortiGate Advanced Routing and VPN
Refer to the exhibit, which shows the output of a BGP summary. What two conclusions can you draw from this BGP summary? (Choose two.)
BGP summaryEBGPBFDneighbor-range - Question #11
Refer to the exhibit, which shows a custom signature. Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Ch...
- Question #12
What are two functions of automation stitches? (Choose two.)
- Question #13Advanced Security Features
Refer to the exhibit which shows config system central-management information. Which setting must you configure for the web filtering feature to function?
central managementweb filteringFortiGuardserver-type rating - Question #14
Which two statements about the Security Fabric are true? (Choose two.)
- Question #15FortiGate High Availability (HA)
Refer to the exhibit which shows two configured FortiGate devices and peering over FGSP. The main link directly connects the two FortiGate devices and is configured using the set s...
FGSPsession synchronizationmain linklayer 2 - Question #16
Refer to the exhibit, which shows a network diagram. Which protocol should you use to configure the FortiGate cluster?
- Question #17FortiGate Security Features
After enabling IPS, you receive feedback about traffic being dropped. What could be the reason?
IPSfail-opentraffic dropinspection mode - Question #18
Refer to the exhibit which shows an ADVPN network. Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)
- Question #19FortiGate System and Session Management
Which two statements about metadata variables are true? (Choose two.)
metadata variablesscriptingautomationFortiManager - Question #20FortiGate VPN
Refer to the exhibits, which contain the network topology and BGP configuration for a hub. Exhibit A. Exhibit B. An administrator is trying to configure ADVPN with a hub and spoke...
ADVPNiBGProute reflectorhub-and-spoke - Question #21FortiGate VPN
Refer to the exhibit, which contains a partial VPN configuration. What can you conclude from this configuration?
dial-up VPNIPsec virtual interfacerouting tabledynamic routing - Question #22FortiGate Routing
Refer to the exhibit which shows information about an OSPF interface. What two conclusions can you draw from this command output? (Choose two.)
OSPFdesignated routerMTUmulti-access network - Question #23FortiGate Routing
Which two statements about the BFD parameter in BGP are true? (Choose two.)
BFDBGPfailure detectionmultihop - Question #24FortiGate VPN
You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over t...
FortiManagerVPN communityIPsec interface mappingpolicy configuration - Question #25FortiGuard
Refer to the exhibit, which shows a central management configuration. Which server will FortiGate choose for web filter rating requests, if 10.0.1.240 is experiencing an outage?
FortiGuardweb filter ratingserver failovercentral management - Question #26FortiGate Routing
Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?
OSPFDRBDRmulti-access network - Question #27
Refer to the exhibit, which contains a partial policy configuration. Which setting must you configure to allow SSH?
- Question #28FortiGate Security Features
Refer to the exhibit, which shows an SSL certification inspection configuration. Which action does FortiGate take if the server name indication (SNI) does not match either the comm...
SSL inspectionSNIcertificate CNSAN - Question #29FortiGate Routing
Refer to the exhibit, which contains a partial OSPF configuration. What can you conclude from this output?
OSPF graceful restartgrace LSAhelper modetopology change - Question #30FortiGate VPN
Refer to the exhibit, which contains an ADVPN network diagram and a partial BGP configuration. Network diagram Partial BGP configuration Which two parameters should you configure i...
ADVPNBGP neighbor-rangeneighbor-groupspoke routing - Question #31
You want to have faster detection for OSPF. Which parameter should you enable on both connected FortiGate devices?
- Question #32FortiGate Routing
Refer to the exhibit, which provides information on BGP neighbors. What can you conclude from this command output?
BGPTCP connectionneighbor stateidle state - Question #33
Which two statements about ADVPN are true? (Choose two.)
- Question #34
Which statement about network processor (NP) offloading is true?
- Question #35FortiGuard
Refer to the exhibit, which shows an error in system fortiguard configuration. What is the reason you cannot set the protocol to udp in config system fortiguard?
FortiGuard anycastprotocol restrictionUDPsystem fortiguard - Question #36FortiGate Routing
Which, three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)
OSPF adjacencynetwork typeauthenticationrouter ID - Question #37FortiGate VPN
Refer to the exhibit, which shows a network diagram. Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?
IPsec phase 2route-overlapdial-up VPNsingle connection - Question #38FortiGate Routing
You want to configure faster failure detection for BGP. Which parameter should you enable on both connected FortiGate devices?
BFDBGPfailure detectionfast convergence - Question #39FortiGuard
Refer to the exhibit, which shows the output from the webfilter fortiguard cache dump and webfilter categories commands. Using the output, how can an administrator determine the ca...
FortiGuard cacheweb filter categorieshex conversioncache dump - Question #40FortiGate Routing
Which two statements about bfd are true? (Choose two)
BFDOSPFBGPprotocol-level configuration - Question #41FortiGate VPN
Winch two statements about ADVPN are true? (Choose two)
ADVPNauto-discovery-receiverspoke configurationon-demand tunnels - Question #42FortiGate Routing
Refer to the exhibit, which contains a partial BGP combination. You want to configure a loopback as the OGP source. Which two parameters must you set in the BGP configuration? (Cho...
BGPloopback sourceebgp-enforce-multihopupdate-source - Question #43
Refer to the exhibit, which shows a partial web filter profile conjuration. categorized as Social Networking?
- Question #44FortiGuard
In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)
FortiManagerlocal FDSupdate serverVM license validation - Question #45FortiGate Routing
Refer to the exhibit, which shows a routing table. What two options can you configure in OSPF to block the advertisement of the 10.1.10.0 prefix? (Choose two.)
OSPFroute advertisementdistribute-list-outredistribute connected - Question #46FortiGate VPN
Refer to the exhibit, which shows a partial touting table. What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)
IPSecnet-deviceadd-routerouting table analysis - Question #47FortiGate VPN
Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?
ADVPNFortiManager VPN ManagerIPSec phase 1CLI script - Question #48FortiGate Security Features
You want to block access to the website ww.eicar.org using a custom IPS signature. Which custom IPS signature should you configure?
custom IPS signatureHTTPflow directionpattern matching - Question #49FortiGate VPN
Refer to the exhibit, which shows an ADVPN network. The client behind Spoke-1 generates traffic to the device located behind Spoke-2. Which first message does the hub send to Spoke...
ADVPNshortcut offerhub-spokedynamic tunnel establishment - Question #50FortiGate VPN
Refer to the exhibit, which contains a partial VPN configuration. What can you conclude from this configuration1?
IPSec dial-upvirtual interfacenet-devicerouting table