NSE7-LED-7-0 Fortinet NSE 7 - LAN Edge 7.0 Practice Questions
Prepare for NSE7-LED-7-0 with more than an answer.
- Exam fee
- $200 USD
- Level
- Advanced Professional
- Valid for
- 2 years
Domains covered on the exam 4
- Authentication25%
- FortiSwitch Management30%
- Wireless Networks35%
- Monitoring and Troubleshooting10%
- 1
A consultant is designing a guest Wi-Fi solution for a hotel using FortiAuthenticator as an external captive portal. The hotel requires a branded login page and wants to collect guest email addresses during registration. Which three components are necessary to build this solution? (Select THREE)
Show answer details
Correct answer: A, B, D
This is the starting point. The FortiGate's wireless controller needs an SSID configured to redirect unauthenticated users to an external portal, which in this case is FortiAuthenticator.
The FortiGate communicates with FortiAuthenticator via RADIUS to authenticate the guest users. FortiAuthenticator needs a client entry for the FortiGate to accept these requests. Enabling accounting is best practice for tracking guest sessions.
The Portal Policy on FortiAuthenticator is where the customization happens. It controls the look and feel of the login page, defines the fields for the self-registration form (like email), and specifies how the user credentials will be validated and what access they will be granted.
- 2
An organization uses digital certificates for SSL VPN authentication. A user who recently renewed their certificate reports that they can no longer connect. The administrator verifies the new certificate is valid and issued by the correct CA. On the FortiGate, the administrator observes the following debug output:
sslvpn_auth_check_usr_cert_peer: Peer cert verification failed, err=19:self signed certificate in certificate chain. What is the most likely cause of this error?Show answer details
Correct answer: B
The error
err=19:self signed certificate in certificate chainspecifically indicates that during the validation process, the FortiGate encountered a certificate that it could not trace back to a trusted root CA in its store. This typically happens when an intermediate CA certificate is missing. The FortiGate must have the entire chain of trust, from the user's certificate through any intermediate CAs up to the root CA, to successfully verify the peer's certificate. - 3
Which CLI command would an administrator use on a FortiGate to view the status and statistics of all connected FortiAPs?
Show answer details
Correct answer: C
The
diagnose wireless-controller wlac -c statuscommand provides a comprehensive overview of all FortiAPs managed by the FortiGate. It shows details such as the AP's serial number, IP address, uptime, firmware version, profile, and current connection state, making it a primary tool for CLI-based monitoring and troubleshooting. - 4
Case Study: Global Retail Inc.
Global Retail Inc. is overhauling its network infrastructure across 200 stores using Fortinet LAN Edge solutions. Each store has a FortiGate, multiple FortiSwitches, and several FortiAPs. All devices are managed centrally by FortiManager at the corporate headquarters.
The primary goal is to enforce a zero-trust policy at the network edge. Corporate users with domain-joined laptops must be authenticated via 802.1X and placed in VLAN 10. Store inventory scanners, which are non-802.1X capable, must be authenticated via MAB and placed in a segregated VLAN 20. A dedicated guest Wi-Fi network must use a captive portal and be completely isolated in VLAN 30.
An administrator has created a single switch port policy
corp-accesswith security mode802.1X-mac-basedto handle both corporate laptops and inventory scanners. Dynamic VLAN assignment is configured on the RADIUS server (FortiAuthenticator). However, early testing reveals that when an inventory scanner connects, it is not placed in VLAN 20 but instead gets the port's default native VLAN.What is the most likely reason for the dynamic VLAN assignment failing for the MAB-authenticated inventory scanners?
Show answer details
Correct answer: B
Dynamic VLAN assignment relies on the RADIUS server returning the correct attributes (
Tunnel-Type,Tunnel-Medium-Type,Tunnel-Private-Group-ID). In a combined 802.1X/MAB scenario, separate policies or rules are often needed on the RADIUS server. It is highly likely that while the policy for 802.1X users correctly returns the VLAN 10 attributes, the policy that matches the MAB request for the inventory scanner is not configured to return the attributes for VLAN 20, causing the switch to fall back to the native VLAN. - 5
An administrator is troubleshooting an EAP-TLS authentication failure for a corporate wireless user. The RADIUS server is FortiAuthenticator. The debug logs on FortiAuthenticator show the error "client certificate untrusted". The administrator has confirmed that the client certificate was issued by the correct internal CA. What is the most likely cause of this issue?
sequenceDiagram participant Supplicant participant FortiAP as Authenticator participant FAC as Auth Server Supplicant->>FortiAP: EAP-Start FortiAP->>FAC: Access-Request (EAP-Start) FAC-->>FortiAP: Access-Challenge (Server Hello, Server Cert) FortiAP-->>Supplicant: EAP-Request (Server Hello, Server Cert) Supplicant->>FortiAP: EAP-Response (Client Hello, Client Cert) FortiAP->>FAC: Access-Request (EAP-Response, Client Cert) FAC-->>FAC: Validate Client Cert against Trusted CAs Note right of FAC: Fails: "client certificate untrusted" FAC-->>FortiAP: Access-Reject FortiAP-->>Supplicant: EAP-FailureShow answer details
Correct answer: B
For FortiAuthenticator to validate and trust a client's certificate, it must have the complete certificate chain of the issuing CA in its own trusted CA certificate store. If the intermediate or root CA certificate is missing, FortiAuthenticator cannot establish the chain of trust and will reject the client certificate as untrusted.
- 6
A hospital is deploying a secure wired network using FortiSwitch and FortiAuthenticator. The requirements are to authenticate medical devices using MAC Authentication Bypass (MAB) and doctors' laptops using 802.1X EAP-TLS. Both device types connect to the same switch ports. The network administrator has configured the port security mode to
802.1X-mac-based. However, only the 802.1X authentications are succeeding; the MAB devices fail to connect. What is a potential cause for this issue on the FortiSwitch port configuration?Show answer details
Correct answer: B
In
802.1X-mac-basedsecurity mode, both 802.1X and MAB can be used. However, MAB is not enabled by default. The administrator must explicitly enable it on the interface using theset mac-auth-bypass enablecommand. If this is not set, the switch will not attempt MAB for non-802.1X capable devices, causing their connections to fail. - 7
An administrator is setting up RADIUS Single Sign-On (RSSO) with FortiAuthenticator to gather user group information from a Cisco Wireless LAN Controller (WLC). The WLC is configured to send RADIUS accounting messages to FortiAuthenticator. Despite correct configuration, no user logon events are appearing in the FortiAuthenticator logs. Which two settings are critical to verify for RSSO to function correctly in this scenario? (Select TWO)
Show answer details
Correct answer: C, D
For FortiAuthenticator to map users to groups via RSSO, it relies on specific RADIUS attributes. The
fortinet-group-nameVSA is the primary attribute used to convey group membership information in RADIUS accounting records.FortiAuthenticator will not process accounting messages from a RADIUS client unless the 'Enable RADIUS accounting' checkbox is explicitly enabled for that client's definition under
Authentication > RADIUS Service > Clients. - 8
An engineer is deploying a large campus network with FortiAPs managed by a FortiGate wireless controller. To improve roaming performance and reduce the impact of broadcast traffic, the engineer wants to convert broadcast traffic to unicast for known clients. Which FortiAP profile setting achieves this?
Show answer details
Correct answer: C
The
broadcast-suppressionsetting controls how the FortiAP handles broadcast packets. Setting it toarp-known-clientsinstructs the AP to convert ARP request broadcasts into unicast frames for clients it already has in its ARP table. This reduces unnecessary broadcast traffic over the air, improving overall wireless network efficiency. - 9
True or False: When configuring Zero-Touch Provisioning (ZTP) for a FortiSwitch using DHCP option 43, the FortiGate's IP address and the FortiLink interface name must be encoded in the option string.
Show answer details
Correct answer: A
This is true. For ZTP to work via DHCP option 43, the string must contain the IP address of the managing FortiGate and the name of the FortiLink interface that the switch should connect to. This information allows the switch to automatically establish the FortiLink connection upon boot-up.
- 10
A financial services company is implementing automatic quarantine for wired clients using the Fortinet Security Fabric. A requirement is that if a client PC is compromised and starts communicating with a known command-and-control server, it must be immediately moved to a remediation VLAN. Which component is responsible for triggering the quarantine action on the FortiSwitch?
Show answer details
Correct answer: C
In the Security Fabric, the FortiGate acts as the central enforcement point. When its security services (like IPS or Web Filter) detect an Indicator of Compromise (IoC), such as traffic to a C&C server, an automation stitch can be triggered. This stitch then instructs the FortiSwitch, via the FortiLink connection, to quarantine the offending client's switch port.
