Fortinet NSE 7 Enterprise Firewall 6.2 Exam
- Which of the following best describes the primary purpose of a firewall policy in FortiGate
- To monitor system resources
- To filter network traffic according to security rules
- To configure hardware acceleration
- To manage VPN tunnels
devices?
Answer: B
Explanation: Firewall policies in FortiGate are designed to filter incoming and outgoing traffic based on predefined rules.
- In FortiGate firewall policies, what does “implicit deny” mean?
- Traffic is always allowed
- Traffic is denied unless explicitly permitted
- Traffic is monitored only
- Traffic is rerouted to another zone
Answer: B
Explanation: The implicit deny rule means that any traffic not explicitly allowed by the firewall policy is denied by default.
- Which firewall policy feature allows the inspection of traffic for viruses and malware?
- Routing
B. NAT
- Security Profiles 1 / 4
Fortinet NSE 7 Enterprise Firewall 6.2 Exam
- HA Clustering
Answer: C
Explanation: Security profiles, such as antivirus scanning, are applied within firewall policies to inspect and filter traffic for malicious content.
- How does FortiGate handle advanced custom firewall rules?
- By using static routing
- By integrating with intrusion prevention systems
- By managing user accounts
- Through firmware updates only
Answer: B
Explanation: Advanced firewall rules often incorporate security profiles like intrusion prevention systems (IPS) to enhance traffic filtering.
- When configuring policy routing in FortiGate, which of the following is a key consideration?
- Load balancing between HA clusters
- The firewall’s web filtering rules
- Defining specific route maps based on traffic type
- Enabling antivirus scanning
Answer: C
Explanation: Policy routing in FortiGate involves creating route maps that determine how different types of traffic are forwarded.
- / 4
Fortinet NSE 7 Enterprise Firewall 6.2 Exam
- What is the main benefit of configuring multi-factor authentication (MFA) on a FortiGate
- To reduce system load
- To increase the complexity of user passwords
- To enhance security by requiring multiple forms of verification
- To speed up data packet inspection
device?
Answer: C
Explanation: MFA adds an extra layer of security by requiring additional verification beyond just a password.
- Which protocol is commonly integrated with FortiGate for external authentication?
A. HTTP
B. FTP
C. LDAP
D. SMTP
Answer: C
Explanation: LDAP is commonly used to integrate FortiGate with existing directory services for external authentication.
- In certificate-based authentication for FortiGate, what is typically required on both the client
- A matching IP address
- Digital certificates issued by a trusted authority 3 / 4
and server sides?
Fortinet NSE 7 Enterprise Firewall 6.2 Exam
- A shared secret key
- A manual firewall rule update
Answer: B
Explanation: Certificate-based authentication requires a digital certificate on both ends to ensure secure, trusted communication.
- Which type of VPN is designed for site-to-site connectivity on FortiGate?
A. SSL VPN
- IPsec VPN
- Remote access VPN
D. DHCP VPN
Answer: B
Explanation: IPsec VPNs are typically used for secure site-to-site connections between networks.
- When configuring a remote access VPN, which feature helps secure communications on
- DNS forwarding
- SSL encryption
- DHCP relay
- ARP caching
FortiGate?
Answer: B
Explanation: SSL VPNs use SSL encryption to secure remote access communications.
- / 4