Exit demo NSE7_EFW-7.2 Fortinet NSE 7 - Enterprise Firewall 7.2 PDF format · free preview

Fortinet NSE7_EFW-7.2 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/nse7-efw-72.html

Question 1
Single choice

Refer to the exhibit which shows an OSPF network.

Which types of link-state advertisements (LSA) will NGFW-1 send if it is a backup designated router (BDR)

A.

NGFW-1 will send type 1 and type 2 LSAs

B.

NGFW-1 will send type 1 and type 4 LSAs.

C.

NGFW-1 will send type 1 and type 3 LSAs

D.

NGFW-1 will send type 1 and type 5 LSAs

Question 2
Multiple choice

You are testing the implementation of a new custom remote desktop application in your network In which two ways can you eliminate false positives in IPS during this testing phase? (Choose two)

A.

Create an IP address exception

B.

Adjust the rate-based signature threshold and its duration.

C.

Enable the preserve source pore option in the firewall policy

D.

Permanently bypass the affected endpoints

Question 3
Single choice

Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

A.

Enable AD-VPN in IPsec phase 1

B.

Disable add-route on hub

C.

Configure IP addresses on IPsec virtual interfaces

D.

Set protected network to all

Question 4
Single choice

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A.

F-SBID( --name "eicar"; --protocol udp; --flow from_server; --pattern "eicar"; --context host;)

B.

F-SBID( --name "detect_eicar"; --protocol udp; --service ssl; --flow from_client; --pattern
"www.eicar.org"; --no_case; --context host;)

C.

F-SBID( --name "detect_eicar"; --protocol tcp; --service dns; --flow from_server; --pattern "eicar"; --
no_case;)

D.

F-SBID( --name "eicar"; --protocol tcp; --service HTTP; --flow from_client; --pattern "www.eicar.org"; --
no_case; --context host;)

Question 5
Single choice

Refer to the exhibit, which contains a partial OSPF configuration.

What can you conclude from this output?

A.

Neighbors maintain communication with the restarting router.

B.

The router sends grace LSAs before it restarts.

C.

FortiGate restarts if the topology changes.

D.

The restarting router sends gratuitous ARP for 30 seconds.

Question 6
Multiple choice

Exhibit.

ISFW is installed in the access layer NGFW is performing SNAT and web tittering DCFW is running IPS

Which two statements are true regarding the Security Fabric logging? (Choose two.)

A.

DCFW is responsible for generating UTM logs for file server sessions initiated by Client-1. only if an IPS inspection is triggered

B.

ISFW is responsible for generating traffic logs for only Web traffic and SMB traffic from Client-1.

C.

The SMB session which is forwarded to NGFW logs that event

D.

DCFW generates traffic logs for all sessions from Corporate File Server

E.

The web session forwarded to the NGFW generates the relevant UTM logs along with initial traffic log

Question 7
Multiple choice

In which two ways does FortiManager function when it is deployed as a local FDS? (Choose two.)

A.

It caches available firmware updates for both managed and unmanaged devices

B.

It can be configured as an update server a rating server or both

C.

It functions as rating server only for web filtering and antispam services

D.

It downloads license information for registered and unregistered devices

Question 8
Multiple choice

Refer to the exhibit, which shows a custom signature.

Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Choose two.)

A.

Add severity.

B.

Add attack_id.

C.

Ensure that the header syntax is F-SBID.

D.

Start options with --.

Question 9
Single choice

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

A.

FortiManager provides FortiGuard.

B.

fortiguard-anycast is set to enable.

C.

You do not have the corresponding write access.

D.

udp is not a protocol option.

Question 10
Multiple choice

How are bulk configuration changes made using FortiManager CLI scripts? (Choose two.)

A.

When run on the Device Database, changes are applied directly to the managed FortiGate device.

B.

When run on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.

C.

When run on the All FortiGate in ADOM, changes are automatically installed without the creation of a new revision history.

D.

When run on the Policy Package, ADOM database, you must use the installation wizard to apply the changes to the managed FortiGate device.

Showing 10 of 80 questions · Unlock the full set