Fortinet NSE7_EFW-6.4 Exam Practice Questions (P. 2)
- Full Access (35 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Refer to the exhibit, which shows the output of a BGP debug command.

Which statement about the exhibit is true?

Which statement about the exhibit is true?
- AThe local router has not established a TCP session with 100.64.3.1Most Voted
- BThe local router BGP state is OpenConfirm with the 10.127.0.75 peer.
- CSince the counters were last reset, the 100.64.3.1 peer has never been down.
- DThe local router has received a total of three BGP prefixes from all peers.
Correct Answer:
A
Active means it is actively trying to establish a TCP connection using port 179, but has not yet actually established one.
A
Active means it is actively trying to establish a TCP connection using port 179, but has not yet actually established one.
send
light_mode
delete
Question #7
Refer to the exhibit, which contains a TCL script configuration on FortiManager.

An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any changes to the managed device after being run.
Why did the TCL script fail to make any changes to the managed device?

An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any changes to the managed device after being run.
Why did the TCL script fail to make any changes to the managed device?
- AThe TCL script must start with #include <>.
- BThe TCL command run_cmd has not been created.
- CChanges to an interface configuration can be made only by a CLI script.
- DIncomplete commands are ignored in TCL scripts.
Correct Answer:
B
B
send
light_mode
delete
Question #8
Refer to the exhibit, which contains the debug output of diagnose dvm device list.

Which two statements about the output shown in the exhibit are correct? (Choose two.)

Which two statements about the output shown in the exhibit are correct? (Choose two.)
- AADOMs are disabled on the FortiManager
- BThe FortiGate configuration is in sync with latest running revision history.
- CThere are pending device-level changes yet to be installed on Local-FortiGate.
- DThe policy package has been modified for Local-FortiGate.
Correct Answer:
BC
Reference:
https://docs.fortinet.com/document/fortimanager/7.0.0/upgrade-guide/959309/cli-example-of-diagnose-dvm-device-list
BC
Reference:
https://docs.fortinet.com/document/fortimanager/7.0.0/upgrade-guide/959309/cli-example-of-diagnose-dvm-device-list

send
light_mode
delete
Question #9
Refer to the exhibit, which shows a FortiGate configuration.

An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator change to fix the issue?

An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator change to fix the issue?
- AThe administrator must increase webfilter-timeout.
- BThe administrator must disable webfilter-force-off.Most Voted
- CThe administrator must change protocol to TCP.
- DThe administrator must enable fortiguard-anycast.
Correct Answer:
D
Reference:
https://docs.fortinet.com/document/fortigate/6.4.5/cli-reference/109620/config-system-fortiguard
D
Reference:
https://docs.fortinet.com/document/fortigate/6.4.5/cli-reference/109620/config-system-fortiguard

send
light_mode
delete
Question #10
When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does not provide the server name indication (SNI) extension?
- AFortiGate uses the CN information from the Subject field in the server certificate.
- BFortiGate switches to the full SSL inspection method to decrypt the data.
- CFortiGate uses the requested URL from the user's web browser.
- DFortiGate blocks the request without any further inspection.
Correct Answer:
A
Reference:
https://checkthefirewall.com/blogs/fortinet/ssl-inspection
A
Reference:
https://checkthefirewall.com/blogs/fortinet/ssl-inspection

send
light_mode
delete
All Pages