Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet NSE 7 Network Security Architect NSE7_LED-7.0 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE7_LED-7.0 Premium Access

View all detail and faqs for the NSE7_LED-7.0 exam


396 Students Passed

95% Average Score

97% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Examine the network diagram and packet capture shown in the exhibit

The packet capture was taken between FortiGate and FortiAuthenticator and shows a RADIUS Access-Request packet sent by FortiSwitch to FortiAuthenticator through FortiGate

Why does the User-Name attribute in the RADIUS Access-Request packet contain the client MAC address?

Options:

A.

The client is performing AD machine authentication

B.

FortiSwitch is authenticating the client using MAC authentication bypass

C.

The client is performing user authentication

D.

FortiSwitch is sending a RADIUS accounting message to FortiAuthenticator

Questions # 2:

Refer to the exhibit

Question # 2

Examine the FortiGate RSSO configuration shown in the exhibit

FortiGate is configured to receive RADIUS accounting messages on port3 to authenticate RSSO users The users are located behind port3 and the internet link is connected to port1 FortiGate is processing incoming RADIUS accounting messages successfully and RSSO users are getting associated with the RSSO Group user group However all the users are able to access the internet, and the administrator wants to restrict internet access to RSSO users only

Which configuration change should the administrator make to fix the problem?

Options:

A.

Change the RADIUS Attribute Value selling to match the name of the RADIUS attribute containing the group membership information of the RSSO users

B.

Add RSSO Group to the firewall policy

C.

Enable Security Fabric Connection on port3

D.

Create a second firewall policy from port3 lo port1 and select the target destination subnets

Questions # 3:

Where can FortiGate learn the FortiManager IP address or FQDN for zero-touch provisioning'?

Options:

A.

From an LDAP server using a simple bind operation

B.

From a TFTP server

C.

From a DHCP server using options 240 and 241

D.

From a DNS server using A or AAAA records

Questions # 4:

A wireless network in a school provides guest access using a captive portal to allow unregistered users to self-register and access the network The administrator is requested to update the existing configuration to provide captive portal authentication through a secure connection (HTTPS)

Which two changes must the administrator make to enforce HTTPS authentication"? (Choose two >

Options:

A.

Create a new SSID with the HTTPS captive portal URL

B.

Enable HTTP redirect in the user authentication settings

C.

Disable HTTP administrative access on the guest SSID to enforce HTTPS connection

D.

Update the captive portal URL to use HTTPS on FortiGate and FortiAuthenticator

Questions # 5:

Which FortiSwitch VLANs are automatically created on FortGate when the first FortiSwitch device is discovered1?

Options:

A.

default quarantine, rspan voice video onboarding and nac_segment

B.

access, quarantine, rspan. voice, video, and onboarding

C.

default quarantine rspan voice video and nac_segment

D.

fortilink. quarantine erspan voice video and onboarding

Questions # 6:

Which two statements about FortiSwitch trunks are true? (Choose two.)

Options:

A.

A trunk is a link aggregation group interface.

B.

By default, when connecting two FortiSwitch devices to each other, a trunk is automatically created between the switches.

C.

Trunks do not support tagged Ethernet frames.

D.

LACP is not supported.

Questions # 7:

Refer to the exhibit.

Question # 7

Examine the IPsec VPN phase 1 configuration shown in the exhibit

An administrator wants to use certificate-based authentication for an IPsec VPN user

Which three configuration changes must you make on FortiGate to perform certificate-based authentication for the IPsec VPN user? (Choose three)

Options:

A.

Create a PKI user for the IPsec VPN user, and then configure the IPsec VPN tunnel to accept the PKI user as peer certificate.

B.

In the IKE section of the IPsec VPN tunnel, in the Mode field, select Main (ID protection).

C.

Import the CA that signed the user certificate.

D.

Enable XAUTH on the IPsec VPN tunnel.

E.

In the Authentication section of the IPsec VPN tunnel, in the Method drop-down list, select Signature, and then select the certificate that FortiGate will use for IPsec VPN.

Questions # 8:

Refer to the exhibit.

Question # 8

Examine the debug output shown in the exhibit

Which two statements about the RADIUS debug output are true'' (Choose two)

Options:

A.

The user student belongs to the SSLVPN group

B.

User authentication failed

C.

The RADIUS server sent a vendor-specific attribute in the RADIUS response

D.

User authentication succeeded using MSCHAP

Questions # 9:

Refer to the exhibits.

Question # 9

Examine the LDAP server configuration and output shown in the exhibits.

Question # 9

Note that the Distinguished Name and Username settings on the LDAP server configuration have been expanded to display their full contents.

An LDAP user named student cannot authenticate. While testing the student account, the administrator gets the CLI output shown in the exhibit.

According to the output, which FortiGate LDAP server settings must the administrator check?

Options:

A.

Distinguished Name

B.

Bind Type

C.

Common Name Identifier

D.

Username

Questions # 10:

An administrator is deploying AP's that are connecting over an IPsec network. All APs have been configured to connect to FortiGate manually. FortiGate can discover the APs and authorize them. However, FortiGate is unable to establish CAPWAP tunnels to manage the APs.

Which configuration setting can the administrator perform to resolve the problem?

Options:

A.

Upgrade the FortiAP firmware image to ensure compatibility with the FortiOS version.

B.

Decrease the CAPWAP tunnel MTU size for APs to prevent fragmentation.

C.

Enable CAPWAP administrative access on the IPsec interface.

D.

Assign a custom AP profile for the remote APs with the set mpls-connection option enabled.

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.