Exam Code: NSE7_EFW-6.4 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: Fortinet NSE 7 - Enterprise Firewall 6.4
Certification Provider: Fortinet
Free Today! Guaranteed Training- Pass NSE7_EFW-6.4 Exam.

Check NSE7_EFW-6.4 free dumps before getting the full version:

NEW QUESTION 1
Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)

  • A. Installing configuration changes to managed devices
  • B. Importing interface mappings from managed devices
  • C. Adding devices to FortiManager
  • D. Previewing pending configuration changes for managed devices

Answer: AD

NEW QUESTION 2
Refer to the exhibit, which contains the output of diagnose sys session list.
NSE7_EFW-6.4 dumps exhibit
If the HA ID for the primary unit is zero (0), which statement about the output is true?

  • A. This session cannot be synced with the slave unit.
  • B. The inspection of this session has been offloaded to the slave unit.
  • C. The master unit is processing this traffic.
  • D. This session is for HA heartbeat traffic.

Answer: C

NEW QUESTION 3
When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does not provide the server name indication (SNI) extension?

  • A. FortiGate uses the requested URL from the user’s web browser.
  • B. FortiGate uses the CN information from the Subject field in the server certificate.
  • C. FortiGate blocks the request without any further inspection.
  • D. FortiGate switches to the full SSL inspection method to decrypt the data.

Answer: B

NEW QUESTION 4
View the exhibit, which contains the output of get sys ha status, and then answer the question below.
NSE7_EFW-6.4 dumps exhibit
Which statements are correct regarding the output? (Choose two.)

  • A. The slave configuration is not synchronized with the master.
  • B. The HA management IP is 169.254.0.2.
  • C. Master is selected because it is the only device in the cluster.
  • D. port 7 is used the HA heartbeat on all devices in the cluster.

Answer: AD

NEW QUESTION 5
What global configuration setting changes the behavior for content-inspected traffic while FortiGate is in system conserve mode?

  • A. av-failopen
  • B. mem-failopen
  • C. utm-failopen
  • D. ips-failopen

Answer: A

Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles-54/Other_Profile_Consideratio

NEW QUESTION 6
View the exhibit, which contains the output of a diagnose command, and then answer the question below.
NSE7_EFW-6.4 dumps exhibit
Which statements are true regarding the output in the exhibit? (Choose two.)

  • A. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
  • B. Servers with the D flag are considered to be down.
  • C. Servers with a negative TZ value are experiencing a service outage.
  • D. FortiGate used 209.222.147.3 as the initial server to validate its contract.

Answer: AD

Explanation:
A – because flag is Failed so fortigate will check if server is available every 15 minD-state is I , contact to validate contract info

NEW QUESTION 7
View the exhibit, which contains the output of a diagnose command, and the answer the question below.
NSE7_EFW-6.4 dumps exhibit
Which statements are true regarding the Weight value?

  • A. Its initial value is calculated based on the round trip delay (RTT).
  • B. Its initial value is statically set to 10.
  • C. Its value is incremented with each packet lost.
  • D. It determines which FortiGuard server is used for license validation.

Answer: C

NEW QUESTION 8
Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.
NSE7_EFW-6.4 dumps exhibit
Which statement are true regarding the output in the exhibit? (Choose two.)

  • A. There are three FortiGuard servers that are not responding to the queries sent by the FortiGate.
  • B. The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone.
  • C. FortiGate will send the FortiGuard queries to the server with highest weight.
  • D. A server's round trip delay (RTT) is not used to calculate its weight.

Answer: BC

NEW QUESTION 9
An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug:
diagnose debug application ike-1 diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?

  • A. Phase1; IKE mode configuration; XAuth; phase 2.
  • B. Phase1; XAuth; IKE mode configuration; phase2.
  • C. Phase1; XAuth; phase 2; IKE mode configuration.
  • D. Phase1; IKE mode configuration; phase 2; XAuth.

Answer: B

Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-ipsecvpn-54/IPsec_VPN_Concepts/IKE_Packet

NEW QUESTION 10
Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router The second unit is elected as the backup designated router Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?

  • A. 1
  • B. 2
  • C. 3
  • D. 4

Answer: B

NEW QUESTION 11
Examine the output of the ‘get router info bgp summary’ command shown in the exhibit; then answer the question below.
NSE7_EFW-6.4 dumps exhibit
Which statement can explain why the state of the remote BGP peer 10.200.3.1 is Connect?

  • A. The local peer is receiving the BGP keepalives from the remote peer but it has not received any BGP prefix yet.
  • B. The TCP session for the BGP connection to 10.200.3.1 is down.
  • C. The local peer has received the BGP prefixed from the remote peer.
  • D. The local peer is receiving the BGP keepalives from the remote peer but it has not received the OpenConfirm yet.

Answer: B

Explanation:
http://www.ciscopress.com/articles/article.asp?p=2756480&seqNum=4

NEW QUESTION 12
Refer to the exhibit, which contains the output of a BGP debug command.
NSE7_EFW-6.4 dumps exhibit
Which statement about the exhibit is true?

  • A. The local router has received a total of three BGP prefixes from all peers.
  • B. The local router has not established a TCP session with 100.64.3.1.
  • C. Since the counters were last reset, the 10.200.3.1 peer has never been down.
  • D. The local router BGP state is OpenConfirm with the 10.127.0.75 peer.

Answer: B

NEW QUESTION 13
Examine the following partial outputs from two routing debug commands; then answer the question below.
# get router info kernel
tab=254 vf=0 scope=0type=1 proto=11 prio=0 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0 gwy=10.200.1.254 dev=2(port1)
tab=254 vf=0 scope=0type=1 proto=11 prio=10 0.0.0.0/0.0.0.0/0->0.0.0.0/0 pref=0.0.0.0 gwy=10.200.2.254 dev=3(port2)
tab=254 vf=0 scope=253type=1 proto=2 prio=0 0.0.0.0/0.0.0.0/.->10.0.1.0/24 pref=10.0.1.254 gwy=0.0.0.0 dev=4(port3)
# get router info routing-table all s*0.0.0.0/0 [10/0] via 10.200.1.254, portl [10/0] via 10.200.2.254, port2, [10/0] dO.0.1.0/24 is directly connected, port3 dO.200.1.0/24 is directly connected, portl d0.200.2.0/24 is directly connected, port2
Which outbound interface or interfaces will be used by this FortiGate to route web traffic from internal users to the Internet?

  • A. port!
  • B. port2.
  • C. Both portl and port2.
  • D. port3.

Answer: B

NEW QUESTION 14
Refer to the exhibit, which contains the output of get system ha status.
NSE7_EFW-6.4 dumps exhibit
Which two statements about the output are true? (Choose two.)

  • A. The slave configuration is synchronized with the master.
  • B. port7 is used as the HA heartbeat on all devices in the cluster.
  • C. Master is selected based on the priority configured under config system ha.
  • D. The HA management IP is 169.254.0.2.

Answer: BC

NEW QUESTION 15
Refer to the exhibit, which contains the debug output of diagnose dvm device list.
NSE7_EFW-6.4 dumps exhibit
Which two statements about the output shown in the exhibit are correct? (Choose two.)

  • A. ADOMs are disabled on the FortiManager
  • B. The FortiGate configuration is in sync with latest running revision history.
  • C. There are pending device-level changes yet to be installed on Local-FortiGate.
  • D. The policy package has been modified for Local-FortiGate.

Answer: BC

NEW QUESTION 16
......

P.S. Easily pass NSE7_EFW-6.4 Exam with 115 Q&As Thedumpscentre.com Dumps & pdf Version, Welcome to Download the Newest Thedumpscentre.com NSE7_EFW-6.4 Dumps: https://www.thedumpscentre.com/NSE7_EFW-6.4-dumps/ (115 New Questions)