Free NSE7-EFW-7-2 Fortinet NSE7-EFW-7-2 Practice Test Question

Loading demo links...

Showing 1–3 of 8 questions

Question 1 (Topic 1)

Refer to the exhibit, which contains a partial VPN configuration. What can you conclude from this configuration?

Select an option, then click Submit answer.

  • FortiGate creates separate virtual interfaces for each dial-up client
  • The VPN should use the dynamic routing protocol to exchange routing information through the tunnels
  • Dead peer detection is disabled
  • The routing table shows a single IPSec virtual interface
Question 2 (Topic 1)

You created a VPN community using VPN Manager on FortiManager. You also added gateways to the VPN community. Now you are trying to create firewall policies to permit traffic over the tunnel; however, the VPN interfaces do not appear as available options. What step must you take to resolve this issue?

Select an option, then click Submit answer.

  • Refresh the device status using the Device Manager so that FortiGate populates the IPSec interfaces.
  • Install the VPN community and gateway configuration on the FortiGate devices so that the VPN interfaces appear on the Policy Objects on FortiManager.
  • Configure the phase 1 settings in the VPN community that you didn’t initially configure. FortiGate automatically generates the interfaces after you configure the required settings.
  • Create interface mappings for the IPsec VPN interfaces before you use them in a policy.
Question 3 (Topic 1)

Refer to the exhibit, which contains a partial BGP configuration. You want to configure a loopback as the BGP source. Which two parameters must you set in the BGP configuration? (Choose two.)

Select an option, then click Submit answer.

  • ebgp-enforce-multihop
  • recursive-next-hop
  • ibgp-enforce-multihop
  • update-source