exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 34 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 34
Topic #: 1
[All NSE7_EFW-7.2 Questions]

Which statement about network processor (NP) offloading is true?

  • A. The NP checks the session key or IPSec SA.
  • B. The NP provides IPS signature matching.
  • C. You can disable the NP for each firewall policy using the command np-acceleration set to loose.
  • D. For TCP traffic, FortiGate CPU offloads the first packets of SYN/ACK and ACK of the three-way handshake to NP.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
myrmidon3
1 day, 16 hours ago
Selected Answer: A
The NP verifies the session key or IPSec Security Association (SA) to ensure that the traffic matches an established session and is eligible for offloading. This process is part of the NP's function in optimizing secure traffic handling.
upvoted 1 times
...
sugar12
5 months, 1 week ago
Selected Answer: A
For TCP traffic, the first packets of the three-way handshake must first go to the FortiGate CPU Correct answer is A
upvoted 1 times
...
havokdu
7 months, 3 weeks ago
Selected Answer: A
A is correct, according to Study guide page 44. D is not correct. Fortigate CPU doesn't immediately offload the first packets of SYN/ACK and ACK of the three-way handshake to NP like the question implies. It processes them, to perform the required checks to determine whether the packets can be accelerated and offloaded to the NP processor.
upvoted 1 times
...
charruco
8 months, 3 weeks ago
Selected Answer: A
A is correct study guide 7.2, page 44
upvoted 1 times
...
truserud
10 months, 1 week ago
Selected Answer: A
Both A & D are correct though, as stated on page 44 for NP check of SA and session, and on page 46 for TCP NP Session Flow. Here the following is stated: If the FortiGate CPU determines that the conditions are met for the first part of the traffic, then the CPU accelerates and offloads the rest of the traffic to the NP6 processor.
upvoted 1 times
havokdu
7 months, 3 weeks ago
D is not correct. Fortigate CPU doesn't immediately offload the first packets of SYN/ACK and ACK of the three-way handshake to NP. It processes them, to perform the required checks to determine whether the packets can be accelerated and offloaded to the NP processor.
upvoted 2 times
...
...
5deee77
10 months, 2 weeks ago
Selected Answer: A
study guide 7.2, page 44
upvoted 1 times
...
33k_
10 months, 3 weeks ago
Selected Answer: A
Only A is correct, D is wrong because for TCP traffic, the first packets of the three-way handshake must first go to the FortiGate CPU.
upvoted 4 times
...
mollyk70
10 months, 3 weeks ago
D is also correct....
upvoted 1 times
havokdu
7 months, 3 weeks ago
D is not correct. Fortigate CPU doesn't offload the first packets of SYN/ACK and ACK of the three-way handshake to NP. It processes them, to perform the required checks to determine whether the packets can be accelerated and offloaded to the NP processor.
upvoted 2 times
...
...
mollyk70
10 months, 3 weeks ago
A correct, P44 study guide 7.2
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago