NSE7-EFW-7-0 Sample Questions & Answers
Meshed IPsec and ADVPN tunnel troubleshooting takes the biggest share, next to Security Fabric, resource, and connectivity diagnostics, central-management problem solving, FortiGuard and web-filtering issues, and static or BGP/OSPF routing faults.
Launch the full NSE7-EFW-7-0 simulator →Showing 10 of 20 free samples.
- Question 1IntermediateSelect 2
Content Inspection · Troubleshoot the Intrusion Prevention System (IPS)
A security analyst is investigating an IPS alert. The alert shows that traffic was blocked by a specific signature, but the analyst suspects it is a false positive. Which two actions are recommended next steps for troubleshooting and mitigating this issue without disabling the entire IPS profile? (Choose two.)
Show answer & explanation
Correct answers: B, C
Creating a targeted exemption is the most precise way to mitigate a false positive. It allows the signature to remain active for all other traffic while permitting the specific, legitimate traffic flow that was being incorrectly blocked.
Changing the signature's action to 'Monitor' allows the traffic to pass but continues to generate logs. This is a good troubleshooting step to confirm the traffic is legitimate and to assess the impact of the signature without causing a service disruption.
- Question 2Beginner
VPN · Troubleshoot Autodiscovery VPN (ADVPN) to enable on-demand VPN tunnels between sites
True or False: When configuring ADVPN with OSPF, the
net-devicesetting must be disabled under the BGP neighbor configuration to ensure proper next-hop resolution.Show answer & explanation
Correct answer: B
The statement is false because it confuses the settings for BGP and OSPF. When using OSPF with ADVPN,
net-devicemust be enabled on the hub for the spokes so that the hub advertises its own IP as the next hop. Conversely, when using BGP with ADVPN,net-devicemust be disabled so the hub preserves the original spoke's IP as the next hop, which is required for NHRP to resolve the address and build the shortcut tunnel. - Question 3Advanced
System and Session Troubleshooting · Diagnose and troubleshoot connectivity problems using built-in tools
An administrator is using the
diagnose debug flowcommand to trace a packet. The output shows the packet is being processed, but it ends withiprope_in_check() check-is-not-forward failed on policy 0. What does this specific message indicate?Show answer & explanation
Correct answer: B
The message
check-is-not-forward failed on policy 0is the specific debug flow output that indicates the packet did not match any configured firewall policy and was therefore dropped by the invisible, default 'implicit deny' rule (Policy ID 0). This means no explicit policy allowed the traffic to be forwarded. - Question 4Intermediate
System and Session Troubleshooting · Diagnose and troubleshoot resource problems using built-in tools
A FortiGate is experiencing high CPU utilization, and the
get system performance topcommand shows that theipsengineprocess is consuming the majority of resources. Which action would be the most effective first step to reduce the load caused by the IPS engine without compromising security?Show answer & explanation
Correct answer: B
The
ipsengineprocess load is directly related to the number and complexity of signatures it must evaluate for each packet. A common cause of high CPU is an overly broad IPS sensor. The most effective first step is to tune the sensor by removing signatures that are not relevant to the protected environment (e.g., signatures for servers if only clients are behind the policy, or signatures for operating systems not in use). This reduces the inspection workload without disabling the feature entirely. - Question 5IntermediateSelect 2
VPN · Implement a meshed or partially redundant IPsec VPN
When troubleshooting a route-based IPsec VPN tunnel, an administrator has confirmed that Phase 1 and Phase 2 are up. However, traffic is not passing through the tunnel. A
diagnose sniffer packetshows the traffic entering the FortiGate, but not leaving through the IPsec interface. Which two configuration items are most likely missing or incorrect? (Choose two.)Show answer & explanation
Correct answers: A, B
For a route-based VPN, the FortiGate needs a route in its routing table to direct traffic destined for the remote network into the tunnel interface. Without this route, the FortiGate does not know where to send the packets.
Even with a correct route, traffic will be dropped by the implicit deny rule unless there is a firewall policy explicitly allowing the traffic flow from the source interface (e.g., LAN) to the destination interface (the IPsec tunnel). A corresponding policy is also needed for the return traffic.
- Question 6Beginner
Content Inspection · Troubleshoot web filtering issues
A company has implemented a web filter profile with deep inspection enabled. Users are complaining that they cannot access a critical business partner's website because of a certificate warning in their browser. The administrator confirms the partner site uses a valid, publicly trusted certificate. What is the most common cause for this issue?
Show answer & explanation
Correct answer: B
With deep inspection, the FortiGate intercepts the TLS session and re-signs the website's certificate with its own CA certificate. For the browser to accept this, the FortiGate's CA certificate must be installed and trusted in the client's certificate store. If it is not trusted, the browser will display a certificate warning because the certificate issuer (the FortiGate) is unknown.
- Question 7Intermediate
System and Session Troubleshooting · Troubleshoot different operation modes for a FGCP HA cluster
The
diagnose sys ha checksum showcommand reveals a checksum mismatch forsystem.interfacebetween the primary and secondary units in an FGCP cluster. What is the implication of this mismatch?Show answer & explanation
Correct answer: C
The HA checksum is a hash of a specific part of the configuration. A mismatch for
system.interfaceindicates that the interface configurations on the primary and secondary units are different. This means synchronization for this part of the configuration has failed. If a failover occurs, the secondary unit will use its incorrect interface configuration, likely leading to a network outage. - Question 8Beginner
Routing · Troubleshoot Border Gateway Protocol (BGP) routing for enterprise traffic
What is the primary purpose of using a route map in a BGP configuration on a FortiGate?
Show answer & explanation
Correct answer: B
A route map is a powerful policy tool used in BGP to control and modify routing information. Its primary purposes are to filter which routes are accepted from or advertised to a neighbor (using
matchstatements) and to modify BGP path attributes (like local preference, MED, or community) for traffic engineering purposes (usingsetstatements). - Question 9Intermediate
Central Management · Troubleshoot central management issues
A FortiGate is configured to send logs to a FortiAnalyzer. However, no logs from the FortiGate are appearing in the FortiAnalyzer's log view. The administrator has verified network connectivity between the two devices. Which CLI command on the FortiGate should be used to troubleshoot the reliability of the log transport?
Show answer & explanation
Correct answer: C
The
diagnose log testcommand is a comprehensive tool for testing the entire logging mechanism. It generates test logs for all configured destinations (including FortiAnalyzer, memory, disk) and reports on the status of the connection, including encryption, registration, and log transmission statistics. This is the best command to quickly verify if the logging daemon (logd) can successfully connect and send logs to the configured FortiAnalyzer. - Question 10Beginner
VPN · Implement a meshed or partially redundant IPsec VPN
Which statement accurately describes the function of Dead Peer Detection (DPD) in an IPsec VPN tunnel?
Show answer & explanation
Correct answer: B
Dead Peer Detection (DPD) is a mechanism used to detect when an IPsec peer is no longer available. The FortiGate sends periodic DPD messages (IKEv1 R-U-THERE or IKEv2 INFORMATIONAL exchanges) to its peer. If it does not receive a response after a configured number of retries, it considers the peer 'dead' and tears down the VPN tunnel. This allows for faster failure detection and failover to a redundant tunnel.
Ready for the real thing?
The full NSE7-EFW-7-0 simulator has every exam-style question, timed mode, and instant scoring.