Fortinet NSE7_EFW-6.2 Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Firewall-Richtlinien und Datenverkehrsverarbeitung | - Grundlagen von NAT und zentralem NAT - Richtliniensuche und Auswertungsreihenfolge |
| Hochverfügbarkeit (HA) | - Verhalten und Diagnose bei einem HA-Failover - HA-Modi Aktiv-Passiv und Aktiv-Aktiv |
| SD-WAN und Optimierung des Datenverkehrs | - Konfiguration von SD-WAN-Regeln und Pfadauswahl - Leistungsbezogene SLA und Failover-Mechanismen |
| VPN-Technologien | - Konfiguration und Fehlersuche bei SSL-VPN - IPsec-VPN (Standort-zu-Standort sowie Sternverbindung) |
| Sicherheitsprofile und Datenverkehrsprüfung | - Antivirenschutz, IPS und Anwendungssteuerung - Webfilterung und SSL-Prüfung |
| Protokollierung, Überwachung und Fehlersuche | - Auswertung von Protokollen und Integration mit FortiAnalyzer - Paketerfassung und Analyse des Datenverkehrsablaufs |
| Routing und Netzwerkplanung | - Richtlinienbasiertes Routing und Fehlersuche im Routing - Statisches und dynamisches Routing (Grundlagen von OSPF/BGP) |
| Erweiterte Verwaltung von FortiGate | - Systemkonfiguration und erweiterte Geräteeinstellungen - Administrativer Zugriff und Verwaltungskontrolle |
Fortinet NSE 7 - Enterprise Firewall 6.2 NSE7_EFW-6.2 Prüfungsfragen mit Lösungen
Frage #1
Which statement is true regarding File description (FD) conserve mode?
A. FD conserve mode affects all daemons running on the device.
B. A FortiGate enters FD conserve mode when the amount of available description is less than 5%.
C. Restarting the WAD process is required to leave FD conserve mode.
D. IPS inspection is affected when FortiGate enters FD conserve mode.
Frage #2
An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug:
diagnose debug application ike-1
diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?
A. Phase1; IKE mode configuration; phase 2; XAuth.
B. Phase1; XAuth; IKE mode configuration; phase2.
C. Phase1; XAuth; phase 2; IKE mode configuration.
D. Phase1; IKE mode configuration; XAuth; phase 2.
Frage #3
Refer to the exhibit, which contains the partial output of a diagnose command.
Based on the output, which two statements are correct? (Choose two.)
A. Remote gateway IP is 10.200.4.1.
B. Anti-replay is enabled.
C. Quick mode selectors are disabled.
D. DPD is disabled.
Frage #4
Examine the following partial outputs from two routing debug commands; then answer the question below:
Why the default route using port2 is not displayed in the output of the second command?
A. It is disabled in the FortiGate configuration.
B. It has a higher distance than the default route using port1.
C. It has a lower priority than the default route using port1.
D. It has a higher priority than the default route using port1.
Frage #5
View the exhibit, which contains the output of get sys ha status, and then answer the question below.
Which statements are correct regarding the output? (Choose two.)
A. Master is selected because it is the only device in the cluster.
B. The slave configuration is not synchronized with the master.
C. The HA management IP is 169.254.0.2.
D. port 7 is used the HA heartbeat on all devices in the cluster.
Fragen und Antworten:
| Frage #1 Antwort: B | Frage #2 Antwort: B | Frage #3 Antwort: A,B | Frage #4 Antwort: B | Frage #5 Antwort: B,D |






0 Kundenbewertungen

