NSE7-EFW-7-2 Sample Questions

NSE7-EFW-7-2 Sample Questions & Answers

Five equally weighted areas run from building the Security Fabric and tuning hardware acceleration to configuring HA cluster behavior, central management via FortiManager, web filtering and application control, OSPF and BGP routing, and IPsec VPN with ADVPN.

Launch the full NSE7-EFW-7-2 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    System Configuration · Configure hardware acceleration

    A systems administrator is reviewing the performance of a FortiGate 1800F with NP7 processors. They observe that traffic matching a firewall policy with a per-IP traffic shaper applied is not being offloaded to the NP7 processors, resulting in high CPU utilization. Why is the traffic not being offloaded?

    Show answer & explanation

    Correct answer: B

    Certain features, by their nature, require CPU processing and are incompatible with hardware acceleration. Per-IP traffic shaping is one such feature. It requires the FortiGate CPU to track and manage bandwidth for each individual IP address, preventing the session from being offloaded to the NP7 processor. To enable offloading, a shared traffic shaper would need to be used instead.

  2. Question 2Intermediate

    Routing · Implement OSPF to route enterprise traffic

    An engineer is troubleshooting an OSPF adjacency issue between two FortiGates. The diagnose ip router ospf neighbor command shows the neighbor is stuck in the ExStart/Exchange state. What is the most likely cause of this issue?

    flowchart LR A[FortiGate-A] -- OSPF Hello --> B(FortiGate-B) B -- OSPF Hello --> A A -- DB Description --> B B -- DB Description --> A subgraph Stuck Here A -- "ExStart/Exchange" -- B end
    Show answer & explanation

    Correct answer: C

    When an OSPF adjacency is stuck in the ExStart/Exchange state, it indicates that the routers are failing to exchange Database Description (DBD) packets successfully. A common cause for this is a mismatched Maximum Transmission Unit (MTU) on the interfaces. If one router sends a DBD packet larger than the other router's interface MTU, the packet will be dropped, and the exchange process cannot complete. Mismatched area IDs or authentication keys would prevent the adjacency from forming at an earlier stage.

  3. Question 3Intermediate

    Central Management · Implement central management

    A global logistics company is using FortiManager to manage over 500 FortiGate devices across different countries. The security team wants to create a standardized security policy for all devices but needs to allow regional administrators to add specific local exceptions. Which FortiManager feature allows for this combination of centralized control and localized flexibility within a single policy package?

    Show answer & explanation

    Correct answer: C

    Policy Blocks are a FortiManager feature specifically designed for this purpose. They allow an administrator to define a standard, centralized set of policies while also creating placeholders (Policy Blocks) where device-level or group-level policies can be inserted. This provides a hierarchical policy structure, enabling a balance between global standardization and local customization without needing separate policy packages or ADOMs.

  4. Question 4BeginnerSelect 2

    VPN · Implement IPsec VPN IKE version 2

    When troubleshooting a route-based IPsec VPN tunnel that is up but not passing traffic, which two areas should an administrator investigate first on the FortiGate? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    For a route-based VPN, even if the tunnel (Phase 1 and Phase 2) is successfully established, traffic will not flow unless two other conditions are met. First, there must be firewall policies that explicitly allow traffic from the local network to the VPN interface and vice-versa. Second, the FortiGate's routing table must have a static or dynamic route that directs traffic destined for the remote network to use the virtual IPsec interface as its gateway. Since the tunnel is already up, Phase 1 and Phase 2 settings are likely correct.

  5. Question 5Intermediate

    Security Profiles · Configure Application Control

    A university is using application control to block peer-to-peer (P2P) applications. However, students are using encrypted and obfuscated P2P clients that are not being detected. To improve the detection rate, what is the most critical prerequisite that must be configured on the firewall policy handling student traffic?

    Show answer & explanation

    Correct answer: C

    Modern applications, including P2P clients, heavily use SSL/TLS encryption to obfuscate their traffic. Application control can only inspect the content of traffic it can see. By enabling a 'deep-inspection' SSL/SSH Inspection profile on the firewall policy, the FortiGate can decrypt the traffic, allowing the application control engine to accurately identify and block the underlying P2P application. Without decryption, the engine can only rely on less reliable indicators like IP addresses or certificate information.

  6. Question 6Advanced

    Central Management · Implement central management

    Case Study

    Global Retail Inc. is deploying a new enterprise network architecture managed by FortiManager 7.2. The architecture consists of a central headquarters (HQ) with a FortiGate HA cluster, and 200 retail stores, each with a single FortiGate. All store FortiGates are in a single ADOM named 'Retail-Stores'. The HQ FortiGate is in a separate ADOM.

    A new corporate policy requires that all stores must block social media access for guest Wi-Fi users. However, the Marketing department must be able to access social media from the HQ network. A single, unified policy package is desired to manage all 200 store devices to simplify administration.

    The network team has created a shared Web Filter profile named 'Block-Social-Media' and a shared firewall address object for the 'Guest-WiFi-Subnet'. They are struggling with how to apply this policy only to the retail stores while using a separate policy for the HQ.

    Which FortiManager approach should the administrator use to meet these requirements efficiently?

    Show answer & explanation

    Correct answer: B

    The most efficient and scalable solution is to place both the HQ and retail devices in the Global ADOM, which allows management of devices from different ADOMs under a single policy framework. A single policy package can be created containing policies for both HQ and retail. The key is to use installation targets. The social media blocking policy would have its installation target set to the device group containing the 200 retail stores, ensuring it is only installed on those devices. The marketing access policy would be targeted to the HQ device. This avoids ADOM sprawl and simplifies management.

  7. Question 7Intermediate

    Routing · Implement Border Gateway Protocol (BGP) to route enterprise traffic

    A FortiGate is configured as a BGP speaker and is learning the same prefix (192.168.100.0/24) from two different eBGP peers. Peer A has a LOCAL_PREF of 150 and an AS_PATH of 65001 65002. Peer B has a LOCAL_PREF of 100 and an AS_PATH of 65003. All other attributes are equal. Which peer's route will be installed in the FortiGate's routing table?

    Show answer & explanation

    Correct answer: A

    The BGP path selection process follows a specific order of attributes. One of the earliest and most influential attributes is LOCAL_PREF. A higher LOCAL_PREF value is always preferred. In this scenario, Peer A's route has a LOCAL_PREF of 150, which is higher than Peer B's 100. Therefore, the router will select the path through Peer A, regardless of the shorter AS_PATH from Peer B. The AS_PATH length is considered much later in the selection process.

  8. Question 8Beginner

    System Configuration · Configure Different Operation Modes for an HA Cluster

    In an Active-Passive FortiGate HA cluster, what is the primary purpose of the session pickup feature?

    Show answer & explanation

    Correct answer: B

    The primary purpose of session pickup (session-pickup enable) is to provide stateful failover. It synchronizes the session tables from the primary unit to the secondary unit. In the event of a failover, the new primary unit will have information about existing TCP connections, UDP sessions, and IPsec tunnels, allowing them to continue without being dropped. This prevents users from having to re-authenticate or re-establish connections.

  9. Question 9Advanced

    VPN · Implement IPsec VPN IKE version 2

    An administrator configures an IPsec VPN using IKEv2 with certificate-based authentication. The tunnel fails to come up. The debug logs on the initiator show the message 'Received unauthenticated notify: AUTHENTICATION_FAILED'. Which of the following is the most probable cause for this error?

    sequenceDiagram participant Initiator participant Responder Initiator->>Responder: IKE_SA_INIT Responder-->>Initiator: IKE_SA_INIT Response Initiator->>Responder: IKE_AUTH Request (with Cert) Responder-->>Initiator: Notify: AUTHENTICATION_FAILED
    Show answer & explanation

    Correct answer: B

    The 'AUTHENTICATION_FAILED' error during the IKE_AUTH exchange in IKEv2 with certificates typically means the peer could not validate the certificate it received. The most common reason is that the responding FortiGate is missing the certificate of the Certificate Authority (CA) that signed the initiator's certificate. Without the trusted CA certificate, the responder cannot verify the signature on the initiator's certificate and thus rejects the authentication attempt. Mismatched proposals would fail earlier in the IKE_SA_INIT phase.

  10. Question 10Beginner

    Central Management · Implement central management

    True or False: In a FortiManager policy package, a firewall policy with a 'disabled' status will be completely ignored during installation and will not be pushed to the managed FortiGate.

    Show answer & explanation

    Correct answer: B

    This statement is false. When a policy package is installed, a policy marked as 'disabled' in FortiManager is still pushed to the managed FortiGate. On the FortiGate, it will exist in the configuration but will be in a disabled state (set status disable). This is useful for pre-staging policies that can be enabled later without requiring another push from FortiManager.

Ready for the real thing?

The full NSE7-EFW-7-2 simulator has every exam-style question, timed mode, and instant scoring.