Latest NSE7_EFW-7.0 exam dumps with real Fortinet questions and answers [Q16-Q35]

Share

Latest NSE7_EFW-7.0 exam dumps with real Fortinet questions and answers

NSE7_EFW-7.0 Exam in First Attempt Guaranteed

NEW QUESTION 16
Which of the following statements is true regarding a FortiGate configured as an explicit web proxy?

  • A. FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT be modified by the administrator.
  • B. FortiGate limits the number of workstations that authenticate using the same web proxy user credentials. This limit CANNOT be modified by the administrator.
  • C. FortiGate limits the total number of simultaneous explicit web proxy users.
  • D. FortiGate limits the number of simultaneous sessions per explicit web proxy user The limit CAN be modified by the administrator

Answer: C

 

NEW QUESTION 17
Refer to exhibit, which contains the output of a BGP debug command.

Which statement explains why the state of the 10.200.3.1 peer is Connect?

  • A. The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the OpenConfirm yet.
  • B. The local router has received the BGP prefixes from the remote peer.
  • C. The TCP session to 10.200.3.1 has not completed the three-way handshake.
  • D. The local router is receiving the BGP keepalives from the peer, but it has not received a BGP prefix yet.

Answer: C

 

NEW QUESTION 18
Which configuration can be used to reduce the number of BGP sessions in an IBGP network?

  • A. Route reflector Next-hop-self Neighbor group
  • B. Neighbor range

Answer: A

 

NEW QUESTION 19
A corporate network allows Internet Access to FSSO users only. The FSSO user student does not have Internet access after successfully logged into the Windows AD network. The output of the 'diagnose debug authd fsso list' command does not show student as an active FSSO user. Other FSSO users can access the Internet without problems .
What should the administrator check? (Choose two.)

  • A. The user student must not be listed in the CA's ignore user list.
  • B. The user student must belong to one or more of the monitored user groups.
  • C. At least one of the student's user groups must be allowed by a FortiGate firewall policy.
  • D. The student workstation's IP subnet must be listed in the CA's trusted list.

Answer: A,C

 

NEW QUESTION 20
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.

Why didn't the tunnel come up?

  • A. The remote gateway is using aggressive mode and the local gateway is configured to use man mode.
  • B. The remote gateway's phase 2 configuration does not match the local gateway's phase 2 configuration.
  • C. The remote gateway's phase 1 configuration does not match the local gateway's phase 1 configuration.
  • D. The pre-shared keys do not match.

Answer: C

 

NEW QUESTION 21
Examine the partial output from two web filter debug commands; then answer the question below:

Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99.com?

  • A. Business.
  • B. Information technology.
  • C. General organization.
  • D. Finance and banking

Answer: A

 

NEW QUESTION 22
A FortiGate is rebooting unexpectedly without any apparent reason .
What troubleshooting tools could an administrator use to get more information about the problem? (Choose two.)

  • A. Logs.
  • B. Crashlogs.
  • C. Policy monitor.
  • D. Firewall monitor.

Answer: A,B

 

NEW QUESTION 23
Examine the output from the 'diagnose vpn tunnel list' command shown in the exhibit; then answer the question below.

Which command can be used to sniffer the ESP traffic for the VPN DialUP_0?

  • A. diagnose sniffer packet any 'port 500'
  • B. diagnose sniffer packet any 'port 4500'
  • C. diagnose sniffer packet any 'host 10.0.10.10'
  • D. diagnose sniffer packet any 'esp'

Answer: B

 

NEW QUESTION 24
Examine the following partial outputs from two routing debug commands; then answer the question below.
# get router info kernel
tab=254 vf=0 scope=0type=1 proto=11 prio=0 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0 gwy=10.200.1.254 dev=2(port1) tab=254 vf=0 scope=0type=1 proto=11 prio=10 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0 gwy=10.200.2.254 dev=3(port2) tab=254 vf=0 scope=253type=1 proto=2 prio=0 0.0.0.0/0.0.0.0/.->10.0.1.0/24 pref=10.0.1.254 gwy=0.0.0.0 dev=4(port3)
# get router info routing-table all s*0.0.0.0/0 [10/0] via 10.200.1.254, portl [10/0] via 10.200.2.254, port2, [10/0] dO.0.1.0/24 is directly connected, port3 dO.200.1.0/24 is directly connected, portl d0.200.2.0/24 is directly connected, port2 Which outbound interface or interfaces will be used by this FortiGate to route web traffic from internal users to the Internet?

  • A. port2.
  • B. port!
  • C. port3.
  • D. Both portl and port2.

Answer: A

 

NEW QUESTION 25
Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)

  • A. Previewing pending configuration changes for managed devices
  • B. Importing interface mappings from managed devices
  • C. Adding devices to FortiManager
  • D. Installing configuration changes to managed devices

Answer: A,D

 

NEW QUESTION 26
View the following FortiGate configuration.

All traffic to the Internet currently egresses from port1.
The exhibit shows partial session information for Internet traffic from a user on the internal network:

If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user's session?

  • A. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
  • B. The session would remain in the session table, and its traffic would start to egress from port2.
  • C. The session would remain in the session table, and its traffic would still egress from port1.
  • D. The session would be deleted, so the client would need to start a new session.

Answer: C

 

NEW QUESTION 27
An administrator is running the following sniffer in a FortiGate: diagnose sniffer packet any "host 10.0.2.10" 2
What information is included in the output of the sniffer? (Choose two.)

  • A. Port names.
  • B. Ethernet headers.
  • C. IP headers.
  • D. IP payload.

Answer: C,D

 

NEW QUESTION 28
A corporate network allows Internet Access to FSSO users only. The FSSO user student does not have Internet access after successfully logged into the Windows AD network. The output of the 'diagnose debug authd fsso list' command does not show student as an active FSSO user. Other FSSO users can access the Internet without problems .
What should the administrator check? (Choose two.)

  • A. The user student must not be listed in the CA's ignore user list.
  • B. At least one of the student's user groups must be allowed by a FortiGate firewall policy.
  • C. The user student must belong to one or more of the monitored user groups.
  • D. The student workstation's IP subnet must be listed in the CA's trusted list.

Answer: A,C

 

NEW QUESTION 29
Examine the output of the 'get router info bgp summary' command shown in the exhibit; then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. Local BGP peer has not received an OpenConfirm from 10.200.3.1.
  • B. The local BGP peer has received a total of 3 BGP prefixes.
  • C. BGP peer 10.200.3.1 has never been down since the BGP counters were cleared.
  • D. BGP state of the peer 10.125.0.60 is Established.

Answer: A,D

 

NEW QUESTION 30
Which two statements about an auxiliary session are true? (Choose two.)

  • A. With the auxiliary session setting disabled, for each traffic path, FortiGate will use the same auxiliary session.
  • B. With the auxiliary session setting enabled, ECMP traffic is accelerated to the NP6 processor.
  • C. With the auxiliary session setting enabled, two sessions will be created in case of routing change.
  • D. With the auxiliary session disabled, only auxiliary sessions will be offloaded.

Answer: B,C

 

NEW QUESTION 31
An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs the debug flow while attempting the connection using HTTP.
The output of the debug flow is shown in the exhibit:

Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)

  • A. HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.
  • B. HTTP administrative access is configured with a port number different than 80.
  • C. Redirection of HTTP to HTTPS administrative access is disabled.
  • D. The packet is denied because of reverse path forwarding check.

Answer: A,B

 

NEW QUESTION 32
View the exhibit, which contains the output of diagnose sys session list, and then answer the question below.

If the HA ID for the primary unit is zero (0), which statement is correct regarding the output?

  • A. This session is synced with the slave unit.
  • B. This session cannot be synced with the slave unit.
  • C. The inspection of this session has been offloaded to the slave unit.
  • D. This session is for HA heartbeat traffic.

Answer: A

 

NEW QUESTION 33
An administrator has enabled HA session synchronization in a HA cluster with two members .
Which flag is added to a primary unit's session to indicate that it has been synchronized to the secondary unit?

  • A. nds.
  • B. redir.
  • C. synced
  • D. dirty.

Answer: C

 

NEW QUESTION 34
An administrator has configured a FortiGate device with two VDOMs: root and internal. The administrator has also created and inter-VDOM link that connects both VDOMs. The objective is to have each VDOM advertise some routes to the other VDOM via OSPF through the inter-VDOM link .
What OSPF configuration settings must match in both VDOMs to have the OSPF adjacency successfully forming? (Choose three.)

  • A. OSPF interface area.
  • B. OSPF interface MTU.
  • C. Router ID.
  • D. OSPF interface cost.
  • E. Interface subnet mask.

Answer: A,B,E

 

NEW QUESTION 35
......

Exam Sure Pass Fortinet Certification with NSE7_EFW-7.0 exam questions: https://prepaway.testkingpass.com/NSE7_EFW-7.0-testking-dumps.html