[Sep-2021] Verified Fortinet Exam Dumps with NSE7_EFW-6.4 Exam Study Guide
Best Quality Fortinet NSE7_EFW-6.4 Exam Questions PrepAwayPDF Realistic Practice Exams [2021]
NEW QUESTION 34
Which of the following statements are correct regardingapplication layer test commands? (Choose two.)
- A. They are used to filter real-time debugs.
- B. Some of them display statistics and configuration information about a feature or process.
- C. They display real-time application debugs.
- D. Some of them can beused to restart an application.
Answer: B,D
Explanation:
Explanation
Application layer test commands don't display info in real time, but they do show statistics and configuration info about a feature or process. You can also use some of these commands to restart a pr ocess or execute a change in its operation.
NEW QUESTION 35
An administrator has configured two FortiGate devices for an HA cluster. While testing the HA failover, the administrator noticed that some of the switches in the network continue to send traffic to the former primary unit. The administrator decides to enable the setting link-failed-signal to fix the problem. Which statement is correct regarding this command?
- A. Sends a link failed signal to all connected devices.
- B. Forces the former primary device to shut down all its non-heartbeat interfaces forone second while the failover occurs.
- C. Disables all the non-heartbeat interfaces in all the HA members for two seconds after a failover.
- D. Sends an ARP packet to all connected devices, indicating that the HA virtual MAC address is reachable through a new master after a failover.
Answer: B
NEW QUESTION 36
Examine the output ofthe 'get router info bgp summary' command shown in the exhibit; then answer the question below.
Which statement can explain why the state of the remote BGP peer 10.200.3.1 is Connect?
- A. The local peer is receiving the BGP keepalives from the remote peer but it has not received the OpenConfirm yet.
- B. The local peer is receiving the BGP keepalives from the remote peer but it has not received any BGP prefix yet.
- C. The local peer has received the BGP prefixed from the remote peer.
- D. The TCP session for the BGP connection to 10.200.3.1 is down.
Answer: D
Explanation:
Explanation
http://www.ciscopress.com/articles/article.asp?p=2756480
NEW QUESTION 37
The CLI command set intelligent-mode <enable | disable> controls the IPS engine's adaptivescanning behavior. Which of the following statements describes IPS adaptive scanning?
- A. Determines when it is secure enough to stop scanning session traffic.
- B. Choose a matching algorithm based on available memory and the type of inspection being performed.
- C. Determines the optimal number of IPS engines required based on system load.
- D. Downloads signatures on demand from FDS based on scanning requirements.
Answer: A
Explanation:
Explanation
Configuring IPS intelligenceStarting with FortiOS 5.2,intelligent-mode is a new adaptive detection method. This command is enabled the default and it means that the IPS engine will perform adaptive scanning so that, for some traffic, the FortiGate can quickly finish scanning and offload the traffic to NPU orkernel. It is a balanced method which could cover all known exploits. When disabled, the IPS engine scans every single byte.
config ips globalset intelligent-mode {enable|disable}
NEW QUESTION 38
An administrator has configured the following CLIscript on FortiManager, which failed to apply any changes to the managed device after being executed.
Why didn't the script make any changes to the managed device?
- A. Static routes can only be added using TCL scripts.
- B. Commands that start with the # sign are not executed.
- C. CLI scripts will add objectsonly if they are referenced by policies.
- D. Incomplete commands are ignored in CLI scripts.
Answer: B
Explanation:
Explanation
https://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1000_Device%20Manager/2400_Scr A sequence of FortiGate CLI commands, as you would type them at the command line. A comment line starts with the number sign (#). A comment line will not be executed.
NEW QUESTION 39
Examine the output of the 'get router info ospfneighbor' command shown in the exhibit; then answer the question below.
Which statements are true regarding the output in the exhibit? (Choose two.)
- A. The OSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the wan1 network.
- B. The interface ToRemote is OSPF network type point-to-point.
- C. The OSPF router with the ID 0.0.0.2is the designated router for the ToRemote network.
- D. The local FortiGate is the backup designated router for the wan1 network.
Answer: B,D
Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html
NEW QUESTION 40
Examine the output from the 'diagnose debug authd fsso list' command; then answer the question below.
# diagnose debug authd fsso list-FSSO logons-IP: 192.168.3.1 User: STUDENT Groups: TRAINI NGAD/USERS Workstation: INTERNAL2. TRAINING. LAB The IP address 192.168.3.1 is NOT the one used by the workstation INTERNAL2. TRAINING. LAB.
What should the administrator check?
- A. The IP address recorded in the logon event for the user STUDENT.
- B. The reserve DNS lookup forthe IP address 192.168.3.1.
- C. The DNS name resolution for the workstation name INTERNAL2. TRAINING. LAB.
- D. The source IP address of the traffic arriving to the FortiGate from the workstation INTERNAL2.
TRAINING. LAB.
Answer: D
NEW QUESTION 41
View the global IPS configuration, and then answer the question below.
Which of the following statements is true regarding this configuration?
- A. FortiGate will spawn IPS engine instances based on the system load.
- B. New packets will be passed through without inspection if the IPS socket buffer runs out of memory.
- C. IPS will scan every byte in every session.
- D. IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.
Answer: C
NEW QUESTION 42 
Refer to the exhibit, which contains the output ofget system ha status.
Which two statements about the output are true? (Choose two.)
- A. Master is selected based on the priority configured underconfig system ha.
- B. The slave configuration is synchronized with the master.
- C. port7is used as the HA heartbeat on all devices in the cluster.
- D. The HA management IP is 169.254.0.2.
Answer: A,C
NEW QUESTION 43
Which two statements about FortiManager is true when it is deployed as alocal FDS? (Choose two.)
- A. It supports rating requests from both managed and unmanaged devices.
- B. It provides VM license validation services.
- C. It caches available firmware updates for unmanaged devices.
- D. It can be configured as an update server, or a rating server, but not both.
Answer: B,C
NEW QUESTION 44
A FortiGate device has the following LDAP configuration:
The LDAP user student cannot authenticate. The exhibit shows the output of the authentication real time debug while testing the student account:
Based on the above output, what FortiGate LDAP settings must the administer check? (Choose two.)
- A. cnid.
- B. dn.
- C. password.
- D. username.
Answer: C,D
Explanation:
Explanation
https://kb.fortinet.com/kb/viewContent.do?externalId=13141
NEW QUESTION 45
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.
Which statements about this debug output are correct? (Choose two.)
- A. The initiator has provided remote as its IPsec peer ID.
- B. The negotiation is using AES128 encryption with CBC hash.
- C. It showsa phase 1 negotiation.
- D. The remote gateway IP address is 10.0.0.1.
Answer: A,C
NEW QUESTION 46
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.
Why didn't the tunnel come up?
- A. The remote gateway's phase 2configuration does not match the local gateway's phase 2 configuration.
- B. The remote gateway's phase 1 configuration does not match the local gateway's phase 1 configuration.
- C. The remote gateway is using aggressive mode and the local gateway is configured to use man mode.
- D. The pre-shared keys do not match.
Answer: B
NEW QUESTION 47
View the exhibit, which contains the output of a debug command, and then answer the question below.
What statement is correct about this FortiGate?
- A. It is currently in kernel conserve mode because of high memory usage.
- B. It iscurrently in system conserve mode because of high CPU usage.
- C. It is currently in FD conserve mode.
- D. It is currently in system conserve mode because of high memory usage.
Answer: D
NEW QUESTION 48
Examine the following traffic log; then answer the question below.
date-20xx-02-01 time=19:52:01 devname=master device_id="xxxxxxx" log_id=0100020007 type=event subtype=system pri critical vd=root service=kemel status=failure msg="NAT port is exhausted." What does the log mean?
- A. There is not enough available memory in the system to create a new entry inthe NAT port table.
- B. The limit for the maximum number of entries in the NAT port table has been reached.
- C. The limit for the maximum number of simultaneous sessions sharing the same NAT port has been reached.
- D. FortiGate does not have any available NAT port for a new connection.
Answer: C
NEW QUESTION 49
Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router The second unit is elected as the backup designated router Under normal operation, how many OSPFfull adjacencies are formed to each of the other two units?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 50
An administrator is running the following sniffer in a FortiGate:
diagnose sniffer packet any "host 10.0.2.10" 2
What information isincluded in the output of the sniffer? (Choose two.)
- A. IP payload.
- B. Port names.
- C. IP headers.
- D. Ethernet headers.
Answer: A,C
Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=11186
NEW QUESTION 51
Examine the partial output from the IKE real time debug shown in the exhibit; then answer the question below.
Why didn't the tunnel come up?
- A. Theremote gateway's Phase-2 configuration does not match the local gateway's phase-2 configuration.
- B. IKE mode configuration is not enabled in the remote IPsec gateway.
- C. The remote gateway's Phase-1 configuration does not match the local gateway's phase-1 configuration.
- D. One IPsec gateway is using main mode, while theother IPsec gateway is using aggressive mode.
Answer: C
NEW QUESTION 52
Which statement about memory conserve mode is true?
- A. A FortiGate exits conserve mode when the configured memory use threshold reaches yellow.
- B. A FortiGate enters conserve mode when the configured memory use threshold reaches red
- C. A FortiGate starts dropping new sessions when the configured memory use threshold reaches red
- D. A FortiGate starts dropping all the new and old sessions when the configured memory use threshold reaches extreme.
Answer: C
NEW QUESTION 53
What is the purpose of an internal segmentation firewall (ISFW)?
- A. It is the first line of defense at the network perimeter.
- B. It is anall-in-one security appliance that is placed at remote sites to extend the enterprise network.
- C. It inspects incoming traffic to protect services in the corporate DMZ.
- D. It splits the network into multiple security segments to minimize the impact of breaches.
Answer: D
Explanation:
Explanation
ISFW splits your network into multiple security segments. They serve as a breach containers from attacks that come from inside.
NEW QUESTION 54
View the exhibit, which contains the output of a debug command, and then answer the question below.
Which of the following statements about theexhibit are true? (Choose two.)
- A. In the network on port4, two OSPF routers are down.
- B. The local FortiGate has been elected as the OSPF backup designated router.
- C. Port4 is connected to the OSPF backbone area.
- D. The local FortiGate's OSPF router ID is 0.0.0.4
Answer: C,D
NEW QUESTION 55
View the following FortiGate configuration.
All traffic to theInternet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network:
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user's session?
- A. The session would remain in thesession table, and its traffic would start to egress from port2.
- B. The session would remain in the session table, and its traffic would still egress from port1.
- C. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
- D. The session would be deleted, so the client would need to start a new session.
Answer: B
Explanation:
Explanation
http://kb.fortinet.com/kb/documentLink.do?externalID=FD40943
NEW QUESTION 56
Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.
Which statement are true regarding the output in the exhibit? (Choose two.)
- A. There are three FortiGuard serversthat are not responding to the queries sent by the FortiGate.
- B. FortiGate will send the FortiGuard queries to the server withhighest weight.
- C. A server's round trip delay (RTT) is not used to calculate its weight.
- D. The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone.
Answer: B,D
NEW QUESTION 57
View the IPS exit log, and then answer the question below.
# diagnose test application ipsmonitor 3
ipsengine exit log"
pid = 93 (cfg), duration = 5605322 (s) at Wed Apr19 09:57:26 2017
code = 11, reason: manual
What is the status of IPS on this FortiGate?
- A. IPS engine memory consumption has exceeded the model-specific predefined value.
- B. There are communication problems between theIPS engine and the management database.
- C. IPS daemon experienced a crash.
- D. All IPS-related features have been disabled in FortiGate's configuration.
Answer: D
Explanation:
Explanation
The command diagnose test application ipsmonitor includes many options that are useful for troubleshooting purposes.Option 3 displays the log entries generated every time an IPS engine process stopped. There are various reasons why these logs are generated:Manual: Because of the configuration, IPS no longer needs to run (that is, all IPS-releated features have been disabled)
NEW QUESTION 58
......
Authentic Best resources for NSE7_EFW-6.4: https://www.prepawaypdf.com/Fortinet/NSE7_EFW-6.4-practice-exam-dumps.html
NSE7_EFW-6.4 Test Engine Practice Exam: https://drive.google.com/open?id=1PI1dUIwMF237NB_OqkAzaCuvF4x1FxX0