Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Fortinet NSE7_EFW-7.2 Practice Exam with Questions & Answers

Questions 1

Which statement about network processor (NP) offloading is true?

Options:
A.

For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP

B.

The NP provides IPS signature matching

C.

You can disable the NP for each firewall policy using the command np-acceleration st to loose.

D.

The NP checks the session key or IPSec SA

Fortinet NSE7_EFW-7.2 Premium Access
Questions 2

Which two statements about bfd are true? (Choose two)

Options:
A.

It can support neighbor only over the next hop in BGP

B.

You can disable it at the protocol level

C.

It works for OSPF and BGP

D.

You must configure n globally only

Questions 3

Exhibit.

NSE7_EFW-7.2 Question 3

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

Options:
A.

FortiGate creates separate virtual interfaces for each dial up client.

B.

The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.

C.

Dead peer detection s disabled.

D.

The routing table shows a single IPSec virtual interface.

Questions 4

Refer to the exhibit, which shows an ADVPN network.

NSE7_EFW-7.2 Question 4

Which VPN phase 1 parameters must you configure on the hub for the ADVPN feature to function? (Choose two.)

Options:
A.

set auto-discovery-forwarder enable

B.

set add-route enable

C.

set auto-discovery-receiver enable

D.

set auto-discovery-sender enable

Questions 5

Exhibit.

NSE7_EFW-7.2 Question 5

Refer to the exhibit, which contains the partial ADVPN configuration of a spoke.

Which two parameters must you configure on the corresponding single hub? (Choose two.)

Options:
A.

Set auto-discovery-sender enable

B.

Set ike-version 2

C.

Set auto-discovery-forwarder enable

D.

Set auto-discovery-receiver enable

Questions 6

Exhibit.

NSE7_EFW-7.2 Question 6

Refer to the exhibit, which shows an ADVPN network.

The client behind Spoke-1 generates traffic to the device located behind Spoke-2.

Which first message floes the hub send to Spoke-110 bring up the dynamic tunnel?

Options:
A.

Shortcut query

B.

Shortcut reply

C.

Shortcut offer

D.

Shortcut forward

Questions 7

Refer to the exhibit, which contains a partial BGP combination.

NSE7_EFW-7.2 Question 7

You want to configure a loopback as the OGP source.

Which two parameters must you set in the BGP configuration? (Choose two)

Options:
A.

ebgp-enforce-multihop

B.

recursive-next-hop

C.

ibgp-enfoce-multihop

D.

update-source

Questions 8

Which two statements about the Security fabric are true? (Choose two.)

Options:
A.

FortiGate uses the FortiTelemetry protocol to communicate with FortiAnatyzer.

B.

Only the root FortiGate sends logs to FortiAnalyzer

C.

Only FortiGate devices with configuration-sync receive and synchronize global CMDB objects that the toot FortiGate sends

D.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer

Questions 9

Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

Options:
A.

Enable AD-VPN in IPsec phase 1

B.

Disable add-route on hub

C.

Configure IP addresses on IPsec virtual interlaces

D.

Set protected network to all

Questions 10

Exhibit.

NSE7_EFW-7.2 Question 10

Refer to the exhibit, which contains a CLI script configuration on fortiManager. An administrator configured the CLI script on FortiManager rut the script tailed to apply any changes to the managed

device after being executed.

What are two reasons why the script did not make any changes to the managed device? (Choose two)

Options:
A.

The commands that start with the # sign did not run.

B.

Incomplete commands can cause CLI scripts to fail.

C.

Static routes can be added using only TCI scripts.

D.

CLI scripts must start with #!.

Exam Code: NSE7_EFW-7.2
Certification Provider: Fortinet
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.2
Last Update: Jul 11, 2025
Questions: 80
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

Fortinet Free Exams

Fortinet Free Exams
Access free Fortinet exam study guides and practice tests at Examstrack. Ensure your success with top-notch preparation resources at Examstrack.