Fortinet

NSE7_NST-7.2 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 57-question bank.

Provider
Fortinet
Question bank
57
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE7_NST-7.2, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which action will FortiGate take when using the default settings for SSL certificate inspection?

    Choose one answer.

    • FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
    • FortiGate uses the CN information from the Subject field in the server certificate.
    • FortiGate uses the first entry listed in the SAN field in the server certificate.
    • FortiGate uses the SNI from the user’s web browser.
  2. Question 2 · 1

    Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs. What three conclusions can you draw from these log entries? (Choose three.)

    Choose all answers that apply.

    Question illustration 1
    • Remote registry is not running on the workstation.
    • The FortiGate firmware version is not compatible with that of the collector agent.
    • DNS resolution is unable to resolve the workstation name.
    • The user’s status shows as “not verified” in the collector agent.
    • A firewall is blocking traffic to port 139 and 445.
  3. Question 3 · 1

    Refer to the exhibit, which shows the output of get router info ospf neighbor. What can you conclude from the command output?

    Choose one answer.

    Question illustration 1
    • The local FortiGate is not a DROther.
    • All neighbors are in area 0.0.0.0.
    • The local FortiGate is the BDR.
    • The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.
  4. Question 4 · 1

    Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?

    Choose one answer.

    Question illustration 1
    • In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
    • In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
    • In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
    • In the phase 1 network configuration, set the IKE version to 2.
  5. Question 5 · 1

    What are two functions of automation stitches? (Choose two.)

    Choose all answers that apply.

    • You can configure automation stitches on any FortiGate device in a Security Fabric environment.
    • You can create automation stitches to run diagnostic commands and attach the results to an email message when CPU or memory usage exceeds specified thresholds.
    • An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action.
    • You can set an automation stitch configured to execute actions in parallel to insert a specific delay between actions.
  6. Question 6 · 1

    Refer to the exhibit, which shows partial outputs from two routing debug commands. Why is the port2 default route not in the second command output?

    Choose one answer.

    Question illustration 1
    • The port2 interface is disabled in the FortiGate configuration.
    • The port1 default route has a higher priority value than the default route using port2.
    • The port1 default route has a lower priority value than the default route using port2.
    • The port1 default route has a lower distance than the default route using port2.
  7. Question 7 · 1

    Refer to the exhibit, which shows the output of diagnose sys session stat. Which statement about the output shown in the exhibit is correct?

    Choose one answer.

    Question illustration 1
    • All the sessions in the session table are TCP sessions.
    • 162 sessions have been deleted because of memory page exhaustion.
    • There are 166 TCP sessions waiting to complete the three-way handshake.
    • There are two sessions that have not been removed in case of any out-of- order packets that arrive.
  8. Question 8 · 1

    Refer to the exhibit, which shows a truncated output of a real-time LDAP debug. What two conclusions can you draw from the output? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The name of the configured LDAP server is Lab.
    • The user is authenticating using CN=John Smith.
    • FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.
    • FortiOS is performing the second step (Search Request) in the LDAP authentication process.
  9. Question 9 · 1

    Refer to the exhibits. An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix. Which two actions can the administrator take to fix this problem? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    Question illustration 3
    • Restart BGP using a soft reset, which forces both peers to exchange their complete BGP routing tables.
    • Manually add the BGP route on FGT-A.
    • Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.
    • Use the set network-import-check disable command.
  10. Question 10 · 1

    Refer to the exhibit, which shows the output of a BGP debug command. Which statement explains why the state of the 10.200.3.1 peer is Connect?

    Choose one answer.

    Question illustration 1
    • The local router initiated the BGP session to 10.200.3.1 but did not receive a response.
    • The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the OpenConfirm yet.
    • The router 10.200.3.1 has authentication configured for BGP and the local router does not.
    • The local router has a different AS number than the remote peer.
  11. Question 11 · 1

    Refer to the exhibit, which shows the modified output of the routing kernel. Which statement is true?

    Choose one answer.

    Question illustration 1
    • The BGP route to 10.0.4.0/24 is not in the forwarding information base.
    • The default static route through port2 is in the forwarding information base.
    • The default static route through 10.200.1.254 is not in the forwarding information base.
    • The egress interface associated with static route 8.8.8.8/32 is administratively up.
  12. Question 12 · 1

    Refer to the exhibit. FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3. Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?

    Choose one answer.

    Question illustration 1
    • Enable asymmetric routing under config system settings.
    • Modify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
    • A firewall policy that allows all ICMP traffic from port3 to port1.
    • Change the configuration from strict RPF check mode to feasible RPF check mode.
  13. Question 13 · 1

    Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real-time debug? (Choose three.)

    Choose all answers that apply.

    • Refused connection. Potential mismatch of TCP port.
    • Mismatched pre-shared password.
    • Inability to reach IP address of the collector agent.
    • Log is full on the collector agent.
    • Incompatible collector agent software version.
  14. Question 14 · 1

    Refer to the exhibit, which shows one way communication of the downstream FortiGate with the upstream FortiGate within a Security Fabric. What three actions must you take to ensure successful communication? (Choose three.)

    Choose all answers that apply.

    Question illustration 1
    • Ensure the port for Neighbor Discovery has been changed.
    • FortiGate must not be in NAT mode.
    • Ensure TCP port 8013 is not blocked along the way.
    • You must authorize the downstream FortiGate on the root FortiGate.
    • You must enable Security Fabric/Fortitelemetry on the receiving interface of the upstream FortiGate.
  15. Question 15 · 1

    Which two statements about conserve mode are true? (Choose two.)

    Choose all answers that apply.

    • FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.
    • FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.
    • FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.
    • FortiGate exits conserve mode when the system memory goes below the configured green threshold.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free