Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.2 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?

Options:

A.

Only the DR receives link state information from non-DR routers.


B.

Non-DR and non-BDR routers form full adjacencies to DR only.


C.

FortiGate first checks the OSPF ID to elect a DR.


D.

Non-DR and non-BDR routers send link state updates and acknowledgements to 224.0.0.6.


Expert Solution
Questions # 22:

Refer to the exhibit, which shows a partial routing table.

Question # 22

What two conclusions can you draw from the FortiGate output shown in the

exhibit? (Choose two.)

Options:

A.

FortiGate creates separate virtual interfaces for each VPN client.


B.

add-route is enabled in the tunnel IPSec phase 1 configuration.


C.

FortiGate is not using the destination subnets of the quick mode selectors to

populate the routing table.


D.

net-device is disabled in the tunnel IPSec phase 1 configuration.


Expert Solution
Questions # 23:

Exhibit.

Question # 23

Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.

Which two conclusions can you draw from this con figuration? (Choose two)

Options:

A.

10.1.5.254 is the default gateway of the internal network


B.

On failover new primary device uses the same MAC address as the old primary


C.

The VRRP domain uses the physical MAC address of the primary FortiGate


D.

By default FortiGate B is the primary virtual router


Expert Solution
Questions # 24:

Exhibit.

Question # 24

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

Options:

A.

FortiGate creates separate virtual interfaces for each dial up client.


B.

The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.


C.

Dead peer detection s disabled.


D.

The routing table shows a single IPSec virtual interface.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions