Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Fortinet NSE 7 - LAN Edge 7.0 Question and Answers

Fortinet NSE 7 - LAN Edge 7.0

Last Update May 18, 2024
Total Questions : 37

We are offering FREE NSE7_LED-7.0 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE7_LED-7.0 free exam questions and then go for complete pool of Fortinet NSE 7 - LAN Edge 7.0 test questions that will help you more.

NSE7_LED-7.0 pdf

NSE7_LED-7.0 PDF

$35  $99.99
NSE7_LED-7.0 Engine

NSE7_LED-7.0 Testing Engine

$42  $119.99
NSE7_LED-7.0 PDF + Engine

NSE7_LED-7.0 PDF + Testing Engine

$56  $159.99
Questions 1

Which two statements about the MAC-based 802 1X security mode available on FortiSwitch are true? (Choose two.)

Options:

A.  

FortiSwitch authenticates a single device and opens the port to other devices connected to the port

B.  

FortiSwitch authenticates each device connected to the port

C.  

It cannot be used in conjunction with MAC authentication bypass

D.  

FortiSwitch can grant different access levels to each device connected to the port

Discussion 0
Questions 2

You are investigating a report of poor wireless performance in a network that you manage. The issue is related to an AP interface in the 5 GHz range You are monitoring the channel utilization over time.

What is the recommended maximum utilization value that an interface should not exceed?

Options:

A.  

85%

B.  

95%

C.  

75%

D.  

65%

Discussion 0
Questions 3

Which two pieces of information can the diagnose test authserver ldap command provide? (Choose two.)

Options:

A.  

It displays whether the admin bind user credentials are correct

B.  

It displays whether the user credentials are correct

C.  

It displays the LDAP codes returned by the LDAP server

D.  

It displays the LDAP groups found for the user

Discussion 0
Questions 4

Which FortiSwitch VLANs are automatically created on FortGate when the first FortiSwitch device is discovered1?

Options:

A.  

default quarantine, rspan voice video onboarding and nac_segment

B.  

access, quarantine, rspan. voice, video, and onboarding

C.  

default quarantine rspan voice video and nac_segment

D.  

fortilink. quarantine erspan voice video and onboarding

Discussion 0
Questions 5

Refer to the exhibits

The exhibits show the wireless network (VAP) SSID profiles defined on FortiManager and an AP profile assigned to a group of APs that are supported by FortiGate

None of the APs are broadcasting the SSlDs defined by the AP profile

Which changes do you need to make to enable the SSIDs to broadcast?

Options:

A.  

In the SSIDs section enable Tunnel

B.  

Enable one channel in the Channels section

C.  

Enable multiple channels in the Channels section and enable Radio Resource Provision

D.  

In the SSIDs section enable Manual and assign the networks manually

Discussion 0
Questions 6

Refer to the exhibits.

Firewall Policy

Examine the firewall policy configuration and SSID settings

An administrator has configured a guest wireless network on FortiGate using the external captive portal The administrator has verified that the external captive portal URL is correct However wireless users are not able to see the captive portal login page

Given the configuration shown in the exhibit and the SSID settings which configuration change should the administrator make to fix the problem?

Options:

A.  

Disable the user group from the SSID configuration

B.  

Enable the captivs-portal-exempt option in the firewall policy with the ID 11.

C.  

Apply a guest.portal user group in the firewall policy with the ID 11.

D.  

Include the wireless client subnet range in the Exempt Source section

Discussion 0
Questions 7

Refer to the exhibit.

By default FortiOS creates the following DHCP server scope for the FortiLink interface as shown in the exhibit

What is the objective of the vci-string setting?

Options:

A.  

To ignore DHCP requests coming from FortiSwitch and FortiExtender devices

B.  

To reserve IP addresses for FortiSwitch and FortiExtender devices

C.  

To restrict the IP address assignment to FortiSwitch and FortiExtender devices

D.  

To restrict the IP address assignment to devices that have FortiSwitch or FortiExtender as their hostname

Discussion 0
Questions 8

Refer to the exhibit.

Examine the FortiManager configuration and FortiGate CLI output shown in the exhibit

An administrator is testing the NAC feature The test device is connected to a managed FortiSwitch device {S224EPTF19"53€7)onpOrt2

After applying the NAC policy on port2 and generating traffic on the test device the test device is not matching the NAC policy therefore the test device remains m the onboarding VLAN

Based on the information shown in the exhibit which two scenarios are likely to cause this issue? (Choose two.)

Options:

A.  

Management communication between FortiGate and FortiSwitch is down

B.  

The MAC address configured on the NAC policy is incorrect

C.  

The device operating system detected by FortiGate is not Linux

D.  

Device detection is not enabled on VLAN 4089

Discussion 0
Questions 9

Refer to the exhibit.

Examine the debug output shown in the exhibit

Which two statements about the RADIUS debug output are true'' (Choose two)

Options:

A.  

The user student belongs to the SSLVPN group

B.  

User authentication failed

C.  

The RADIUS server sent a vendor-specific attribute in the RADIUS response

D.  

User authentication succeeded using MSCHAP

Discussion 0
Questions 10

An administrator has configured an SSID in bridge mode for corporate employees All APs are online and provisioned using default AP profiles Employees are unable to locate the SSID to conned

Which two configurations can the administrator verify? (Choose two)

Options:

A.  

Verify that the broadcast SSID option is enabled in the SSID configuration

B.  

Verify that the Block Intra-SSID Traffic (intra-vap-privacy) option in the SSID configuration is disabled

C.  

Verify that the SSID to an AP group that should be broadcasting the SSID is applied

D.  

Verify that the SSID is manually applied on AP profiles for both 2 4 GHz and 5 GHz radios

Discussion 0
Questions 11

Refer to the exhibit

A device connected to port2 on FortiSwitch cannot access the network The port is assigned a security policy to enforce 802 1X authentication While troubleshooting the issue, the administrator obtains the debug output shown in the exhibit

Which two scenarios are likely to cause this issue? (Choose two.)

Options:

A.  

The device is not configured for 802 IX authentication.

B.  

The device has been quarantined for 3600 seconds.

C.  

The device has been assigned the guest VLAN

D.  

The device does not support 802 1X authentication

Discussion 0