Free Fortinet NSE7_EFW-6.4 Exam Actual Questions

The questions for NSE7_EFW-6.4 were last updated On Nov 19, 2024

Question No. 1

Examine the IPsec configuration shown in the exhibit; then answer the question below.

An administrator wants to monitor the VPN by enabling the IKE real time debug using these commands:

diagnose vpn ike log-filter src-addr4 10.0.10.1

diagnose debug application ike -1

diagnose debug enable

The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged between both IPsec gateways. However, the IKE real time debug does NOT show any output. Why isn't there any output?

Show Answer Hide Answer
Correct Answer: B

Question No. 2

What is the diagnose test application ipsmonitor 99 command used for?

Show Answer Hide Answer
Correct Answer: D

Question No. 3

View the exhibit, which contains a partial web filter profile configuration, and then answer the question below.

Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

Show Answer Hide Answer
Correct Answer: B

fortigate does it in order Static URL -> FortiGuard -- > Content -> Advanced (java, cookie removal..) so block it in first step


Question No. 4

View the exhibit, which contains the output of a BGP debug command, and then answer the question below.

Which of the following statements about the exhibit are true? (Choose two.)

Show Answer Hide Answer
Correct Answer: A, D

Question No. 5

An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug:

diagnose debug application ike-1

diagnose debug enable

In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?

Show Answer Hide Answer