Free Fortinet NSE7_EFW-6.4 Exam Questions and Answer from Training Expert Actual4dump
Top Fortinet NSE7_EFW-6.4 Courses Online
Fortinet NSE7_EFQ-6.4: Fortinet NSE 7 - Enterprise Firewall 6.4 Exam Certification Path
The Fortinet Network Security Expert (NSE) program is an eight-level training and certification program designed to provide objective confirmation of your network security expertise and knowledge to interested technical professionals. A broad range of self-paced and instructor-led courses are included in the NSE curriculum, as well as realistic, experiential activities that demonstrate mastery of complex concepts of network security.
For the Network Security Analyst, candidates must complete only 2 exams from the available five options. These exams are listed below:
- Fortinet NSE 7 - Advanced Threat Protection
- Fortinet NSE 7 - Cloud Security
- Fortinet NSE 7 - Secure Access
For more info read reference:
Exam Blueprint Preparatory Course
NEW QUESTION 31
View the exhibit, which contains the output of a BGP debug command, and then answer the question below.
Which of the following statements about the exhibit are true? (Choose two.)
- A. Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.
- B. For the peer 10.125.0.60, the BGP state of is Established.
- C. The local BGP peer has received a total of three BGP prefixes.
- D. The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.
Answer: B,D
NEW QUESTION 32
Examine the output of the 'get router info bgp summary' command shown in the exhibit; then answer the question below.
Which statements are true regarding the output in the exhibit? (Choose two.)
- A. Local BGP peer has not received an OpenConfirm from 10.200.3.1.
- B. BGP state of the peer 10.125.0.60 is Established.
- C. BGP peer 10.200.3.1 has never been down since the BGP counters were cleared.
- D. The local BGP peer has received a total of 3 BGP prefixes.
Answer: A,B
NEW QUESTION 33
Which statement about NGFW policy-based application filtering is true?
- A. After IPS identifies the application, it adds an entry to a dynamic ISDB table.
- B. The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT.
- C. After the application has been identified, the kernel uses only the Layer 4 header to match the traffic.
- D. FortiGate will drop all packets until the application can be identified.
Answer: D
NEW QUESTION 34
Which of the following conditions must be met fora static route to be active in the routing table? (Choose three.)
- A. The next-hop IP address belongs to one of the outgoing interface subnets.
- B. The link health monitor (if configured) is up.
- C. The next-hop IP address is up.
- D. There is no other route, to the same destination, with a higher distance.
- E. The outgoing interface is up.
Answer: A,B,E
Explanation:
Explanation
A configured static route only goes to routing table from routing database when all the following are met :
* The outgoing interface is up
* There isno other matching route with a lower distance
* The link health monitor (if configured) is successful
* The next-hop IP address belongs to one of the outgoing interface subnets
NEW QUESTION 35
Refer to the exhibit, which contains partial output from an IKE real-time debug.
Which two statements about this debug output are correct? (Choose two.)
- A. It shows a phase 1 negotiation.
- B. The remote gateway IP address is 10.0.0.1.
- C. The initiator provided remote as its IPsec peer ID.
- D. The negotiation is using AES128 encryption with CBC hash.
Answer: A,C
NEW QUESTION 36
Refer to the exhibit, which contains the output of get system ha status.
Which two statements about the output are true? (Choose two.)
- A. The HA management IP is 169.254.0.2.
- B. The slave configuration is synchronized with the master.
- C. port7 is used as the HA heartbeat on all devices in the cluster.
- D. Primary is selected based on the priority configured under config system ha.
Answer: C,D
NEW QUESTION 37
Which statement about memory conserve mode is true?
- A. A FortiGate enters conserve mode when the configured memory use threshold reaches red
- B. A FortiGate exits conserve mode when the configured memory use threshold reaches yellow.
- C. A FortiGate starts dropping new sessions when the configured memory use threshold reaches red
- D. A FortiGate starts dropping all the new and old sessions when the configured memory use threshold reaches extreme.
Answer: C
NEW QUESTION 38
A FortiGate device has the following LDAP configuration:
The administrator executed the 'dsquery' command in the Windows LDAp server 10.0.1.10, and got the following output:
>dsquery user -samid administrator
"CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab"
Based on the output, what FortiGate LDAP setting is configured incorrectly?
- A. password.
- B. username.
- C. dn.
- D. cnid.
Answer: B
Explanation:
https://kb.fortinet.com/kb/viewContent.do?externalId=FD37516
NEW QUESTION 39
Examine the output of the 'get router info ospf interface' command shown in the exhibit; then answer the question below.
Which statements are true regarding the above output? (Choose two.)
- A. Theport4 interface is connected to the OSPF backbone area.
- B. The local FortiGate has been elected as the OSPF backup designated router.
- C. There are at least 5 OSPF routers connected to the port4 network.
- D. Two OSPF routers are down in the port4 network.
Answer: A,C
Explanation:
Explanation
on BROADCAST network there are 4 neighbors, among which 1*DR +1*BDR. So our FG has 4 neighbors, but create adjacency only with 2 (with DR and BDR). 2 neighbors DRother (not down).
NEW QUESTION 40
View the exhibit, which contains theoutput of get sys ha status, and then answer the question below.
Which statements are correct regarding the output? (Choose two.)
- A. The HA management IP is 169.254.0.2.
- B. The slave configuration is not synchronized with the master.
- C. Master is selected because it is the only device in the cluster.
- D. port 7 is used the HA heartbeat on all devices in the cluster.
Answer: B,D
NEW QUESTION 41
View the exhibit, which contains a partial web filter profile configuration, and then answer the question below.
Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?
- A. FortiGate will exempt the connection based on the Web Content Filter configuration.
- B. FortiGate will block the connection as an invalid URL.
- C. FortiGate will block the connection based on the URL Filter configuration.
- D. FortiGate will allow the connection based on the FortiGuard category based filter configuration.
Answer: C
Explanation:
fortigate does it in order Static URL -> FortiGuard - > Content -> Advanced (java, cookie removal..) so block it in first step
NEW QUESTION 42
View the exhibit, which contains the partial output of adiagnose command, and then answer the question below.
Based on the output, which of the following statements is correct?
- A. Anti-reply is enabled.
- B. Quick mode selectors are disabled.
- C. DPD is disabled.
- D. Remote gateway IP is 10.200.5.1.
Answer: A
NEW QUESTION 43
An administrator has enabled HA session synchronization in a HA cluster with two members. Which flag is added to a primary unit's session to indicate that it has been synchronized to the secondary unit?
- A. redir.
- B. synced
- C. nds.
- D. dirty.
Answer: B
Explanation:
The synced sessions have the 'synced' flag. The command 'diag sys session list' can be used to see the sessions on the member, with the associated flags.
NEW QUESTION 44
Examine the output of the 'diagnose sys session list expectation' command shown in the exhibit; than answer the question below.
Which statement is true regarding the session in the exhibit?
- A. It is for managementtraffic terminating at the FortiGate.
- B. It was created by the FortiGate kernel to allow push updates from FotiGuard.
- C. It is for traffic originated from the FortiGate.
- D. It was created by a session helper or ALG.
Answer: D
NEW QUESTION 45
An administrator added the following Ipsec VPN to a FortiGate configuration:
configvpn ipsec phasel -interface
edit "RemoteSite"
set type dynamic
set interface "portl"
set mode main
set psksecret ENC LCVkCiK2E2PhVUzZe
next
end
config vpn ipsec phase2-interface
edit "RemoteSite"
set phasel name "RemoteSite"
set proposal 3des-sha256
next
end
However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit.

What is causing the IPsec problem in the phase 1 ?
- A. The phrase-1 mode must be changed to aggressive
- B. NAT-T settings do not match
- C. The pre-shared key is wrong
- D. The incoming IPsec connection is matching the wrong VPN configuration
Answer: C
NEW QUESTION 46
Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network. What HA setting must be changed in one of the HA clusters to fix the problem?
- A. Gratuitous ARPs.
- B. Session pickup.
- C. Group name.
- D. Group ID.
Answer: D
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_failoverVMAC.htm
NEW QUESTION 47
View the exhibit, which contains a screenshot of some phase-1settings, and then answer the question below.
The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:
However, the IKE real time debug does not show any output. Why?
- A. The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.
- B. The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
- C. The debug shows only error messages. If there is no output, then the tunnel is operating normally.
- D. The log-filter setting was set incorrectly. The VPN's traffic does not match thisfilter.
Answer: D
NEW QUESTION 48
Viewthe exhibit, which contains the output of a real-time debug, and then answer the question below.
Which of the following statements is true regarding this output? (Choose two.)
- A. The web request was allowed by FortiGate.
- B. FortiGate found the requested URL in its local cache.
- C. This web request was inspected using the root web filter profile.
- D. The requested URL belongs to category ID 52.
Answer: B,D
NEW QUESTION 49
Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)
- A. Installing configuration changes to managed devices
- B. Previewing pending configuration changes for managed devices
- C. Adding devices to FortiManager
- D. Importing interface mappings from managed devices
Answer: A,B
NEW QUESTION 50
An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device. The administrator decides to enable the setting link-failed-signal to fix the problem.
Which statement about this setting is true?
- A. It forces the former primary device to shut down all its non-heartbeat interfaces for one second, while the failover occurs.
- B. It sends a link failed signal to all connected devices.
- C. It disabled all the non-heartbeat interfaces in all HA members for two seconds after a failover.
- D. It sends an ARP packet to all connected devices, indicating that the HA virtual MAC address is reachable through a new master after a failover.
Answer: A
NEW QUESTION 51
View the following FortiGate configuration.
All traffic to theInternet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network:
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user's session?
- A. The session would remain in the session table, and its traffic would still egress from port1.
- B. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
- C. The session would be deleted, so the client would need to start a new session.
- D. The session would remain in thesession table, and its traffic would start to egress from port2.
Answer: A
Explanation:
Explanation
http://kb.fortinet.com/kb/documentLink.do?externalID=FD40943
NEW QUESTION 52
An administrator has configured the following CLI script on FortiManager, which failed to apply any changes to the managed device after being executed.
Why didn't the script make any changes to the managed device?
- A. CLI scripts will add objects only if they are referenced by policies.
- B. Incomplete commands are ignored in CLI scripts.
- C. Commands that start with the # sign are not executed.
- D. Static routes can only be added using TCL scripts.
Answer: C
Explanation:
https://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1000_Device%20Manager/2400_Scripts/1000_Script%20samples/0200_CLI%20scripts+.htm#Error_Messages
A sequence of FortiGate CLI commands, as you would type them at the command line. A comment line starts with the number sign (#). A comment line will not be executed.
NEW QUESTION 53
View the central management configuration shown in the exhibit, and then answer the question below.
Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an outage?
- A. 10.0.1.242
- B. 10.0.1.244
- C. 10.0.1.240
- D. One of the public FortiGuard distribution servers
Answer: D
NEW QUESTION 54
Refer to the exhibit, which shows a partial routing table.
Assuming all the appropriate firewall policies are configured, which two pings will FortiGate route? (Choose two.)
- A. Source IP address: 10.1.0.10. Destination IP address: 10.64.1.52
- B. Source IPaddress: 10.72.3.52. Destination IP address: 10.1.0.254
- C. Source IPaddress: 10.10.4.24, Destination IPaddress: 10.72.3.20
- D. Source IPaddress: 10.73.9.10, Destination IPaddress: 10.72.3.15
Answer: A,B
NEW QUESTION 55
What is the purpose of an internal segmentation firewall (ISFW)?
- A. It inspects incoming traffic to protect services in the corporate DMZ.
- B. It splits the network into multiple security segments to minimize the impact of breaches.
- C. It is the first line of defense at the network perimeter.
- D. It is anall-in-one security appliance that is placed at remote sites to extend the enterprise network.
Answer: B
Explanation:
Explanation
ISFW splits your network into multiple security segments. They serve as a breach containers from attacks that come from inside.
NEW QUESTION 56
......
New (2023) Fortinet NSE7_EFW-6.4 Exam Dumps: https://whizlabs.actual4dump.com/Fortinet/NSE7_EFW-6.4-actualtests-dumps.html