Leads4pass > Fortinet > Fortinet Certifications > NSE7_EFW-7.2 > NSE7_EFW-7.2 Online Practice Questions and Answers

NSE7_EFW-7.2 Online Practice Questions and Answers

Questions 4

Which two statements about bfd are true? (Choose two)

A. It can support neighbor only over the next hop in BGP

B. You can disable it at the protocol level

C. It works for OSPF and BGP

D. You must configure n globally only

Buy Now
Questions 5

Exhibit.

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

A. IPSec Tunnel aggregation is configured

B. net-device is enabled in the tunnel IPSec phase 1 configuration

C. OSPI is configured to run over IPSec.

D. add-route is disabled in the tunnel IPSec phase 1 configuration.

Buy Now
Questions 6

Refer to the exhibit, which shows a network diagram.

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

A. Set route-overlap to allow.

B. Set single-source to enable

C. Set route-overlap to either use--new or use-old

D. Set net-device to enable

Buy Now
Questions 7

Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)

A. Dead peer detection is set to enable.

B. The IKE version is 2.

C. Both IPsec SAs are loaded on the kernel.

D. Forward error correction in phase 2 is set to enable.

Buy Now
Questions 8

Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

A. Enable AD-VPN in IPsec phase 1

B. Disable add-route on hub

C. Configure IP addresses on IPsec virtual interlaces

D. Set protected network to all

Buy Now
Questions 9

After enabling IPS you receive feedback about traffic being dropped.

What could be the reason?

A. Np-accel-mode is set to enable

B. Traffic-submit is set to disable

C. IPS is configured to monitor

D. Fail-open is set to disable

Buy Now
Questions 10

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel however, the VPN interfaces do not appear as available options.

A. Create interface mappings for the IPsec VPN interfaces before you use them in a policy.

B. Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces

C. Configure the phase 1 settings in the VPN community that you didnt initially configure. FortiGate automatically generates the interfaces after you configure the required settings

D. install the VPN community and gateway configuration on the fortiGate devices so that the VPN interfaces appear on the Policy Objects on fortiManager.

Buy Now
Questions 11

Refer to the exhibit, which contains a partial BGP combination.

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

A. ebgp-enforce-multihop

B. recursive-next-hop

C. ibgp-enfoce-multihop

D. update-source

Buy Now
Questions 12

Refer to the exhibit, which shows a routing table.

What two options can you configure in OSPF to block the advertisement of the 10.1.10.0 prefix? (Choose two.)

A. Remove the 16.1.10.C prefix from the OSPF network

B. Configure a distribute-list-out

C. Configure a route-map out

D. Disable Redistribute Connected

Buy Now
Questions 13

In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)

A. lt can be configured as an update server a rating server or both

B. It provides VM license validation services

C. It supports rating requests from non-FortiGate devices.

D. It caches available firmware updates for unmanaged devices

Buy Now
Exam Code: NSE7_EFW-7.2
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.2
Last Update: Jan 13, 2025
Questions: 50
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99