Official Bank 0/163

Fortinet NSE 7 – Enterprise Firewall 7.0 (NSE7_EFW-7.0) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
163 Total Questions
1
Question
View the exhibit, which contains the output of diagnose sys session stat, and then answer the question below.

Exhibit

Which statements are correct regarding the output shown? (Choose two.)
Select 2
Options
A No sessions have been deleted because of memory pages exhaustion.
B There are 0 ephemeral sessions.
C All the sessions in the session table are TCP sessions.
D There are 166 TCP sessions waiting to complete the three-way handshake.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Examine the output of the ‘get router info bgp summary’ command shown in the exhibit; then
Reveal Only
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which statement about the designated router (DR) and backup designated router (BDR) in an OSPF multi-access network is true?
Options
A Non-DR and non-BDR routers send link state updates and acknowledgements to 224.0.0.6.
B Non-DR and non-BDR routers form full adjacencies to DR only.
C Only the DR receives link state information from non-DR routers.
D FortiGate first checks the OSPF ID to elect a DR.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to the exhibit, which contains partial output from an IKE real-time debug.

Exhibit

Which two statements about this debug output are correct? (Choose two.)
Select 2
Options
A It shows a phase 1 negotiation.
B The remote gateway IP address is 10.0.0.1.
C The initiator provided remote as its IPsec peer ID.
D The negotiation is using AES128 encryption with CBC hash.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
An administrator added the following Ipsec VPN to a FortiGate configuration: configvpn ipsec phasel -interface set interface "portl" set type dynamic set psksecret ENC LCVkCiK2E2PhVUzZe set mode main config vpn ipsec phase2-interface edit "RemoteSite" edit "RemoteSite" set phasel name "RemoteSite" set proposal 3des-sha256 However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while next end attempting the Ipsec connection. The output is shown in the exhibit.

Exhibit

next end

Exhibit

What is causing the IPsec problem in the phase 1 ?
Options
A The pre-shared key is wrong
B The phrase-1 mode must be changed to aggressive
C The incoming IPsec connection is matching the wrong VPN configuration
D NAT-T settings do not match
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.