Month End Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

NSE7_LED-7.0 Questions and Answers

Question # 6

Which three FortiOS tools can you use to troubleshoot RADIUS authentication issues? (Choose three.)

A.

You can enable debug for the fssod process to view RADIUS authentication details.

B.

You can use the diagnose test authserver radius command to verify RADIUS server configuration, user credentials, and user group membership.

C.

You can check the Firewall Users widget to view the list of active RADIUS users.

D.

You can enable debug for the fnbamd process to view RADIUS authentication details.

E.

You can use the diagnose test application radiusd command to verify the RADIUS server configuration, user credentials, and user group membership.

Full Access
Question # 7

Refer to the exhibits.

Firewall Policy

Examine the firewall policy configuration and SSID settings

An administrator has configured a guest wireless network on FortiGate using the external captive portal The administrator has verified that the external captive portal URL is correct However wireless users are not able to see the captive portal login page

Given the configuration shown in the exhibit and the SSID settings which configuration change should the administrator make to fix the problem?

A.

Disable the user group from the SSID configuration

B.

Enable the captivs-portal-exempt option in the firewall policy with the ID 11.

C.

Apply a guest.portal user group in the firewall policy with the ID 11.

D.

Include the wireless client subnet range in the Exempt Source section

Full Access
Question # 8

Which two statements about FortiSwitch manager are true1? (Choose two)

A.

Per-device management is the default management mode on FortiManager

B.

FortiManager obtains the FortiSwitch status information by querying the FortiGate REST API every three minutes

C.

If the administrator makes any changes on FortiSwitch manager they must also install those changes on FortiGate so that those changes are applied on the managed switches

D.

Any switch discovered or authorized on FortiGate must be added manually on FortiSwitch manager

Full Access
Question # 9

Exhibit.

Refer to the exhibit showing a network topology and SSID settings.

FortiGate is configured to use an external captive portal However wireless users are not able to see the captive portal login page

Which configuration change should the administrator make to fix the problem?

A.

Enable NAT in the firewall policy with the ID 13.

B.

Add the FortiAuthenticator and WindowsAD address objects as exempt destinations services

C.

Enable the captive-portal-exempt option in the firewall policy with the ID 12

D.

Remove the guest.portal user group in the firewall policy with the ID 12

Full Access
Question # 10

An administrator has configured an SSID in bridge mode for corporate employees All APs are online and provisioned using default AP profiles Employees are unable to locate the SSID to conned

Which two configurations can the administrator verify? (Choose two)

A.

Verify that the broadcast SSID option is enabled in the SSID configuration

B.

Verify that the Block Intra-SSID Traffic (intra-vap-privacy) option in the SSID configuration is disabled

C.

Verify that the SSID to an AP group that should be broadcasting the SSID is applied

D.

Verify that the SSID is manually applied on AP profiles for both 2 4 GHz and 5 GHz radios

Full Access
Question # 11

Which CLI command should an administrator use on FortiGate to view the RSSO authentication process in real time?

A.

diagnose debug application fnbamd -1

B.

diagnose debug application authd -1

C.

diagnose debug application radiusd -1

D.

diagnose debug application foauthd -1

Full Access
Question # 12

An administrator is testing the connectivity for a new VLAN The devices in the VLAN are connected to a FortiSwitch device that is managed by FortiGate Quarantine is disabled on FortiGate

While testing the administrator noticed that devices can ping FortiGate and FortiGate can ping the devices The administrator also noticed that inter-VLAN communication works However intra-VLAN communication does not work

Which scenario is likely to cause this issue?

A.

Access VLAN is enabled on the VLAN

B.

The native VLAN configured on the ports is incorrect

C.

The FortiSwitch MAC address table is missing entries

D.

The FortiGate ARP table is missing entries

Full Access
Question # 13

Which two statements about MAC address quarantine by redirect mode are true? (Choose two)

A.

The quarantined device is moved to the quarantine VLAN

B.

The device MAC address is added to the Quarantined Devices firewall address group

C.

It is the default mode for MAC address quarantine

D.

The quarantined device is kept in the current VLAN

Full Access
Question # 14

Refer to the exhibits

The exhibits show the wireless network (VAP) SSID profiles defined on FortiManager and an AP profile assigned to a group of APs that are supported by FortiGate

None of the APs are broadcasting the SSlDs defined by the AP profile

Which changes do you need to make to enable the SSIDs to broadcast?

A.

In the SSIDs section enable Tunnel

B.

Enable one channel in the Channels section

C.

Enable multiple channels in the Channels section and enable Radio Resource Provision

D.

In the SSIDs section enable Manual and assign the networks manually

Full Access
Question # 15

Refer to the exhibit.

Examine the FortiSwitch security policy shown in the exhibit

If the security profile shown in the exhibit is assigned to all ports on a FortiSwitch device for 802 1X authentication which statement about the switch is correct?

A.

FortiSwitch cannot authenticate multiple devices connected to the same port

B.

FortiSwitch will try to authenticate non-802 1X devices using the device MAC address as the username and password

C.

FortiSwitch will assign non-802 1X devices to the onboarding VLAN

D.

All EAP messages will be terminated on FortiSwitch

Full Access
Question # 16

Refer to the exhibit

A device connected to port2 on FortiSwitch cannot access the network The port is assigned a security policy to enforce 802 1X authentication While troubleshooting the issue, the administrator obtains the debug output shown in the exhibit

Which two scenarios are likely to cause this issue? (Choose two.)

A.

The device is not configured for 802 IX authentication.

B.

The device has been quarantined for 3600 seconds.

C.

The device has been assigned the guest VLAN

D.

The device does not support 802 1X authentication

Full Access
Question # 17

Refer to the exhibits.

Examine the debug output and the SSL VPN configuration shown in the exhibits.

An administrator has configured SSL VPN on FortiGate. To improve security, the administrator enabled Required Client Certificate on the SSL VPN configuration page. However, a user is unable to successfully authenticate to SSL VPN.

Which configuration change should the administrator make to fix the problem?

A.

Enable Redirect HTTP to SSL-VPN on the SSL VPN configuration page.

B.

Import the CA that signed the SSL VPN Server Certificate to FortiGate.

C.

Set the user certificate as the Server Certificate on the SSL VPN configuration page.

D.

Import the CA that signed the user certificate to FortiGate.

Full Access
Question # 18

Refer to the exhibit.

The exhibit shows a network topology and SSID settings. FortiGate is configured to use an external captive portal.

However, wireless users are not able to see the captive portal login page.

Which configuration change should the administrator make to fix the problem?

A.

Remove the guest.portal user group in the firewall policy.

B.

Enable the captive-portal-exempt option in the firewall policy with the ID 10.

C.

Create a firewall policy to allow traffic from the Guest SSID to FortiAuthenticator and Windows AD devices.

D.

Add the FortiAuthenticator and WindowsAD address objects as exempt sources.

Full Access