Fortinet NSE7_EFW-7.2参考書内容、NSE7_EFW-7.2日本語版試験勉強法他人の話を大切にしないで重要なのは自分の感じです。あなたに我々の誠意を感じさせるために、弊社は無料のFortinetのNSE7_EFW-7.2ソフトを提供して、ご購入の前にデモを利用してみてあなたに安心させます。最高のアフターサービスも提供します。FortinetのNSE7_EFW-7.2ソフトが更新されたら、もうすぐあなたに送っています。あなたに一年間の無料更新サービスを提供します。 Fortinet NSE 7 - Enterprise Firewall 7.2 認定 NSE7_EFW-7.2 試験問題 (Q19-Q24):質問 # 19
Exhibit.
Refer to the exhibit, which shows information about an OSPF interlace
What two conclusions can you draw from this command output? (Choose two.)
A. The interfaces of the OSPF routers match the MTU value that is configured as 1500.
B. The OSPF routers are in the area ID of 0.0.0.1.
C. NGFW-1 is the designated router
D. The port3 network has more man one OSPF router
正解:A、D
解説:
From the OSPF interface command output, we can conclude that the port3 network has more than one OSPF router because the Neighbor Count is 2, indicating the presence of another OSPF router besides NGFW-1.
Additionally, we can deduce that the interfaces of the OSPF routers match the MTU value configured as 1500, which is necessary for OSPF neighbors to form adjacencies. The MTU mismatch would prevent OSPF from forming a neighbor relationship.
References:
* Fortinet FortiOS Handbook: OSPF Configuration
質問 # 20
Examine the output of the 'get router info ospf interface' command shown in the exhibit; then answer the question below.
Which statements are true regarding the above output? (Choose two.)
A. The port4 interface is connected to the OSPF backbone area.
B. Two OSPF routers are down in the port4 network.
C. The local FortiGate has been elected as the OSPF backup designated router
D. There are at least 5 OSPF routers connected to the port4 network.
正解:A、D
解説:
On BROADCAST network there are 4 neighbors, among which 1*DR +1*BDR. So our FG has 4 neighbors, but create adjacency only with 2 (with DR and BDR). 2 neighbors DRother (not down).
質問 # 21
Refer to the exhibits, which show the configurations of two address objects from the same FortiGate.
Why can you modify the Engineering address object, but not the Finance address object?
A. Another user is editing the Finance address object in workspace mode.
B. You have read-only access.
C. FortiGate joined the Security Fabric and the Finance address object was configured on the root FortiGate.
D. FortiGate is registered on FortiManager.
正解:A
解説:
The inability to modify the Finance address object while being able to modify the Engineering address object suggests that the Finance object is being managed by a higher authority in the Security Fabric, likely the root FortiGate. When a FortiGate is part of a Security Fabric, address objects and other configurations may be managed centrally. This aligns with the Fortinet FortiGate documentation on Security Fabric and central management of address objects.
質問 # 22
Refer to the exhibit, which shows an ADVPN network.
Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)
A. set auto-discovery-sender enable
B. set add-route enable
C. set auto-discovery-receiver enable
D. set auto-discovery-forwarder enable
正解:C、D
解説:
For the ADVPN feature to function properly on the hub, the following phase 1 parameters must be configured:
A: set auto-discovery-forwarder enable: This enables the hub to forward shortcut information to the spokes, which is essential for them to establish direct tunnels.
C: set auto-discovery-receiver enable: This allows the hub to receive shortcut offers from the spokes.
This information is corroborated by the Fortinet documentation, which explains that in an ADVPN setup, the hub must be able to both forward and receive shortcut information for dynamic tunnel creation between spokes.
質問 # 23
After enabling IPS you receive feedback about traffic being dropped.
What could be the reason?
A. Traffic-submit is set to disable
B. Fail-open is set to disable
C. IPS is configured to monitor
D. Np-accel-mode is set to enable
正解:A
解説:
Fail-open is a feature that allows traffic to pass through the IPS sensor without inspection when the sensor fails or is overloaded. If fail-open is set to disable, traffic will be dropped in such scenarios1. References:
= IPS | FortiGate / FortiOS 7.2.3 - Fortinet Documentation
When IPS (Intrusion Prevention System) is configured, if fail-open is set to disable, it means that if the IPS engine fails, traffic will not be allowed to pass through, which can result in traffic being dropped (D). This is in contrast to a fail-open setting, which would allow traffic to bypass the IPS engine if it is not operational.