exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 5 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 5
Topic #: 1
[All NSE7_EFW-7.2 Questions]

Refer to the exhibits, which show the configurations of two address objects from the same FortiGate.

Engineering address object -


Finance address object -

Why can you modify the Engineering address object, but not the Finance address object?

  • A. You have read-only access.
  • B. Another user is editing the Finance address object in workspace mode.
  • C. FortiGate joined the Security Fabric and the Finance address object was configured on the root FortiGate.
  • D. FortiGate is registered on FortiManager.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
charruco
Highly Voted 1 year ago
Selected Answer: C
C is Correct B is not correct because "Workspace mode is available only through CLI mode: Pg. 25 in Enterprise_Firewall_7.2_Study_Guide-Online.pdf
upvoted 8 times
rac_sp
9 months, 4 weeks ago
very true !! furthermore a warning message is shown to let the administrator know that the object is currently being configured in another workstpace transaction
upvoted 2 times
...
...
truserud
Highly Voted 1 year ago
Selected Answer: C
I made a mistake earlier and voted B as that made most sense at the time. After checking in my lab, C is the correct answer. You are indeed presented with only the "return" option on the object on a downstream device when trying to edit a Global fabric object created on the root device.
upvoted 6 times
...
myrmidon3
Most Recent 3 months, 1 week ago
Selected Answer: C
Security Fabric Configuration: When a FortiGate is part of a Security Fabric, address objects and other configurations can be synchronized across devices. If an address object (e.g., the Finance object) was created on the root FortiGate, it is synchronized downstream, and you cannot modify it on the downstream FortiGate. You can only modify such objects on the root FortiGate. Engineering Address Object: The Engineering address object is editable because it was created locally on the current FortiGate and is not synchronized from the root FortiGate. Why the Other Options Are Incorrect: A. You have read-only access: If this were the case, you wouldn’t be able to modify the Engineering object either. B. Another user is editing the Finance address object in workspace mode: In such a scenario, the interface would indicate that the object is locked due to workspace editing. D. FortiGate is registered on FortiManager: While FortiManager can push configurations, the question and behavior are specific to Security Fabric synchronization, not FortiManager.
upvoted 1 times
...
BatherDom
6 months, 2 weeks ago
Selected Answer: B
Leer pagina 25 del libro FW 7.2
upvoted 1 times
...
rac_sp
10 months ago
Selected Answer: C
Fgt is joined in the security fabric
upvoted 2 times
...
evdw
10 months, 4 weeks ago
Selected Answer: C
Correct answer is C
upvoted 2 times
...
havokdu
11 months ago
Selected Answer: C
I created a firewall object on a root fortigate. Then, on a downstream FG the object appeared, but when I tried to edit it the OK button was missing. Only the return button is present. It doesn't happen like that in Workspace mode. So C is the correct option.
upvoted 3 times
...
Selected Answer: B
When an administrator edits an object in workspace mode, it is locked, preventing other administrators from editing that object. A warning message is shown to let the administrator know that the object is currently being configured in another workspace transaction. Pg. 25 in Enterprise_Firewall_7.2_Study_Guide-Online.pdf
upvoted 2 times
...
r3n0
1 year, 1 month ago
Selected Answer: C
In workspace mode the "OK" button is present, you get an error message as soon as you click on it. When you create a fabric object on a root device, it will synchronize to the downstream devices (if enable) and you will not be able to modify the object on any downstream devices. The "OK" button will NOT be available on downstream devices.
upvoted 4 times
...
Totoahren
1 year, 1 month ago
Selected Answer: B
Page 25 Enabling strict header checking disables all hardware acceleration. This includes NP, SP, and CP processing.
upvoted 1 times
...
Totoahren
1 year, 1 month ago
Answer B: Answer: D when check-protocol-header is enabled in strict or loose mode all NPs and CPs are disabled.
upvoted 1 times
Totoahren
1 year, 1 month ago
Answer: B when check-protocol-header is enabled in strict or loose mode all NPs and CPs are disabled.
upvoted 1 times
...
...
ac89l
1 year, 1 month ago
Selected Answer: C
tested in lab
upvoted 2 times
...
truserud
1 year, 1 month ago
Selected Answer: B
A bit tricky from the screenshots, as if B was indeed the correct answer, a warning should be shown that the object is being edited by a different user. A doesn't make much sense, as you wouldn't be able to make changes to either of the objects if you were in read-mode. You can edit and configure downstream Fortigates in a Security Fabric at will. There is nothing in the screenshots signifying that this is a downstream device, or the root device. We you can still configure objects on local devices even if they are managed by FortiManager, and as with question A; if you had logged into a Centrally managed device as read-only, you wouldn't be able to edit any of the objects. I believe the answer is B, as that makes most sense, even though it is difficult to tell from the screenshots themselves.
upvoted 2 times
truserud
1 year ago
Scratch that. The Answer is C. Just tested in my lab, and when creating as a global fabric object, I am not able to edit the adress object on the downstream Fortigate. If it was an object in workspace mode, you would get a warning that the object is locked in a different transistion by a different user.
upvoted 1 times
...
...
MikeSco001
1 year, 1 month ago
Selected Answer: C
Answer is C. Tested in Lab
upvoted 3 times
...
tenebrox
1 year, 1 month ago
Selected Answer: D
Answer is D, i test in my lab with two user, and you always can modify the address but the other user see the warning
upvoted 2 times
...
5deee77
1 year, 2 months ago
Selected Answer: B
The answer is B page 25
upvoted 1 times
...
rananaj
1 year, 2 months ago
Selected Answer: B
The answer is B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago