Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE7_EFW-7.0 Fortinet NSE 7 - Enterprise Firewall 7.0 Questions and Answers

Questions 4

Examine the output from the BGP real time debug shown in the exhibit, then the answer the question below:

NSE7_EFW-7.0 Question 4

Which statements are true regarding the output in the exhibit? (Choose two.)

Options:

A.

BGP peers have successfully interchanged Open and Keepalive messages.

B.

Local BGP peer received a prefix for a default route.

C.

The state of the remote BGP peer is OpenConfirm.

D.

The state of the remote BGP peer will go to Connect after it confirms the received prefixes.

Buy Now
Questions 5

When using the SSL certificate inspection method for HTTPS traffic, how does FortiGate filter web requests when the browser client does not provide the server name indication (SNI) extension?

Options:

A.

FortiGate uses CN information from the Subject field in the server’s certificate.

B.

FortiGate switches to the full SSL inspection method to decrypt the data.

C.

FortiGate blocks the request without any further inspection.

D.

FortiGate uses the requested URL from the user’s web browser.

Buy Now
Questions 6

Refer to the exhibit, which shows the output of a debug command.

NSE7_EFW-7.0 Question 6

What can be concluded from the debug command output?

Options:

A.

The OSPF router with the ID 0.0.0.69 has its OSPF priority set to 0.

B.

The local FortiGate has a different MTU value from the OSPF router with ID 0.0.0.2, based on the state information.

C.

There are more than two OSPF routers on the wan2 network.

D.

The interface ToRemote is a broadcast OSPF network.

Buy Now
Questions 7

Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)

Options:

A.

Preview pending configuration changes for managed devices.

B.

Add devices to FortiManager.

C.

Import policy packages from managed devices.

D.

Install configuration changes to managed devices.

E.

Import interface mappings from managed devices.

Buy Now
Questions 8

An administrator has configured the following CLI script on FortiManager, which failed to apply any changes to the managed device after being executed.

NSE7_EFW-7.0 Question 8

Why didn’t the script make any changes to the managed device?

Options:

A.

Commands that start with the # sign are not executed.

B.

CLI scripts will add objects only if they are referenced by policies.

C.

Incomplete commands are ignored in CLI scripts.

D.

Static routes can only be added using TCL scripts.

Buy Now
Questions 9

Refer to the exhibit, which contains a screenshot of some phase 1 settings.

NSE7_EFW-7.0 Question 9

The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands to an SSH session on FortiGate: diagnose vpn ike log-filter dst-addr4 10.0.10.1 diagnose debug application ike -1

However, the IKE real-time debug does not show any output. Why?

Options:

A.

The administrator must also run the command diagnose debug enable.

B.

The administrator must enable the following real-time debug: diagnose debug application ipsec -1.

C.

The log-filter setting is incorrect. The VPN traffic does not match this filter.

D.

The debug shows only error messages. If there is no output, then the phase 1 and phase 2 configurations match.

Buy Now
Questions 10

Refer to the exhibit, which contains partial output from an IKE real-time debug.

NSE7_EFW-7.0 Question 10

The administrator does not have access to the remote gateway.

Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?

Options:

A.

In the phase 1 network configuration, set the IKE version to 2.

B.

In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.

C.

In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.

D.

In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.

Buy Now
Questions 11

Examine the following partial outputs from two routing debug commands; then answer the question below.

# get router info kernel

tab=254 vf=0 scope=0type=1 proto=11 prio=0 0.0.0.0/0.0.0.0/0- > 0.0.0.0/0 pref=0.0.0.0

gwy=10.200.1.254 dev=2(port1)

tab=254 vf=0 scope=0type=1 proto=11 prio=10 0.0.0.0/0.0.0.0/0- > 0.0.0.0/0 pref=0.0.0.0

gwy=10.200.2.254 dev=3(port2)

tab=254 vf=0 scope=253type=1 proto=2 prio=0 0.0.0.0/0.0.0.0/.- > 10.0.1.0/24 pref=10.0.1.254

gwy=0.0.0.0 dev=4(port3)

# get router info routing-table all s*0.0.0.0/0 [10/0] via 10.200.1.254, portl [10/0] via 10.200.2.254, port2, [10/0] dO.0.1.0/24 is directly connected, port3 dO.200.1.0/24 is directly connected, portl d0.200.2.0/24 is directly connected, port2

Which outbound interface or interfaces will be used by this FortiGate to route web traffic from internal users to the Internet?

Options:

A.

port!

B.

port2.

C.

Both portl and port2.

D.

port3.

Buy Now
Questions 12

How are bulk configuration changes made using FortiManager CLI scripts? (Choose two.)

Options:

A.

When run on the All FortiGate in ADOM, changes are automatically installed without the creation of a new revision history.

B.

When run on the Device Database, changes are applied directly to the managed FortiGate device.

C.

When run on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.

D.

When run on the Policy Package, ADOM database, you must use the installation wizard to apply the changes to the managed FortiGate device

Buy Now
Questions 13

View the exhibit, which contains the output of a debug command, and then answer the question below.

NSE7_EFW-7.0 Question 13

Which of the following statements about the exhibit are true? (Choose two.)

Options:

A.

In the network on port4, two OSPF routers are down.

B.

Port4 is connected to the OSPF backbone area.

C.

The local FortiGate’s OSPF router ID is 0.0.0.4

D.

The local FortiGate has been elected as the OSPF backup designated router.

Buy Now
Questions 14

View the global IPS configuration, and then answer the question below.

NSE7_EFW-7.0 Question 14

Which of the following statements is true regarding this configuration?

Options:

A.

IPS will scan every byte in every session.

B.

FortiGate will spawn IPS engine instances based on the system load.

C.

New packets will be passed through without inspection if the IPS socket buffer runs out of memory.

D.

IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.

Buy Now
Questions 15

View the following FortiGate configuration.

NSE7_EFW-7.0 Question 15

All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network:

NSE7_EFW-7.0 Question 15

If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user’s session?

Options:

A.

The session would remain in the session table, and its traffic would still egress from port1.

B.

The session would remain in the session table, but its traffic would now egress from both port1 and port2.

C.

The session would remain in the session table, and its traffic would start to egress from port2.

D.

The session would be deleted, so the client would need to start a new session.

Buy Now
Questions 16

When does a RADIUS server send an Access-Challenge packet?

Options:

A.

The server does not have the user credentials yet.

B.

The server requires more information from the user, such as the token code for two-factor authentication.

C.

The user credentials are wrong.

D.

The user account is not found in the server.

Buy Now
Questions 17

Examine the output of the ' diagnose debug rating ' command shown in the exhibit; then answer the question below.

NSE7_EFW-7.0 Question 17

Which statement are true regarding the output in the exhibit? (Choose two.)

Options:

A.

There are three FortiGuard servers that are not responding to the queries sent by the FortiGate.

B.

The TZ value represents the delta between each FortiGuard server ' s time zone and the FortiGate ' s time zone.

C.

FortiGate will send the FortiGuard queries to the server with highest weight.

D.

A server ' s round trip delay (RTT) is not used to calculate its weight.

Buy Now
Questions 18

Which statement is true regarding File description (FD) conserve mode?

Options:

A.

IPS inspection is affected when FortiGate enters FD conserve mode.

B.

A FortiGate enters FD conserve mode when the amount of available description is less than 5%.

C.

FD conserve mode affects all daemons running on the device.

D.

Restarting the WAD process is required to leave FD conserve mode.

Buy Now
Questions 19

Refer to the exhibit, which shows the output of a web filtering diagnose command.

NSE7_EFW-7.0 Question 19

Which configuration change would result in non-zero results in the cache statistics section?

Options:

A.

set server-type rating under config system central-management

B.

set webfilter-cache enable under config system fortiguard

C.

set webfilter-force-off disable under config system fortiguard

D.

set ngfw-mode policy-based under config system settings

Buy Now
Questions 20

View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.

NSE7_EFW-7.0 Question 20

Which statements about this debug output are correct? (Choose two.)

Options:

A.

The remote gateway IP address is 10.0.0.1.

B.

It shows a phase 1 negotiation.

C.

The negotiation is using AES128 encryption with CBC hash.

D.

The initiator has provided remote as its IPsec peer ID.

Buy Now
Questions 21

Which two configuration commands change the default behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

Options:

A.

set av-failopen off

B.

set av-failopen pass

C.

set fail-open enable

D.

set ips fail-open disable

Buy Now
Questions 22

View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.

NSE7_EFW-7.0 Question 22

The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:

NSE7_EFW-7.0 Question 22

However, the IKE real time debug does not show any output. Why?

Options:

A.

The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.

B.

The log-filter setting was set incorrectly. The VPN’s traffic does not match this filter.

C.

The debug shows only error messages. If there is no output, then the tunnel is operating normally.

D.

The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.

Buy Now
Questions 23

Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week.

NSE7_EFW-7.0 Question 23

Which two statements about the output are true? (Choose two.)

Options:

A.

If FGVM...649 is rebooted, FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.

B.

If no action is taken, the primary FortiGate will leave the cluster due to the current sync status.

C.

If port7 becomes disconnected on the secondary, both FortiGate devices will elect itself the primary.

D.

If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.

Buy Now
Questions 24

How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as a local FDS?

Options:

A.

FortiManager can download and maintain local copies of FortiGuard databases.

B.

FortiManager supports only FortiGuard push to managed devices.

C.

FortiManager will respond to update requests only if they originate from a managed device.

D.

FortiManager does not support rating requests.

Buy Now
Questions 25

A FortiGate ' s portl is connected to a private network. Its port2 is connected to the Internet. Explicit web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP. Which statements are true regarding the two entries in the FortiGate session table related with this traffic? (Choose two.)

Options:

A.

Both session have the local flag on.

B.

The destination IP addresses of both sessions are IP addresses assigned to FortiGate ' s interfaces.

C.

One session has the proxy flag on, the other one does not.

D.

One of the sessions has the IP address of port2 as the source IP address.

Buy Now
Questions 26

Refer to the exhibit, which contains the debug output of diagnose dvm device list.

NSE7_EFW-7.0 Question 26

Which two statements about the output shown in the exhibit are correct? (Choose two.)

Options:

A.

ADOMs are disabled on the FortiManager

B.

The FortiGate configuration is in sync with latest running revision history.

C.

There are pending device-level changes yet to be installed on Local-FortiGate.

D.

The policy package has been modified for Local-FortiGate.

Buy Now
Questions 27

An administrator wants to capture encrypted phase 2 traffic between two FortiGate devices using the built-in sniffer.

If the administrator knows that there is no NAT device located between both FortiGate devices, which command should the administrator run?

Options:

A.

diagnose sniffer packet any ‘ah’

B.

diagnose sniffer packet any ‘ip proto 50’

C.

diagnose sniffer packet any ‘udp port 4500’

D.

diagnose sniffer packet any ‘udp port 500’

Buy Now
Questions 28

View the exhibit, which contains the output of a BGP debug command, and then answer the question below.

NSE7_EFW-7.0 Question 28

Which of the following statements about the exhibit are true? (Choose two.)

Options:

A.

For the peer 10.125.0.60, the BGP state of is Established.

B.

The local BGP peer has received a total of three BGP prefixes.

C.

Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.

D.

The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.

Buy Now
Questions 29

Which statement about memory conserve mode is true?

Options:

A.

A FortiGate exits conserve mode when the configured memory use threshold reaches yellow.

B.

A FortiGate starts dropping all the new and old sessions when the configured memory use threshold reaches extreme.

C.

A FortiGate starts dropping new sessions when the configured memory use threshold reaches red

D.

A FortiGate enters conserve mode when the configured memory use threshold reaches red

Buy Now
Questions 30

View the exhibit, which contains the output of a BGP debug command, and then answer the question below.

NSE7_EFW-7.0 Question 30

Which of the following statements about the exhibit are true? (Choose two.)

Options:

A.

The local router ' s BGP state is Established with the 10.125.0.60 peer.

B.

Since the counters were last reset; the 10.200.3.1 peer has never been down.

C.

The local router has received a total of three BGP prefixes from all peers.

D.

The local router has not established a TCP session with 100.64.3.1.

Buy Now
Questions 31

Refer to the exhibit, which shows partial outputs from two routing debug commands.

NSE7_EFW-7.0 Question 31

Why is the port2 default route not in the second command output?

Options:

A.

The port2 interface is disabled in the FortiGate configuration.

B.

The port1 default route has a lower distance than the default route using port2.

C.

The port1 default route has a higher priority value than the default route using port2.

D.

The port1 default route has a lower priority value than the default route using port2.

Buy Now
Questions 32

View the exhibit, which contains the output of a debug command, and then answer the question below.

NSE7_EFW-7.0 Question 32

Which one of the following statements about this FortiGate is correct?

Options:

A.

It is currently in system conserve mode because of high CPU usage.

B.

It is currently in extreme conserve mode because of high memory usage.

C.

It is currently in proxy conserve mode because of high memory usage.

D.

It is currently in memory conserve mode because of high memory usage.

Buy Now
Questions 33

Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network. What HA setting must be changed in one of the HA clusters to fix the problem?

Options:

A.

Group ID.

B.

Group name.

C.

Session pickup.

D.

Gratuitous ARPs.

Buy Now
Questions 34

View the exhibit, which contains the output of get sys ha status, and then answer the question below.

NSE7_EFW-7.0 Question 34

Which statements are correct regarding the output? (Choose two.)

Options:

A.

The slave configuration is not synchronized with the master.

B.

The HA management IP is 169.254.0.2.

C.

Master is selected because it is the only device in the cluster.

D.

port 7 is used the HA heartbeat on all devices in the cluster.

Buy Now
Questions 35

Which two statements about conserve mode are true? (Choose two.)

Options:

A.

FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.

B.

FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.

C.

FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.

D.

FortiGate exits conserve mode when the system memory goes below the configured green threshold.

Buy Now
Questions 36

View these partial outputs from two routing debug commands:

NSE7_EFW-7.0 Question 36

Which outbound interface will FortiGate use to route web traffic from internal users to the Internet?

Options:

A.

Both port1 and port2

B.

port3

C.

port1

D.

port2

Buy Now
Questions 37

Which two statements about the Security Fabric are true? (Choose two.)

Options:

A.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer.

B.

Only the root FortiGate sends logs to FortiAnalyzer.

C.

Only FortiGate devices with fabric-object-unification set to default will receive and synchronize global CMDB objects sent by the root FortiGate.

D.

FortiGate uses FortiTelemetry protocol to communicate with FortiAnalyzer.

Buy Now
Questions 38

In which two ways does FortiManager function when it is deployed as a local FDS? (Choose two.)

Options:

A.

It provides VM license validation services.

B.

It supports rating requests from non-FortiGate devices.

C.

It caches available firmware updates for unmanaged devices.

D.

It can be configured as an update server, a rating server, or both.

Buy Now
Questions 39

View the exhibit, which contains the output of a web diagnose command, and then answer the question below.

NSE7_EFW-7.0 Question 39

Which one of the following statements explains why the cache statistics are all zeros?

Options:

A.

The administrator has reallocated the cache memory to a separate process.

B.

There are no users making web requests.

C.

The FortiGuard web filter cache is disabled in the FortiGate’s configuration.

D.

FortiGate is using a flow-based web filter and the cache applies only to proxy-based inspection.

Buy Now
Questions 40

Refer to the exhibit, which shows partial outputs from two routing debug commands.

NSE7_EFW-7.0 Question 40

Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?

Options:

A.

Set the priority of the static default route using port1 to 10. Most Voted

B.

Set the priority of the static default route using port2 to 1.

C.

Set preserve-session-route to enable.

D.

Set snat-route-change to enable.

Buy Now
Questions 41

Refer to the exhibit, which contains partial output from an IKE real-time debug.

NSE7_EFW-7.0 Question 41

Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?

Options:

A.

auto-discovery-shortcut

B.

auto-discovery-forwarder

C.

auto-discovery-sender

D.

auto-discovery-receiver

Buy Now
Questions 42

View the central management configuration shown in the exhibit, and then answer the question below.

NSE7_EFW-7.0 Question 42

Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an outage?

Options:

A.

10.0.1.240

B.

One of the public FortiGuard distribution servers

C.

10.0.1.244

D.

10.0.1.242

Buy Now
Questions 43

Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

Options:

A.

IPS failopen

B.

mem failopen

C.

AV failopen

D.

UTM failopen

Buy Now
Questions 44

Refer to the exhibit, which shows a partial routing table.

NSE7_EFW-7.0 Question 44

Assuming all the appropriate firewall policies are configured, which two pings will FortiGate route? (Choose two.)

Options:

A.

Source IP address: 10.1.0.10. Destination IP address: 10.64.1.52

B.

Source IPaddress: 10.72.3.52. Destination IP address: 10.1.0.254

C.

Source IPaddress: 10.10.4.24, Destination IPaddress: 10.72.3.20

D.

Source IPaddress: 10.73.9.10, Destination IPaddress: 10.72.3.15

Buy Now
Questions 45

An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs the debug flow while attempting the connection using HTTP. The output of the debug flow is shown in the exhibit:

NSE7_EFW-7.0 Question 45

Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)

Options:

A.

HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.

B.

Redirection of HTTP to HTTPS administrative access is disabled.

C.

HTTP administrative access is configured with a port number different than 80.

D.

The packet is denied because of reverse path forwarding check.

Buy Now
Questions 46

Refer to the exhibit, which shows the output of a BGP debug command.

NSE7_EFW-7.0 Question 46

Which statement explains why the state of the 10.200.3.1 peer is Connect?

Options:

A.

The local router has a different AS number than the remote peer.

B.

The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the openConfirm yet.

C.

The local router initiated the BGP session to 10.200.3.1 but did not receive a response.

D.

The router 10.200.3.1 has authentication configured for BGP and the local router does not.

Buy Now
Questions 47

An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device.

What can the administrator do to fix this problem?

Options:

A.

Configure remote link monitoring to detect an issue in the forwarding path.

B.

Configure set send-garp-on-failover enable under config system ha on both cluster members.

C.

Verify that the speed and duplex settings match between the FortiGate interfaces and the connected switch ports.

D.

Configure set link-failed-signal enable under config system ha on both cluster members.

Buy Now
Questions 48

View the exhibit, which contains the output of a diagnose command, and then answer the question below.

NSE7_EFW-7.0 Question 48

What statements are correct regarding the output? (Choose two.)

Options:

A.

This is an expected session created by a session helper.

B.

Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.0.1.10.

C.

Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.200.1.1.

D.

This is an expected session created by an application control profile.

Buy Now
Exam Code: NSE7_EFW-7.0
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.0
Last Update: May 17, 2026
Questions: 163

PDF + Testing Engine

$64.99  $185.69

Testing Engine

$49.99  $142.83
buy now NSE7_EFW-7.0 testing engine

PDF (Q&A)

$54.99  $157.11
buy now NSE7_EFW-7.0 pdf