Fortinet NSE 7 - Enterprise Firewall 6.2 認定 NSE7_EFW-6.2 試験問題:
1. What global configuration setting changes the behavior for content-inspected traffic while FortiGate is in system conserve mode?
A) ips-failopen
B) av-failopen
C) mem-failopen
D) utm-failopen
2. The CLI command set intelligent-mode <enable | disable> controls the IPS engine's adaptive scanning behavior. Which of the following statements describes IPS adaptive scanning?
A) Determines the optimal number of IPS engines required based on system load.
B) Choose a matching algorithm based on available memory and the type of inspection being performed.
C) Downloads signatures on demand from FDS based on scanning requirements.
D) Determines when it is secure enough to stop scanning session traffic.
3. An administrator has enabled HA session synchronization in a HA cluster with two members. Which flag is added to a primary unit's session to indicate that it has been synchronized to the secondary unit?
A) redir.
B) synced
C) dirty.
D) nds.
4. View the exhibit, which contains an entry in the session table, and then answer the question below.
Which one of the following statements is true regarding FortiGate's inspection of this session?
A) FortiGate applied proxy-based inspection.
B) FortiGate applied explicit proxy-based inspection.
C) FortiGate applied flow-based inspection.
D) FortiGate forwarded this session without any inspection.
5. An administrator added the following Ipsec VPN to a FortiGate configuration:
configvpn ipsec phasel -interface
edit "RemoteSite"
set type dynamic
set interface "portl"
set mode main
set psksecret ENC LCVkCiK2E2PhVUzZe
next
end
config vpn ipsec phase2-interface
edit "RemoteSite"
set phasel name "RemoteSite"
set proposal 3des-sha256
next
end
However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit.

What is causing the IPsec problem in the phase 1 ?
A) The pre-shared key is wrong
B) The incoming IPsec connection is matching the wrong VPN configuration
C) The phrase-1 mode must be changed to aggressive
D) NAT-T settings do not match
質問と回答:
| 質問 # 1 正解: B | 質問 # 2 正解: D | 質問 # 3 正解: B | 質問 # 4 正解: A | 質問 # 5 正解: A |














0 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
