Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE7_EFW-7.2 Fortinet NSE 7 - Enterprise Firewall 7.2 Questions and Answers

Questions 4

Refer to the exhibit.

NSE7_EFW-7.2 Question 4

The exhibit shows a prefix list configuration

What can you conclude from the above prefix-list configuration?

Options:

A.

The prefix 10.10.0.0/16 will be denied

B.

The prefixes 10.10.0/16 and 10.0.0.0/16 will be denied

C.

The prefix 10.10.10.0/24 will be permitted

D.

The prefix 10.0.0.0/8 will be permitted

Buy Now
Questions 5

Refer to the exhibit.

NSE7_EFW-7.2 Question 5

which contains a partial configuration of the global system. What can you conclude from this output?

Options:

A.

NPs and CPs are enabled

B.

Only CPs arc disabled

C.

Only NPs are disabled

D.

NPs and CPs arc disabled

Buy Now
Questions 6

Refer to the exhibit, which shows device registration on FortiManager.

NSE7_EFW-7.2 Question 6

What can you conclude about the Spoke-1 and Spoke-2 configurations with respect to the information cond: Modified (recent auto-updated)?

Options:

A.

Based on the policy configuration on NGFW-1, the configuration on both spokes is modified and automatically updated.

B.

On NGFW-A, the configuration was changed and spokes are wailing for an autoupdate.

C.

On both Spoke-1 and Spoke-2, the configuration was changed directly on the FortiGate device, and the changes were automatically retrieved by the device database.

D.

Spoke-1 and Spoke-2 are sharing the same security policy configuration and the same policy package.

Buy Now
Questions 7

Which configuration can be used to reduce the number of BGP sessions in on IBGP network?

Options:

A.

Route-reflector-peer enable

B.

Route-reflector-client enable

C.

Route-reflector enable

D.

Route-reflector-server enable

Buy Now
Questions 8

While configuring the BGP protocol, an administrator applies the set netuork-inport-check disable command under config network.

What will FortiGate do as a result of this command?

Options:

A.

FortiGate will advertise only the corresponding prefixes in the BGP network table to its BGP neighbor, even if itis not in the routing table.

B.

FortiGate will advertise all the prefixes in the BGP network table to its BGP neighbor, even f itis not in the routing table.

C.

FortiGate will not advertise any imported routes received from one BGP neighbor to another.

D.

FortiGate will not advertise the prefixes, if it is not in the routing table.

Buy Now
Questions 9

Exhibit.

NSE7_EFW-7.2 Question 9

Refer to the exhibit, which contains an active-active toad balancing scenario.

During the traffic flow the primary FortiGate forwards the SYN packet to the secondary FortiGate.

What is the destination MAC address or addresses when packets are forwarded from the primary FortiGate to the secondary FortiGate?

Options:

A.

Secondary physical MAC port1

B.

Secondary virtual MAC port1

C.

Secondary virtual MAC port1 then physical MAC port1

D.

Secondary physical MAC port2 then virtual MAC port2

Buy Now
Questions 10

Refer to the exhibit, which shows a network diagram.

NSE7_EFW-7.2 Question 10

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

Options:

A.

Set route-overlap to allow.

B.

Set single-source to enable

C.

Set route-overlap to either use—new or use-old

D.

Set net-device to enable

Buy Now
Questions 11

Refer to the exhibit, which contains a partial BGP combination.

NSE7_EFW-7.2 Question 11

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

Options:

A.

ebgp-enforce-multihop

B.

recursive-next-hop

C.

ibgp-enfoce-multihop

D.

update-source

Buy Now
Questions 12

What are two functions of automation stitches? (Choose two.)

Options:

A.

Automation stitches can be created to run diagnostic commands and email the results when CPU or memory usage exceeds specified thresholds.

B.

An automation stitch configured to execute actions in parallel can be set to insert a specific delay between actions.

C.

Automation stitches can be configured on any FortiGate device in a Security Fabric environment.

D.

An automation stitch configured to execute actions sequentially can take parameters from previous actions as input for the current action.

Buy Now
Questions 13

Winch two statements about ADVPN are true? (Choose two)

Options:

A.

auto-discovery receiver must be set to enable on the Spokes.

B.

Spoke to-spoke traffic never goes through the hub

C.

lt supports NAI for on-demand tunnels

D.

Routing is configured by enabling add-advpn-route

Buy Now
Questions 14

Exhibit.

NSE7_EFW-7.2 Question 14

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

Options:

A.

FortiGate creates separate virtual interfaces for each dial up client.

B.

The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.

C.

Dead peer detection s disabled.

D.

The routing table shows a single IPSec virtual interface.

Buy Now
Questions 15

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

Options:

A.

fec-ingress and fec-egress

B.

Odpd and dpd-retryinterval

C.

fragmentation and fragmentation-mtu

D.

keepalive and keylive

Buy Now
Questions 16

Refer to the exhibit, which shows an ADVPN network,

NSE7_EFW-7.2 Question 16

An administrator must configure an ADVPN using IBGP and EBGP to connect

overlay network 1 with 2.

What must the administrator configure in the phase 1 VPN IPSEC configuration

of the Hub2¢ub tunnels?

Options:

A.

set auto-discovery-sender enable

B.

set auto-discovery-forwarder enable

C.

set add-route enable

D.

set auto-discovery-receiver enable

Buy Now
Questions 17

Refer to the exhibit, which shows an ADVPN network.

NSE7_EFW-7.2 Question 17

Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

Options:

A.

set auto-discovery-forwarder enable

B.

set add-route enable

C.

set auto-discovery-receiver enable

D.

set auto-discovery-sender enable

Buy Now
Questions 18

Refer to the exhibit, which shows an OSPF network.

NSE7_EFW-7.2 Question 18

Which types of ink-state advertisements (LSA) will NGFW-1 send, if itis a backup designated router (BDR)?

Options:

A.

ONGFW-1 will send type 1 and type 2 LSAs.

B.

NGFW-1 will send type 1and type 3 LSA.

C.

ONGFW-1 will send type 1 and type 4 LSA.

D.

ONGFW-1 will send type 1and type 5 LSA.

Buy Now
Questions 19

An administrator has configured two fortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device What can the administrator do to fix this problem?

Options:

A.

Verify that the speed and duplex settings match between me FortiGate interfaces and the connected switch ports

B.

Configure set link -failed signal enable under-config system ha on both Cluster members

C.

Configure remote Iink monitoring to detect an issue in the forwarding path

D.

Configure set send-garp-on-failover enables under config system ha on both cluster members

Buy Now
Questions 20

Refer to the exhibit, which shows the output of a BGP summary.

NSE7_EFW-7.2 Question 20

What two conclusions can you draw from this BGP summary? (Choose two.)

Options:

A.

External BGP (EBGP) exchanges routing information.

B.

The BGP session with peer 10. 127. 0. 75 is established.

C.

The router 100. 64. 3. 1 has the parameter bfd set to enable.

D.

The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.

Buy Now
Questions 21

Refer to the exhibit.

NSE7_EFW-7.2 Question 21

NSE7_EFW-7.2 Question 21

The partial interlace configurator! of two FortiGate devices is shown

Which two conclusions can you draw from this configuration? (Choose two.)

Options:

A.

You can include 4.4.4.4 and 4.4.4.2 IP addresses using sat vrdst command

B.

At the time of failover, FortiGate_A will change its priority to 30

C.

By default, preemption mode is enabled

D.

In VRRP, you are restricted to add a third FortiGate into VRRP group 1.

Buy Now
Questions 22

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A)

NSE7_EFW-7.2 Question 22

B)

NSE7_EFW-7.2 Question 22

C)

NSE7_EFW-7.2 Question 22

D)

NSE7_EFW-7.2 Question 22

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 23

An administrator is configuring two FortiGate devices in an HA cluster. While configuring the devices, the administrator issues the following commands on both HA cluster members:

NSE7_EFW-7.2 Question 23

In which two ways do these commands impact the HA cluster? (Choose two.)

Options:

A.

They force the former primary to send gratuitous ARP packets when the failover happens to indicate that the virtual MAC address is now using a different device.

B.

They force the former primary to shut down all ts interfaces for one second when failover happens, excluding the heartbeat and reserved management interfaces.

C.

They force both HA devices for remote link monitoring to detect an issue in the forwarding path.

D.

They force the switches to update their MAC forwarding tables, when failover happens.

Buy Now
Questions 24

Which two statements about metadata variables are true? (Choose two.)

Options:

A.

You create them on FortiGate

B.

They apply only to non-firewall objects.

C.

The metadata format is $ < metadata_variabie_name > .

D.

They can be used as variables in scripts

Buy Now
Exam Code: NSE7_EFW-7.2
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.2
Last Update: May 19, 2026
Questions: 80

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11