New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

NSE7_EFW-7.2 Fortinet NSE 7 - Enterprise Firewall 7.2 Questions and Answers

Questions 4

Exhibit.

Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.

Which two conclusions can you draw from this con figuration? (Choose two)

Options:

A.

10.1.5.254 is the default gateway of the internal network

B.

On failover new primary device uses the same MAC address as the old primary

C.

The VRRP domain uses the physical MAC address of the primary FortiGate

D.

By default FortiGate B is the primary virtual router

Buy Now
Questions 5

Refer to the exhibit, which shows a network diagram.

Which protocol should you use to configure the FortiGate cluster?

Options:

A.

FGCP in active-passive mode

B.

OFGSP

C.

VRRP

D.

FGCP in active-active mode

Buy Now
Questions 6

Which two statements about the BFD parameter in BGP are true? (Choose two.)

Options:

A.

It allows failure detection in less than one second.

B.

The two routers must be connected to the same subnet.

C.

It is supported for neighbors over multiple hops.

D.

It detects only two-way failures.

Buy Now
Questions 7

Which two statements about bfd are true? (Choose two)

Options:

A.

It can support neighbor only over the next hop in BGP

B.

You can disable it at the protocol level

C.

It works for OSPF and BGP

D.

You must configure n globally only

Buy Now
Questions 8

Refer to the exhibit.

which contains a partial configuration of the global system. What can you conclude from this output?

Options:

A.

NPs and CPs are enabled

B.

Only CPs arc disabled

C.

Only NPs are disabled

D.

NPs and CPs arc disabled

Buy Now
Questions 9

After enabling IPS you receive feedback about traffic being dropped.

What could be the reason?

Options:

A.

Np-accel-mode is set to enable

B.

Traffic-submit is set to disable

C.

IPS is configured to monitor

D.

Fail-open is set to disable

Buy Now
Questions 10

Which two statements about ADVPN are true? (Choose two.)

Options:

A.

You must disable add-route in the hub.

B.

AllFortiGate devices must be in the same autonomous system (AS).

C.

The hub adds routes based on IKE negotiations.

D.

You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0.

Buy Now
Questions 11

Exhibit.

Refer to the exhibit, which shows a partial web filter profile conjuration

What can you cone udo from this configuration about access towww.facebook , com, which is categorized as Social Networking?

Options:

A.

The access is blocked based on the Content Filter configuration

B.

The access is allowed based on the FortiGuard Category Based Filter configuration

C.

The access is blocked based on the URL Filter configuration

D.

The access is hocked if the local or the public FortiGuard server does not reply

Buy Now
Questions 12

You contoured an address object on the tool fortiGate in a Security Fabric. This object is not synchronized with a downstream device. Which two reasons could be the cause? (Choose two)

Options:

A.

The address object on the tool FortiGate has fabric-object set to disable

B.

The root FortiGate has configuration-sync set to enable

C.

The downstream TortiGate has fabric-object-unification set to local

D.

The downstream FortiGate has configuration-sync set to local

Buy Now
Questions 13

Exhibit.

Refer to the exhibit, which shows information about an OSPF interlace

What two conclusions can you draw from this command output? (Choose two.)

Options:

A.

The port3 network has more man one OSPF router

B.

The OSPF routers are in the area ID of 0.0.0.1.

C.

The interfaces of the OSPF routers match the MTU value that is configured as 1500.

D.

NGFW-1 is the designated router

Buy Now
Questions 14

Refer to the exhibit, which shows a routing table.

What two options can you configure in OSPF to block the advertisement of the 10.1.10.0 prefix? (Choose two.)

Options:

A.

Remove the 16.1.10.C prefix from the OSPF network

B.

Configure a distribute-list-out

C.

Configure a route-map out

D.

Disable Redistribute Connected

Buy Now
Questions 15

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

Options:

A.

fec-ingress and fec-egress

B.

Odpd and dpd-retryinterval

C.

fragmentation and fragmentation-mtu

D.

keepalive and keylive

Buy Now
Exam Code: NSE7_EFW-7.2
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.2
Last Update: Dec 23, 2024
Questions: 50
NSE7_EFW-7.2 pdf

NSE7_EFW-7.2 PDF

$25.5  $84.99
NSE7_EFW-7.2 Engine

NSE7_EFW-7.2 Testing Engine

$30  $99.99
NSE7_EFW-7.2 PDF + Engine

NSE7_EFW-7.2 PDF + Testing Engine

$40.5  $134.99