Fortinet NSE 7 - Enterprise Firewall 6.2 認定 NSE7_EFW-6.2 試験問題:
1. Which statements about bulk configuration changes using FortiManager CLI scripts are correct? (Choose two.)
A) When executed on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.
B) When executed on the Device Database, you must use the installation wizard to apply the changes to the managed FortiGate.
C) When executed on the All FortiGate in ADOM, changes are automatically installed without creating a new revision history.
D) When executed on the Policy Package, ADOM database, changes are applied directly to the managed FortiGate.
2. Which two conditions must be met for a statistic route to be active in the routing table? (Choose two.)
A) The link health monitor (if configured) is up.
B) The next-hop IP address is up.
C) The outgoing interface is up.
D) There is no other route, to the same destination, with a higher distance.
3. When does a RADIUS server send an Access-Challenge packet?
A) The user account is not found in the server.
B) The user credentials are wrong.
C) The server requires more information from the user, such as the token code for two-factor authentication.
D) The server does not have the user credentials yet.
4. An administrator added the following Ipsec VPN to a FortiGate configuration:
configvpn ipsec phasel -interface
edit "RemoteSite"
set type dynamic
set interface "portl"
set mode main
set psksecret ENC LCVkCiK2E2PhVUzZe
next
end
config vpn ipsec phase2-interface
edit "RemoteSite"
set phasel name "RemoteSite"
set proposal 3des-sha256
next
end
However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit.

What is causing the IPsec problem in the phase 1 ?
A) The pre-shared key is wrong
B) The incoming IPsec connection is matching the wrong VPN configuration
C) The phrase-1 mode must be changed to aggressive
D) NAT-T settings do not match
5. View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.
The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:
However, the IKE real time debug does not show any output. Why?
A) The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
B) The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.
C) The log-filter setting was set incorrectly. The VPN's traffic does not match this filter.
D) The debug shows only error messages. If there is no output, then the tunnel is operating normally.
質問と回答:
| 質問 # 1 正解: A、B | 質問 # 2 正解: A、C | 質問 # 3 正解: C | 質問 # 4 正解: A | 質問 # 5 正解: C |














0 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
