Free NSE7_EFW-6.4 Exam Braindumps (page: 14)

Page 13 of 32

View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below.



Which statements about this debug output are correct? (Choose two.)

  1. The remote gateway IP address is 10.0.0.1.
  2. It shows a phase 1 negotiation.
  3. The negotiation is using AES128 encryption with CBC hash.
  4. The initiator has provided remote as its IPsec peer I

Answer(s): B,D



Which of the following statements are correct regarding application layer test commands? (Choose two.)

  1. They are used to filter real-time debugs.
  2. They display real-time application debugs.
  3. Some of them display statistics and configuration information about a feature or process.
  4. Some of them can be used to restart an application.

Answer(s): C,D

Explanation:

Application layer test commands don't display info in real time, but they do show statistics and configuration info about a feature or process. You can also use some of these commands to restart a process or execute a change in its operation.



When using the SSL certificate inspection method for HTTPS traffic, how does FortiGate filter web requests when the browser client does not provide the server name indication (SNI) extension?

  1. FortiGate uses CN information from the Subject field in the server's certificate.
  2. FortiGate switches to the full SSL inspection method to decrypt the data.
  3. FortiGate blocks the request without any further inspection.
  4. FortiGate uses the requested URL from the user's web browser.

Answer(s): A



What global configuration setting changes the behavior for content-inspected traffic while FortiGate is in system conserve mode?

  1. av-failopen
  2. mem-failopen
  3. utm-failopen
  4. ips-failopen

Answer(s): A

Explanation:

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-security-profiles- 54/Other_Profile_Considerations/Conserve%20mode.htm






Post your Comments and Discuss Fortinet NSE7_EFW-6.4 exam with other Community members:

Exam Discussions & Posts