Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

[Q37-Q62] Best Quality Fortinet NSE7_EFW-6.4 Exam Questions Actual4test Realistic Practice Exams [2021]

Share

Best Quality Fortinet NSE7_EFW-6.4 Exam Questions Actual4test Realistic Practice Exams [2021]

Critical Information To Fortinet NSE 7 - Enterprise Firewall 6.4 Pass the First Time

NEW QUESTION 37
Examine the output of the 'get router info ospfneighbor' command shown in the exhibit; then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. The OSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the wan1 network.
  • B. The interface ToRemote is OSPF network type point-to-point.
  • C. The OSPF router with the ID 0.0.0.2is the designated router for the ToRemote network.
  • D. The local FortiGate is the backup designated router for the wan1 network.

Answer: B,D

Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html

 

NEW QUESTION 38
View theexhibit, which contains the output of diagnose sys session stat, and then answer the question below.

Which statements are correct regarding the output shown? (Choose two.)

  • A. There are 0 ephemeral sessions.
  • B. No sessions have been deleted because of memory pages exhaustion.
  • C. There are 166 TCP sessions waiting to complete the three-way handshake.
  • D. All the sessions in the session table areTCP sessions.

Answer: A,B

Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=FD40578

 

NEW QUESTION 39
View the exhibit, which contains an entry in the session table, and then answer the question below.

Which one of the following statements is true regarding FortiGate's inspection of this session?

  • A. FortiGate applied explicit proxy-based inspection.
  • B. FortiGate forwarded this session without any inspection.
  • C. FortiGate applied flow-based inspection.
  • D. FortiGate applied proxy-based inspection.

Answer: D

Explanation:
Explanation
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042

 

NEW QUESTION 40
View the exhibit, which contains the output of a diagnose command, and then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
  • B. Servers with the D flag are considered to be down.
  • C. Servers with a negative TZ value are experiencing a service outage.
  • D. FortiGate used 209.222.147.3 as the initial server to validate its contract.

Answer: A,D

Explanation:
Explanation
A - because flag is Failed so fortigate will check if server is available every 15 minD-state is I , contact to validate contract info

 

NEW QUESTION 41
The CLI command set intelligent-mode <enable | disable> controls the IPS engine's adaptivescanning behavior. Which of the following statements describes IPS adaptive scanning?

  • A. Determines when it is secure enough to stop scanning session traffic.
  • B. Choose a matching algorithm based on available memory and the type of inspection being performed.
  • C. Determines the optimal number of IPS engines required based on system load.
  • D. Downloads signatures on demand from FDS based on scanning requirements.

Answer: A

Explanation:
Explanation
Configuring IPS intelligenceStarting with FortiOS 5.2,intelligent-mode is a new adaptive detection method. This command is enabled the default and it means that the IPS engine will perform adaptive scanning so that, for some traffic, the FortiGate can quickly finish scanning and offload the traffic to NPU orkernel. It is a balanced method which could cover all known exploits. When disabled, the IPS engine scans every single byte.
config ips globalset intelligent-mode {enable|disable}

 

NEW QUESTION 42
What configuration changes can reduce the memory utilization in a FortiGate? (Choose two.)

  • A. Increase the FortiGuard cache time to live.
  • B. Reduce the maximum file size to inspect.
  • C. Increase the TCP session timers.
  • D. Reduce the session time to live.

Answer: B,D

 

NEW QUESTION 43
View the exhibit, which contains the output of a web diagnose command, and then answer the question below.

Which one of the following statements explains why the cache statistics are all zeros?

  • A. FortiGate is using a flow-based web filter and the cache applies only to proxy-based inspection.
  • B. There are no users making web requests.
  • C. The FortiGuard web filter cache is disabled in the FortiGate's configuration.
  • D. Theadministrator has reallocated the cache memory to a separate process.

Answer: C

 

NEW QUESTION 44
Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router The second unit is elected as the backup designated router Under normal operation, how many OSPFfull adjacencies are formed to each of the other two units?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

 

NEW QUESTION 45
Refer to exhibit, which contains the output of a BGP debug command.

Which statement explains why the state of the 10.200.3.1 peer is Connect?

  • A. The TCP session to 10.200.3.1 has not completed the 3-way handshake.
  • B. The local router has received the BGP prefixes from the remote peer.
  • C. The local router is receiving BGP keepalives from theremote peer, but the local peer has not received the OpenConfirm yet.
  • D. The local router is receiving the BGP keepalives from the peer, but it has not received a BGP prefix yet.

Answer: A

Explanation:
Explanation
BGP neighbor states and how they change:* Idle: Initial state* Connect: Waiting for a successful three-way TCP connection* Active: Unable to establish the TCP session* OpenSent: Waiting for an OPEN message from the peer* OpenConfirm: Waiting for the keepalive message from the peer* Established: Peers have successfully exchanged OPEN and keepalive messages

 

NEW QUESTION 46
A FortiGate device has the following LDAP configuration:

The LDAP user student cannot authenticate. The exhibit shows the output of the authentication real time debug while testing the student account:

Based on the above output, what FortiGate LDAP settings must the administer check? (Choose two.)

  • A. cnid.
  • B. dn.
  • C. password.
  • D. username.

Answer: C,D

Explanation:
Explanation
https://kb.fortinet.com/kb/viewContent.do?externalId=13141

 

NEW QUESTION 47
Anadministrator has decreased all the TCP session timers to optimize the FortiGate memory usage. However, after the changes, one network application started to have problems. During the troubleshooting, the administrator noticed that the FortiGate deletes the sessions after the clients send the SYN packets, and before the arrival of the SYN/ACKs. When the SYN/ACK packets arrive to the FortiGate, the unit has already deleted the respective sessions. Which TCP session timer must be increased to fix this problem?

  • A. TCP time wait.
  • B. TCP session time to live.
  • C. TCP half close.
  • D. TCP half open.

Answer: D

Explanation:
Explanation
http://docs-legacy.fortinet.com/fos40hlp/43prev/wwhelp/wwhimpl/common/html/wwhe lp.htm?context=fgt&file=CLI_get_Commands.58.25.html The tcp-halfopen-timer controls for how long, after a SYN packet, a session without SYN/ACKremains in the table.
The tcp-halfclose-timer controls for how long, after a FIN packet, a session without FIN/ACKremains in the table.
The tcp-timewait-timer controls for how long, after a FIN/ACK packet, a session remains in thetable. A closed session remains in the session table for a few seconds more to allow any out-of-sequence packet.

 

NEW QUESTION 48
Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network. What HA setting must be changed in one of the HA clusters to fix the problem?

  • A. Group ID.
  • B. Session pickup.
  • C. Gratuitous ARPs.
  • D. Group name.

Answer: A

Explanation:
Explanation
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_failoverVMAC.htm

 

NEW QUESTION 49
Which two configuration settings change the behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

  • A. IPS failopen
  • B. mem failopen
  • C. UTM failopen
  • D. AV failopen

Answer: A,D

 

NEW QUESTION 50
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.

Which statements about this debug output are correct? (Choose two.)

  • A. The initiator has provided remote as its IPsec peer ID.
  • B. The negotiation is using AES128 encryption with CBC hash.
  • C. It showsa phase 1 negotiation.
  • D. The remote gateway IP address is 10.0.0.1.

Answer: A,C

 

NEW QUESTION 51
Examine the output of the 'diagnose ips anomaly list' command shown in the exhibit; then answer the question below.

Which IP addresses are included in the output of thiscommand?

  • A. Those whose traffic was detected as an anomaly by an IPS sensor.
  • B. Those whose traffic matches an IPS sensor.
  • C. Those whose traffic matches a DoS policy.
  • D. Those whose traffic exceeded a threshold of a matching DoS policy.

Answer: C

 

NEW QUESTION 52
Which of the following statements is trueregarding a FortiGate configured as an explicit web proxy?

  • A. FortiGate limits the number of workstations that authenticate using the same web proxy usercredentials.
    This limit CANNOT be modified by the administrator.
  • B. FortiGate limits the total number of simultaneous explicit web proxy users.
  • C. FortiGate limits the number of simultaneous sessions per explicit web proxy user The limit CAN be modified by the administrator
  • D. FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT be modified by the administrator.

Answer: B

Explanation:
Explanation
https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-WAN-opt-52/web_proxy.htm#Explicit2 The explicit proxy does not limit the number of active sessions for each user. As a result the actual explicit proxy session count is usually much higherthan the number of explicit web proxy users. If an excessive number of explicit web proxy sessions is compromising system performance you can limit the amount of users if the FortiGate unit is operating with multiple VDOMs.

 

NEW QUESTION 53
Examine the following partial outputs from two routing debug commands; then answer the question below.
# get router info kernel
tab=254 vf=0 scope=0type=1 proto=11 prio=00.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0 gwy=10.200.1.254 dev=2(port1) tab=254 vf=0 scope=0type=1 proto=11 prio=10 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0 gwy=10.200.2.254 dev=3(port2) tab=254 vf=0 scope=253type=1 proto=2 prio=0 0.0.0.0/0.0.0.0/.->10.0.1.0/24 pref=10.0.1.254 gwy=0.0.0.0 dev=4(port3)
# get router info routing-table all s*0.0.0.0/0 [10/0] via 10.200.1.254, portl [10/0] via 10.200.2.254, port2,
[10/0] dO.0.1.0/24 is directly connected, port3 dO.200.1.0/24 is directly connected, portl d0.200.2.0/24 is directly connected, port2 Which outbound interface or interfaces will be used by this FortiGate to route web traffic from internal users to the Internet?

  • A. port2.
  • B. Both portl and port2.
  • C. port3.
  • D. port!

Answer: A

 

NEW QUESTION 54
An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs thedebug flow while attempting the connection using HTTP. The output of the debug flow is shown in the exhibit:

Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)

  • A. HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.
  • B. HTTP administrative access is configured with a port number different than 80.
  • C. The packet is denied because of reverse path forwarding check.
  • D. Redirection of HTTP to HTTPS administrative access is disabled.

Answer: A,B

 

NEW QUESTION 55
What global configuration setting changes the behavior for content-inspected traffic while FortiGate is in system conserve mode?

  • A. ips-failopen
  • B. av-failopen
  • C. utm-failopen
  • D. mem-failopen

Answer: B

Explanation:
Explanation
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles-54/Other_Profile_Consideration

 

NEW QUESTION 56
Refer to the exhibit, which contains the output of diagnose sys session list.

If the HA ID for the primary unit is zero (0), which statement about the output is true?

  • A. This session cannot be synced with the slave unit.
  • B. This session is for HA heartbeat traffic.
  • C. The inspection of this session has been offloaded to the slave unit.
  • D. The master unit is processing this traffic.

Answer: D

 

NEW QUESTION 57
View the exhibit, which contains theoutput of get sys ha status, and then answer the question below.

Which statements are correct regarding the output? (Choose two.)

  • A. Master is selected because it is the only device in the cluster.
  • B. The slave configuration is not synchronized with the master.
  • C. port 7 is used the HA heartbeat on all devices in the cluster.
  • D. The HA management IP is 169.254.0.2.

Answer: B,C

 

NEW QUESTION 58
Examine the output ofthe 'get router info bgp summary' command shown in the exhibit; then answer the question below.

Which statement can explain why the state of the remote BGP peer 10.200.3.1 is Connect?

  • A. The local peer is receiving the BGP keepalives from the remote peer but it has not received the OpenConfirm yet.
  • B. The local peer is receiving the BGP keepalives from the remote peer but it has not received any BGP prefix yet.
  • C. The local peer has received the BGP prefixed from the remote peer.
  • D. The TCP session for the BGP connection to 10.200.3.1 is down.

Answer: D

Explanation:
Explanation
http://www.ciscopress.com/articles/article.asp?p=2756480

 

NEW QUESTION 59
View the exhibit, which contains a screenshot of some phase-1settings, and then answer the question below.

The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:

However, the IKE real time debug does not show any output. Why?

  • A. The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
  • B. The debug shows only error messages. If there is no output, then the tunnel is operating normally.
  • C. The log-filter setting was set incorrectly. The VPN's traffic does not match thisfilter.
  • D. The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.

Answer: C

 

NEW QUESTION 60
Which of the following statements are true regardingthe SIP session helper and the SIP application layer gateway (ALG)? (Choose three.)

  • A. SIP ALG supports SIP HA failover; SIP helper does not.
  • B. SIP ALG can create expected sessions for media traffic; SIP helper does not.
  • C. SIP session helper runs in the kernel; SIP ALG runs as a user space process.
  • D. SIP helper supports SIP over TCP and UDP; SIP ALG supports only SIP over UDP.
  • E. SIP ALG supports SIP over IPv6; SIP helper does not.

Answer: A,B,E

 

NEW QUESTION 61
View theexhibit, which contains the output of a BGP debug command, and then answer the question below.

Which of the following statements about the exhibit are true? (Choose two.)

  • A. For the peer 10.125.0.60, the BGP state of is Established.
  • B. The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.
  • C. Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.
  • D. The local BGPpeer has received a total of three BGP prefixes.

Answer: A,B

 

NEW QUESTION 62
......

NSE7_EFW-6.4 EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.actual4test.com/NSE7_EFW-6.4_examcollection.html

Best Quality Fortinet NSE7_EFW-6.4 Exam Questions: https://drive.google.com/open?id=1ZLw_Ia43k-7STXdZpvqZcUbgD3yKnpKv