Fortinet

NSE7_EFW-7.0 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 59-question bank.

Provider
Fortinet
Question bank
59
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE7_EFW-7.0, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)

    Choose all answers that apply.

    • OSPF interface network types match.
    • OSPF router IDs are unique.
    • OSPF interface priority settings are unique.
    • Authentication settings match.
    • OSPF link costs match.
  2. Question 2 · 1

    Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate. An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovered that FortiGate is not matching the user-2 VPN for members of the Users-2 group. Which two changes must the administrator make to fix the issue? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • Use different pre-shared keys on both VPNs.
    • Enable XAuth on both VPNs.
    • Set up specific peer IDs on both VPNs.
    • Change to aggressive mode on both VPNs.
  3. Question 3 · 1

    Refer to the exhibit, which shows partial outputs from two routing debug commands. Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?

    Choose one answer.

    Question illustration 1
    • Set the priority of the static default route using port1 to 10.
    • Set the priority of the static default route using port2 to 1.
    • Set preserve-session-route to enable.
    • Set snat-route-change to enable.
  4. Question 4 · 1

    Refer to the exhibit, which shows a partial routing table. Assuming all the appropriate firewall policies are configured, what two changes would an administrator need to make if they wanted to send traffic from a client directly connected to port3, to a server directly connected to port4? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Configure route leaking between VRF 12 and VRF 21.
    • Disable auto-asic-offload as this is not supported between VRF instances.
    • Configure RIPv2 to exchange route information between the VRF instances.
    • Configure route leaking between port3 and port4.
    • Enable SNAT on the relevant firewall policies to prevent RPF check drops.
  5. Question 5 · 1

    What is the diagnose test application ipsmenitor 5 command used for?

    Choose one answer.

    • To enable IPS bypass mode
    • To disable the IPS engine
    • To restart all IPS engines and monitors
    • To provide information regarding IPS sessions
  6. Question 6 · 1

    An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device. What can the administrator do to fix this problem?

    Choose one answer.

    • Configure remote link monitoring to detect an issue in the forwarding path.
    • Configure set send-garp-on-failover enable under config system ha on both cluster members.
    • Verify that the speed and duplex settings match between the FortiGate interfaces and the connected switch ports.
    • Configure set link-failed-signal enable under config system ha on both cluster members.
  7. Question 7 · 1

    Which statement about IKE and IKE NAT-T is true?

    Choose one answer.

    • IKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface.
    • IKE is the standard implementation for IKEv1 and IKE NAT-T is an extension added in IKEv2.
    • They both use UDP as their transport protocol and the port number is configurable.
    • They each use their own IP protocol number.
  8. Question 8 · 1

    Refer to the exhibit, which contains the partial output of a diagnose command. Based on the output, which two statements are correct? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The remote gateway has quick mode selectors containing a destination subnet of 10.1.2.0/24.
    • The remote gateway IP is 10.200.5.1.
    • DPD is disabled.
    • Anti-replay is enabled.
  9. Question 9 · 1

    Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?

    Choose one answer.

    • Only the DR receives link state information from non-DR routers.
    • Non-DR and non-BDR routers form full adjacencies to DR only.
    • Non-DR and non-BDR routers send link state updates and acknowledgements to 224.0.0.6.
    • FortiGate first checks the OSPF ID to elect a DR.
  10. Question 10 · 1

    An administrator has been assigned the task of creating a set of firewall policies which must be evaluated before any custom policies defined within the policy packages of managed FortiGate devices, across all 25 ADOMSs in FortiManager. How should the administrator accomplish this task?

    Choose one answer.

    • Create a footer policy in the Global ADOM containing the firewall policies that must be evaluated first, and then assign this footer policy to all other ADOMs.
    • Create a header policy in the Global ADOM containing the firewall policies that must be evaluated first, and then assign this header policy to all other ADOMs.
    • Move the FortiGate devices into a single globally scoped ADOM, and merge policy packages, inserting the new firewall policies at the top.
    • Use a CLI script from the root ADOM on FortiManager to push these new policies to all FortiGate devices, through the FGFM tunnel.
  11. Question 11 · 1

    Which configuration can be used to reduce the number of BGP sessions in an IBGP network?

    Choose one answer.

    • route-reflector enable
    • route-reflector-server enable
    • route-reflector-client enable
    • route-reflector-peer enable
  12. Question 12 · 1

    Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?

    Choose one answer.

    Question illustration 1
    • In the phase 1 network configuration, set the IKE version to 2.
    • In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
    • In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
    • In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
  13. Question 13 · 1

    Refer to the exhibit, which shows the output of a debug command. What can be concluded from the debug command output?

    Choose one answer.

    Question illustration 1
    • The OSPF router with the ID 0.0.0.69 has its OSPF priority set to 0.
    • The local FortiGate has a different MTU value from the OSPF router with ID 0.0.0.2, based on the state information.
    • There are more than two OSPF routers on the wan2 network.
    • The interface ToRemote is a broadcast OSPF network.
  14. Question 14 · 1

    Refer to the exhibit, which shows a FortiGate configuration. An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy. What must the administrator do to fix the issue?

    Choose one answer.

    Question illustration 1
    • Increase webfilter-timeout.
    • Change protocol to TCP.
    • Enable fortiguard-anycast.
    • Disable webfilter-force-off.
  15. Question 15 · 1

    Which two configuration commands change the default behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

    Choose all answers that apply.

    • set av-failopen off
    • set av-failopen pass
    • set fail-open enable
    • set ips fail-open disable

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free