Fortinet NSE7_NST-7.2 Exam Practice Questions (P. 1)
- Full Access (71 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.
Which action will FortiGate take when using the default settings for SSL certificate inspection?
Which action will FortiGate take when using the default settings for SSL certificate inspection?
- AFortiGate closes the connection because this represents an invalid SSL/TLS configuration.
- BFortiGate uses the CN information from the Subject field in the server certificate.
- CFortiGate uses the first entry listed in the SAN field in the server certificate.
- DFortiGate uses the SNI from the user’s web browser.
send
light_mode
delete
Question #2
Refer to the exhibit.

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.
Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.
Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?
- AEnable asymmetric routing under config system settings.
- BModify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
- CA firewall policy that allows all ICMP traffic from port3 to port1.
- DChange the configuration from strict RPF check mode to feasible RPF check mode.
send
light_mode
delete
Question #3
Refer to the exhibit, which contains the output of a debug command.

If the default settings are in place, what can you conclude about the conserve mode shown in the exhibit?

If the default settings are in place, what can you conclude about the conserve mode shown in the exhibit?
- AFortiGate is currently blocking new sessions that require flow-based or proxy-based content inspection.
- BFortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings because of high memory use.
- CFortiGate is currently allowing new sessions that require flow-based or proxy-based content inspection but is not performing inspection on those sessions.
- DFortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection.
send
light_mode
delete
Question #4
Refer to the exhibit, which shows a session table entry.

Which statement about FortiGate behavior relating to this session is true?

Which statement about FortiGate behavior relating to this session is true?
- AFortiGate forwarded this session without any inspection.
- BFortiGate is performing a security profile inspection using the CPU.
- CFortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made.
- DFortiGate applied only IPS inspection to this session.
send
light_mode
delete
Question #5
Refer to the exhibit, which shows the omitted output of a real-time OSPF debug.

Which statement is false?

Which statement is false?
- AA password has been configured on the local OSPF router but is not shown in the output.
- BThe Hello packet is being sent from an OSPF router with ID 0.0.0.112.
- CThe two FortiGate devices attempting adjacency are in area 0.0.0.0.
- DOne FortiGate device is configured to require authentication, while the other is not.
send
light_mode
delete
All Pages