Fortinet NSE7_FSN_AR-7.6 Exam Prep
Fortinet NSE 7 - Secure Networking 7.6 Architect (Page 4 )

Updated On: 7-Oct-2026

Exhibit.

Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator do to fix the issue?

  1. Disable webfilter-force-off.
  2. Increase webfilter-timeout.
  3. Enable fortiguard-anycast.
  4. Change protocol to TCP.

Answer(s): A

Explanation:

The exhibit showsa FortiGate configurationunderconfig system fortiguardrelated to web filtering and FortiGuard options. There is a line:
set webfilter-force-off enable
According to official Fortinet documentation, the 'webfilter-force-off' option, when enabled, causes the FortiGate tobypassweb filteringfor all traffic---even if a webfilter profileis applied toa policy. Thisoverride is typicallyused for troubleshootingor performancereasons and isdocumented asan explicit bypassfeature.
Ifan administratorwants to enforceweb filteringinspection, thissettingmustbe disabled. The correctway to restoreweb filteringfunctionalityis to run:
set webfilter-force-off disable
Once done, traffic passing throughpolicies withweb filter profileswill be inspectedand filteredas per configuration. Other settingssuch as timeoutor cache TTLdo not bypassweb filtering; they only affectoperational nuances.
FortiOS AdministrationGuide: Web Filtering, FortiGuard Options, ''webfilter-force-off'' CLI



MULTIPLE CHOICE
Exhibit 1.

Exhibit 2.

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.
An administrator would like to lest session failover between the two service provider connections.
Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

  1. Change the priority of the port1 static route to 11.
  2. Change the priority of the port2 static route to 5.
  3. Configure unset snat-route-change to return it to the default setting.
  4. Configure set snat-route-change enable.

Answer(s): A,D

Explanation:

FortiOS Admin Guide: Static Routing, SNAT Route Change Feature



MULTIPLE CHOICE
Refer to the exhibit, which shows the output of a debug command.

Which two statements about the output are true? (Choose two.)

  1. The interlace is part of the OSPF backbone area.
  2. There are a total of five OSPF routers attached to the vorz4 network segment
  3. One of the neighbors has a router ID of 0.0.0.4.
  4. In the network connected to port4, two OSPF routers are down.

Answer(s): A,B

Explanation:

FortiOS Admin Guide: OSPF, Debug Outputs



MULTIPLE CHOICE
Refer to the exhibit.

Which three pieces of information does the diagnose sys top command provide? (Choose three.)

  1. The miglogd daemon is running on CPU core ID 0.
  2. The diagnose sys top command has been running for 18 minutes.
  3. The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.
  4. The cmdbsvr process is occupying 2.4% of the total user memory space.
  5. If the neweli daemon continues to be in the R state, it will need to be manually restarted.

Answer(s): A,C,D

Explanation:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-diagnose-sys-top-CLI-co-mand/ta-p/190238



MULTIPLE CHOICE
Refer to the exhibit, which shows the output o! the BGP database.

Which two statements are correct? (Choose two.)

  1. The advertised prefix of 10.20.30.0/24 was configured using the network command.
  2. The first four prefixes are being advertised using a legacy route advertisement.
  3. The advertised prefix of 10.20.30.0/24 is being advertised through the redistribution of another routing protocol.
  4. The output shows all prefixes advertised by all neighbors as well as the local router.

Answer(s): A,D

Explanation:

For Option A:In Fortinet BGP (and standard BGP), when a prefix is displayed with an 'i' (lowercase i) in the Path column, it represents aninternalprefix that originated from the local router, typically configured via the BGP 'network' command. In the exhibit, the prefix 10.20.30.0/24 is listed with a Path value ofi, indicating it was injected into BGP by the local router using the network statement, not via redistribution from another routing protocol. The same logic applies toias documented: 'Origin code 'i' means the route was injected via the network command.'
For Option D:Theget router info bgp networkoutput is a summary table displaying both local and received BGP routes. It lists all known routes to the BGP process, whether received from peers or originated locally. The exhibit shows all BGP prefixes known to the local router, matching the official admin guide's description of this command's output.
Explanation for B and C:
The phrase ''legacy route advertisement'' is not formalized in BGP documentation or Fortinet's admin guide; the output uses standard BGP mechanics.
If a route was redistributed into BGP from another routing protocol, the Path field would display a '?' (question mark) for incomplete (redistributed) origin. Here the /24 route has 'i' so it is NOT a redistribution.
FortiOS Administration Guide: BGP Configuration and Route Table Interpretation
Official BGP Command Reference:
Show BGP Network, Path Codes, Route Origination Indicators



Viewing page 4 of 34
Viewing questions 16 - 20 out of 164 questions


Post your Comments and Discuss Fortinet NSE7_FSN_AR-7.6 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!