NSE7_EFW-6.0 Dumps

NSE7_EFW-6.0 Free Practice Test

Fortinet NSE7_EFW-6.0: Fortinet NSE 7 - Enterprise Firewall 6.0

QUESTION 16

Which statement is true regarding File description (FD) conserve mode?

Correct Answer: B

QUESTION 17

View the exhibit, which contains a session entry, and then answer the question below.
<>

Correct Answer: A

QUESTION 18

An administrator wants to capture ESP traffic between two FortiGates using the built-in sniffer. If the administrator knows that there is no NAT device located between both FortiGates, what command should the administrator execute?

Correct Answer: C

QUESTION 19

An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug:
diagnose debug application ike-1 diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?

Correct Answer: B
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-ipsecvpn-54/IPsec_VPN_Concepts/IKE_Packet

QUESTION 20

Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network. What HA setting must be changed in one of the HA clusters to fix the problem?

Correct Answer: A
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_failoverVMAC.htm