Fortinet NSE7_LED-7.0 Exam Practice Questions (P. 1)
- Full Access (51 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Refer to the exhibit.


Examine the FortiGate user group configuration and the Windows AD LDAP group membership information shown in the exhibit.
FortiGate is configured to authenticate SSL VPN users against Windows AD using LDAP. The administrator configured the SSL VPN user group for SSL VPN users. However, the administrator noticed that both the t and student and jsmith users can connect to SSL VPN.
Which change can the administrator make on FortiGate to restrict the SSL VPN service to the student user only?


Examine the FortiGate user group configuration and the Windows AD LDAP group membership information shown in the exhibit.
FortiGate is configured to authenticate SSL VPN users against Windows AD using LDAP. The administrator configured the SSL VPN user group for SSL VPN users. However, the administrator noticed that both the t and student and jsmith users can connect to SSL VPN.
Which change can the administrator make on FortiGate to restrict the SSL VPN service to the student user only?
- AIn the SSL VPN user group configuration, set Group Name to CN=SSLVPN,CN=Users,DC=trainingAD,DC=training,DC=lab.
- BIn the SSL VPN user group configuration, change Name to CN=SSLVPN,CN=Users,DC=trainingAD,DC=training,DC=lab.
- CIn the SSL VPN user group configuration, set Group Name to CN=Domain Users,CN=Users,DC=trainingAD,DC=training,DC=lab.
- DIn the SSL VPN user group configuration, change Type to Fortinet Single Sign-On (FSSO).
Correct Answer:
A
A
send
light_mode
delete
Question #2
Refer to the exhibits.


Examine the firewall policy configuration and SSID settings.
An administrator has configured a guest wireless network on FortiGate using the external captive portal. The administrator has verified that the external captive portal URL is correct. However, wireless users are not able to see the captive portal login page.
Given the configuration shown in the exhibit and the SSID settings, which configuration change should the administrator make to fix the problem?


Examine the firewall policy configuration and SSID settings.
An administrator has configured a guest wireless network on FortiGate using the external captive portal. The administrator has verified that the external captive portal URL is correct. However, wireless users are not able to see the captive portal login page.
Given the configuration shown in the exhibit and the SSID settings, which configuration change should the administrator make to fix the problem?
- ADisable the user group from the SSID configuration.
- BEnable the captive-portal-exempt option in the firewall policy with the ID 11.Most Voted
- CApply a guest.portal user group in the firewall policy with the ID 11.
- DInclude the wireless client subnet range in the Exempt Source section.
Correct Answer:
B
B
send
light_mode
delete
Question #3
Which two statements about the MAC-based 802.1X security mode available on FortiSwitch are true? (Choose two.)
- AFortiSwitch authenticates a single device, and opens the port to other devices connected to the port.
- BFortiSwitch authenticates each device connected to the port.Most Voted
- CIt cannot be used in conjunction with MAC authentication bypass.
- DFortiSwitch can grant different access levels to each device connected to the port.Most Voted
Correct Answer:
BD
BD
send
light_mode
delete
Question #4
A wireless network in a school provides guest access using a captive portal to allow unregistered users to self-register and access the network. The administrator is requested to update the existing configuration to provide captive portal authentication through a secure connection (HTTPS).
Which two changes must the administrator make to enforce HTTPS authentication? (Choose two.)
Which two changes must the administrator make to enforce HTTPS authentication? (Choose two.)
- ACreate a new SSID with the HTTPS captive portal URL.
- BEnable HTTP redirect in the user authentication settings.Most Voted
- CDisable HTTP administrative access on the guest SSID to enforce HTTPS connection.
- DUpdate the captive portal URL to use HTTPS on FortiGate and FortiAuthenticator.Most Voted
Correct Answer:
BD
BD
send
light_mode
delete
Question #5
Refer to the exhibit.

The exhibits show the wireless network (VAP) SSID profiles defined on FortiManager and an AP profile assigned to a group of APs that are supported by FortiGate.
None of the APs are broadcasting the SSIDs defined by the AP profile.
Which changes do you need to make to enable the SSIDs to broadcast?

The exhibits show the wireless network (VAP) SSID profiles defined on FortiManager and an AP profile assigned to a group of APs that are supported by FortiGate.
None of the APs are broadcasting the SSIDs defined by the AP profile.
Which changes do you need to make to enable the SSIDs to broadcast?
- AIn the SSIDs section, enable Tunnel.
- BEnable one channel in the Channels section.Most Voted
- CEnable multiple channels in the Channels section and enable Radio Resource Provision.
- DIn the SSIDs section, enable Manual and assign the networks manually.
Correct Answer:
D
D
send
light_mode
delete
All Pages