Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.2 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit, which contains a TCL script configuration on FortiManager.

Question # 1

An administrator has configured the TCL script on FortiManager, but the TCL script failed

to apply any changes to the managed device after being run.

Why did the TCL script fail to make any changes to the managed device?

Options:

A.

The TCL procedure run_cmd has not been created.


B.

The TCL script must start with #include.


C.

There is no corresponding #! to signify the end of the script.


D.

The TCL procedure lacks the required loop statements to iterate through the changes.


Expert Solution
Questions # 2:

Which two statements about the neighbor-group command are true? (Choose two.)

Options:

A.

You can configure it on the GUI.


B.

It applies common settings in an OSPF area.


C.

It is combined with the neighbor-range parameter.


D.

You can apply it in Internal BGP (IBGP) and External BGP (EBGP).


Expert Solution
Questions # 3:

In which two ways does FortiManager function when it is deployed as a local FDS? (Choose two.)

Options:

A.

It caches available firmware updates for both managed and unmanaged devices


B.

It can be configured as an update server a rating server or both


C.

It functions as rating server only for web filtering and antispam services


D.

It downloads license information for registered and unregistered devices


Expert Solution
Questions # 4:

Exhibit.

Question # 4

Refer to the exhibit, which contains a partial policy configuration.

Which setting must you configure to allow SSH?

Options:

A.

Specify SSH in the Service field


B.

Configure pot 22 in the Protocol Options field.


C.

Include SSH in the Application field


D.

Select an application control profile corresponding to SSH in the Security Profiles section


Expert Solution
Questions # 5:

Refer to the exhibit, which shows two configured FortiGate devices and peering over FGSP.

Question # 5

The main link directly connects the two FortiGate devices and is configured using the set

session-syn-dev command.

What is the primary reason to configure the main link?

Options:

A.

To have both sessions and configuration synchronization in layer 2


B.

To load balance both sessions and configuration synchronization between layer 2 and 3


C.

To have only configuration synchronization in layer 3


D.

To have both sessions and configuration synchronization in layer 3


Expert Solution
Questions # 6:

In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)

Options:

A.

lt can be configured as an update server a rating server or both


B.

It provides VM license validation services


C.

It supports rating requests from non-FortiGate devices.


D.

It caches available firmware updates for unmanaged devices


Expert Solution
Questions # 7:

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A)

Question # 7

B)

Question # 7

C)

Question # 7

D)

Question # 7

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 8:

Refer to the exhibit, which contains a partial configuration of the global system.

Question # 8

What can you conclude from the output?

Options:

A.

set strict-d^rty-session-check enable command instructs the FortiGate to offload all dirty session traffic to its SPU


B.

set check-protocol-header loose command enables hardware acceleration on this FortiGate device.


C.

set av-failopen pass command instructs the FortiGate to offload all traffic that uses the antivirus proxy to NP.


D.

set memory-use-threshoId-extreme command instructs the FortiGate to disable hardware acceleration if the memory extreme threshold reaches 95%


Expert Solution
Questions # 9:

Exhibit.

Question # 9

Question # 9

Refer to the exhibit, which contains an ADVPN network diagram and a partial BGP con figuration Which two parameters Should you configure in config neighbor range? (Choose two.)

Options:

A.

set prefix 172.16.1.0 255.255.255.0


B.

set route reflector-client enable


C.

set neighbor-group advpn


D.

set prefix 10.1.0 255.255.254.0


Expert Solution
Questions # 10:

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

Options:

A.

fec-ingress and fec-egress


B.

Odpd and dpd-retryinterval


C.

fragmentation and fragmentation-mtu


D.

keepalive and keylive


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions