Fortinet

NSE7_LED-7.0 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 44-question bank.

Provider
Fortinet
Question bank
44
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE7_LED-7.0, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit. Examine the FortiGate user group configuration and the Windows AD LDAP group membership information shown in the exhibit. FortiGate is configured to authenticate SSL VPN users against Windows AD using LDAP. The administrator configured the SSL VPN user group for SSL VPN users. However, the administrator noticed that both the t and student and jsmith users can connect to SSL VPN. Which change can the administrator make on FortiGate to restrict the SSL VPN service to the student user only?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • In the SSL VPN user group configuration, set Group Name to CN=SSLVPN,CN=Users,DC=trainingAD,DC=training,DC=lab.
    • In the SSL VPN user group configuration, change Name to CN=SSLVPN,CN=Users,DC=trainingAD,DC=training,DC=lab.
    • In the SSL VPN user group configuration, set Group Name to CN=Domain Users,CN=Users,DC=trainingAD,DC=training,DC=lab.
    • In the SSL VPN user group configuration, change Type to Fortinet Single Sign-On (FSSO).
  2. Question 2 · 1

    Refer to the exhibits. In the wireless configuration shown in the exhibits, an AP is deployed in a remote site and has a wireless network (VAP) called Corporate deployed to it. The network is a tunnelled network; however, clients connecting to a wireless network require access to a local printer. Clients are trying to print to a printer on the remote site, but are unable to do so. Which configuration change is required to allow clients connected to the Corporate SSID to print locally?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Configure split-tunneling in the vap configuration.
    • Configure split-tunneling in the wtp-profile configuration.
    • Disable the Block Intra-SSID Traffic (Intra-vap-privacy) setting on the SSID (VAP) profile.
    • Configure the printer as a wireless client on the Corporate wireless network.
  3. Question 3 · 1

    Which EAP method requires the use of a digital certificate on both the server end and the client end?

    Choose one answer.

    • EAP-TTLS
    • PEAP
    • EAP-GTC
    • EAP-TLS
  4. Question 4 · 1

    Refer to the exhibit. Examine the FortiManager configuration and FortiGate CLI output shown in the exhibit. An administrator is testing the NAC feature. The test device is connected to a managed FortiSwitch device (S224EPTF19005867) on port2. After applying the NAC policy on port2 and generating traffic on the test device, the test device is not matching the NAC policy; therefore, the test device remains in the onboarding VLAN. Based on the information shown in the exhibit, which two scenarios are likely to cause this issue? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Management communication between FortiGate and FortiSwitch is down.
    • The MAC address configured on the NAC policy is incorrect.
    • The device operating system detected by FortiGate is not Linux.
    • Device detection is not enabled on VLAN 4089.
  5. Question 5 · 1

    Which two pieces of information can the diagnose test authserver ldap command provide? (Choose two.)

    Choose all answers that apply.

    • It displays whether the admin bind user credentials are correct.
    • It displays whether the user credentials are correct.
    • It displays the LDAP codes returned by the LDAP server.
    • It displays the LDAP groups found for the user.
  6. Question 6 · 1

    You are setting up an SSID (VAP) to perform RADIUS-authenticated dynamic VLAN allocation. Which three RADIUS attributes must be supplied by the RADIUS server to enable successful VLAN allocation? (Choose three.)

    Choose all answers that apply.

    • Tunnel-Private-Group-ID
    • Tunnel-Pvt-Group-ID
    • Tunnel-Preference
    • Tunnel-Type
    • Tunnel-Medium-Type
  7. Question 7 · 1

    Refer to the exhibit. Examine the FortiManager information shown in the exhibit. Which two statements about the FortiManager status are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • FortiSwitch manager is working in per-device management mode.
    • FortiSwitch is not authorized.
    • FortiSwitch manager is working in central management mode.
    • FortiSwitch is authorized and offline.
  8. Question 8 · 1

    An administrator is testing the connectivity for a new VLAN. The devices in the VLAN are connected to a FortiSwitch device that is managed by FortiGate. Quarantine is disabled on FortiGate. While testing, the administrator noticed that devices can ping FortiGate and FortiGate can ping the devices. The administrator also noticed that inter-VLAN communication works. However, intra-VLAN communication does not work. Which scenario is likely to cause this issue?

    Choose one answer.

    • The native VLAN configured on the ports is incorrect.
    • The FortiSwitch MAC address table is missing entries.
    • The FortiGate ARP table is missing entries.
    • Access VLAN is enabled on the VLAN.
  9. Question 9 · 1

    Refer to the exhibit. By default, FortiOS creates the following DHCP server scope for the FortiLink interface as shown in the exhibit. What is the objective of the vci-string setting?

    Choose one answer.

    Question illustration 1
    • To ignore DHCP requests coming from FortiSwitch and FortiExtender devices
    • To reserve IP addresses for FortiSwitch and FortiExtender devices
    • To restrict the IP address assignment to FortiSwitch and FortiExtender devices
    • To restrict the IP address assignment to devices that have FortiSwitch or FortiExtender as their hostname
  10. Question 10 · 1

    What is the purpose of enabling Windows Active Directory Domain Authentication on FortiAuthenticator?

    Choose one answer.

    • It enables FortiAuthenticator to use Windows administrator credentials to perform an LDAP lookup for a user search.
    • It enables FortiAuthenticator to use a Windows CA certificate when authenticating RADIUS users.
    • It enables FortiAuthenticator to import users from Windows AD.
    • It enables FortiAuthenticator to register itself as a Windows trusted device to proxy authentication using Kerberos.
  11. Question 11 · 1

    Refer to the exhibits. Examine the firewall policy configuration and SSID settings. An administrator has configured a guest wireless network on FortiGate using the external captive portal. The administrator has verified that the external captive portal URL is correct. However, wireless users are not able to see the captive portal login page. Given the configuration shown in the exhibit and the SSID settings, which configuration change should the administrator make to fix the problem?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Disable the user group from the SSID configuration.
    • Enable the captive-portal-exempt option in the firewall policy with the ID 11.
    • Apply a guest.portal user group in the firewall policy with the ID 11.
    • Include the wireless client subnet range in the Exempt Source section.
  12. Question 12 · 1

    Refer to the exhibit. Examine the LDAP server configuration shown in the exhibit. Note that the Username setting has been expanded to display its full content. On the Windows AD server 10.0.1.10, the administrator used dsquery, which returned the following output: >dsquery user -samid student "CN=student,CN=Users,DC=trainingAD,DC=training,DC=lab" According to the output, which FortiGate LDAP setting is configured incorrectly?

    Choose one answer.

    Question illustration 1
    • Common Name Identifier
    • Bind Type
    • Distinguished Name
    • Username
  13. Question 13 · 1

    Refer to the exhibit. Examine the FortiGate configuration, FortiAnalyzer logs, and FortiGate widget shown in the exhibit. An administrator is testing the Security Fabric quarantine automation. The administrator added FortiAnalyzer to the Security Fabric, and configured an automation stitch to automatically quarantine compromised devices. The test device (10.0.2.1) is connected to a managed FortiSwitch device. After trying to access a malicious website from the test device, the administrator verifies that FortiAnalyzer has a log for the test connection. However, the device is not getting quarantined by FortiGate, as shown in the quarantine widget. Which two scenarios are likely to cause this issue? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The web filtering rating service is not working.
    • FortiAnalyzer does not have a valid threat detection services license.
    • The device does not have FortiClient installed.
    • FortiAnalyzer does not consider the malicious website an indicator of compromise (IOC).
  14. Question 14 · 1

    Refer to the exhibits. Examine the troubleshooting outputs shown in the exhibits. Users have been reporting issues with the speed of their wireless connection in a particular part of the wireless network. The interface that is having issues is the 2.4 GHz interface that is currently configured on channel 6. The administrator of the wireless network has investigated and surveyed the local RF environment using the tools available at the AP and FortiGate. Which configuration would improve the wireless connection?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Change the AP 2.4 GHz channel to 11
    • Change the AP 2.4 GHz channel to 1
    • Change the AP 2.4 GHz channel to 9.
    • Change the AP 2.4 GHz channel to 13.
  15. Question 15 · 1

    Refer to the exhibit. Examine the debug output shown in the exhibit. Which two statements about the RADIUS debug output are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The user student belongs to the SSLVPN group.
    • User authentication failed.
    • The RADIUS server sent a vendor-specific attribute in the RADIUS response.
    • User authentication succeeded using MSCHAP.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free