NSE7-EFW-7-0 Fortinet NSE 7 - Enterprise Firewall 7.0 Practice Questions
Prepare for NSE7-EFW-7-0 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 204 questions Locked
- NSE7_EFW-6.2Legacy Fortinet NSE 7 - Enterprise Firewall 6.2 53 questions Locked
- NSE7-EFW-7-0Legacy Fortinet NSE 7 - Enterprise Firewall 7.0 222 questions Current
- NSE7-EFW-7-2Legacy Fortinet NSE 7 - Enterprise Firewall 7.2 203 questions Locked
- Exam fee
- $400 USD
- Level
- Solution Specialist
- Valid for
- 2 years from completion of second exam
Domains covered on the exam 5
- System and Session Troubleshooting20%
- Central Management15%
- Content Inspection20%
- Routing20%
- VPN25%
- 1
The command
diagnose firewall iprope lookup 10.1.1.5 8.8.8.8 6 50000 10.1.1.1is executed on a FortiGate. What specific information is this command trying to find?Show answer details
Correct answer: B
The
diagnose firewall iprope lookupcommand simulates the path a packet would take through the FortiGate's forwarding plane. It uses the provided parameters (source IP, destination IP, protocol, source port, destination port, and source interface) to determine which route in the FIB (Forwarding Information Base) and which firewall policy would match this specific traffic flow. It is a powerful tool for verifying both routing and policy configuration for a hypothetical packet without actually sending traffic. - 2
What are two key functions of the Next Hop Resolution Protocol (NHRP) in a FortiOS ADVPN implementation? (Choose two.)
Show answer details
Correct answer: B, C
Spokes use NHRP registration messages to inform the hub (which acts as the Next Hop Server) of their public 'underlay' IP address and the corresponding 'overlay' VPN tunnel IP address. This builds a dynamic mapping database on the hub.
When one spoke needs to build a direct shortcut tunnel to another, it sends an NHRP resolution request to the hub. The hub uses its registration database to look up the public IP of the destination spoke and sends this information back to the requesting spoke, enabling the direct tunnel negotiation.
- 3
An administrator needs to allow a specific web application that is currently being blocked by the 'Proxy Avoidance' web filter category. The application uses multiple, dynamically changing domain names, making a static URL filter impractical. What is the best method to allow this application while minimizing changes to the existing security posture?
Show answer details
Correct answer: B
Since the domains change dynamically, URL-based or category-based filtering is unreliable. The best approach is to use Application Control. If a pre-defined signature exists for the application, it can be allowed. If not, a custom application signature can be created based on unique patterns in the application's traffic (like hostnames, user agents, or other headers). This allows for precise control of the application itself, regardless of its IP or domain, without weakening the 'Proxy Avoidance' web filter category for all other traffic.
- 4
True or False: In a FortiGate active-active HA cluster, if
session-pickupis enabled, both TCP and UDP sessions established on the primary unit will be synchronized and maintained after a failover to the secondary unit.Show answer details
Correct answer: A
True. When
session-pickupis enabled, the primary unit synchronizes its session table with the secondary unit(s). This includes both connection-oriented TCP sessions and connectionless UDP and ICMP sessions. After a failover, the new primary unit has a copy of the session table and can continue processing the existing traffic without requiring sessions to be re-established. - 5
An FGCP cluster is configured in active-passive mode. The command
get system ha statusshows that both units believe they are the primary (master) unit. What is this condition called and what is the most likely cause?graph TD subgraph "Data Center" FW1[FortiGate-1 (Master?)] FW2[FortiGate-2 (Master?)] SW1[Switch-1] SW2[Switch-2] end FW1 -- Heartbeat --> SW1 FW2 -- Heartbeat --> SW2 SW1 -. X .-> SW2 style X fill:#f00,stroke:#f00,stroke-width:2px,color:#fffShow answer details
Correct answer: B
This condition is called a split-brain. It occurs when the HA cluster members can no longer communicate with each other over the heartbeat link. When the slave unit stops receiving heartbeat packets from the master, it assumes the master has failed and promotes itself to master. The result is two active master units, both trying to process traffic, which can cause severe network instability. The root cause is almost always a physical or logical failure of the heartbeat link (e.g., a disconnected cable, a failed switch port, or a VLAN misconfiguration).
- 6
An administrator is troubleshooting an OSPF adjacency issue between two FortiGate devices. The
diagnose ip router ospf neighborcommand shows the neighbor state is stuck inExStart. Both devices are on the same broadcast network segment. What is the most likely cause of this issue?Show answer details
Correct answer: B
The OSPF
ExStartstate indicates that the devices have established two-way communication but are failing to exchange database description (DBD) packets. A common reason for this failure on broadcast networks is an MTU mismatch between the interfaces, which prevents the larger DBD packets from being successfully exchanged. Mismatched area IDs or router IDs would prevent the adjacency from even reaching theExStartstate, and mismatched hello timers would result in a state flapping betweenDownandInitor2-Way. - 7
A financial firm uses an ADVPN architecture with BGP for routing between its headquarters (Hub) and multiple branches (Spokes). A new spoke is deployed, but it is unable to establish dynamic spoke-to-spoke tunnels with other spokes. The new spoke can, however, communicate with resources behind the hub. Which two settings are common causes for this specific issue? (Choose two.)
Show answer details
Correct answer: B, E
For ADVPN to function, the
advpnoption must be enabled in the IPsec Phase 1 configuration on all participating spokes. If it's disabled on the new spoke, it will not attempt to create dynamic shortcut tunnels.The
auto-discovery-sendersetting on a spoke's Phase 1 allows it to initiate shortcut offers to other spokes. If this is disabled, the spoke cannot trigger the creation of a spoke-to-spoke tunnel, which matches the described symptom. - 8
During a failover event in an active-passive FGCP cluster, an administrator observes that all BGP sessions are torn down and must be re-established, causing a significant traffic disruption. Which configuration setting is required to minimize this disruption?
Show answer details
Correct answer: B
BGP Graceful Restart allows a BGP speaker to inform its neighbors of its impending restart (or in this case, a failover). The neighbors will then retain the routes learned from the restarting speaker for a specified period, preventing the forwarding table from being cleared. This allows traffic to continue flowing while the BGP sessions are re-established on the newly active cluster member, minimizing disruption.
session-pickupis for user sessions, not control plane protocols like BGP. - 9
A FortiGate is configured with two static default routes pointing to different ISPs. Route 1 has a priority of 10 and Route 2 has a priority of 20. An active session is using Route 1. The administrator changes the priority of Route 1 to 30. What happens to the existing session if
snat-route-changeis disabled?Show answer details
Correct answer: C
When
snat-route-changeis disabled (the default setting), FortiOS does not re-evaluate the route for existing sessions when the routing table changes. The session is tied to its original egress interface and next-hop. Therefore, the existing session will continue to use Route 1, even though it is no longer the preferred route, until the session naturally concludes or times out. New sessions would use the new best route (Route 2). - 10
An administrator is diagnosing why a policy package installation from FortiManager to a managed FortiGate is failing. The error message indicates a 'commit failure'. The administrator verifies that there is network connectivity between the devices and that the FortiGate is online in FortiManager. What is a likely cause of this failure?
Show answer details
Correct answer: B
A 'commit failure' typically means that FortiManager successfully sent the configuration to the FortiGate, but the FortiGate itself rejected the configuration when trying to commit it to its running config. This is often due to a syntax error, a reference to a non-existent object (like an interface or address object that doesn't exist on that specific FortiGate), or a feature that is not supported by the device's specific hardware model or license.
