Pass the Fortinet NSE 7 Network Security Architect NSE7_LED-7.0 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Examine the FortiGate configuration FortiAnalyzer logs and FortiGate widget shown in the exhibit

An administrator is testing the Security Fabric quarantine automation The administrator added FortiAnalyzer to the Security Fabric and configured an automation stitch to automatically quarantine compromised devices The test device (::.:.:.!) s connected to a managed Fort Switch dev :e

After trying to access a malicious website from the test device, the administrator verifies that FortiAnalyzer has a log (or the test connection However the device is not getting quarantined by FortiGate as shown in the quarantine widget

Which two scenarios are likely to cause this issue? (Choose two)

Options:

A.

The web filtering rating service is not working


B.

FortiAnalyzer does not have a valid threat detection services license


C.

The device does not have FortiClient installed


D.

FortiAnalyzer does not consider the malicious website an indicator of compromise (IOC)


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

Examine the FortiSwitch security policy shown in the exhibit.

A device that does not support 802.1X authentication is connected to a port using the Port-Security security policy.

What action does the FortiSwitch take on the port?

Options:

A.

FortiSwitch assigns the port to the onboarding VLAN.


B.

FortiSwitch shuts down the port.


C.

FortiSwitch assigns the port to the quarantine VLAN.


D.

FortiSwitch authenticates the device using the device MAC address as username and password.


Expert Solution
Questions # 3:

A wireless network in a school provides guest access using a captive portal to allow unregistered users to self-register and access the network The administrator is requested to update the existing configuration to provide captive portal authentication through a secure connection (HTTPS)

Which two changes must the administrator make to enforce HTTPS authentication"? (Choose two >

Options:

A.

Create a new SSID with the HTTPS captive portal URL


B.

Enable HTTP redirect in the user authentication settings


C.

Disable HTTP administrative access on the guest SSID to enforce HTTPS connection


D.

Update the captive portal URL to use HTTPS on FortiGate and FortiAuthenticator


Expert Solution
Questions # 4:

Refer to the exhibits.

Question # 4

The CLI output shows a FortiGate configuration supporting a remote AP in an employee's home. The employee requires access to resources located on the company network, including the database server and AD server. The employee is trying to print to a printer connected in their home, but is not able to.

Which two solutions would resolve the issue? (Choose two.)

Options:

A.

Configure the EmployeeHome VAP profile for local bridging using the command set local-bridging enable.


B.

Configure the EmployeeHome VAP profile to disable host isolation using the command set intra-vap-privacy disable.


C.

Configure the FAPU431F-EmployeeHome WTP profile to enable split tunneling to the AP subnet using the command set split-tunneling-acl-local-ap-subnet enable.


D.

Configure the FARU431F-EmployeeHome wtp-profile to add a split tunneling ACL with a destination subnet of 192.168.1.1/24, using the command set dest-ip 192.168.1.1/24.


Expert Solution
Questions # 5:

Which statement correctly describes the guest portal behavior on FortiAuthenticator?

Options:

A.

FortiAuthenticator uses POST parameters and a RADIUS client configuration to map the request to a guest portal for authentication.


B.

Sponsored accounts cannot authenticate using guest portals.


C.

All self-registered and sponsored accounts are listed on the local Users GUI page on FortiAuthenticator.


D.

All guest accounts must be activated using SMS or email activation codes.


Expert Solution
Questions # 6:

Exhibit.

Question # 6

Refer to the exhibit showing a network topology and SSID settings.

FortiGate is configured to use an external captive portal However wireless users are not able to see the captive portal login page

Which configuration change should the administrator make to fix the problem?

Options:

A.

Enable NAT in the firewall policy with the ID 13.


B.

Add the FortiAuthenticator and WindowsAD address objects as exempt destinations services


C.

Enable the captive-portal-exempt option in the firewall policy with the ID 12


D.

Remove the guest.portal user group in the firewall policy with the ID 12


Expert Solution
Questions # 7:

Which two statements about the MAC-based 802 1X security mode available on FortiSwitch are true? (Choose two.)

Options:

A.

FortiSwitch authenticates a single device and opens the port to other devices connected to the port


B.

FortiSwitch authenticates each device connected to the port


C.

It cannot be used in conjunction with MAC authentication bypass


D.

FortiSwitch can grant different access levels to each device connected to the port


Expert Solution
Questions # 8:

Refer to the exhibits.

Question # 8

Examine the debug output and the SSL VPN configuration shown in the exhibits.

Question # 8

An administrator has configured SSL VPN on FortiGate. To improve security, the administrator enabled Required Client Certificate on the SSL VPN configuration page. However, a user is unable to successfully authenticate to SSL VPN.

Which configuration change should the administrator make to fix the problem?

Options:

A.

Enable Redirect HTTP to SSL-VPN on the SSL VPN configuration page.


B.

Import the CA that signed the SSL VPN Server Certificate to FortiGate.


C.

Set the user certificate as the Server Certificate on the SSL VPN configuration page.


D.

Import the CA that signed the user certificate to FortiGate.


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

An administrator wants to telnet into the S224EPTF19005867 switch over the FortiGate FortiLink interface.

Which configuration change should the administrator make?

Options:

A.

Enable telnet access on the FortiLink interface.


B.

On the default local-access profile, add telnet to the list of allowed protocols for mgmt-allowaccess.


C.

On the default local-access profile, add telnet to the list of allowed protocols for internal-allowaccess.


D.

Factory reset the switch to enable telnet access.


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

Examine the FortiSwitch port configuration and the FortiGate interface configuration shown in the exhibit.

Question # 10

Based on the configuration shown in the exhibit, which two statements about how port2 handles tagged and untagged traffic are true? (Choose two.)

Options:

A.

Port2 accepts ingress untagged traffic for VLAN IDs 10, 4091, and 4093 only.


B.

Port2 assigns ingress untagged traffic to VLAN 10.


C.

Port2 tags egress traffic for VLAN 10.


D.

Port2 accepts ingress tagged traffic for VLAN IDs 4091 and 4093 only.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions