Fortinet NSE7_NST-7.2 Exam Practice Questions (P. 2)
- Full Access (71 questions)
- One Year of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Which statement about IKE and IKE NAT-T is true?
- AIKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface.
- BIKE is the standard implementation for IKEv1 and IKE NAT-T is an extension added in IKEv2.
- CThey each use their own IP protocol number.
- DThey both use UDP as their transport protocol and the port number is configurable.
send
light_mode
delete
Question #7
Refer to the exhibit, which shows the output of diagnose sys session list.

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?
- AThe session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.
- BThe session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.
- CTraffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.
- DThe secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.
send
light_mode
delete
Question #8
Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)
- AOSPF link costs match.
- BOSPF interface priority settings are unique.
- COSPF interface network types match.
- DAuthentication settings match.
- EOSPF router IDs are unique.
send
light_mode
delete
Question #9
Refer to the exhibits, which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network.


If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?


If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?
- AThe session would be deleted, and the client would need to start a new session.
- BThe session would remain in the session table, but its traffic would now egress from both port1 and port2.
- CThe session would remain in the session table, and its traffic would egress from port2.
- DThe session would remain in the session table, and its traffic would egress from port1.
send
light_mode
delete
Question #10
Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.

What three conclusions can you draw from these log entries? (Choose three.)

What three conclusions can you draw from these log entries? (Choose three.)
- ARemote registry is not running on the workstation.
- BThe FortiGate firmware version is not compatible with that of the collector agent.
- CDNS resolution is unable to resolve the workstation name.
- DThe user’s status shows as “not verified” in the collector agent.
- EA firewall is blocking traffic to port 139 and 445.
send
light_mode
delete
All Pages
