Fortinet NSE7_EFW-6.4 Practice Test Pdf Exam Material
NSE7_EFW-6.4 Answers NSE7_EFW-6.4 Free Demo Are Based On The Real Exam
Topics of Fortinet NSE7_EFQ-6.4: Fortinet NSE 7 - Enterprise Firewall 6.4 Exam
Following are the objectives and agenda for this certification exam. A detailed practice for these contents could be done via the NSE7 EFW-6.4 practice exams as they are made on the same contents and offer the same environment for students to experience as the real exam does:
System and session troubleshooting
- FortiOS architecture
- Security Fabric
- High availability
- Perform initial configuration
- Implement the Fortinet Security Fabric
- Traffic and session monitoring
Central management
- Central management and analysis using FortiManager and FortiAnalyzer
Content inspection
- FortiGuard
- Antivirus
- Intrusion Prevention System (IPS)
- Web filtering
Routing and Layer 2 switching
- Dynamic routing: OSPF, Border Gateway Protocol (BGP)
- Static routing
VPN
- IPsec
- Autodiscovery VPN (ADVPN)
NEW QUESTION 26
Examine the partial output from the IKE real time debug shown in the exhibit; then answer the question below.
Why didn't the tunnel come up?
- A. One IPsec gateway is using main mode, while theother IPsec gateway is using aggressive mode.
- B. The remote gateway's Phase-1 configuration does not match the local gateway's phase-1 configuration.
- C. IKE mode configuration is not enabled in the remote IPsec gateway.
- D. Theremote gateway's Phase-2 configuration does not match the local gateway's phase-2 configuration.
Answer: B
NEW QUESTION 27
Examine the following routing table and BGP configuration; then answer the question below.
TheBGP connection is up, but the local peer is NOT advertising the prefix192.168.1.0/24. Which configuration change will make the local peer advertise this prefix?
- A. Disable the settingnetwork-import-check.
- B. Enable the redistribution of connected routers into BGP.
- C. Enable the redistribution of static routers into BGP.
- D. Enable the setting ebgp-multipath.
Answer: A
NEW QUESTION 28
View the IPS exit log, and then answer the question below.
# diagnose test application ipsmonitor 3
ipsengine exit log"
pid = 93 (cfg), duration = 5605322 (s) at Wed Apr19 09:57:26 2017
code = 11, reason: manual
What is the status of IPS on this FortiGate?
- A. IPS engine memory consumption has exceeded the model-specific predefined value.
- B. IPS daemon experienced a crash.
- C. There are communication problems between theIPS engine and the management database.
- D. All IPS-related features have been disabled in FortiGate's configuration.
Answer: D
Explanation:
Explanation
The command diagnose test application ipsmonitor includes many options that are useful for troubleshooting purposes.Option 3 displays the log entries generated every time an IPS engine process stopped. There are various reasons why these logs are generated:Manual: Because of the configuration, IPS no longer needs to run (that is, all IPS-releated features have been disabled)
NEW QUESTION 29
View the exhibit, which contains the partial output of adiagnose command, and then answer the question below.
Based on the output, which of the following statements is correct?
- A. Quick mode selectors are disabled.
- B. DPD is disabled.
- C. Anti-reply is enabled.
- D. Remote gateway IP is 10.200.5.1.
Answer: C
NEW QUESTION 30
Refer to exhibit, which contains the output of a BGP debug command.
Which statement explains why the state of the 10.200.3.1 peer is Connect?
- A. The local router has received the BGP prefixes from the remote peer.
- B. The local router is receiving the BGP keepalives from the peer, but it has not received a BGP prefix yet.
- C. The TCP session to 10.200.3.1 has not completed the 3-way handshake.
- D. The local router is receiving BGP keepalives from theremote peer, but the local peer has not received the OpenConfirm yet.
Answer: C
Explanation:
Explanation
BGP neighbor states and how they change:* Idle: Initial state* Connect: Waiting for a successful three-way TCP connection* Active: Unable to establish the TCP session* OpenSent: Waiting for an OPEN message from the peer* OpenConfirm: Waiting for the keepalive message from the peer* Established: Peers have successfully exchanged OPEN and keepalive messages
NEW QUESTION 31
Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)
- A. IPS failopen
- B. AV failopen
- C. UTM failopen
- D. mem failopen
Answer: A,B
NEW QUESTION 32
What does the dirty flag mean in aFortiGate session?
- A. The next packet must be re-evaluated against the firewall policies.
- B. Traffic has been identified as from an application that is not allowed.
- C. The session must be removed from the former primary unit after an HA failover.
- D. Traffic has been blocked by the antivirus inspection.
Answer: A
Explanation:
Explanation
https://kb.fortinet.com/kb/viewContent.do?externalId=FD40119&sliceId=1
NEW QUESTION 33
What is the purpose of an internal segmentation firewall (ISFW)?
- A. It is anall-in-one security appliance that is placed at remote sites to extend the enterprise network.
- B. It splits the network into multiple security segments to minimize the impact of breaches.
- C. It is the first line of defense at the network perimeter.
- D. It inspects incoming traffic to protect services in the corporate DMZ.
Answer: B
Explanation:
Explanation
ISFW splits your network into multiple security segments. They serve as a breach containers from attacks that come from inside.
NEW QUESTION 34
View the exhibit, which contains a partial output of an IKE real-time debug, and then answer the question below.
Based on the debug output, which phase-1 setting is enabled in the configuration of this VPN?
- A. auto-discovery-forwarder
- B. auto-discovery-shortcut
- C. auto-discovery-receiver
- D. auto-discovery-sender
Answer: A
NEW QUESTION 35
When using the SSL certificate inspection method for HTTPS traffic, how does FortiGate filter web requests when the browser client does not provide the server name indication (SNI) extension?
- A. FortiGate switches to the full SSL inspection method to decrypt the data.
- B. FortiGate blocks the request without any further inspection.
- C. FortiGate uses the requested URL from the user's web browser.
- D. FortiGate uses CN information from the Subject field in the server's certificate.
Answer: D
NEW QUESTION 36
Which configuration can be used to reduce the number of BGP sessions in an IBGP network?
- A. Neighbor range
- B. Next-hop-self
- C. Route reflector
- D. Neighbor group
Answer: C
Explanation:
Explanation
Route reflectors help to reduce the number of IBGP sessions inside an AS. A route reflector forwards the routers learned from one peer to the other peers. If you configure route reflectors, you dont' need to create a full mesh IBGP network. All clients in a cluster only talck to route reflector to get sync routing updates. Route reflectors pass the routing updates to other route reflectors and border routers within the AS.
NEW QUESTION 37
An administrator has enabled HA session synchronization in a HA cluster with two members. Which flag is added to a primary unit's session to indicate that it has been synchronized to the secondary unit?
- A. synced
- B. dirty.
- C. nds.
- D. redir.
Answer: A
Explanation:
Explanation
The synced sessions have the 'synced' flag. The command 'diag sys session list' can be used to see the sessions on the member, with the associated flags.
NEW QUESTION 38
An administrator is running the following sniffer in a FortiGate:
diagnose sniffer packet any "host 10.0.2.10" 2
What information isincluded in the output of the sniffer? (Choose two.)
- A. Port names.
- B. IP headers.
- C. IP payload.
- D. Ethernet headers.
Answer: B,C
Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=11186
NEW QUESTION 39
The CLI command set intelligent-mode <enable | disable> controls the IPS engine's adaptivescanning behavior. Which of the following statements describes IPS adaptive scanning?
- A. Determines when it is secure enough to stop scanning session traffic.
- B. Choose a matching algorithm based on available memory and the type of inspection being performed.
- C. Determines the optimal number of IPS engines required based on system load.
- D. Downloads signatures on demand from FDS based on scanning requirements.
Answer: A
Explanation:
Explanation
Configuring IPS intelligenceStarting with FortiOS 5.2,intelligent-mode is a new adaptive detection method. This command is enabled the default and it means that the IPS engine will perform adaptive scanning so that, for some traffic, the FortiGate can quickly finish scanning and offload the traffic to NPU orkernel. It is a balanced method which could cover all known exploits. When disabled, the IPS engine scans every single byte.
config ips globalset intelligent-mode {enable|disable}
NEW QUESTION 40
View the exhibit, which contains the output of a BGP debug command, and then answer the question below.
Which ofthe following statements about the exhibit are true? (Choose two.)
- A. The local router has received atotal of three BGP prefixes from all peers.
- B. Since the counters were last reset; the 10.200.3.1 peer has never been down.
- C. The local router's BGP state is Established with the 10.125.0.60 peer.
- D. The local router has not established a TCP session with 100.64.3.1.
Answer: C,D
NEW QUESTION 41
View the exhibit, which contains the output of a debug command, and then answer the question below.
What statement is correct about this FortiGate?
- A. It is currently in FD conserve mode.
- B. It is currently in system conserve mode because of high memory usage.
- C. It iscurrently in system conserve mode because of high CPU usage.
- D. It is currently in kernel conserve mode because of high memory usage.
Answer: B
NEW QUESTION 42
Examine the output of the 'diagnose ips anomaly list' command shown in the exhibit; then answer the question below.
Which IP addresses are included in the output of thiscommand?
- A. Those whose traffic matches an IPS sensor.
- B. Those whose traffic exceeded a threshold of a matching DoS policy.
- C. Those whose traffic was detected as an anomaly by an IPS sensor.
- D. Those whose traffic matches a DoS policy.
Answer: D
NEW QUESTION 43
What is the diagnose test application ipsmonitor 99 command used for?
- A. To restart all IPS engines and monitors
- B. To provide information regarding IPS sessions
- C. To disable the IPS engine
- D. To enable IPS bypass mode
Answer: A
NEW QUESTION 44
Examine the partial output fromtwo web filter debug commands; then answer the question below:
Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99.com?
- A. Information technology.
- B. Finance and banking
- C. General organization.
- D. Business.
Answer: D
NEW QUESTION 45
Viewthe exhibit, which contains the output of a real-time debug, and then answer the question below.
Which of the following statements is true regarding this output? (Choose two.)
- A. This web request was inspected using the root web filter profile.
- B. FortiGate found the requested URL in its local cache.
- C. The web request was allowed by FortiGate.
- D. The requested URL belongs to category ID 52.
Answer: B,D
NEW QUESTION 46
Examine the following partialoutput from a sniffer command; then answer the question below.
What is the meaning of the packets dropped counter at the end of the sniffer?
- A. Number of packets that matched the sniffer filter and were dropped by the FortiGate.
- B. Number of packets that didn't match the sniffer filter.
- C. Number of packets that matched the sniffer filter but could not be captured by the sniffer.
- D. Number of total packets dropped by the FortiGate.
Answer: C
Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=11655
NEW QUESTION 47
View the global IPS configuration, and then answer the question below.
Which of the following statements is true regarding this configuration?
- A. New packets will be passed through without inspection if the IPS socket buffer runs out of memory.
- B. FortiGate will spawn IPS engine instances based on the system load.
- C. IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.
- D. IPS will scan every byte in every session.
Answer: D
NEW QUESTION 48
View the exhibit, which contains the partial output of an IKE real time debug, and then answerthe question below.
The administrator does not have access to the remote gateway. Based on the debug output, what configuration changes can the administrator make to the local gateway to resolve the phase 1 negotiation error?
- A. Change phase 1encryption to AESCBC and authentication to SHA128.
- B. Change phase 1 encryption to AES128 and authentication to SHA512.
- C. Change phase 1 encryption to 3DES and authentication to CBC.
- D. Change phase 1 encryption to 3DES and authentication to SHA256.
Answer: C
NEW QUESTION 49
An administrator has configured two FortiGate devices for an HA cluster. While testing the HA failover, the administrator noticed that some of the switches in the network continue to send traffic to the former primary unit. The administrator decides to enable the setting link-failed-signal to fix the problem. Which statement is correct regarding this command?
- A. Sends an ARP packet to all connected devices, indicating that the HA virtual MAC address is reachable through a new master after a failover.
- B. Disables all the non-heartbeat interfaces in all the HA members for two seconds after a failover.
- C. Sends a link failed signal to all connected devices.
- D. Forces the former primary device to shut down all its non-heartbeat interfaces forone second while the failover occurs.
Answer: D
NEW QUESTION 50
......
NSE7_EFW-6.4 [Dec-2021] Newly Released] Exam Questions For You To Pass: https://www.exam-killer.com/NSE7_EFW-6.4-valid-questions.html
Fortinet NSE7_EFW-6.4 Exam: Basic Questions With Answers: https://drive.google.com/open?id=1sedGyvGKNqyqYuN_FhZNEae7M7XjzF7w

