Free NSE7_LED-7.0 Exam Braindumps (page: 4)

Page 3 of 10

Refer to the exhibit.



Examine the FortiGate user group configuration and the Windows AD LDAP group membership information shown in the exhibit
FortiGate is configured to authenticate SSL VPN users against Windows AD using LDAP The administrator configured the SSL VPN user group for SSL VPN users However the administrator noticed that both the student and j smith users can connect to SSL VPN Which change can the administrator make on FortiGate to restrict the SSL VPN service to the student user only?

  1. In the SSL VPN user group configuration set Group Nam© to CN-SSLVPN, CN="users, DC-
    trainingAD, DC-training, DC-lab
  2. In the SSL VPN user group configuration, change Name to cn=sslvpn, CN=users, DC=trainingAD, Detraining, DC-lab.
  3. In the SSL VPN user group configuration set Group Name to ::;=Domain users.CN- Users/DC=trainingAD, DC-training, DC=lab.
  4. In the SSL VPN user group configuration change Type to Fortinet Single Sign-On (FSSO)

Answer(s): A

Explanation:

According to the FortiGate Administration Guide, "The Group Name is the name of the LDAP group that you want to use for authentication. The name must match exactly the name of the LDAP group on the LDAP server." Therefore, option A is true because it will set the Group Name to match the LDAP group that contains only the student user. Option B is false because changing the Name will not affect the authentication process, as it is only a local identifier for the user group on FortiGate. Option C is false because setting the Group Name to Domain Users will include all users in the domain, not just the student user. Option D is false because changing the Type to FSSO will require a different configuration method and will not solve the problem.



Refer to the exhibits.



Exhibit.



Examine the troubleshooting outputs shown in the exhibits Users have been reporting issues with the speed of their wireless connection in a particular part of the wireless network The interface that is having issues is the 2 4 GHz interface that is currently configured on channel 6
The administrator of the wireless network has investigated and surveyed the local RF environment using the tools available at the AP and FortiGate
Which configuration would improve the wireless connection?

  1. Change the AP 2 4 GHz channel to 11
  2. Change the AP 2 4 GHz channel to 1.
  3. Change the AP 2 4 GHz channel to 9.
  4. Change the AP 2 4 GHz channel to 13.

Answer(s): B

Explanation:

According to the exhibits, the AP 2.4 GHz interface is currently configured on channel 6, which is overlapping with other nearby APs on channels 4 and 8. This can cause interference and reduce the wireless performance. Therefore, changing the AP 2.4 GHz channel to 1 would improve the wireless connection, as it would avoid the overlapping channels and use a non-overlapping channel instead. Option A is false because changing the AP 2.4 GHz channel to 11 would still overlap with other nearby APs on channels 9 and 13. Option C is false because changing the AP 2.4 GHz channel to 9 would still overlap with other nearby APs on channels 6, 8, and 11. Option D is false because changing the AP 2.4 GHz channel to 13 would still overlap with other nearby APs on channels 9 and 11.



Refer to the exhibit.



Examine the FortiSwitch security policy shown in the exhibit If the security profile shown in the exhibit is assigned to all ports on a FortiSwitch device for 802 1X authentication which statement about the switch is correct?

  1. FortiSwitch cannot authenticate multiple devices connected to the same port
  2. FortiSwitch will try to authenticate non-802 1X devices using the device MAC address as the username and password
  3. FortiSwitch will assign non-802 1X devices to the onboarding VLAN
  4. All EAP messages will be terminated on FortiSwitch

Answer(s): C

Explanation:

According to the FortiSwitch Administration Guide, "If a device does not support 802.1X authentication, you can configure the switch to assign the device to an onboarding VLAN. The onboarding VLAN is a separate VLAN that you can use to provide limited network access to non- 802.1X devices." Therefore, option C is true because it describes the behavior of FortiSwitch when the security profile shown in the exhibit is assigned to all ports. Option A is false because FortiSwitch can authenticate multiple devices connected to the same port using MAC-based or MAB-EAP modes. Option B is false because FortiSwitch will not try to authenticate non-802.1X devices using the device MAC address as the username and password, but rather use MAC authentication bypass (MAB) or EAP pass-through modes. Option D is false because all EAP messages will be terminated on FortiGate, not FortiSwitch, when using 802.1X authentication.



Which two statements about the MAC-based 802 1X security mode available on FortiSwitch are true? (Choose two.)

  1. FortiSwitch authenticates a single device and opens the port to other devices connected to the port
  2. FortiSwitch authenticates each device connected to the port
  3. It cannot be used in conjunction with MAC authentication bypass
  4. FortiSwitch can grant different access levels to each device connected to the port

Answer(s): B,D

Explanation:

According to the FortiSwitch Administration Guide, "MAC-based 802.1X security mode allows you to authenticate each device connected to a port using its MAC address as the username and password." Therefore, option B is true because it describes the MAC-based 802.1X security mode available on FortiSwitch. Option D is also true because FortiSwitch can grant different access levels to each device connected to the port based on the user group and security policy assigned to them. Option A is false because FortiSwitch does not authenticate a single device and open the port to other devices connected to the port, but rather authenticates each device individually. Option C is false because MAC-based 802.1X security mode can be used in conjunction with MAC authentication bypass (MAB) or EAP pass-through modes, which are fallback options for non-802.1X devices.






Post your Comments and Discuss Fortinet NSE7_LED-7.0 exam with other Community members:

NSE7_LED-7.0 Discussions & Posts