Fortinet

NSE7_EFW-7.2 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 72-question bank.

Provider
Fortinet
Question bank
72
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE7_EFW-7.2, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit, which contains a TCL script configuration on FortiManager. An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any changes to the managed device after being run. Why did the TCL script fail to make any changes to the managed device?

    Choose one answer.

    Question illustration 1
    • The TCL procedure run_cmd has not been created.
    • The TCL script must start with #include.
    • There is no corresponding #! to signify the end of the script.
    • The TCL procedure lacks the required loop statements to iterate through the changes.
  2. Question 2 · 1

    Refer to the exhibit, which shows the output of a BGP summary. What two conclusions can you draw from this BGP summary? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The BGP session with peer 10.127.0.75 is established.
    • External BGP (EBGP) exchanges routing information.
    • The router 100.64.3.1 has the parameter bfd set to enable.
    • The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.
  3. Question 3 · 1

    Refer to the exhibit, which shows a custom signature. Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Ensure that the header syntax is F-SBID.
    • Add severity.
    • Add attack_id.
    • Start options with --.
  4. Question 4 · 1

    What are two functions of automation stitches? (Choose two.)

    Choose all answers that apply.

    • Automation stitches can be created to run diagnostic commands and email the results when CPU or memory usage exceeds specified thresholds.
    • An automation stitch configured to execute actions in parallel can be set to insert a specific delay between actions.
    • Automation stitches can be configured on any FortiGate device in a Security Fabric environment.
    • An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action.
  5. Question 5 · 1

    Refer to the exhibit which shows config system central-management information. Which setting must you configure for the web filtering feature to function?

    Choose one answer.

    Question illustration 1
    • Set update-server-location to automatic
    • Add server.fortiguard.net to the Server list
    • Configure securewf.fortiguard.net on the default servers
    • Configure server-type with the rating option
  6. Question 6 · 1

    Which two statements about the Security Fabric are true? (Choose two.)

    Choose all answers that apply.

    • FortiGate uses the FortiTelemetry protocol to communicate with FortiAnalyzer
    • Only the root FortiGate sends logs to FortiAnalyzer
    • Only FortiGate devices with configuration-sync set to default receive and synchronize global CMDB objects that the root FortiGate sends
    • Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer
  7. Question 7 · 1

    Refer to the exhibit, which shows a network diagram. Which protocol should you use to configure the FortiGate cluster?

    Choose one answer.

    Question illustration 1
    • FGCP in active-passive mode
    • FGCP in active-active mode
    • FGSP
    • VRRP
  8. Question 8 · 1

    After enabling IPS, you receive feedback about traffic being dropped. What could be the reason?

    Choose one answer.

    • IPS is configured to monitor.
    • np-accel-node is set to enable.
    • fail-open is set to disable.
    • traffic-submit is set to disable.
  9. Question 9 · 1

    Refer to the exhibit which shows an ADVPN network. Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • set auto-discovery-sender enable
    • set auto-discovery-receiver enable
    • set add-route enable
    • set auto-discovery-forwarder enable
  10. Question 10 · 1

    You want to improve reliability over a lossy IPSec tunnel. Which combination of IPSec phase 1 parameters should you configure?

    Choose one answer.

    • fec-ingress and fsc-egrsss
    • dpd and dpd-retryinterval
    • fragmentation and fragmentation-mtu
    • keepalive and keylive
  11. Question 11 · 1

    Refer to the exhibits, which contain the network topology and BGP configuration for a hub. Exhibit A. Exhibit B. An administrator is trying to configure ADVPN with a hub and spoke VPN setup using iBGP. All the VPNs are up and connected to the hub. The hub is receiving route information from both spokes over iBGP; however the spokes are not receiving route information from each other. What change must the administrator make to the hub BGP configuration so that the routes learned from one spoke are forwarded to the other spoke?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Configure the hub as a route reflector
    • Configure auto-discovery-sender on the hub
    • Add a prefix list to the hub that permits routes to be shared between the spokes
    • Enable route redistribution under config router bgp
  12. Question 12 · 1

    Refer to the exhibit, which contains a partial VPN configuration. What can you conclude from this configuration?

    Choose one answer.

    Question illustration 1
    • FortiGate creates separate virtual interfaces for each dial-up client
    • The VPN should use the dynamic routing protocol to exchange routing information through the tunnels
    • Dead peer detection is disabled
    • The routing table shows a single IPSec virtual interface
  13. Question 13 · 1

    Refer to the exhibit which shows information about an OSPF interface. What two conclusions can you draw from this command output? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The interfaces of the OSPF routers match the MTU value that is configured as 1500.
    • NGFW-1 is the designated router.
    • The port3 network has more than one OSPF router.
    • The OSPF routers are in the area ID of 0.0.0.1.
  14. Question 14 · 1

    Which two statements about the BFD parameter in BGP are true? (Choose two.)

    Choose all answers that apply.

    • It detects only two-way failures.
    • The two routers must be connected to the same subnet.
    • It allows failure detection in less than one second.
    • It is supported for neighbors over multiple hops.
  15. Question 15 · 1

    You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel; however, the VPN interfaces do not appear as available options. What step must you take to resolve this issue?

    Choose one answer.

    • Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces.
    • Install the VPN community and gateway configuration on the FortiGate devices so that the VPN interfaces appear on the Policy Objects on FortiManager.
    • Configure the phase 1 settings in the VPN community that you didn’t initially configure. FortiGate automatically generates the interfaces after you configure the required settings.
    • Create interface mappings for the IPsec VPN interfaces before you use them in a policy.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free