[Nov-2021] Fortinet NSE7_EFW-6.4 Official Cert Guide PDF [Q38-Q55]

Share

[Nov-2021] Fortinet NSE7_EFW-6.4 Official Cert Guide PDF

Exam NSE7_EFW-6.4: Fortinet NSE 7 - Enterprise Firewall 6.4 - ExamPrepAway


What is the duration, language, and format of the Fortinet NSE7_EFQ-6.4: Fortinet NSE 7 - Enterprise Firewall 6.4 Exam

  • Number of questions: 30
  • Duration of Exam: 60 minutes
  • Examination platform: Online proctored
  • Language of Exam: English and Japanese

For more info read reference:

Exam Blueprint Preparatory Course

 

NEW QUESTION 38
An administrator added the following Ipsec VPN to a FortiGate configuration:
configvpn ipsec phasel -interface
edit"RemoteSite"
set type dynamic
set interface "portl"
set mode main
set psksecret ENC LCVkCiK2E2PhVUzZe
next
end
config vpn ipsec phase2-interface
edit "RemoteSite"
set phasel name "RemoteSite"
set proposal 3des-sha256
next
end
However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit.


What is causing the IPsec problem in the phase 1 ?

  • A. The incoming IPsec connection is matching the wrongVPN configuration
  • B. NAT-T settings do not match
  • C. The pre-shared key is wrong
  • D. The phrase-1 mode must be changed to aggressive

Answer: C

 

NEW QUESTION 39
Which the following events can trigger the election of a new primary unit in a HA cluster? (Choose two.)

  • A. Primary unit stops sending HA heartbeat
  • B. One of the monitored interfaces in the primary unit is disconnected.
  • C. A secondary unit is removed from the HA cluster.
  • D. The FortiGuard license for the primary unit is updated.

Answer: A,B

 

NEW QUESTION 40
An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs thedebug flow while attempting the connection using HTTP. The output of the debug flow is shown in the exhibit:

Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)

  • A. Redirection of HTTP to HTTPS administrative access is disabled.
  • B. HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.
  • C. HTTP administrative access is configured with a port number different than 80.
  • D. The packet is denied because of reverse path forwarding check.

Answer: B,C

 

NEW QUESTION 41
Examine the output from the BGP real time debugshown in the exhibit, then the answer the question below:

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. The state of the remote BGP peer will go toConnectafter it confirms the received prefixes.
  • B. Local BGP peer received a prefix fora default route.
  • C. The state of the remote BGP peer isOpenConfirm.
  • D. BGP peers have successfully interchangedOpenandKeepalivemessages.

Answer: B,D

 

NEW QUESTION 42
View the exhibit, which contains the output of a diagnose command, and the answer the question below.

Which statements are true regarding the Weight value?

  • A. It determines which FortiGuard server is used for license validation.
  • B. Its value is incremented with each packet lost.
  • C. Its initial value is calculated based on the round trip delay (RTT).
  • D. Its initial value is statically set to 10.

Answer: B

 

NEW QUESTION 43
What is the diagnose test application ipsmonitor 99 command used for?

  • A. To restart all IPS engines and monitors
  • B. To provide information regarding IPS sessions
  • C. To disable the IPS engine
  • D. To enable IPS bypass mode

Answer: A

 

NEW QUESTION 44
A FortiGate is rebooting unexpectedly without any apparent reason. What troubleshooting tools could an administrator use to get more information about the problem? (Choose two.)

  • A. Policy monitor.
  • B. Firewall monitor.
  • C. Logs.
  • D. Crashlogs.

Answer: C,D

 

NEW QUESTION 45

Refer to the exhibit, which contains the output ofget system ha status.
Which two statements about the output are true? (Choose two.)

  • A. port7is used as the HA heartbeat on all devices in the cluster.
  • B. The slave configuration is synchronized with the master.
  • C. The HA management IP is 169.254.0.2.
  • D. Master is selected based on the priority configured underconfig system ha.

Answer: A,D

 

NEW QUESTION 46
Examine the output of the 'diagnose sys session list expectation' command shown in the exhibit; than answer the question below.

Which statement is true regarding the session in the exhibit?

  • A. It was created by the FortiGate kernel to allow push updates from FotiGuard.
  • B. It is for traffic originated from the FortiGate.
  • C. It was created by a session helper or ALG.
  • D. It is for managementtraffic terminating at the FortiGate.

Answer: C

 

NEW QUESTION 47
Examine the partial output from the IKE real time debug shown in the exhibit; then answer the question below.

Why didn't the tunnel come up?

  • A. One IPsec gateway is using main mode, while theother IPsec gateway is using aggressive mode.
  • B. The remote gateway's Phase-1 configuration does not match the local gateway's phase-1 configuration.
  • C. IKE mode configuration is not enabled in the remote IPsec gateway.
  • D. Theremote gateway's Phase-2 configuration does not match the local gateway's phase-2 configuration.

Answer: B

 

NEW QUESTION 48
Examine the following routing table and BGP configuration; then answer the question below.

TheBGP connection is up, but the local peer is NOT advertising the prefix192.168.1.0/24. Which configuration change will make the local peer advertise this prefix?

  • A. Disable the settingnetwork-import-check.
  • B. Enable the redistribution of connected routers into BGP.
  • C. Enable the redistribution of static routers into BGP.
  • D. Enable the setting ebgp-multipath.

Answer: A

 

NEW QUESTION 49
How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as a local FDS?

  • A. FortiManager can download and maintain local copies of FortiGuard databases.
  • B. FortiManager will respond to update requests only if they originate from a managed device.
  • C. FortiManager supports only FortiGuard push to managed devices.
  • D. FortiManager does not support rating requests.

Answer: A

 

NEW QUESTION 50
What is the purpose of an internal segmentation firewall (ISFW)?

  • A. It is anall-in-one security appliance that is placed at remote sites to extend the enterprise network.
  • B. It splits the network into multiple security segments to minimize the impact of breaches.
  • C. It is the first line of defense at the network perimeter.
  • D. It inspects incoming traffic to protect services in the corporate DMZ.

Answer: B

Explanation:
Explanation
ISFW splits your network into multiple security segments. They serve as a breach containers from attacks that come from inside.

 

NEW QUESTION 51
Anadministrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug:
diagnose debug application ike-1
diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?

  • A. Phase1; XAuth; IKE mode configuration; phase2.
  • B. Phase1; XAuth; phase 2; IKE mode configuration.
  • C. Phase1; IKE mode configuration; XAuth; phase 2.
  • D. Phase1; IKE mode configuration; phase 2; XAuth.

Answer: A

Explanation:
Explanation
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-ipsecvpn-54/IPsec_VPN_Concepts/IKE_Packet_

 

NEW QUESTION 52
View the exhibit, which contains the output of a debug command, and then answer the question below.

Which of the following statements about theexhibit are true? (Choose two.)

  • A. In the network on port4, two OSPF routers are down.
  • B. The local FortiGate's OSPF router ID is 0.0.0.4
  • C. Port4 is connected to the OSPF backbone area.
  • D. The local FortiGate has been elected as the OSPF backup designated router.

Answer: B,C

 

NEW QUESTION 53
Which of the following statements are correct regardingapplication layer test commands? (Choose two.)

  • A. They display real-time application debugs.
  • B. Some of them can beused to restart an application.
  • C. They are used to filter real-time debugs.
  • D. Some of them display statistics and configuration information about a feature or process.

Answer: B,D

Explanation:
Explanation
Application layer test commands don't display info in real time, but they do show statistics and configuration info about a feature or process. You can also use some of these commands to restart a pr ocess or execute a change in its operation.

 

NEW QUESTION 54
An administrator is running the following sniffer in a FortiGate:
diagnose sniffer packet any "host 10.0.2.10" 2
What information isincluded in the output of the sniffer? (Choose two.)

  • A. Port names.
  • B. IP headers.
  • C. IP payload.
  • D. Ethernet headers.

Answer: B,C

Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=11186

 

NEW QUESTION 55
......

Free NSE7_EFW-6.4 Exam Dumps to Improve Exam Score: https://www.examprepaway.com/Fortinet/braindumps.NSE7_EFW-6.4.ete.file.html

2021 Realistic NSE7_EFW-6.4 Dumps Exam Tips Test Pdf Exam Materials: https://drive.google.com/open?id=1tlJNKAwdPZUOoJS3uY97LPMbA_dpOzug