[Oct-2021] NSE 7 Network Security Architect NSE7_EFW-6.4 Exam Practice Dumps [Q54-Q77]

Share

[Oct-2021] NSE 7 Network Security Architect NSE7_EFW-6.4 Exam Practice Dumps

2021 NSE7_EFW-6.4 Premium Files Test pdf - Free Dumps Collection

NEW QUESTION 54
Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.

Which statement are true regarding the output in the exhibit? (Choose two.)

  • A. There are three FortiGuard serversthat are not responding to the queries sent by the FortiGate.
  • B. FortiGate will send the FortiGuard queries to the server withhighest weight.
  • C. A server's round trip delay (RTT) is not used to calculate its weight.
  • D. The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone.

Answer: B,D

 

NEW QUESTION 55
View the exhibit, which contains the output of a debug command, and then answer the question below.

Which of the following statements about theexhibit are true? (Choose two.)

  • A. In the network on port4, two OSPF routers are down.
  • B. The local FortiGate has been elected as the OSPF backup designated router.
  • C. Port4 is connected to the OSPF backbone area.
  • D. The local FortiGate's OSPF router ID is 0.0.0.4

Answer: C,D

 

NEW QUESTION 56
What does the dirty flag mean in aFortiGate session?

  • A. Traffic has been blocked by the antivirus inspection.
  • B. The next packet must be re-evaluated against the firewall policies.
  • C. The session must be removed from the former primary unit after an HA failover.
  • D. Traffic has been identified as from an application that is not allowed.

Answer: B

Explanation:
Explanation
https://kb.fortinet.com/kb/viewContent.do?externalId=FD40119&sliceId=1

 

NEW QUESTION 57
An administrator has configured the following CLIscript on FortiManager, which failed to apply any changes to the managed device after being executed.

Why didn't the script make any changes to the managed device?

  • A. Static routes can only be added using TCL scripts.
  • B. Commands that start with the # sign are not executed.
  • C. CLI scripts will add objectsonly if they are referenced by policies.
  • D. Incomplete commands are ignored in CLI scripts.

Answer: B

Explanation:
Explanation
https://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1000_Device%20Manager/2400_Scr A sequence of FortiGate CLI commands, as you would type them at the command line. A comment line starts with the number sign (#). A comment line will not be executed.

 

NEW QUESTION 58
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.

Which statements about this debug output are correct? (Choose two.)

  • A. The initiator has provided remote as its IPsec peer ID.
  • B. The negotiation is using AES128 encryption with CBC hash.
  • C. It showsa phase 1 negotiation.
  • D. The remote gateway IP address is 10.0.0.1.

Answer: A,C

 

NEW QUESTION 59
Which two conditions must be met for a statistic route to be active in the routing table? (Choose two.)

  • A. There is no other route, to the same destination, with a higherdistance.
  • B. The outgoing interface is up.
  • C. The link health monitor (if configured) is up.
  • D. The next-hop IP address is up.

Answer: B,C

 

NEW QUESTION 60
Which two statements about FortiManager is true when it is deployed as alocal FDS? (Choose two.)

  • A. It supports rating requests from both managed and unmanaged devices.
  • B. It provides VM license validation services.
  • C. It caches available firmware updates for unmanaged devices.
  • D. It can be configured as an update server, or a rating server, but not both.

Answer: B,C

 

NEW QUESTION 61
Examine the output from the BGP real time debugshown in the exhibit, then the answer the question below:

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. The state of the remote BGP peer will go toConnectafter it confirms the received prefixes.
  • B. The state of the remote BGP peer isOpenConfirm.
  • C. BGP peers have successfully interchangedOpenandKeepalivemessages.
  • D. Local BGP peer received a prefix fora default route.

Answer: C,D

 

NEW QUESTION 62
Examine the following traffic log; then answer the question below.
date-20xx-02-01 time=19:52:01 devname=master device_id="xxxxxxx" log_id=0100020007 type=event subtype=system pri critical vd=root service=kemel status=failure msg="NAT port is exhausted." What does the log mean?

  • A. There is not enough available memory in the system to create a new entry inthe NAT port table.
  • B. The limit for the maximum number of entries in the NAT port table has been reached.
  • C. The limit for the maximum number of simultaneous sessions sharing the same NAT port has been reached.
  • D. FortiGate does not have any available NAT port for a new connection.

Answer: C

 

NEW QUESTION 63
Examine the output of the 'get router info ospfneighbor' command shown in the exhibit; then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. The OSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the wan1 network.
  • B. The interface ToRemote is OSPF network type point-to-point.
  • C. The OSPF router with the ID 0.0.0.2is the designated router for the ToRemote network.
  • D. The local FortiGate is the backup designated router for the wan1 network.

Answer: B,D

Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html

 

NEW QUESTION 64
View the exhibit, which contains the output of a diagnose command, and then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
  • B. Servers with the D flag are considered to be down.
  • C. Servers with a negative TZ value are experiencing a service outage.
  • D. FortiGate used 209.222.147.3 as the initial server to validate its contract.

Answer: A,D

Explanation:
Explanation
A - because flag is Failed so fortigate will check if server is available every 15 minD-state is I , contact to validate contract info

 

NEW QUESTION 65
Examine the partial output fromtwo web filter debug commands; then answer the question below:

Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99.com?

  • A. Information technology.
  • B. Business.
  • C. General organization.
  • D. Finance and banking

Answer: B

 

NEW QUESTION 66
When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does notprovide the server name indication (SNI) extension?

  • A. FortiGate blocks the request without any furtherinspection.
  • B. FortiGate uses the CN information from the Subject field in the server certificate.
  • C. FortiGate uses the requested URL from the user's web browser.
  • D. FortiGate switches to the full SSL inspection method to decrypt the data.

Answer: B

 

NEW QUESTION 67
Which configuration can be used to reduce the number of BGP sessions in an IBGP network?

  • A. Next-hop-self
  • B. Neighbor range
  • C. Neighbor group
  • D. Route reflector

Answer: D

Explanation:
Explanation
Route reflectors help to reduce the number of IBGP sessions inside an AS. A route reflector forwards the routers learned from one peer to the other peers. If you configure route reflectors, you dont' need to create a full mesh IBGP network. All clients in a cluster only talck to route reflector to get sync routing updates. Route reflectors pass the routing updates to other route reflectors and border routers within the AS.

 

NEW QUESTION 68
Which real time debug should an administrator enable to troubleshoot RADIUS authentication problems?

  • A. Diagnose authd console -log enable.
  • B. Diagnose radius console -log enable.
  • C. Diagnose debug application radius -1.
  • D. Diagnose debug application fnbamd -1.

Answer: D

 

NEW QUESTION 69
Which statement about memory conserve mode is true?

  • A. A FortiGate exits conserve mode when the configured memory use threshold reaches yellow.
  • B. A FortiGate enters conserve mode when the configured memory use threshold reaches red
  • C. A FortiGate starts dropping new sessions when the configured memory use threshold reaches red
  • D. A FortiGate starts dropping all the new and old sessions when the configured memory use threshold reaches extreme.

Answer: C

 

NEW QUESTION 70
Which real time debug should an administrator enable to troubleshoot RADIUS authentication problems?

  • A. Diagnose authd console -log enable.
  • B. Diagnose radius console -log enable.
  • C. Diagnose debug application radius -1.
  • D. Diagnose debug application fnbamd -1.

Answer: D

Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=FD32838

 

NEW QUESTION 71
View the exhibit, which contains the output of a debug command, and then answer the question below.

Which one of the following statements about this FortiGate is correct?

  • A. It is currently in extreme conserve mode because of high memory usage.
  • B. It is currently in memory conserve mode because of high memory usage.
  • C. It is currently in proxy conserve mode because of high memory usage.
  • D. It is currently in system conserve mode because of high CPU usage.

Answer: B

 

NEW QUESTION 72
View theexhibit, which contains the output of diagnose sys session stat, and then answer the question below.

Which statements are correct regarding the output shown? (Choose two.)

  • A. There are 0 ephemeral sessions.
  • B. No sessions have been deleted because of memory pages exhaustion.
  • C. There are 166 TCP sessions waiting to complete the three-way handshake.
  • D. All the sessions in the session table areTCP sessions.

Answer: A,B

Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=FD40578

 

NEW QUESTION 73
A FortiGate has two default routes:

All Internet traffic is currently using port1. The exhibit shows partial information for one sample session of Internet traffic from an internal user:

What would happen with the traffic matching the above session if the priority on the firstdefault route (IDd1) were changed from 5 to 20?

  • A. Session would remain in the session table and its traffic would be shared between port1 and port2.
  • B. Session would remain in the session table and its traffic would keep using port1 as the outgoing interface.
  • C. Session would remain in the session table and its traffic would start using port2 as the outgoing interface.
  • D. Session would be deleted, so the client would need to start a new session.

Answer: B

 

NEW QUESTION 74
View the exhibit, which contains the output of a diagnose command, and then answer the question below.

What statements are correct regarding the output? (Choose two.)

  • A. Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.200.1.1.
  • B. This is anexpected session created by a session helper.
  • C. Traffic in the original direction (coming from the IP address 10.171.122.38) will be routed to the next-hop IP address 10.0.1.10.
  • D. This is an expected session created by an application control profile.

Answer: A,B

 

NEW QUESTION 75
A FortiGate device hasthe following LDAP configuration:

The administrator executed the 'dsquery' command in the Windows LDAp server 10.0.1.10, and got the following output:
>dsquery user -samid administrator
"CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab"
Based on the output, what FortiGate LDAP setting is configured incorrectly?

  • A. password.
  • B. cnid.
  • C. dn.
  • D. username.

Answer: D

Explanation:
Explanation
https://kb.fortinet.com/kb/viewContent.do?externalId=FD37516

 

NEW QUESTION 76
Which statements about bulk configuration changes using FortiManager CLI scripts are correct? (Choose two.)

  • A. When executed on the Device Database, you must use the installation wizard to apply the changes to the managed FortiGate.
  • B. When executed on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.
  • C. When executed on the All FortiGate in ADOM, changes are automatically installed without creating a new revision history.
  • D. When executed on the Policy Package, ADOM database, changes are applied directly to the managed FortiGate.

Answer: A,B

Explanation:
Explanation
CLI scripts can be run in three different ways:Device Database: By default, a script is executed on the device database. It is recommend you run the changes on the device database (default setting), as this allows you to check what configuration changes you will send to the managed device. Once scripts are run on the device database, you can install these changes to a managed device using the installation wizard.
Policy Package, ADOM database: If a script contains changes related to ADOM level objects and policies, you can change the default selection to run on Policy Package, ADOM database and can then be installed using the installation wizard.
Remote FortiGate directly (through CLI): A script can be executed directly on the device and you don't need to install these changes using the installation wizard. As the changes are directly installed on the managed device, no option is provided to verify and check the configuration changes through FortiManager prior to executing it.

 

NEW QUESTION 77
......

Get ready to pass the NSE7_EFW-6.4 Exam right now using our NSE 7 Network Security Architect  Exam Package: https://www.dumpsquestion.com/NSE7_EFW-6.4-exam-dumps-collection.html