Which configuration can be used to reduce the number of BGP sessions in on IBGP network?
A. Route-reflector-client enable
B. Route-reflector enable
C. Route-reflector-server enable
D. Route-reflector-peer enable
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which two statements about metadata variables are true? (Choose two.)
A. They apply only to non-firewall objects.
B. You create them on FortiGate
C. The metadata format is $<metadata_variabie_name>.
D. They can be used as variables in scripts
正解:C,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
An administrator is configuring two FortiGate devices in an HA cluster. While configuring the devices, the administrator issues the following commands on both HA cluster members:

In which two ways do these commands impact the HA cluster? (Choose two.)
A. They force the former primary to shut down all ts interfaces for one second when failover happens, excluding the heartbeat and reserved management interfaces.
B. They force the former primary to send gratuitous ARP packets when the failover happens to indicate that the virtual MAC address is now using a different device.
C. They force both HA devices for remote link monitoring to detect an issue in the forwarding path.
D. They force the switches to update their MAC forwarding tables, when failover happens.
正解:A,B
質問 4:
Refer to the exhibit, which shows a network diagram.

Which protocol should you use to configure the FortiGate cluster?
A. FGCP in active-passive mode
B. FGCP in active-active mode
C. FGSP
D. VRRP
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Refer to the exhibit, which shows a network diagram.

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?
A. Set route-overlap to allow.
B. Set net-device to enable
C. Set single-source to enable
D. Set route-overlap to either use-new or use-old
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Refer to the exhibit, which contains a TCL script configuration on FortiManager.

An administrator has configured the TCL script on FortiManager, but the TCL script failed to apply any changes to the managed device after being run.
Why did the TCL script fail to make any changes to the managed device?
A. The TCL procedure lacks the required loop statements to iterate through the changes.
B. There is no corresponding #! to signify the end of the script.
C. The TCL procedure run_cmd has not been created.
D. The TCL script must start with #include.
正解:C
質問 7:
Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?
A. Set protected network to all
B. Disable add-route on hub
C. Configure IP addresses on IPsec virtual interfaces
D. Enable AD-VPN in IPsec phase 1
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
Miyazawa -
Pass4Testさんの問題集NSE7_EFW-7.2は最高でした。やっと合格できた!
こんな俺が1ヵ月の勉強のみで合格できたので
是非参考にして合格し就活や転職の成功の足しにしてくれ。
Fortinetさん、本当に感謝してます!