Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Fortinet NSE 7 - Enterprise Firewall 7.2 Question and Answers

Fortinet NSE 7 - Enterprise Firewall 7.2

Last Update May 18, 2024
Total Questions : 50

We are offering FREE NSE7_EFW-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE7_EFW-7.2 free exam questions and then go for complete pool of Fortinet NSE 7 - Enterprise Firewall 7.2 test questions that will help you more.

NSE7_EFW-7.2 pdf

NSE7_EFW-7.2 PDF

$35  $99.99
NSE7_EFW-7.2 Engine

NSE7_EFW-7.2 Testing Engine

$42  $119.99
NSE7_EFW-7.2 PDF + Engine

NSE7_EFW-7.2 PDF + Testing Engine

$56  $159.99
Questions 1

Which two statements about the neighbor-group command are true? (Choose two.)

Options:

A.  

You can configure it on the GUI.

B.  

It applies common settings in an OSPF area.

C.  

It is combined with the neighbor-range parameter.

D.  

You can apply it in Internal BGP (IBGP) and External BGP (EBGP).

Discussion 0
Questions 2

Exhibit.

Refer to the exhibit, which shows an ADVPN network.

The client behind Spoke-1 generates traffic to the device located behind Spoke-2.

Which first message floes the hub send to Spoke-110 bring up the dynamic tunnel?

Options:

A.  

Shortcut query

B.  

Shortcut reply

C.  

Shortcut offer

D.  

Shortcut forward

Discussion 0
Questions 3

Refer to the exhibit, which shows config system central-management information.

Which setting must you configure for the web filtering feature to function?

Options:

A.  

Add server. fortiguard. net to the server list.

B.  

Configure securewf.fortiguard. net on the default servers.

C.  

Set update-server-location to automatic.

D.  

Configure server-type with the rating option.

Discussion 0
Questions 4

Which two statements about the BFD parameter in BGP are true? (Choose two.)

Options:

A.  

It allows failure detection in less than one second.

B.  

The two routers must be connected to the same subnet.

C.  

It is supported for neighbors over multiple hops.

D.  

It detects only two-way failures.

Discussion 0
Questions 5

Refer to the exhibit, which contains a partial BGP combination.

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

Options:

A.  

ebgp-enforce-multihop

B.  

recursive-next-hop

C.  

ibgp-enfoce-multihop

D.  

update-source

Discussion 0
Questions 6

Refer to the exhibit, which shows a routing table.

What two options can you configure in OSPF to block the advertisement of the 10.1.10.0 prefix? (Choose two.)

Options:

A.  

Remove the 16.1.10.C prefix from the OSPF network

B.  

Configure a distribute-list-out

C.  

Configure a route-map out

D.  

Disable Redistribute Connected

Discussion 0
Questions 7

Which two statements about bfd are true? (Choose two)

Options:

A.  

It can support neighbor only over the next hop in BGP

B.  

You can disable it at the protocol level

C.  

It works for OSPF and BGP

D.  

You must configure n globally only

Discussion 0
Questions 8

Exhibit.

Refer to the exhibit, which contains a CLI script configuration on fortiManager. An administrator configured the CLI script on FortiManager rut the script tailed to apply any changes to the managed

device after being executed.

What are two reasons why the script did not make any changes to the managed device? (Choose two)

Options:

A.  

The commands that start with the # sign did not run.

B.  

Incomplete commands can cause CLI scripts to fail.

C.  

Static routes can be added using only TCI scripts.

D.  

CLI scripts must start with #!.

Discussion 0
Questions 9

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

Options:

A.  

FortiManager provides FortiGuard.

B.  

fortiguard-anycast is set to enable.

C.  

You do not have the corresponding write access.

D.  

udp is not a protocol option.

Discussion 0
Questions 10

Exhibit.

Refer to the exhibit, which provides information on BGP neighbors.

Which can you conclude from this command output?

Options:

A.  

The router are in the number to match the remote peer.

B.  

You must change the AS number to match the remote peer.

C.  

BGP is attempting to establish a TCP connection with the BGP peer.

D.  

The bfd configuration to set to enable.

Discussion 0
Questions 11

Which, three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)

Options:

A.  

OSPF interface network types match

B.  

OSPF router IDs are unique

C.  

OSPF interface priority settings are unique

D.  

OSPF link costs match

E.  

Authentication settings match

Discussion 0
Questions 12

Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

Options:

A.  

Enable AD-VPN in IPsec phase 1

B.  

Disable add-route on hub

C.  

Configure IP addresses on IPsec virtual interlaces

D.  

Set protected network to all

Discussion 0
Questions 13

Exhibit.

Refer to the exhibit, which shows information about an OSPF interlace

What two conclusions can you draw from this command output? (Choose two.)

Options:

A.  

The port3 network has more man one OSPF router

B.  

The OSPF routers are in the area ID of 0.0.0.1.

C.  

The interfaces of the OSPF routers match the MTU value that is configured as 1500.

D.  

NGFW-1 is the designated router

Discussion 0
Questions 14

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel however, the VPN interfaces do not appear as available options.

Options:

A.  

Create interface mappings for the IPsec VPN interfaces before you use them in a policy.

B.  

Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces

C.  

Configure the phase 1 settings in the VPN community that you didnt initially configure. FortiGate automatically generates the interfaces after you configure the required settings

D.  

install the VPN community and gateway configuration on the fortiGate devices so that the VPN interfaces appear on the Policy Objects on fortiManager.

Discussion 0
Questions 15

Exhibit.

Refer to the exhibit, which contains the partial ADVPN configuration of a spoke.

Which two parameters must you configure on the corresponding single hub? (Choose two.)

Options:

A.  

Set auto-discovery-sender enable

B.  

Set ike-version 2

C.  

Set auto-discovery-forwarder enable

D.  

Set auto-discovery-receiver enable

Discussion 0