NSE7_EFW-7.0 Dumps

NSE7_EFW-7.0 Free Practice Test

Fortinet NSE7_EFW-7.0: Fortinet NSE 7 - Enterprise Firewall 7.0

QUESTION 6

An administrator added the following Ipsec VPN to a FortiGate configuration:
configvpn ipsec phasel -interface edit "RemoteSite"
set type dynamic
set interface "portl" set mode main
set psksecret ENC LCVkCiK2E2PhVUzZe next
end
config vpn ipsec phase2-interface edit "RemoteSite"
set phasel name "RemoteSite" set proposal 3des-sha256
next end
However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit.
NSE7_EFW-7.0 dumps exhibit
NSE7_EFW-7.0 dumps exhibit
What is causing the IPsec problem in the phase 1 ?

Correct Answer: C

QUESTION 7

What is the diagnose test application ipsmonitor 99 command used for?

Correct Answer: D

QUESTION 8

Examine the IPsec configuration shown in the exhibit; then answer the question below.
NSE7_EFW-7.0 dumps exhibit
An administrator wants to monitor the VPN by enabling the IKE real time debug using these commands: diagnose vpn ike log-filter src-addr4 10.0.10.1
diagnose debug application ike -1 diagnose debug enable
The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged between both IPsec gateways. However, the IKE real time debug does NOT show any output. Why isn’t there any output?

Correct Answer: B

QUESTION 9

Refer to the exhibit, which contains the partial output of a diagnose command.
NSE7_EFW-7.0 dumps exhibit
Based on the output, which two statements are correct? (Choose two.)

Correct Answer: AB

QUESTION 10

Which statements about bulk configuration changes using FortiManager CLI scripts are correct? (Choose two.)

Correct Answer: BD
CLI scripts can be run in three different ways:Device Database: By default, a script is executed on the device database. It is recommend you run the changes on the device database (default setting), as this allows you to check what configuration changes you will send to the managed device. Once scripts are run on the device database, you can install these changes to a managed device using the installation wizard.
Policy Package, ADOM database: If a script contains changes related to ADOM level objects and policies, you can change the default selection to run on Policy Package, ADOM database and can then be installed using the installation wizard.
Remote FortiGate directly (through CLI): A script can be executed directly on the device and you don’t need to install these changes using the installation wizard. As the changes are directly installed on the managed device, no option is provided to verify and check the configuration changes through FortiManager prior to executing it.