Pass the Fortinet NSE 7 Network Security Architect NSE7_LED-7.0 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Question # 11

Wireless guest users are unable to authenticate because they are getting a certificate error while loading the captive portal login page. This URL string is the HTTPS POST URL guest wireless users see when attempting to access the network using the web browser

Question # 11

Which two settings are the likely causes of the issue? (Choose two.)

Options:

A.

The external server FQDN is incorrect


B.

The wireless user's browser is missing a CA certificate


C.

The FortiGate authentication interface address is using HTTPS


D.

The user address is not in DDNS form


Expert Solution
Questions # 12:

An administrator is deploying a new FortiGate device using zero-touch provisioning. Before deployment, the administrator added the FortiGate serial number on FortiManager and configured all the FortiGate settings FortiGate has a factory default configuration. However, when the administrator connects FortiGate to the network, FortiManager does not start the installation automatically. Which two scenarios are likely to cause this issue? (Choose two.)

Options:

A.

The serial number added on FortiManager does not match the FortiGate serial number.


B.

The DHCP server that serves FortiGate is not configured with options 240 and 241.


C.

Zero-touch provisioning is disabled on FortiManager.


D.

The pre-shared key set on FortiManager does not match the one set on FortiGate.


Expert Solution
Questions # 13:

Which three protocols are used for controlling FortiSwitch devices on FortiGate? (Choose three.)

Options:

A.

HTTPS


B.

CAPWAP


C.

IGMP


D.

FTP


E.

FortiLink


Expert Solution
Questions # 14:

Where can FortiGate learn the FortiManager IP address or FQDN for zero-touch provisioning'?

Options:

A.

From an LDAP server using a simple bind operation


B.

From a TFTP server


C.

From a DHCP server using options 240 and 241


D.

From a DNS server using A or AAAA records


Expert Solution
Questions # 15:

An administrator is deploying AP's that are connecting over an IPsec network. All APs have been configured to connect to FortiGate manually. FortiGate can discover the APs and authorize them. However, FortiGate is unable to establish CAPWAP tunnels to manage the APs.

Which configuration setting can the administrator perform to resolve the problem?

Options:

A.

Upgrade the FortiAP firmware image to ensure compatibility with the FortiOS version.


B.

Decrease the CAPWAP tunnel MTU size for APs to prevent fragmentation.


C.

Enable CAPWAP administrative access on the IPsec interface.


D.

Assign a custom AP profile for the remote APs with the set mpls-connection option enabled.


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

Examine the partial debug output shown in the exhibit.

Question # 16

Which two statements about the debug output are true? (Choose1 two.)

Options:

A.

The LDAP DN search did not match any LDAP user.


B.

The credentials provided for student are correct.


C.

The Training-Lab LDAP server is configured to use regular bind.


D.

The connection to the Training-Lab LDAP server timed out.


Expert Solution
Questions # 17:

Which FortiSwitch VLANs are automatically created on FortGate when the first FortiSwitch device is discovered1?

Options:

A.

default quarantine, rspan voice video onboarding and nac_segment


B.

access, quarantine, rspan. voice, video, and onboarding


C.

default quarantine rspan voice video and nac_segment


D.

fortilink. quarantine erspan voice video and onboarding


Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

Examine the FortiManager configuration and FortiGate CLI output shown in the exhibit

An administrator is testing the NAC feature The test device is connected to a managed FortiSwitch device {S224EPTF19"53€7)onport2

After applying the NAC policy on port2 and generating traffic on the test device the test device is not matching the NAC policy therefore the test device remains m the onboarding VLAN

Based on the information shown in the exhibit which two scenarios are likely to cause this issue? (Choose two.)

Options:

A.

Management communication between FortiGate and FortiSwitch is down


B.

The MAC address configured on the NAC policy is incorrect


C.

The device operating system detected by FortiGate is not Linux


D.

Device detection is not enabled on VLAN 4089


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions