[Sep-2025] NSE7_EFW-7.2 Pre-Exam Practice Tests Exam Questions and Answers for NSE 7 Network Security Architect Study Guide [Q46-Q69]

Share

[Sep-2025] NSE7_EFW-7.2 Pre-Exam Practice Tests | Exam Questions and Answers for NSE 7 Network Security Architect Study Guide

Fortinet NSE 7 - Enterprise Firewall 7.2 Certification Sample Questions

NEW QUESTION # 46
Which statement about network processor (NP) offloading is true?

  • A. For TCP traffic, FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP.
  • B. You can disable the NP for each firewall policy using the command np-acceleration set to loose.
  • C. The NP provides IPS signature matching.
  • D. The NP checks the session key or IPSec SA.

Answer: D


NEW QUESTION # 47
Exhibit.

Refer to the exhibit, which shows the output from the webfilter fortiguard cache dump and webfilter categories commands.
Using the output, how can an administrator determine the category of the training.fortinet.com am website?

  • A. The administrator must convert the first three digits of the IP hex value to binary
  • B. The administrator must convert the first two digits of the Domain hex value to a decimal value
  • C. The administrator must add both the Pima in and Iphex values of 34 to get the category number
  • D. The administrator can look up the hex value of 34 in the second command output.

Answer: D

Explanation:
* Option B is correct because the administrator can determine the category of the training.fortinet.com website by looking up the hex value of 34 in the second command output. This is because the first command output shows that the domain and the IP of the website are both in category (Hex) 34, which corresponds to Information Technology in the second command output1.
* Option A is incorrect because the administrator does not need to convert the first three digits of the IP hex value to binary. The IP hex value is already in the same format as the category hex value, so the administrator can simply compare them without any conversion2.
* Option C is incorrect because the administrator does not need to add both the Pima in and Iphex values of 34 to get the category number. The Pima in and Iphex values are not related to the category number, but to the cache TTL and the database version respectively3.
* Option D is incorrect because the administrator does not need to convert the first two digits of the Domain hex value to a decimal value. The Domain hex value is already in the same format as the category hex value, so the administrator can simply compare them without any conversion2. References: =
* 1: Technical Tip: Verify the webfilter cache content4
* 2: Hexadecimal to Decimal Converter5
* 3: FortiGate - Fortinet Community6
* : Web filter | FortiGate / FortiOS 7.2.0 - Fortinet Documentation7


NEW QUESTION # 48
Refer to the exhibit, which contains the output of the diagnose vpn tunnel list.

Which command will capture ESP traffic for the VPN named DialUp_0?

  • A. diagnose sniffer packet any 'host 10.0.10.10'
  • B. diagnose sniffer packet any 'port 4500'
  • C. diagnose sniffer packet any 'esp and host 10.200.3.2'
  • D. diagnose sniffer packet any 'ip proto 50'

Answer: B


NEW QUESTION # 49
An administrator configured the following command on FortiGate
config router ospf
sec reszart-mode graceful-restart
Which two statements correctly describe the result of the above command? (Choose two.)

  • A. FortiGate is configured with graceful restart and will exit graceful mode, if the network topology changes
  • B. The OSPF neighbor that receives the grace link-state advertisement (LSA) will enter into helper mode
  • C. After the default 40 seconds wait time the OSPF neighbors will resume communication with the restarting router
  • D. In an HA cluster FortiGate devices will keep the OSPF routes in their routing table to avoid traffic interruption during an HA failover

Answer: B,C


NEW QUESTION # 50
An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device.
What can the administrator do to fix this problem?

  • A. Verify that the speed and duplex settings match between the FortiGate interfaces and the connected switch ports.
  • B. Configure set send-garp-on-failover enable under config system ha on both cluster members.
  • C. Configure set link-failed-signal enable under config system ha on both cluster members
  • D. Configure remote link monitoring to detect an issue in the forwarding path.

Answer: C

Explanation:
Virtual MAC Address and Failover
- The new primary broadcasts Gratuitous ARP packets to notify the network that each virtual MAC is now reachable through a different switch port.
- Some high-end switches might not clear their MAC table correctly after a failover - Solution:
Force former primary to shut down all its interfaces for one second when the failover happens (excluding heartbeat and reserved management interfaces):
#Config system ha
set link-failed-signal enable
end
- This simulates a link failure that clears the related entries from MAC table of the switches.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-HA-link-failed-signal- and/ta-p/198050


NEW QUESTION # 51
While configuring the BGP protocol, an administrator applies the set netuork-inport-check disable command under config network.
What will FortiGate do as a result of this command?

  • A. FortiGate will advertise all the prefixes in the BGP network table to its BGP neighbor, even f itis not in the routing table.
  • B. FortiGate will not advertise the prefixes, if it is not in the routing table.
  • C. FortiGate will not advertise any imported routes received from one BGP neighbor to another.
  • D. FortiGate will advertise only the corresponding prefixes in the BGP network table to its BGP neighbor, even if itis not in the routing table.

Answer: A


NEW QUESTION # 52
Refer to the exhibit, which contains a partial configuration of the global system.

What can you conclude from the output?

  • A. set memory-use-threshoId-extreme command instructs the FortiGate to disable hardware acceleration if the memory extreme threshold reaches 95%
  • B. set check-protocol-header loose command enables hardware acceleration on this FortiGate device.
  • C. set strict-d^rty-session-check enable command instructs the FortiGate to offload all dirty session traffic to its SPU
  • D. set av-failopen pass command instructs the FortiGate to offload all traffic that uses the antivirus proxy to NP.

Answer: B


NEW QUESTION # 53
You want to configure faster failure detection for BGP
Which parameter should you enable on both connected FortiGate devices?

  • A. Graceful-restart
  • B. Ebgp-enforce-multihop
  • C. bfd
  • D. Distribute-list-in

Answer: C

Explanation:
BFD (Bidirectional Forwarding Detection) is a protocol that provides fast failure detection for BGP by sending periodic messages to verify the connectivity between two peers1. BFD can be enabled on both connected FortiGate devices by using the command set bfd enable under the BGP configuration2. Reference: = Technical Tip : FortiGate BFD implementation and examples ..., Configure BGP | FortiGate / FortiOS 7.0.2 - Fortinet Documentation


NEW QUESTION # 54
Refer to the exhibit.

which contains a partial configuration of the global system. What can you conclude from this output?

  • A. Only CPs arc disabled
  • B. NPs and CPs are enabled
  • C. NPs and CPs arc disabled
  • D. Only NPs are disabled

Answer: B

Explanation:
The configuration output shows various global settings for a FortiGate device. The terms NP (Network Processor) and CP (Content Processor) relate to FortiGate's hardware acceleration features. However, the provided configuration output does not directly mention the status (enabled or disabled) of NPs and CPs.
Typically, the command to disable or enable hardware acceleration features would specifically mention NP or CP in the command syntax. Therefore, based on the output provided, we cannot conclusively determine the status of NPs and CPs, hence option D is the closest answer since the output does not confirm that they are enabled.


NEW QUESTION # 55
Exhibit.

Refer to the exhibit, which shows a partial touting table
What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

  • A. add-route is disabled in the tunnel IPSec phase 1 configuration.
  • B. OSPI is configured to run over IPSec.
  • C. IPSec Tunnel aggregation is configured
  • D. net-device is enabled in the tunnel IPSec phase 1 configuration

Answer: A,D

Explanation:
* Option B is correct because the routing table shows that the tunnel interfaces have a netmask of
255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing, without adding a route to the phase 2 destination1.
* Option D is correct because the routing table does not show any routes to the phase 2 destination networks, which indicates that add-route is disabled in the phase 1 configuration. This option controls whether the FortiGate adds a static route to the phase 2 destination network using the tunnel interface as the gateway2.
* Option A is incorrect because IPSec tunnel aggregation is a feature that allows multiple phase 2 selectors to share a single phase 1 tunnel, reducing the number of tunnels and improving performance3.
This feature is not related to the routing table or the phase 1 configuration.
* Option C is incorrect because OSPF is a dynamic routing protocol that can run over IPSec tunnels, but it requires additional configuration on the FortiGate and the peer device4. This option is not related to the routing table or the phase 1 configuration. References: =
* 1: Technical Tip: 'set net-device' new route-based IPsec logic2
* 2: Adding a static route5
* 3: IPSec VPN concepts6
* 4: Dynamic routing over IPsec VPN7


NEW QUESTION # 56
Refer to the exhibit, which contains a partial BGP combination.

You want to configure a loopback as the OGP source.
Which two parameters must you set in the BGP configuration? (Choose two)

  • A. recursive-next-hop
  • B. ebgp-enforce-multihop
  • C. update-source
  • D. ibgp-enfoce-multihop

Answer: B,C

Explanation:
To configure a loopback as the BGP source, you need to set the "ebgp-enforce-multihop" and
"update-source" parameters in the BGP configuration. The "ebgp-enforce-multihop" allows EBGP connections to neighbor routers that are not directly connected, while "update-source" specifies the IP address that should be used for the BGP session.


NEW QUESTION # 57
You contoured an address object on the tool fortiGate in a Security Fabric. This object is not synchronized with a downstream device. Which two reasons could be the cause? (Choose two)

  • A. The address object on the tool FortiGate has fabric-object set to disable
  • B. The root FortiGate has configuration-sync set to enable
  • C. The downstream TortiGate has fabric-object-unification set to local
  • D. The downstream FortiGate has configuration-sync set to local

Answer: A,C

Explanation:
* Option A is correct because the address object on the tool FortiGate will not be synchronized with the downstream devices if it has fabric-object set to disable. This option controls whether the address object is shared with other FortiGate devices in the Security Fabric or not1.
* Option C is correct because the downstream FortiGate will not receive the address object from the tool FortiGate if it has fabric-object-unification set to local. This option controls whether the downstream FortiGate uses the address objects from the root FortiGate or its own local address objects2.
* Option B is incorrect because the root FortiGate has configuration-sync set to enable by default, which means that it will synchronize the address objects with the downstream devices unless they are disabled by the fabric-object option3.
* Option D is incorrect because the downstream FortiGate has configuration-sync set to local by default, which means that it will receive the address objects from the root FortiGate unless they are overridden by the fabric-object-unification option4. References: =
* 1: Group address objects synchronized from FortiManager5
* 2: Security Fabric address object unification6
* 3: Configuration synchronization7
* 4: Configuration synchronization7
* : Security Fabric - Fortinet Documentation


NEW QUESTION # 58
Refer to the exhibit, which shows two configured FortiGate devices and peering over FGSP.

The main link directly connects the two FortiGate devices and is configured using the set session-syn-dev <interface> command.
What is the primary reason to configure the main link?

  • A. To load balance both sessions and configuration synchronization between layer 2 and 3
  • B. To have both sessions and configuration synchronization in layer 3
  • C. To have both sessions and configuration synchronization in layer 2
  • D. To have only configuration synchronization in layer 3

Answer: B

Explanation:
The primary purpose of configuring a main link between the devices is to synchronize session information so that if one unit fails, the other can continue processing traffic without dropping active sessions.
A:To have both sessions and configuration synchronization in layer 2.This is incorrect because FGSP is used for session synchronization, not configuration synchronization.
B:To load balance both sessions and configuration synchronization between layer 2 and 3.FGSP does not perform load balancing and is not used for configuration synchronization.
C:To have only configuration synchronization in layer 3.The main link is not used solely for configuration synchronization.
D:To have both sessions and configuration synchronization in layer 3.The main link in an FGSP setup is indeed used to synchronize session information across the devices, and it operates at layer 3 since it uses IP addresses to establish the peering.


NEW QUESTION # 59
Refer to the exhibit.

which contains a partial configuration of the global system. What can you conclude from this output?

  • A. Only CPs arc disabled
  • B. NPs and CPs are enabled
  • C. NPs and CPs arc disabled
  • D. Only NPs are disabled

Answer: B

Explanation:
The configuration output shows various global settings for a FortiGate device. The terms NP (Network Processor) and CP (Content Processor) relate to FortiGate's hardware acceleration features. However, the provided configuration output does not directly mention the status (enabled or disabled) of NPs and CPs.
Typically, the command to disable or enable hardware acceleration features would specifically mention NP or CP in the command syntax. Therefore, based on the output provided, we cannot conclusively determine the status of NPs and CPs, hence option D is the closest answer since the output does not confirm that they are enabled.
References:
* FortiOS Handbook - CLI Reference for FortiOS 5.2


NEW QUESTION # 60
Refer to the exhibit, which shows the output of a BGP summary.

What two conclusions can you draw from this BGP summary? (Choose two.)

  • A. The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.
  • B. The BGP session with peer 10. 127. 0. 75 is established.
  • C. The router 100. 64. 3. 1 has the parameter bfd set to enable.
  • D. External BGP (EBGP) exchanges routing information.

Answer: B,D

Explanation:
The output of the BGP (Border Gateway Protocol) summary shows details about the BGP neighbors of a router, their Autonomous System (AS) numbers, the state of the BGP session, and other metrics like messages received and sent.
From the BGP summary provided:
A: External BGP (EBGP) exchanges routing information.This conclusion can be inferred because the AS numbers for the neighbors are different from the local AS number (65117), which suggests that these are external connections.
B: The BGP session with peer 10.127.0.75 is established.This is indicated by the state/prefix received column showing a numeric value (1), which typically means that the session is established and a number of prefixes has been received.
C: The router 100.64.3.1 has the parameter bfd set to enable.This cannot be concluded directly from the summary without additional context or commands specifically showing BFD (Bidirectional Forwarding Detection) configuration.
D: The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.The neighbor-range concept does not apply here; the value 4 in the 'V' column stands for the BGP version number, which is typically 4.


NEW QUESTION # 61
Refer to the exhibit, which contains a partial OSPF configuration.

What can you conclude from this output?

  • A. The restarting router sends gratuitous ARP for 30 seconds.
  • B. Neighbors maintain communication with the restarting router.
  • C. The router sends grace LSAs before it restarts.
  • D. FortiGate restarts if the topology changes.

Answer: D

Explanation:
From the partial OSPF (Open Shortest Path First) configuration output:
B: The router sends grace LSAs before it restarts: This is implied by the command 'set restart-mode graceful- restart'. When OSPF is configured with graceful restart, the router sends grace LSAs (Link State Advertisements) to inform its neighbors that it is restarting, allowing for a seamless transition without recalculating routes.
Fortinet documentation on OSPF configuration clearly states that enabling graceful restart mode allows the router to maintain its adjacencies and routes during a brief restart period.


NEW QUESTION # 62
Refer to the exhibit, which shows an OSPF network.

Which types of ink-state advertisements (LSA) will NGFW-1 send, if itis a backup designated router (BDR)?

  • A. NGFW-1 will send type 1and type 3 LSA.
  • B. ONGFW-1 will send type 1and type 5 LSA.
  • C. ONGFW-1 will send type 1 and type 4 LSA.
  • D. ONGFW-1 will send type 1 and type 2 LSAs.

Answer: A


NEW QUESTION # 63
Refer to the exhibit which shows config system central-management information.

Which setting must you configure for the web filtering feature to function?

  • A. Set update-server-location to automatic
  • B. Add server.fortiguard.net to the Server list
  • C. Configure server-type with the rating option
  • D. Configure securewf.fortiguard.net on the default servers

Answer: C

Explanation:
For the web filtering feature to function effectively, the FortiGate device needs to have a server configured for rating services. The rating option in the server-type setting specifies that the server is used for URL rating lookup, which is essential for web filtering. The displayed configuration does not list any FortiGuard web filtering servers, which would be necessary for web filtering. The setting set include-default-servers disable indicates that the default FortiGuard servers are not being used, and hence, a specific server for web filtering (like securewf.fortiguard.net) needs to be configured.


NEW QUESTION # 64
Exhibit.

Refer to the exhibit, which shows information about an OSPF interlace
What two conclusions can you draw from this command output? (Choose two.)

  • A. NGFW-1 is the designated router
  • B. The OSPF routers are in the area ID of 0.0.0.1.
  • C. The interfaces of the OSPF routers match the MTU value that is configured as 1500.
  • D. The port3 network has more man one OSPF router

Answer: C,D

Explanation:
From the OSPF interface command output, we can conclude that the port3 network has more than one OSPF router because the Neighbor Count is 2, indicating the presence of another OSPF router besides NGFW-1.
Additionally, we can deduce that the interfaces of the OSPF routers match the MTU value configured as
1500, which is necessary for OSPF neighbors to form adjacencies. The MTU mismatch would prevent OSPF from forming a neighbor relationship.


NEW QUESTION # 65
Refer to the exhibit, which contains a partial OSPF configuration.

What can you conclude from this output?

  • A. The restarting router sends gratuitous ARP for 30 seconds.
  • B. Neighbors maintain communication with the restarting router.
  • C. The router sends grace LSAs before it restarts.
  • D. FortiGate restarts if the topology changes.

Answer: C

Explanation:
From the partial OSPF (Open Shortest Path First) configuration output:
B). The router sends grace LSAs before it restarts: This is implied by the command 'set restart-mode graceful-restart'. When OSPF is configured with graceful restart, the router sends grace LSAs (Link State Advertisements) to inform its neighbors that it is restarting, allowing for a seamless transition without recalculating routes.
Fortinet documentation on OSPF configuration clearly states that enabling graceful restart mode allows the router to maintain its adjacencies and routes during a brief restart period.


NEW QUESTION # 66
After enabling IPS, you receive feedback about traffic being dropped.
What could be the reason?

  • A. fail-open is set to disable.
  • B. traffic-submit is set to disable.
  • C. IPS is configured to monitor.
  • D. np-accel-node is set to enable.

Answer: A

Explanation:
Fail-open is a feature that allows traffic to pass through the IPS sensor without inspection when the sensor fails or is overloaded. If fail-open is set to disable, traffic will be dropped in such scenarios.


NEW QUESTION # 67
Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

  • A. udp is not a protocol option.
  • B. fortiguard-anycast is set to enable.
  • C. FortiManager provides FortiGuard.
  • D. You do not have the corresponding write access.

Answer: B

Explanation:
The reason for the command failure when trying to set the protocol to UDP in the config system fortiguard is likely that UDP is not a protocol option in this context. The command syntax might be incorrect or the option to set a protocol for FortiGuard updates might not exist in this manner. So the correct answer is D. udp is not a protocol option.


NEW QUESTION # 68
Refer to the exhibit, which shows a network diagram.

Which protocol should you use to configure the FortiGate cluster?

  • A. FGCP in active-active mode
  • B. VRRP
  • C. FGCP in active-passive mode
  • D. FGSP

Answer: D


NEW QUESTION # 69
......

Fortinet Exam Practice Test To Gain Brilliante Result: https://www.actualtests4sure.com/NSE7_EFW-7.2-test-questions.html

Tested Material Used To NSE7_EFW-7.2: https://drive.google.com/open?id=1fWpmWVBNAVr1AXjpv5f8MzyVPaSuC9Xi