Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

NSE7_EFW-7.2 Exam Dumps - Fortinet NSE 7 - Enterprise Firewall 7.2

Question # 4

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

A.

fec-ingress and fec-egress

B.

Odpd and dpd-retryinterval

C.

fragmentation and fragmentation-mtu

D.

keepalive and keylive

Full Access
Question # 5

Which two statements about IKE vision 2 are true? (Choose two.)

A.

Phase 1 includes main mode

B.

It supports the extensible authentication protocol (EAP)

C.

It supports the XAuth protocol.

D.

It exchanges a minimum of four messages to establish a secure tunnel

Full Access
Question # 6

Exhibit.

Refer to the exhibit, which contains an ADVPN network diagram and a partial BGP con figuration Which two parameters Should you configure in config neighbor range? (Choose two.)

A.

set prefix 172.16.1.0 255.255.255.0

B.

set route reflector-client enable

C.

set neighbor-group advpn

D.

set prefix 10.1.0 255.255.255.0

Full Access
Question # 7

Which two statements about metadata variables are true? (Choose two.)

A.

You create them on FortiGate

B.

They apply only to non-firewall objects.

C.

The metadata format is $.

D.

They can be used as variables in scripts

Full Access
Question # 8

Refer to the exhibit, which shows config system central-management information.

Which setting must you configure for the web filtering feature to function?

A.

Add server. fortiguard. net to the server list.

B.

Configure securewf.fortiguard. net on the default servers.

C.

Set update-server-location to automatic.

D.

Configure server-type with the rating option.

Full Access
Question # 9

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 10

Refer to the exhibit, which contains a partial OSPF configuration.

What can you conclude from this output?

A.

Neighbors maintain communication with the restarting router.

B.

The router sends grace LSAs before it restarts.

C.

FortiGate restarts if the topology changes.

D.

The restarting router sends gratuitous ARP for 30 seconds.

Full Access
Question # 11

Refer to the exhibits, which show the configurations of two address objects from the same FortiGate.

Why can you modify the Engineering address object, but not the Finance address object?

A.

You have read-only access.

B.

FortiGate joined the Security Fabric and the Finance address object was configured on the root FortiGate.

C.

FortiGate is registered on FortiManager.

D.

Another user is editing the Finance address object in workspace mode.

Full Access
Question # 12

Exhibit.

Refer to the exhibit, which provides information on BGP neighbors.

Which can you conclude from this command output?

A.

The router are in the number to match the remote peer.

B.

You must change the AS number to match the remote peer.

C.

BGP is attempting to establish a TCP connection with the BGP peer.

D.

The bfd configuration to set to enable.

Full Access
Question # 13

After enabling IPS you receive feedback about traffic being dropped.

What could be the reason?

A.

Np-accel-mode is set to enable

B.

Traffic-submit is set to disable

C.

IPS is configured to monitor

D.

Fail-open is set to disable

Full Access
Question # 14

Exhibit.

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

A.

IPSec Tunnel aggregation is configured

B.

net-device is enabled in the tunnel IPSec phase 1 configuration

C.

OSPI is configured to run over IPSec.

D.

add-route is disabled in the tunnel IPSec phase 1 configuration.

Full Access
Question # 15

In which two ways does fortiManager function when it is deployed as a local FDS? (Choose two)

A.

lt can be configured as an update server a rating server or both

B.

It provides VM license validation services

C.

It supports rating requests from non-FortiGate devices.

D.

It caches available firmware updates for unmanaged devices

Full Access