Free NSE7_EFW-7.2 Exam Braindumps (page: 6)

Page 5 of 15

Which statement about network processor (NP) offloading is true?

  1. For TCP traffic FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP
  2. The NP provides IPS signature matching
  3. You can disable the NP for each firewall policy using the command np-acceleration st to loose.
  4. The NP checks the session key or IPSec SA

Answer(s): D

Explanation:

Network processors (NPs) are specialized hardware within FortiGate devices that accelerate certain security functions. One of the primary functions of NPs is to provide IPS signature matching (B),

allowing for high-speed inspection of traffic against a database of known threat signatures.



Exhibit.



Refer to exhibit, which shows a central management configuration Which server will FortiGate choose for web filler rating requests if 10.0.1.240 is experiencing an outage?

  1. Public FortiGuard servers
  2. 10.0.1.242
  3. 10.0.1.244
  4. 10.0.1.243

Answer(s): C

Explanation:

In the event of an outage at 10.0.1.240, the FortiGate will choose the next server in the sequence for web filter rating requests, which is 10.0.1.244 according to the configuration shown in the exhibit. This is because the server list is ordered by priority, and the server with the lowest priority number is chosen first. If that server is unavailable, the next server with the next lowest priority number is chosen, and so on. The public FortiGuard servers are only used if the include-default-servers option is enabled and all the custom servers are unavailable.


Reference:

Fortinet Enterprise Firewall Study Guide for FortiOS 7.2, page 132.



Exhibit.



Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.
Which two conclusions can you draw from this con figuration? (Choose two)

  1. 10.1.5.254 is the default gateway of the internal network
  2. On failover new primary device uses the same MAC address as the old primary
  3. The VRRP domain uses the physical MAC address of the primary FortiGate
  4. By default FortiGate B is the primary virtual router

Answer(s): A,B

Explanation:

The Virtual Router Redundancy Protocol (VRRP) configuration in the exhibit indicates that 10.1.5.254 is set as the virtual IP (VRIP), commonly serving as the default gateway for the internal network (A). With vrrp-virtual-mac enabled, both FortiGates would use the same virtual MAC address, ensuring a seamless transition during failover (B). The VRRP domain does not use the physical MAC address (C), and the priority settings indicate that FortiGate-A would be the primary router by default due to its higher priority (D).



After enabling IPS you receive feedback about traffic being dropped.
What could be the reason?

  1. Np-accel-mode is set to enable
  2. Traffic-submit is set to disable
  3. IPS is configured to monitor
  4. Fail-open is set to disable

Answer(s): B

Explanation:

Fail-open is a feature that allows traffic to pass through the IPS sensor without inspection when the sensor fails or is overloaded. If fail-open is set to disable, traffic will be dropped in such scenarios.


Reference:

= IPS | FortiGate / FortiOS 7.2.3 - Fortinet Documentation

When IPS (Intrusion Prevention System) is configured, if fail-open is set to disable, it means that if the IPS engine fails, traffic will not be allowed to pass through, which can result in traffic being dropped (D). This is in contrast to a fail-open setting, which would allow traffic to bypass the IPS engine if it is not operational.






Post your Comments and Discuss Fortinet NSE7_EFW-7.2 exam with other Community members:

NSE7_EFW-7.2 Discussions & Posts