Fortinet NSE7_LED-7.0 Exam Practice Questions (P. 2)
- Full Access (51 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Refer to the exhibit.

Examine the IPsec VPN phase 1 configuration shown in the exhibit.
An administrator wants to use certificate-based authentication for an IPsec VPN user.
Which three configuration changes must you make on FortiGate to perform certificate-based authentication for the IPsec VPN user? (Choose three.)

Examine the IPsec VPN phase 1 configuration shown in the exhibit.
An administrator wants to use certificate-based authentication for an IPsec VPN user.
Which three configuration changes must you make on FortiGate to perform certificate-based authentication for the IPsec VPN user? (Choose three.)
- ACreate a PKI user for the IPsec VPN user, and then configure the IPsec VPN tunnel to accept the PKI user as peer certificate.
- BIn the Authentication section of the IPsec VPN tunnel, in the Method drop-down list, select Signature, and then select the certificate that FortiGate will use for IPsec VPN.Most Voted
- CIn the IKE section of the IPsec VPN tunnel, in the Mode field, select Main (ID protection).
- DImport the CA that signed the user certificate.Most Voted
- EEnable XAUTH on the IPsec VPN tunnel.Most Voted
Correct Answer:
ABD
ABD
send
light_mode
delete
Question #7
You are investigating a report of poor wireless performance in a network that you manage. The issue is related to an AP interface in the 5 GHz range. You are monitoring the channel utilization over time.
What is the recommended maximum utilization value that an interface should not exceed?
What is the recommended maximum utilization value that an interface should not exceed?
send
light_mode
delete
Question #8
Which CLI command should an administrator use to view the certificate verification process in real time?
- Adiagnose debug application foauthd -1
- Bdiagnose debug application radiusd -1
- Cdiagnose debug application authd -1
- Ddiagnose debug application fnbamd -1
Correct Answer:
D
D
send
light_mode
delete
Question #9
Which two statements about the guest portal on FortiAuthenticator are true? (Choose two.)
- AEach remote user on FortiAuthenticator can sponsor up to 10 guest accounts.
- BAdministrators must approve all guest accounts before they can be used.
- CThe guest portal provides pre and post-log in services.Most Voted
- DAdministrators can use one or more incoming parameters to configure a mapping rule for the guest portal.Most Voted
Correct Answer:
CD
CD
send
light_mode
delete
Question #10
Refer to the exhibits.


In the wireless configuration shown in the exhibits, an AP is deployed in a remote site and has a wireless network (VAP) called Corporate deployed to it.
The network is a tunnelled network; however, clients connecting to a wireless network require access to a local printer. Clients are trying to print to a printer on the remote site, but are unable to do so.
Which configuration change is required to allow clients connected to the Corporate SSID to print locally?


In the wireless configuration shown in the exhibits, an AP is deployed in a remote site and has a wireless network (VAP) called Corporate deployed to it.
The network is a tunnelled network; however, clients connecting to a wireless network require access to a local printer. Clients are trying to print to a printer on the remote site, but are unable to do so.
Which configuration change is required to allow clients connected to the Corporate SSID to print locally?
- AConfigure split-tunneling in the vap configuration.Most Voted
- BConfigure split-tunneling in the wtp-profile configuration.
- CDisable the Block Intra-SSID Traffic (Intra-vap-privacy) setting on the SSID (VAP) profile.
- DConfigure the printer as a wireless client on the Corporate wireless network.
Correct Answer:
A
A
send
light_mode
delete
All Pages