Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Fortinet Certification NSE7_EFW-7.2 Syllabus Exam Questions Answers

Fortinet NSE 7 - Enterprise Firewall 7.2 Questions and Answers

Question 9

Which two statements about ADVPN are true? (Choose two.)

Options:

A.

You must disable add-route in the hub.

B.

AllFortiGate devices must be in the same autonomous system (AS).

C.

The hub adds routes based on IKE negotiations.

D.

You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0.

Question 10

Exhibit.

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

Options:

A.

FortiGate creates separate virtual interfaces for each dial up client.

B.

The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.

C.

Dead peer detection s disabled.

D.

The routing table shows a single IPSec virtual interface.

Question 11

You want to block access to the website ww.eicar.org using a custom IPS signature.

Which custom IPS signature should you configure?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 12

Refer to the exhibit, which shows a custom signature.

Which two modifications must you apply to the configuration of this custom signature so that you can save it on FortiGate? (Choose two.)

Options:

A.

Add severity.

B.

Add attack_id.

C.

Ensure that the header syntax is F-SBID.

D.

Start options with --.