Certbus > Fortinet > Fortinet Certifications > NSE7_EFW-7.2 > NSE7_EFW-7.2 Online Practice Questions and Answers

NSE7_EFW-7.2 Online Practice Questions and Answers

Questions 4

Exhibit.

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

A. IPSec Tunnel aggregation is configured

B. net-device is enabled in the tunnel IPSec phase 1 configuration

C. OSPI is configured to run over IPSec.

D. add-route is disabled in the tunnel IPSec phase 1 configuration.

Browse 50 Q&As
Questions 5

Refer to the exhibit, which shows a custom signature.

Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Choose two.)

A. Add severity.

B. Add attack_id.

C. Ensure that the header syntax is F-SBID.

D. Start options with --.

Browse 50 Q&As
Questions 6

Which two statements about the neighbor-group command are true? (Choose two.)

A. You can configure it on the GUI.

B. It applies common settings in an OSPF area.

C. It is combined with the neighbor-range parameter.

D. You can apply it in Internal BGP (IBGP) and External BGP (EBGP).

Browse 50 Q&As
Questions 7

Winch two statements about ADVPN are true? (Choose two)

A. auto-discovery receiver must be set to enable on the Spokes.

B. Spoke to-spoke traffic never goes through the hub

C. lt supports NAI for on-demand tunnels

D. Routing is configured by enabling add-advpn-route

Browse 50 Q&As
Questions 8

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

A. FortiManager provides FortiGuard.

B. fortiguard-anycast is set to enable.

C. You do not have the corresponding write access.

D. udp is not a protocol option.

Browse 50 Q&As
Questions 9

You want to configure faster failure detection for BGP

Which parameter should you enable on both connected FortiGate devices?

A. Ebgp-enforce-multihop

B. bfd

C. Distribute-list-in

D. Graceful-restart

Browse 50 Q&As
Questions 10

Refer to the exhibit, which shows two configured FortiGate devices and peering over FGSP.

The main link directly connects the two FortiGate devices and is configured using the set session-syn-dev command.

What is the primary reason to configure the main link?

A. To have both sessions and configuration synchronization in layer 2

B. To load balance both sessions and configuration synchronization between layer 2 and 3

C. To have only configuration synchronization in layer 3

D. To have both sessions and configuration synchronization in layer 3

Browse 50 Q&As
Questions 11

Refer to the exhibit.

which contains a partial configuration of the global system. What can you conclude from this output?

A. NPs and CPs are enabled

B. Only CPs arc disabled

C. Only NPs are disabled

D. NPs and CPs arc disabled

Browse 50 Q&As
Questions 12

After enabling IPS you receive feedback about traffic being dropped.

What could be the reason?

A. Np-accel-mode is set to enable

B. Traffic-submit is set to disable

C. IPS is configured to monitor

D. Fail-open is set to disable

Browse 50 Q&As
Questions 13

Refer to the exhibit, which shows the output of a BGP summary.

What two conclusions can you draw from this BGP summary? (Choose two.)

A. External BGP (EBGP) exchanges routing information.

B. The BGP session with peer 10. 127. 0. 75 is established.

C. The router 100. 64. 3. 1 has the parameter bfd set to enable.

D. The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.

Browse 50 Q&As
Questions 14

Which statement about network processor (NP) offloading is true?

A. For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP

B. The NP provides IPS signature matching

C. You can disable the NP for each firewall policy using the command np-acceleration st to loose.

D. The NP checks the session key or IPSec SA

Browse 50 Q&As
Questions 15

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel however, the VPN interfaces do not appear as available options.

A. Create interface mappings for the IPsec VPN interfaces before you use them in a policy.

B. Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces

C. Configure the phase 1 settings in the VPN community that you didnt initially configure. FortiGate automatically generates the interfaces after you configure the required settings

D. install the VPN community and gateway configuration on the fortiGate devices so that the VPN interfaces appear on the Policy Objects on fortiManager.

Browse 50 Q&As
Questions 16

Exhibit.

Refer to the exhibit, which shows an ADVPN network.

The client behind Spoke-1 generates traffic to the device located behind Spoke-2.

Which first message floes the hub send to Spoke-110 bring up the dynamic tunnel?

A. Shortcut query

B. Shortcut reply

C. Shortcut offer

D. Shortcut forward

Browse 50 Q&As
Questions 17

Refer to the exhibit, which contains a partial BGP combination.

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

A. ebgp-enforce-multihop

B. recursive-next-hop

C. ibgp-enfoce-multihop

D. update-source

Browse 50 Q&As
Questions 18

Refer to the exhibit, which contains a partial OSPF configuration.

What can you conclude from this output?

A. Neighbors maintain communication with the restarting router.

B. The router sends grace LSAs before it restarts.

C. FortiGate restarts if the topology changes.

D. The restarting router sends gratuitous ARP for 30 seconds.

Browse 50 Q&As
Exam Code: NSE7_EFW-7.2
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.2
Last Update: Mar 13, 2025
Questions: 50 Q&As

PDF

$49.99

VCE

$55.99

PDF + VCE

$65.99