Fortinet NSE 7 - LAN Edge 7.0 Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 200 questions. Use the simulator for timed and flashcard mode.

Try Simulator

NSE7-LED-7-0 Sample Questions

  1. Question 1

    Q1

    A hospital is deploying a secure wired network using FortiSwitch and FortiAuthenticator. The requirements are to authenticate medical devices using MAC Authentication Bypass (MAB) and doctors' laptops using 802.1X EAP-TLS. Both device types connect to the same switch ports. The network administrator has configured the port security mode to 802.1X-mac-based. However, only the 802.1X authentications are succeeding; the MAB devices fail to connect. What is a potential cause for this issue on the FortiSwitch port configuration?

    Show answer & explanation

    Correct answer: B

    In 802.1X-mac-based security mode, both 802.1X and MAB can be used. However, MAB is not enabled by default. The administrator must explicitly enable it on the interface using the set mac-auth-bypass enable command. If this is not set, the switch will not attempt MAB for non-802.1X capable devices, causing their connections to fail.

  2. Question 2

    Q2Multiple answers

    An administrator is setting up RADIUS Single Sign-On (RSSO) with FortiAuthenticator to gather user group information from a Cisco Wireless LAN Controller (WLC). The WLC is configured to send RADIUS accounting messages to FortiAuthenticator. Despite correct configuration, no user logon events are appearing in the FortiAuthenticator logs. Which two settings are critical to verify for RSSO to function correctly in this scenario? (Select TWO)

    Show answer & explanation

    Correct answers: C, D

    For FortiAuthenticator to map users to groups via RSSO, it relies on specific RADIUS attributes. The fortinet-group-name VSA is the primary attribute used to convey group membership information in RADIUS accounting records.

    FortiAuthenticator will not process accounting messages from a RADIUS client unless the 'Enable RADIUS accounting' checkbox is explicitly enabled for that client's definition under Authentication > RADIUS Service > Clients.

  3. Question 3

    Q3

    An engineer is deploying a large campus network with FortiAPs managed by a FortiGate wireless controller. To improve roaming performance and reduce the impact of broadcast traffic, the engineer wants to convert broadcast traffic to unicast for known clients. Which FortiAP profile setting achieves this?

    Show answer & explanation

    Correct answer: C

    The broadcast-suppression setting controls how the FortiAP handles broadcast packets. Setting it to arp-known-clients instructs the AP to convert ARP request broadcasts into unicast frames for clients it already has in its ARP table. This reduces unnecessary broadcast traffic over the air, improving overall wireless network efficiency.

  4. Question 4

    Q4

    True or False: When configuring Zero-Touch Provisioning (ZTP) for a FortiSwitch using DHCP option 43, the FortiGate's IP address and the FortiLink interface name must be encoded in the option string.

    Show answer & explanation

    Correct answer: A

    This is true. For ZTP to work via DHCP option 43, the string must contain the IP address of the managing FortiGate and the name of the FortiLink interface that the switch should connect to. This information allows the switch to automatically establish the FortiLink connection upon boot-up.

  5. Question 5

    Q5

    A financial services company is implementing automatic quarantine for wired clients using the Fortinet Security Fabric. A requirement is that if a client PC is compromised and starts communicating with a known command-and-control server, it must be immediately moved to a remediation VLAN. Which component is responsible for triggering the quarantine action on the FortiSwitch?

    Show answer & explanation

    Correct answer: C

    In the Security Fabric, the FortiGate acts as the central enforcement point. When its security services (like IPS or Web Filter) detect an Indicator of Compromise (IoC), such as traffic to a C&C server, an automation stitch can be triggered. This stitch then instructs the FortiSwitch, via the FortiLink connection, to quarantine the offending client's switch port.

  6. Question 6

    Q6

    An administrator is configuring an LDAP server profile on a FortiGate to authenticate users against a Microsoft Active Directory server. The administrator needs to ensure that only users who are members of the 'VPN_Users' group can authenticate successfully. What is the correct value to use in the Group Filter field?

    Show answer & explanation

    Correct answer: B

    The correct LDAP filter syntax combines multiple conditions. (objectClass=user) ensures only user objects are considered. (sAMAccountName=*) is a placeholder for the username. (memberOf=CN=VPN_Users,CN=Users,DC=example,DC=com) checks for membership in the specified group, requiring the full Distinguished Name (DN) of the group.

  7. Question 7

    Q7Multiple answers

    A university is deploying a guest wireless network. They want to allow guests to self-register for access, but the access should automatically expire after 8 hours. Additionally, all guest traffic must be tunneled back to the FortiGate for inspection and NAT. Which two configurations are required to meet these requirements? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    Setting the security mode to Captive Portal is the fundamental step for creating a guest network. Configuring a local portal with a guest-specific user group on the FortiGate allows for self-registration and policy enforcement, including setting expiration timers for the guest accounts.

    Tunnel Mode (also known as Tunnel to Wireless Controller) encapsulates all wireless client traffic in a CAPWAP tunnel and sends it to the FortiGate. This is necessary for the FortiGate to inspect the traffic, apply security policies, and perform NAT before forwarding it to the internet.

  8. Question 8

    Q8

    An administrator manages a network where FortiSwitches are connected to a FortiGate via FortiLink. When viewing the Managed FortiSwitches page on the FortiGate, one of the switches is showing a status of Pre-authorized. What does this status indicate?

    Show answer & explanation

    Correct answer: A

    The Pre-authorized status means that an administrator has manually added the FortiSwitch's serial number to the FortiGate's managed switch list in anticipation of its connection. It is a placeholder entry waiting for the actual device to connect and establish the FortiLink tunnel.

  9. Question 9

    Q9

    A network security engineer needs to configure two-factor authentication for SSL VPN access. The primary authentication will be Active Directory credentials via LDAP, and the secondary factor will be a client certificate issued by an internal Certificate Authority (CA). Which type of user group must be created on the FortiGate to enforce this specific authentication sequence?

    Show answer & explanation

    Correct answer: C

    To enforce two-factor authentication where both factors must be satisfied, you must create a Firewall group that includes multiple member groups. In this case, one member group would be tied to the remote LDAP server, and the second member group would be for PKI users, linked to the internal CA. By placing both of these groups inside a parent group and setting the logic to AND (the default), the FortiGate requires a user to satisfy the conditions of both member groups to be considered authenticated.

  10. Question 10

    Q10

    During a wireless network deployment, an administrator needs to provide network access for a set of legacy IoT devices that do not support 802.1X authentication. The security policy requires these devices to be placed in a specific IoT VLAN. Which security mode should be configured on the SSID to achieve this with the highest level of security possible for these devices?

    Show answer & explanation

    Correct answer: A

    For devices that cannot use 802.1X, WPA2-Personal is the standard for encrypted communication. To add a layer of access control, MAC address filtering can be enabled. This allows the administrator to create a list of authorized MAC addresses for the IoT devices. While not foolproof, this combination provides both encryption and a basic level of device identity validation, which is a common and practical solution for securing legacy IoT devices.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NSE7-LED-7-0 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 200 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon