Courseiva

NSE7_EFW · domain

Security And VPN

Practise NSE 7 - Enterprise Firewall (NSE7_EFW) Security And VPN practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

30 questions7 easy13 medium10 hard

Focused practice

Practice Security And VPN questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security And VPN

Security And VPN questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security And VPN exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security And VPN questions (30)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE of the following are mandatory for a BGP neighbor adjacency to establish?

Hard
2

You need to inspect traffic between two internal VLANs. How do you ensure this traffic is processed by the FortiGate?

Medium
3

Which TWO of the following are benefits of using the FortiGate flow-based inspection mode?

Medium
4

You notice that an IPsec tunnel is up, but no traffic passes. What is the most common reason related to firewall policy configuration?

Medium
5

In a site-to-site VPN, you need to allow traffic initiated from the remote site. What configuration is essential on the local FortiGate?

Medium
6

Which FortiGate feature should be enabled to prevent internal users from accessing malicious websites based on real-time threat intelligence?

Medium
7

In a BGP deployment, your FortiGate is receiving routes from two different ISPs. You want to influence outbound traffic to prefer ISP1 for specific destinations. Which BGP attribute should you modify?

Hard
8

You are implementing SSL VPN and need to ensure that only compliant corporate laptops can connect. Which feature should you use?

Medium
9

Which TWO of the following can be used to optimize IPsec VPN performance?

Medium
10

When using an IPS sensor, what is the difference between 'Protect' and 'Monitor' mode?

Medium
11

A network administrator is configuring SSL inspection for a group of users. Which certificate must be installed on the client endpoints to prevent browser certificate warnings?

Easy
12

What is the primary function of the FortiGate Security Fabric?

Easy
13

Which command is used to troubleshoot connectivity by checking the routing table of a specific IP address on the FortiGate?

Easy
14

When configuring an IPsec tunnel using IKEv2, which THREE parameters are commonly negotiated during Phase 1?

Hard
15

Which THREE types of traffic are typically inspected by an IPS policy?

Hard
16

What is the purpose of the 'Any' interface in a firewall policy?

Easy
17

In a high availability (HA) cluster, which THREE settings are synchronized between the primary and secondary units?

Hard
18

What is the effect of changing the IPS 'buffer' size on a FortiGate device?

Hard
19

Which FortiGate feature allows you to bypass SSL inspection for specific known-trusted websites to maintain user privacy?

Medium
20

Which method is the most secure for managing FortiGate devices remotely?

Easy
21

You are configuring an IPsec VPN tunnel between two FortiGates. Phase 2 fails to come up. What is the most likely cause?

Medium
22

In a complex VPN scenario with NAT-Traversal (NAT-T) enabled, what is the primary purpose of the UDP 4500 port?

Hard
23

You are configuring an IPS policy to protect a web server. You notice that traffic is being dropped due to a false positive. Which action is the most efficient way to resolve this while maintaining security?

Medium
24

What does the 'FortiGuard' service provide to the FortiGate?

Easy
25

Which THREE actions can be performed by the FortiGate when a policy match occurs?

Hard
26

Which TWO of the following are necessary to successfully deploy an SSL VPN in tunnel mode?

Medium
27

You are configuring BGP and need to advertise a summary route to your ISP. How do you ensure only the summary route is advertised?

Hard
28

A FortiGate is performing OSPF routing. You want to redistribute connected routes into OSPF, but only for a specific subnet. How can this be achieved?

Hard
29

What is the default behavior of a FortiGate firewall policy when no explicit policy matches the traffic?

Easy
30

Which TWO of the following are valid methods for user authentication on a FortiGate?

Medium

Frequently asked questions

What does the Security And VPN domain cover on the NSE7_EFW exam?
Security And VPN questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 30 Security And VPN questions in the NSE7_EFW question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security And VPN questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
fortinet-nse7-efw FORTINET-NSE7-EFW security and vpn Practice Questions