Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.2 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit, which shows an ADVPN network,

Question # 11

An administrator must configure an ADVPN using IBGP and EBGP to connect

overlay network 1 with 2.

What must the administrator configure in the phase 1 VPN IPSEC configuration

of the Hub2¢ub tunnels?

Options:

A.

set auto-discovery-sender enable


B.

set auto-discovery-forwarder enable


C.

set add-route enable


D.

set auto-discovery-receiver enable


Expert Solution
Questions # 12:

Which FortiGate in a Security I auric sends togs to FortiAnalyzer?

Options:

A.

Only the root FortiGate.


B.

Each FortiGate in the Security fabric.


C.

The FortiGate devices performing network address translation (NAT) or unified threat management (UTM). if configured.


D.

Only the last FortiGate that handled a session in the Security Fabric


Expert Solution
Questions # 13:

Which two statements about IKE version 2 fragmentation are true? (Choose two.)

Options:

A.

Only some IKE version 2 packets are considered fragmentable.


B.

The reassembly timeout default value is 30 seconds.


C.

It is performed at the IP layer.


D.

The maximum number of IKE version 2 fragments is 128.


Expert Solution
Questions # 14:

Refer to the exhibit, which shows an OSPF network.

Question # 14

Which types of ink-state advertisements (LSA) will NGFW-1 send, if itis a backup designated router (BDR)?

Options:

A.

ONGFW-1 will send type 1 and type 2 LSAs.


B.

NGFW-1 will send type 1and type 3 LSA.


C.

ONGFW-1 will send type 1 and type 4 LSA.


D.

ONGFW-1 will send type 1and type 5 LSA.


Expert Solution
Questions # 15:

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel however, the VPN interfaces do not appear as available options.

Options:

A.

Create interface mappings for the IPsec VPN interfaces before you use them in a policy.


B.

Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces


C.

Configure the phase 1 settings in the VPN community that you didnt initially configure. FortiGate automatically generates the interfaces after you configure the required settings


D.

install the VPN community and gateway configuration on the fortiGate devices so that the VPN interfaces appear on the Policy Objects on fortiManager.


Expert Solution
Questions # 16:

Refer to the exhibit, which shows an ADVPN network.

Question # 16

Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

Options:

A.

set auto-discovery-forwarder enable


B.

set add-route enable


C.

set auto-discovery-receiver enable


D.

set auto-discovery-sender enable


Expert Solution
Questions # 17:

Exhibit.

Question # 17

Refer to the exhibit, which shows an ADVPN network.

The client behind Spoke-1 generates traffic to the device located behind Spoke-2.

Which first message floes the hub send to Spoke-110 bring up the dynamic tunnel?

Options:

A.

Shortcut query


B.

Shortcut reply


C.

Shortcut offer


D.

Shortcut forward


Expert Solution
Questions # 18:

Which two statements about the Security fabric are true? (Choose two.)

Options:

A.

FortiGate uses the FortiTelemetry protocol to communicate with FortiAnatyzer.


B.

Only the root FortiGate sends logs to FortiAnalyzer


C.

Only FortiGate devices with configuration-sync receive and synchronize global CMDB objects that the toot FortiGate sends


D.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer


Expert Solution
Questions # 19:

Refer to the exhibit, which shows a network diagram.

Question # 19

Which protocol should you use to configure the FortiGate cluster?

Options:

A.

FGCP in active-passive mode


B.

FGSP


C.

VRRP


D.

FGCP in active-active mode


Expert Solution
Questions # 20:

Exhibit.

Question # 20

Refer to the exhibit, which shows the output from the webfilter fortiguard cache dump and webfilter categories commands.

Using the output, how can an administrator determine the category of the training.fortinet.com am website?

Options:

A.

The administrator must convert the first three digits of the IP hex value to binary


B.

The administrator can look up the hex value of 34 in the second command output.


C.

The administrator must add both the Pima in and Iphex values of 34 to get the category number


D.

The administrator must convert the first two digits of the Domain hex value to a decimal value


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions