Fortinet NSE 7 - Enterprise Firewall 7.2 Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 203 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions FCSS-EFW-AD-7-4 204 Questions NSE7_EFW-6.2 53 Questions NSE7-EFW-7-0 222 Questions.

Try Simulator

NSE7-EFW-7-2 Sample Questions

  1. Question 1

    Q1

    A financial services firm has deployed a FortiGate HA cluster in Active-Passive mode. To comply with audit requirements, all administrative changes to the primary unit must be synchronized to the secondary unit in real-time, including CLI commands entered directly on the primary. Which configuration setting ensures this behavior?

    Show answer & explanation

    Correct answer: D

    The set configuration-sync-mode incremental command under config system ha ensures that any configuration changes, including those made via the CLI, are synchronized incrementally and immediately to the secondary unit. This is crucial for maintaining configuration parity for compliance and operational consistency. session-pickup relates to synchronizing session tables, not configuration. The other options are not valid FortiOS commands.

  2. Question 2

    Q2

    A network architect is designing a large-scale enterprise network with multiple regional data centers. They plan to use OSPF as the IGP within each region and BGP to connect the regions. To prevent routing loops and ensure optimal path selection, which BGP attribute should be manipulated on the regional border routers to influence how other regions enter their network?

    Show answer & explanation

    Correct answer: B

    The Multi-Exit Discriminator (MED) is a non-transitive BGP attribute used to influence how a neighboring AS enters your AS when multiple entry points exist. A lower MED value is preferred. This makes it the ideal attribute for regional border routers to signal to other regions which entry point is optimal. Local Preference influences outbound traffic, AS Path Prepending also influences inbound traffic but is less granular, and Weight is local to the router.

  3. Question 3

    Q3Multiple answers

    An administrator is configuring an ADVPN network with two hubs and multiple spokes. To ensure that spoke-to-spoke traffic can establish direct shortcut tunnels without traversing a hub, which two settings are essential on the hub's Phase 1 configuration? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    For ADVPN to function, the hub must act as the central point for shortcut negotiation messages (IKE_CREATE_CHILD_SA). set auto-discovery-sender enable allows the hub to send shortcut offers to spokes. set auto-discovery-receiver enable allows the hub to receive shortcut requests from spokes and forward them to the correct destination spoke. Together, these settings enable the hub to facilitate the dynamic creation of spoke-to-spoke tunnels.

  4. Question 4

    Q4

    A security analyst at a healthcare organization is investigating an alert from the FortiGate IPS. The alert indicates a potential SQL injection attack from an internal IP address to a critical patient records server. To perform a thorough forensic analysis, the analyst needs to see the exact payload that triggered the IPS signature. What must be configured on the IPS sensor for this data to be available in the logs?

    Show answer & explanation

    Correct answer: C

    To capture the actual packet data that triggers an IPS signature, 'packet logging' must be enabled within the specific IPS sensor applied to the traffic. This feature saves a copy of the triggering packet(s) to the log, which is invaluable for forensic analysis to confirm the attack's nature and payload. Other logging settings, like extended logging or firewall policy logging, do not capture the packet payload for IPS events.

  5. Question 5

    Q5

    True or False: When FortiManager is used as a local FortiGuard Distribution Server (FDS), it can cache and distribute antivirus and IPS updates, but web filtering and antispam rating lookups from managed FortiGates still require a direct connection to public FortiGuard servers.

    Show answer & explanation

    Correct answer: B

    This statement is false. When FortiManager is configured as a local FDS, it can serve not only AV and IPS updates but also handle real-time web filtering and antispam rating requests. This allows managed FortiGates in a closed or bandwidth-constrained network to perform these lookups locally against the FortiManager, which then queries the public FortiGuard network on their behalf.

  6. Question 6

    Q6

    A systems administrator is reviewing the performance of a FortiGate 1800F with NP7 processors. They observe that traffic matching a firewall policy with a per-IP traffic shaper applied is not being offloaded to the NP7 processors, resulting in high CPU utilization. Why is the traffic not being offloaded?

    Show answer & explanation

    Correct answer: B

    Certain features, by their nature, require CPU processing and are incompatible with hardware acceleration. Per-IP traffic shaping is one such feature. It requires the FortiGate CPU to track and manage bandwidth for each individual IP address, preventing the session from being offloaded to the NP7 processor. To enable offloading, a shared traffic shaper would need to be used instead.

  7. Question 7

    Q7

    An engineer is troubleshooting an OSPF adjacency issue between two FortiGates. The diagnose ip router ospf neighbor command shows the neighbor is stuck in the ExStart/Exchange state. What is the most likely cause of this issue?

    flowchart LR A[FortiGate-A] -- OSPF Hello --> B(FortiGate-B) B -- OSPF Hello --> A A -- DB Description --> B B -- DB Description --> A subgraph Stuck Here A -- "ExStart/Exchange" -- B end
    Show answer & explanation

    Correct answer: C

    When an OSPF adjacency is stuck in the ExStart/Exchange state, it indicates that the routers are failing to exchange Database Description (DBD) packets successfully. A common cause for this is a mismatched Maximum Transmission Unit (MTU) on the interfaces. If one router sends a DBD packet larger than the other router's interface MTU, the packet will be dropped, and the exchange process cannot complete. Mismatched area IDs or authentication keys would prevent the adjacency from forming at an earlier stage.

  8. Question 8

    Q8

    A global logistics company is using FortiManager to manage over 500 FortiGate devices across different countries. The security team wants to create a standardized security policy for all devices but needs to allow regional administrators to add specific local exceptions. Which FortiManager feature allows for this combination of centralized control and localized flexibility within a single policy package?

    Show answer & explanation

    Correct answer: C

    Policy Blocks are a FortiManager feature specifically designed for this purpose. They allow an administrator to define a standard, centralized set of policies while also creating placeholders (Policy Blocks) where device-level or group-level policies can be inserted. This provides a hierarchical policy structure, enabling a balance between global standardization and local customization without needing separate policy packages or ADOMs.

  9. Question 9

    Q9Multiple answers

    When troubleshooting a route-based IPsec VPN tunnel that is up but not passing traffic, which two areas should an administrator investigate first on the FortiGate? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    For a route-based VPN, even if the tunnel (Phase 1 and Phase 2) is successfully established, traffic will not flow unless two other conditions are met. First, there must be firewall policies that explicitly allow traffic from the local network to the VPN interface and vice-versa. Second, the FortiGate's routing table must have a static or dynamic route that directs traffic destined for the remote network to use the virtual IPsec interface as its gateway. Since the tunnel is already up, Phase 1 and Phase 2 settings are likely correct.

  10. Question 10

    Q10

    A university is using application control to block peer-to-peer (P2P) applications. However, students are using encrypted and obfuscated P2P clients that are not being detected. To improve the detection rate, what is the most critical prerequisite that must be configured on the firewall policy handling student traffic?

    Show answer & explanation

    Correct answer: C

    Modern applications, including P2P clients, heavily use SSL/TLS encryption to obfuscate their traffic. Application control can only inspect the content of traffic it can see. By enabling a 'deep-inspection' SSL/SSH Inspection profile on the firewall policy, the FortiGate can decrypt the traffic, allowing the application control engine to accurately identify and block the underlying P2P application. Without decryption, the engine can only rely on less reliable indicators like IP addresses or certificate information.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NSE7-EFW-7-2 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 682 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon