NSE7-LED-7-0 Sample Questions & Answers
FortiAP provisioning and complex wireless deployments, including guest access, carry the most weight, alongside advanced authentication with two-factor and single sign-on methods, FortiSwitch provisioning and wired-network security, and general monitoring.
Launch the full NSE7-LED-7-0 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Authentication · LDAP Configuration
An administrator is configuring an LDAP server profile on a FortiGate to authenticate users against a Microsoft Active Directory server. The administrator needs to ensure that only users who are members of the 'VPN_Users' group can authenticate successfully. What is the correct value to use in the
Group Filterfield?Show answer & explanation
Correct answer: B
The correct LDAP filter syntax combines multiple conditions.
(objectClass=user)ensures only user objects are considered.(sAMAccountName=*)is a placeholder for the username.(memberOf=CN=VPN_Users,CN=Users,DC=example,DC=com)checks for membership in the specified group, requiring the full Distinguished Name (DN) of the group. - Question 2IntermediateSelect 2
Wireless Networks · Guest Access
A university is deploying a guest wireless network. They want to allow guests to self-register for access, but the access should automatically expire after 8 hours. Additionally, all guest traffic must be tunneled back to the FortiGate for inspection and NAT. Which two configurations are required to meet these requirements? (Select TWO)
Show answer & explanation
Correct answers: A, D
Setting the security mode to Captive Portal is the fundamental step for creating a guest network. Configuring a local portal with a guest-specific user group on the FortiGate allows for self-registration and policy enforcement, including setting expiration timers for the guest accounts.
Tunnel Mode (also known as Tunnel to Wireless Controller) encapsulates all wireless client traffic in a CAPWAP tunnel and sends it to the FortiGate. This is necessary for the FortiGate to inspect the traffic, apply security policies, and perform NAT before forwarding it to the internet.
- Question 3Beginner
FortiSwitch Management · FortiLink Management
An administrator manages a network where FortiSwitches are connected to a FortiGate via FortiLink. When viewing the
Managed FortiSwitchespage on the FortiGate, one of the switches is showing a status ofPre-authorized. What does this status indicate?Show answer & explanation
Correct answer: A
The
Pre-authorizedstatus means that an administrator has manually added the FortiSwitch's serial number to the FortiGate's managed switch list in anticipation of its connection. It is a placeholder entry waiting for the actual device to connect and establish the FortiLink tunnel. - Question 4Advanced
Authentication · Two-Factor Authentication
A network security engineer needs to configure two-factor authentication for SSL VPN access. The primary authentication will be Active Directory credentials via LDAP, and the secondary factor will be a client certificate issued by an internal Certificate Authority (CA). Which type of user group must be created on the FortiGate to enforce this specific authentication sequence?
Show answer & explanation
Correct answer: C
To enforce two-factor authentication where both factors must be satisfied, you must create a Firewall group that includes multiple member groups. In this case, one member group would be tied to the remote LDAP server, and the second member group would be for PKI users, linked to the internal CA. By placing both of these groups inside a parent group and setting the logic to AND (the default), the FortiGate requires a user to satisfy the conditions of both member groups to be considered authenticated.
- Question 5Intermediate
Wireless Networks · IoT Segmentation
During a wireless network deployment, an administrator needs to provide network access for a set of legacy IoT devices that do not support 802.1X authentication. The security policy requires these devices to be placed in a specific IoT VLAN. Which security mode should be configured on the SSID to achieve this with the highest level of security possible for these devices?
Show answer & explanation
Correct answer: A
For devices that cannot use 802.1X, WPA2-Personal is the standard for encrypted communication. To add a layer of access control, MAC address filtering can be enabled. This allows the administrator to create a list of authorized MAC addresses for the IoT devices. While not foolproof, this combination provides both encryption and a basic level of device identity validation, which is a common and practical solution for securing legacy IoT devices.
- Question 6Intermediate
FortiSwitch Management · Centralized Management with FortiManager
A large enterprise uses FortiManager to manage hundreds of FortiSwitches across multiple sites. The administrator needs to push a standardized VLAN configuration to all switches at a specific site. What is the most efficient method to accomplish this in FortiManager?
Show answer & explanation
Correct answer: B
FortiManager's
Switch Templatesare specifically designed for this purpose. An administrator can create a template that defines a standard configuration, such as VLANs, port settings, or security policies. This template can then be applied to a group of FortiSwitches, ensuring consistent configuration and simplifying management at scale. This is far more efficient than applying scripts individually. - Question 7Advanced
Authentication · Syslog Single Sign-On
An administrator is troubleshooting a syslog-based SSO issue where FortiAuthenticator is not creating user logon sessions, despite receiving syslog messages from a domain controller. Which of the following is NOT a valid
Logon event dictionaryentry that FortiAuthenticator can use to parse user logon information?Show answer & explanation
Correct answer: D
FortiAuthenticator has pre-defined dictionaries for various logon event sources, including Windows Security Events, FortiGate logs, and Novell eDirectory. However, a Cisco ISE Posture Report is not a standard, pre-defined logon event dictionary. While a custom parser could potentially be created, it is not a built-in, valid dictionary entry for identifying user logon events.
- Question 8Intermediate
FortiSwitch Management · FortiLink Configuration
What is the primary purpose of the
fortilink-split-interfacesetting on a FortiGate?Show answer & explanation
Correct answer: C
When a FortiGate's internal hardware switch is used for FortiLink, by default, all ports in that switch become part of the FortiLink interface. Enabling
fortilink-split-interfaceallows the administrator to break this behavior, dedicating one or more ports for FortiLink while leaving the remaining ports on the hardware switch available for other purposes, such as connecting to other network segments. - Question 9Intermediate
Wireless Networks · Dynamic VLAN Assignment
When using dynamic VLAN assignment for wireless clients, the RADIUS server must send specific attributes in the Access-Accept message. If the goal is to assign a client to VLAN 100, which attribute and value format is correct?
Show answer & explanation
Correct answer: A
The standard method for RADIUS-based dynamic VLAN assignment uses a combination of three attributes.
Tunnel-Typespecifies the tunneling protocol (VLAN).Tunnel-Medium-Typespecifies the medium (802 for Ethernet/Wi-Fi).Tunnel-Private-Group-IDcontains the actual VLAN ID as a string. - Question 10Beginner
FortiSwitch Management · High Availability (HA)
True or False: In a FortiGate HA cluster, the FortiLink configuration is synchronized and active on both the primary and secondary units, allowing for immediate failover of FortiSwitch management.
Show answer & explanation
Correct answer: B
This is false. While the FortiLink configuration is synchronized to the secondary unit, the FortiLink tunnel itself is only active on the primary FortiGate. In the event of a failover, the secondary unit becomes the new primary and must then establish a new FortiLink connection with the managed FortiSwitches. There is a brief period of management disruption during this process.
Ready for the real thing?
The full NSE7-LED-7-0 simulator has every exam-style question, timed mode, and instant scoring.