NSE7-EFW-7-2 Fortinet NSE 7 - Enterprise Firewall 7.2 Practice Questions
Prepare for NSE7-EFW-7-2 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 204 questions Locked
- NSE7_EFW-6.2Legacy Fortinet NSE 7 - Enterprise Firewall 6.2 53 questions Locked
- NSE7-EFW-7-0Legacy Fortinet NSE 7 - Enterprise Firewall 7.0 222 questions Locked
- NSE7-EFW-7-2Legacy Fortinet NSE 7 - Enterprise Firewall 7.2 203 questions Current
- Exam fee
- $400 USD
- Level
- Solution Specialist
- Valid for
- 2 years
Domains covered on the exam 5
- System Configuration20%
- Central Management20%
- Security Profiles20%
- Routing20%
- VPN20%
- 1
What is the primary function of the
auto-asic-offloadsetting within a FortiGate firewall policy?Show answer details
Correct answer: B
The
auto-asic-offloadsetting, which is enabled by default on firewall policies, instructs the FortiGate to offload sessions that match the policy to hardware ASICs (like NP processors) if the session is eligible for acceleration. This significantly improves performance by moving packet processing from the main CPU to specialized hardware. Disabling this setting forces all matching traffic to be processed by the CPU, which might be necessary for troubleshooting or for features incompatible with offloading. - 2
An OSPF Area Border Router (ABR) is configured to connect Area 0 and Area 1. The administrator wants to reduce the size of the routing table in Area 1. Which OSPF feature should be configured on the ABR to achieve this?
Show answer details
Correct answer: C
Route summarization is the correct feature to reduce the size of routing tables in adjacent areas. By configuring an
area range(summarization) on the ABR for Area 0, the ABR will advertise a single summary route into Area 1 instead of multiple specific prefixes from Area 0. This directly reduces the number of LSAs and routing table entries within Area 1. While stubby areas also reduce routing table size, summarization provides more granular control. - 3
A retail company uses a hub-and-spoke ADVPN topology. The hub is experiencing high CPU load because it is routing a large volume of traffic between two specific spokes that are transferring large backup files nightly. What is the most effective solution to reduce the CPU load on the hub FortiGate?
Show answer details
Correct answer: C
The core benefit of ADVPN is its ability to create dynamic, direct tunnels (shortcuts) between spokes. If the hub is routing traffic between spokes, it implies that these shortcuts are not forming or are not being used. The most effective solution is to troubleshoot the ADVPN configuration (including routing and IKE settings) to ensure that spokes can establish direct tunnels for their traffic. Once the shortcut is established, the backup traffic will flow directly between the spokes, bypassing the hub and significantly reducing its CPU load.
- 4
A junior administrator used a CLI script in FortiManager to change the NTP server settings on a group of 50 managed FortiGates. After running the script, the administrator notices that the device configurations in FortiManager are now shown as 'Out of Sync'. What is the reason for this status?
Show answer details
Correct answer: B
When a script is run with the target set to 'Remote FortiGate Directly', FortiManager connects to the device and applies the configuration changes live. This bypasses the FortiManager's own database for that device. As a result, the live configuration on the FortiGate no longer matches the configuration stored in FortiManager's database, leading to an 'Out of Sync' status. To resolve this, the administrator must re-import the configuration from the device.
- 5
A company has a security policy that prohibits employees from uploading files to personal cloud storage services. Which two FortiGate features are most effective for enforcing this policy? (Select TWO)
Show answer details
Correct answer: B, C
Application Control is the primary tool for identifying and controlling specific applications or categories of applications, such as cloud storage. Blocking the 'Storage.Backup' category will prevent access to most common cloud storage services. For a more granular approach, a Data Loss Prevention (DLP) sensor can be used to inspect traffic and block sessions that involve file uploads, regardless of the specific application, providing a second layer of enforcement.
- 6
A financial services firm has deployed a FortiGate HA cluster in Active-Passive mode. To comply with audit requirements, all administrative changes to the primary unit must be synchronized to the secondary unit in real-time, including CLI commands entered directly on the primary. Which configuration setting ensures this behavior?
Show answer details
Correct answer: D
The
set configuration-sync-mode incrementalcommand underconfig system haensures that any configuration changes, including those made via the CLI, are synchronized incrementally and immediately to the secondary unit. This is crucial for maintaining configuration parity for compliance and operational consistency.session-pickuprelates to synchronizing session tables, not configuration. The other options are not valid FortiOS commands. - 7
A network architect is designing a large-scale enterprise network with multiple regional data centers. They plan to use OSPF as the IGP within each region and BGP to connect the regions. To prevent routing loops and ensure optimal path selection, which BGP attribute should be manipulated on the regional border routers to influence how other regions enter their network?
Show answer details
Correct answer: B
The Multi-Exit Discriminator (MED) is a non-transitive BGP attribute used to influence how a neighboring AS enters your AS when multiple entry points exist. A lower MED value is preferred. This makes it the ideal attribute for regional border routers to signal to other regions which entry point is optimal. Local Preference influences outbound traffic, AS Path Prepending also influences inbound traffic but is less granular, and Weight is local to the router.
- 8
An administrator is configuring an ADVPN network with two hubs and multiple spokes. To ensure that spoke-to-spoke traffic can establish direct shortcut tunnels without traversing a hub, which two settings are essential on the hub's Phase 1 configuration? (Select TWO)
Show answer details
Correct answer: A, D
For ADVPN to function, the hub must act as the central point for shortcut negotiation messages (IKE_CREATE_CHILD_SA).
set auto-discovery-sender enableallows the hub to send shortcut offers to spokes.set auto-discovery-receiver enableallows the hub to receive shortcut requests from spokes and forward them to the correct destination spoke. Together, these settings enable the hub to facilitate the dynamic creation of spoke-to-spoke tunnels. - 9
A security analyst at a healthcare organization is investigating an alert from the FortiGate IPS. The alert indicates a potential SQL injection attack from an internal IP address to a critical patient records server. To perform a thorough forensic analysis, the analyst needs to see the exact payload that triggered the IPS signature. What must be configured on the IPS sensor for this data to be available in the logs?
Show answer details
Correct answer: C
To capture the actual packet data that triggers an IPS signature, 'packet logging' must be enabled within the specific IPS sensor applied to the traffic. This feature saves a copy of the triggering packet(s) to the log, which is invaluable for forensic analysis to confirm the attack's nature and payload. Other logging settings, like extended logging or firewall policy logging, do not capture the packet payload for IPS events.
- 10
True or False: When FortiManager is used as a local FortiGuard Distribution Server (FDS), it can cache and distribute antivirus and IPS updates, but web filtering and antispam rating lookups from managed FortiGates still require a direct connection to public FortiGuard servers.
Show answer details
Correct answer: B
This statement is false. When FortiManager is configured as a local FDS, it can serve not only AV and IPS updates but also handle real-time web filtering and antispam rating requests. This allows managed FortiGates in a closed or bandwidth-constrained network to perform these lookups locally against the FortiManager, which then queries the public FortiGuard network on their behalf.
