Spring Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Fortinet NSE 7 Network Security Architect NSE7_EFW-7.0 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE7_EFW-7.0 Premium Access

View all detail and faqs for the NSE7_EFW-7.0 exam


779 Students Passed

85% Average Score

90% Same Questions
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

What does the dirty flag mean in a FortiGate session configured for NGFW policy mode?

Options:

A.

The existing session table entry has been updated with the app_id and the firewall policy table needs to be checked for a match.

B.

The application or URL category is unknown and needs to be rescanned by the IPS engine to try to identify the Layer 7 details.

C.

The URL category for this session has been updated by FortiGuard and the session needs to be checked against the policy again to ensure proper web filtering is applied.

D.

Traffic has been identified as coming from an application that is not allowed and the relevant replacement message needs to be displayed to the user, if configured.

Questions # 22:

Refer to the exhibit, which shows partial outputs from two routing debug commands.

Question # 22

Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?

Options:

A.

Set the priority of the static default route using port1 to 10. Most Voted

B.

Set the priority of the static default route using port2 to 1.

C.

Set preserve-session-route to enable.

D.

Set snat-route-change to enable.

Questions # 23:

Refer to the exhibit, which shows a partial web filter profile configuration.

Question # 23

Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

Options:

A.

FortiGate will block the connection, based on the FortiGuard category based filter configuration.

B.

FortiGate will block the connection as an invalid URL.

C.

FortiGate will exempt the connection, based on the Web Content Filter configuration.

D.

FortiGate will allow the connection, based on the URL Filter configuration.

Questions # 24:

A corporate network allows Internet Access to FSSO users only. The FSSO user student does not have Internet access after successfully logged into the Windows AD network. The output of the ‘diagnose debug authd fsso list’ command does not show student as an active FSSO user. Other FSSO users can access the Internet without problems. What should the administrator check? (Choose two.)

Options:

A.

The user student must not be listed in the CA’s ignore user list.

B.

The user student must belong to one or more of the monitored user groups.

C.

The student workstation’s IP subnet must be listed in the CA’s trusted list.

D.

At least one of the student’s user groups must be allowed by a FortiGate firewall policy.

Questions # 25:

A FortiGate device has the following LDAP configuration:

Question # 25

The administrator executed the ‘dsquery’ command in the Windows LDAp server 10.0.1.10, and got the following output:

>dsquery user –samid administrator

“CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab”

Based on the output, what FortiGate LDAP setting is configured incorrectly?

Options:

A.

cnid.

B.

username.

C.

password.

D.

dn.

Questions # 26:

View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.

Question # 26

The administrator does not have access to the remote gateway. Based on the debug output, what configuration changes can the administrator make to the local gateway to resolve the phase 1 negotiation error?

Options:

A.

Change phase 1 encryption to 3DES and authentication to SHA128.

B.

Change phase 1 encryption to AES128 and authentication to SHA512.

C.

Change phase 1 encryption to AESCBC and authentication to SHA2.

D.

Change phase 1 encryption to AES256 and authentication to SHA256.

Questions # 27:

An administrator has configured the following CLI script on FortiManager, which failed to apply any changes to the managed device after being executed.

Question # 27

Why didn’t the script make any changes to the managed device?

Options:

A.

Commands that start with the # sign are not executed.

B.

CLI scripts will add objects only if they are referenced by policies.

C.

Incomplete commands are ignored in CLI scripts.

D.

Static routes can only be added using TCL scripts.

Questions # 28:

Refer to the exhibit, which contains the output of a BGP debug command.

Question # 28

Which statement about the exhibit is true?

Options:

A.

The local router has received a total of three BGP prefixes from all peers.

B.

The local router has not established a TCP session with 100.64.3.1.

C.

Since the counters were last reset, the 10.200.3.1 peer has never been down.

D.

The local router BGP state is OpenConfirm with the 10.127.0.75 peer.

Questions # 29:

The CLI command set intelligent-mode controls the IPS engine’s adaptive scanning behavior. Which of the following statements describes IPS adaptive scanning?

Options:

A.

Determines the optimal number of IPS engines required based on system load.

B.

Downloads signatures on demand from FDS based on scanning requirements.

C.

Determines when it is secure enough to stop scanning session traffic.

D.

Choose a matching algorithm based on available memory and the type of inspection being performed.

Questions # 30:

Which two configuration commands change the default behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

Options:

A.

set av-failopen off

B.

set av-failopen pass

C.

set fail-open enable

D.

set ips fail-open disable

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.