Skip to content

NSE7 Fortinet NSE 7 Network Security Architect Practice Questions

Prepare for NSE7 with more than an answer.

217 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Advanced/Architect
Valid for
2 years from completion
  1. 1

    An engineer has configured a FortiGate with two BGP neighbors. Neighbor A is advertising a route to 192.168.1.0/24 with a MED of 200. Neighbor B is advertising the same route with a MED of 100. All other BGP attributes (Weight, Local Preference, AS-Path) are identical for both routes. Which route will the FortiGate install in its routing table?

    Show answer details

    Correct answer: B

    The Multi-Exit Discriminator (MED) is a BGP attribute used to influence how a neighboring AS enters your AS at multiple points. When comparing routes from the same neighboring AS, the route with the lower MED value is preferred. In this case, since all higher-priority attributes are equal, the FortiGate will choose the path from Neighbor B because its MED of 100 is lower than Neighbor A's MED of 200.

  2. 2

    Case Study:

    RetailCorp manages 300 retail stores, each with a FortiGate, all centrally managed by FortiManager 7.2.2. The network team needs to deploy a new, standardized firewall policy to all stores to allow guest Wi-Fi access. However, each store has a unique IP subnet for its guest Wi-Fi network. The team wants to use a single policy package and a single firewall policy rule for easy management.

    The current process involves creating 300 separate address objects and 300 separate policy rules, which is unmanageable. The lead architect wants to leverage FortiManager's dynamic object capabilities to solve this problem.

    Each FortiGate in FortiManager has a device-specific variable defined, guest_subnet, which contains the correct guest network for that store (e.g., '192.168.101.0/24' for Store 101, '192.168.102.0/24' for Store 102).

    How can the architect configure a single firewall policy that uses the correct guest subnet for each store upon installation?

    Show answer details

    Correct answer: B

    This is the primary use case for FortiManager metadata variables (device-specific variables). By creating a dynamic address object and using the $(variable_name) syntax, the architect instructs FortiManager to substitute the placeholder with the value of the guest_subnet variable defined for each specific device during policy installation. This allows a single policy rule to be deployed across all 300 stores, with each store receiving a policy customized with its unique guest subnet.

  3. 3

    Which three elements are part of the Fortinet Security Fabric foundation? (Select THREE)

    Show answer details

    Correct answer: A, B, D

  4. 4

    A financial institution is using application control to block peer-to-peer (P2P) applications. However, they discover that some users are still able to use a custom, internally developed P2P application. The application uses a non-standard port and its traffic is not being identified by the existing application control profile. What is the most effective way for an administrator to block this specific application without affecting other traffic?

    Show answer details

    Correct answer: A

    When a standard application signature does not exist, the best approach is to create a custom signature. By identifying a unique string or pattern within the application's protocol, an administrator can create a custom application signature. This signature can then be categorized and blocked within the application control profile, providing precise control without impacting other legitimate applications.

  5. 5

    An administrator is configuring a dial-up IPsec VPN to allow remote FortiGates to connect to a central hub. The administrator wants to assign specific firewall policies and settings to different groups of remote users. Which feature should be used on the hub FortiGate to accomplish this?

    Show answer details

    Correct answer: B

    The set usrgrp command within the Phase 1 configuration allows the hub FortiGate to match incoming dial-up VPN connections to a specific user group based on the peer ID or certificate information. This group membership can then be used as a source in firewall policies, allowing for granular control and different security profiles for different sets of remote dial-up clients.

  6. 6

    A solutions architect is designing an ADVPN topology with two hubs for redundancy. BGP is the chosen routing protocol. To prevent spokes from becoming a transit for traffic between the two hubs, a specific BGP community is typically used. Which BGP community should be advertised from the spokes to the hubs to achieve this?

    Show answer details

    Correct answer: D

    In a dual-hub ADVPN setup, spokes should advertise their prefixes to both hubs with the 'no-export-subconfed' (or simply 'no-export') community. When a hub receives a route from a spoke with this community, it uses it for its own routing table but does not re-advertise it to the other hub. This prevents the spokes from becoming transit ASs and avoids routing loops or suboptimal routing between data centers.

  7. 7

    A FortiGate is configured in an Active-Passive FGCP cluster. During a scheduled failover test, the administrator notices that all existing connections are dropped and must be re-established. Analysis of the cluster configuration shows that session pickup is enabled. What is the most likely reason for the sessions being dropped despite session pickup being enabled?

    Show answer details

    Correct answer: B

    Session pickup synchronizes session information for flow-based inspected traffic. However, sessions handled by a proxy (e.g., proxy-based web filtering or explicit proxy) are terminated on the primary FortiGate and new sessions are created. These proxy sessions are not synchronized to the secondary unit by default. Upon failover, the proxy daemon on the newly active unit has no state for these connections, causing them to be dropped.

  8. 8

    A network engineer is troubleshooting an OSPF issue where a FortiGate is not forming an adjacency with a Cisco router. The FortiGate is in OSPF area 1, which is configured as a Not-So-Stubby Area (NSSA). The Cisco router is in the same area but is configured as a standard, non-stub area. Both devices are on the same subnet and can ping each other. What is causing the adjacency to fail?

    Show answer details

    Correct answer: B

    For an OSPF adjacency to form, several parameters in the OSPF Hello packet must match between neighbors. One of the critical parameters is the area type (Stub Flag). If one router is configured for a standard area and the other is configured for a special area type like NSSA, the Hello packets will be considered incompatible, and the adjacency will not progress past the Init state.

  9. 9

    A security administrator needs to create a custom IPS signature to detect and block the string "confidential-project-alpha" in plain text HTTP traffic. The traffic could be in either the client request or the server response. Which of the following custom signature syntaxes is the most effective and efficient way to achieve this?

    Show answer details

    Correct answer: B

    This is the correct syntax. The --flow from_client,from_server keyword ensures the signature engine inspects traffic in both directions. The --service HTTP keyword optimizes the signature by telling the engine to only inspect decoded HTTP traffic, which is much more efficient than inspecting all TCP traffic on port 80. The --pattern keyword specifies the string to match.

  10. 10

    During a security audit, it was discovered that a junior administrator configured a new ADOM on FortiManager but assigned a FortiOS version of 6.4, while all the FortiGate devices to be managed are running FortiOS 7.2. What are the primary implications of this misconfiguration? (Select TWO)

    Show answer details

    Correct answer: B, D

Create an account to continue.