Courseiva

NSE 7 - Enterprise Firewall (NSE7_EFW) (NSE7_EFW) — Questions 7691

91 questions total · 2pages · All types, answers revealed

Page 1

Page 2 of 2

76
Multi-Selecthard

Which THREE aspects of the FortiGate system are affected by changing the global 'set vdom-mode' to 'multi-vdom'?

Select 3 answers
A.CLI command hierarchy
B.The HA cluster size
C.Management of system resources
D.The physical port order
E.How firewall policies are applied
AnswersA, C, E

The 'config vdom' context becomes available.

Why this answer

Changing the VDOM mode affects the CLI hierarchy, the available memory for VDOMs, and how system resources are partitioned.

77
MCQeasy

What does the 'FortiGuard' service provide to the FortiGate?

A.User management and authentication
B.Local firmware storage
C.Hardware acceleration support
D.Real-time threat intelligence and database updates
AnswerD

This allows the FortiGate to block the latest threats.

Why this answer

FortiGuard provides real-time updates for security signatures, including IPS, Antivirus, and Web Filtering.

78
Multi-Selecthard

Which THREE actions can be performed by the FortiGate when a policy match occurs?

Select 3 answers
A.Re-route to a specific switch port
B.Disable hardware acceleration
C.Traffic Shaping
D.Deny
E.Accept
AnswersC, D, E

Limits bandwidth usage.

Why this answer

Firewall policies can accept, deny, or perform traffic shaping and logging depending on the configured profile settings.

79
MCQmedium

When using SD-WAN, how does the 'member' configuration interact with physical interfaces?

A.Members replace the IP configuration
B.Members require a separate VDOM
C.Members are logical groups of interfaces
D.Members must have DHCP enabled
AnswerC

You add physical ports to the SD-WAN zone to utilize them for load balancing.

Why this answer

SD-WAN members are physical interfaces (or tunnels) added to the SD-WAN zone, allowing the FortiGate to manage them as a single logical pool.

80
Multi-Selecthard

Which THREE factors influence log storage efficiency on a FortiAnalyzer/FortiManager?

Select 3 answers
A.Log compression settings
B.Log retention days
C.The firewall firmware version
D.Disk quota for specific devices
E.The number of active users
AnswersA, B, D

Compression reduces storage footprint.

Why this answer

Log compression, log retention settings, and disk quota management determine how long logs persist and how much space they consume.

81
MCQmedium

Which FortiManager feature allows an administrator to test policy changes in a sandbox environment before applying them to production FortiGates?

A.Policy Testing Mode
B.Policy Package Cloning/Revision History
C.Global Policy Lockdown
D.Device Manager Simulation
AnswerB

Cloning allows for safe testing of changes.

Why this answer

The 'Revision History' or 'Policy Package cloning' allows admins to modify and verify changes before pushing them to the production devices.

82
Multi-Selectmedium

Which TWO settings are modified to reduce the impact of a failover event in an HA cluster?

Select 2 answers
A.group-password
B.hb-interval
C.hb-lost-threshold
D.priority
E.monitored-interfaces
AnswersB, C

Faster interval leads to faster detection.

Why this answer

'hb-interval' and 'hb-lost-threshold' determine how quickly the cluster reacts to heartbeat loss.

83
Multi-Selectmedium

Which TWO of the following are necessary to successfully deploy an SSL VPN in tunnel mode?

Select 2 answers
A.An IPSec phase 1 configuration
B.A BGP session with the client
C.A valid SSL certificate for the VPN portal
D.A firewall policy allowing the SSL VPN interface to the Internal zone
E.A dedicated hardware switch
AnswersC, D

A trusted certificate is required for secure handshakes.

Why this answer

Tunnel mode requires a configured portal and a policy allowing the VPN tunnel interface to the internal network.

84
MCQhard

You are configuring BGP and need to advertise a summary route to your ISP. How do you ensure only the summary route is advertised?

A.Use a distribute-list
B.Set the weight to 0
C.Use an aggregate-address with summary-only
D.Configure a route map with a prefix list
AnswerC

This command effectively suppresses specific routes.

Why this answer

The 'aggregate-address' command with the 'summary-only' option is the correct way to advertise only the summary and suppress specific component routes.

85
MCQhard

An administrator notices that hardware acceleration (NP6) is failing to offload traffic for a specific policy. Which command is best used to verify if hardware offloading is actually occurring for a specific session?

A.get hardware npu np6
B.get system performance status
C.diagnose npu np6 status
D.diagnose sys session list
AnswerD

The session list output includes flags like 'offload' which indicate if the NP is handling the session.

Why this answer

The command 'diag sys session filter' combined with 'diag sys session list' allows the administrator to view session flags, specifically looking for the 'offload' flag.

86
MCQhard

A FortiGate is performing OSPF routing. You want to redistribute connected routes into OSPF, but only for a specific subnet. How can this be achieved?

A.Configure a distribute-list in the OSPF process
B.Use an IP prefix list under the OSPF area command
C.Use a route map in the OSPF redistribute configuration
D.Use an access list under the interface configuration
AnswerC

Route maps provide the necessary granularity to filter prefixes during redistribution.

Why this answer

A route map must be applied during redistribution to filter the prefixes being injected.

87
MCQmedium

You are troubleshooting high CPU usage on a FortiGate. Which process would you check to see if the IPS engine is the cause?

A.diag sys top
B.get system status
C.diagnose hardware status
D.show sys resource
AnswerA

This shows all running processes and their resource consumption.

Why this answer

The 'diag sys top' command displays real-time resource utilization, allowing the admin to identify specific processes like 'ipsengine' consuming CPU.

88
MCQeasy

Which CLI command shows the current HA synchronization status and the checksums of the configurations?

A.get system ha status
B.diag hardware ha
C.show system ha
D.diagnose sys ha sync
AnswerA

This command provides the cluster state and configuration synchronization verification.

Why this answer

'get system ha status' provides the overall cluster health, including checksum comparison between nodes.

89
MCQeasy

What is the default behavior of a FortiGate firewall policy when no explicit policy matches the traffic?

A.Send to local DNS
B.Implicit Deny
C.Route to DMZ
D.Allow
AnswerB

The implicit deny policy is the default safety catch-all.

Why this answer

The implicit deny policy is the last rule in the firewall policy list and drops all non-matching traffic.

90
Multi-Selectmedium

Which TWO of the following are valid methods for user authentication on a FortiGate?

Select 2 answers
A.BGP
B.RADIUS
C.LDAP
D.IGMP
E.RIP
AnswersB, C

RADIUS is a standard for enterprise authentication.

Why this answer

FortiGate supports both local user databases and integration with external enterprise servers like RADIUS and LDAP.

91
MCQhard

Which feature allows an administrator to offload SSL inspection to the hardware?

A.CP offloading
B.Flow-based inspection
C.IPS engine offloading
D.NP6 offloading
AnswerA

The Content Processor (CP) offloads encryption/decryption.

Why this answer

The FortiASIC CP (Content Processor) hardware chips are specifically designed to offload CPU-intensive tasks like SSL/TLS decryption.

Page 1

Page 2 of 2

All pages

Practice NSE7_EFW by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →