NSE7_EFW-7.0 Dumps

NSE7_EFW-7.0 Free Practice Test

Fortinet NSE7_EFW-7.0: Fortinet NSE 7 - Enterprise Firewall 7.0

QUESTION 1

The CLI command set intelligent-mode controls the IPS engine’s adaptive scanning behavior. Which of the following statements describes IPS adaptive scanning?

Correct Answer: C
Configuring IPS intelligenceStarting with FortiOS 5.2, intelligent-mode is a new adaptive detection method. This command is enabled the default and it means that the IPS engine will perform adaptive scanning so that, for some traffic, the FortiGate can quickly finish scanning and offload the traffic to NPU or kernel. It is a balanced method which could cover all known exploits. When disabled, the IPS engine scans every single byte.
config ips globalset intelligent-mode {enable|disable}end

QUESTION 2

What is the purpose of an internal segmentation firewall (ISFW)?

Correct Answer: C
ISFW splits your network into multiple security segments. They serve as a breach containers from attacks that come from inside.

QUESTION 3

View the following FortiGate configuration.
NSE7_EFW-7.0 dumps exhibit
All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network:
NSE7_EFW-7.0 dumps exhibit
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user’s session?

Correct Answer: A
http://kb.fortinet.com/kb/documentLink.do?externalID=FD40943

QUESTION 4

View the exhibit, which contains the output of a diagnose command, and then answer the question below.
NSE7_EFW-7.0 dumps exhibit
What statements are correct regarding the output? (Choose two.)

Correct Answer: AC

QUESTION 5

Refer to the exhibit, which contains the output of get system ha status. Which two statements about the output are true? (Choose two.)
NSE7_EFW-7.0 dumps exhibit

Correct Answer: BC