NSE7-EFW-7-0 Sample Questions

NSE7-EFW-7-0 Sample Questions & Answers

Meshed IPsec and ADVPN tunnel troubleshooting takes the biggest share, next to Security Fabric, resource, and connectivity diagnostics, central-management problem solving, FortiGuard and web-filtering issues, and static or BGP/OSPF routing faults.

Launch the full NSE7-EFW-7-0 simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 2

    Content Inspection · Troubleshoot the Intrusion Prevention System (IPS)

    A security analyst is investigating an IPS alert. The alert shows that traffic was blocked by a specific signature, but the analyst suspects it is a false positive. Which two actions are recommended next steps for troubleshooting and mitigating this issue without disabling the entire IPS profile? (Choose two.)

    Show answer & explanation

    Correct answers: B, C

    Creating a targeted exemption is the most precise way to mitigate a false positive. It allows the signature to remain active for all other traffic while permitting the specific, legitimate traffic flow that was being incorrectly blocked.

    Changing the signature's action to 'Monitor' allows the traffic to pass but continues to generate logs. This is a good troubleshooting step to confirm the traffic is legitimate and to assess the impact of the signature without causing a service disruption.

  2. Question 2Beginner

    VPN · Troubleshoot Autodiscovery VPN (ADVPN) to enable on-demand VPN tunnels between sites

    True or False: When configuring ADVPN with OSPF, the net-device setting must be disabled under the BGP neighbor configuration to ensure proper next-hop resolution.

    Show answer & explanation

    Correct answer: B

    The statement is false because it confuses the settings for BGP and OSPF. When using OSPF with ADVPN, net-device must be enabled on the hub for the spokes so that the hub advertises its own IP as the next hop. Conversely, when using BGP with ADVPN, net-device must be disabled so the hub preserves the original spoke's IP as the next hop, which is required for NHRP to resolve the address and build the shortcut tunnel.

  3. Question 3Advanced

    System and Session Troubleshooting · Diagnose and troubleshoot connectivity problems using built-in tools

    An administrator is using the diagnose debug flow command to trace a packet. The output shows the packet is being processed, but it ends with iprope_in_check() check-is-not-forward failed on policy 0. What does this specific message indicate?

    Show answer & explanation

    Correct answer: B

    The message check-is-not-forward failed on policy 0 is the specific debug flow output that indicates the packet did not match any configured firewall policy and was therefore dropped by the invisible, default 'implicit deny' rule (Policy ID 0). This means no explicit policy allowed the traffic to be forwarded.

  4. Question 4Intermediate

    System and Session Troubleshooting · Diagnose and troubleshoot resource problems using built-in tools

    A FortiGate is experiencing high CPU utilization, and the get system performance top command shows that the ipsengine process is consuming the majority of resources. Which action would be the most effective first step to reduce the load caused by the IPS engine without compromising security?

    Show answer & explanation

    Correct answer: B

    The ipsengine process load is directly related to the number and complexity of signatures it must evaluate for each packet. A common cause of high CPU is an overly broad IPS sensor. The most effective first step is to tune the sensor by removing signatures that are not relevant to the protected environment (e.g., signatures for servers if only clients are behind the policy, or signatures for operating systems not in use). This reduces the inspection workload without disabling the feature entirely.

  5. Question 5IntermediateSelect 2

    VPN · Implement a meshed or partially redundant IPsec VPN

    When troubleshooting a route-based IPsec VPN tunnel, an administrator has confirmed that Phase 1 and Phase 2 are up. However, traffic is not passing through the tunnel. A diagnose sniffer packet shows the traffic entering the FortiGate, but not leaving through the IPsec interface. Which two configuration items are most likely missing or incorrect? (Choose two.)

    Show answer & explanation

    Correct answers: A, B

    For a route-based VPN, the FortiGate needs a route in its routing table to direct traffic destined for the remote network into the tunnel interface. Without this route, the FortiGate does not know where to send the packets.

    Even with a correct route, traffic will be dropped by the implicit deny rule unless there is a firewall policy explicitly allowing the traffic flow from the source interface (e.g., LAN) to the destination interface (the IPsec tunnel). A corresponding policy is also needed for the return traffic.

  6. Question 6Beginner

    Content Inspection · Troubleshoot web filtering issues

    A company has implemented a web filter profile with deep inspection enabled. Users are complaining that they cannot access a critical business partner's website because of a certificate warning in their browser. The administrator confirms the partner site uses a valid, publicly trusted certificate. What is the most common cause for this issue?

    Show answer & explanation

    Correct answer: B

    With deep inspection, the FortiGate intercepts the TLS session and re-signs the website's certificate with its own CA certificate. For the browser to accept this, the FortiGate's CA certificate must be installed and trusted in the client's certificate store. If it is not trusted, the browser will display a certificate warning because the certificate issuer (the FortiGate) is unknown.

  7. Question 7Intermediate

    System and Session Troubleshooting · Troubleshoot different operation modes for a FGCP HA cluster

    The diagnose sys ha checksum show command reveals a checksum mismatch for system.interface between the primary and secondary units in an FGCP cluster. What is the implication of this mismatch?

    Show answer & explanation

    Correct answer: C

    The HA checksum is a hash of a specific part of the configuration. A mismatch for system.interface indicates that the interface configurations on the primary and secondary units are different. This means synchronization for this part of the configuration has failed. If a failover occurs, the secondary unit will use its incorrect interface configuration, likely leading to a network outage.

  8. Question 8Beginner

    Routing · Troubleshoot Border Gateway Protocol (BGP) routing for enterprise traffic

    What is the primary purpose of using a route map in a BGP configuration on a FortiGate?

    Show answer & explanation

    Correct answer: B

    A route map is a powerful policy tool used in BGP to control and modify routing information. Its primary purposes are to filter which routes are accepted from or advertised to a neighbor (using match statements) and to modify BGP path attributes (like local preference, MED, or community) for traffic engineering purposes (using set statements).

  9. Question 9Intermediate

    Central Management · Troubleshoot central management issues

    A FortiGate is configured to send logs to a FortiAnalyzer. However, no logs from the FortiGate are appearing in the FortiAnalyzer's log view. The administrator has verified network connectivity between the two devices. Which CLI command on the FortiGate should be used to troubleshoot the reliability of the log transport?

    Show answer & explanation

    Correct answer: C

    The diagnose log test command is a comprehensive tool for testing the entire logging mechanism. It generates test logs for all configured destinations (including FortiAnalyzer, memory, disk) and reports on the status of the connection, including encryption, registration, and log transmission statistics. This is the best command to quickly verify if the logging daemon (logd) can successfully connect and send logs to the configured FortiAnalyzer.

  10. Question 10Beginner

    VPN · Implement a meshed or partially redundant IPsec VPN

    Which statement accurately describes the function of Dead Peer Detection (DPD) in an IPsec VPN tunnel?

    Show answer & explanation

    Correct answer: B

    Dead Peer Detection (DPD) is a mechanism used to detect when an IPsec peer is no longer available. The FortiGate sends periodic DPD messages (IKEv1 R-U-THERE or IKEv2 INFORMATIONAL exchanges) to its peer. If it does not receive a response after a configured number of retries, it considers the peer 'dead' and tears down the VPN tunnel. This allows for faster failure detection and failover to a redundant tunnel.

Ready for the real thing?

The full NSE7-EFW-7-0 simulator has every exam-style question, timed mode, and instant scoring.