exam questions

Exam NSE7_EFW-7.0 All Questions

View all questions & answers for the NSE7_EFW-7.0 exam

Exam NSE7_EFW-7.0 topic 1 question 22 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 22
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Which two configuration commands change the default behavior for content-inspected traffic while FortiGate is in conserve mode? (Choose two.)

  • A. set av-failopen off
  • B. set av-failopen pass
  • C. set fail-open enable
  • D. set ips fail-open disable
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
johnnd
Highly Voted 1 year ago
Selected Answer: AC
"change the default behavior" Default: IPS - disable AV - pass Awanser: set av-failopen off set fail-open enable Docs: For IPS: https://docs.fortinet.com/document/fortigate/7.2.3/cli-reference/409620/config-ips-global For AV: https://docs.fortinet.com/document/fortigate/7.2.3/cli-reference/1620/config-system-global
upvoted 7 times
klapek
12 months ago
correct
upvoted 1 times
sauls
11 months, 3 weeks ago
but its 7.0, not 7.2
upvoted 1 times
johnnd
8 months, 2 weeks ago
You connect but in this case, it is the same.
upvoted 1 times
...
...
...
[Removed]
3 months, 3 weeks ago
Another point: The default action of "av-failopen" is pass, BUT the default action of "av-failopen-session" is disable. Such as "av-failopen" is just configurable when "av-failopen-session" is enable, B and C are correct.
upvoted 1 times
...
[Removed]
3 months, 3 weeks ago
Reading again the question "two configuration commands change the default behavior", you're right, A and C change default behavior
upvoted 1 times
...
...
racdab
Highly Voted 12 months ago
Selected Answer: AC
config ips global set fail-open {enable | disable} end When disabled (default), the IPS engine drops all new sessions that require flow-based inspection. config system global set av-failopen {pass | off | one-shot} end pass This is the default settings.
upvoted 5 times
...
ricjscarvalho
Most Recent 2 months ago
Selected Answer: AC
A and C: https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/194558/conserve-mode
upvoted 1 times
...
[Removed]
3 months, 3 weeks ago
Selected Answer: AC
These are correct, A and C. Details.....
upvoted 1 times
...
[Removed]
3 months, 3 weeks ago
Selected Answer: BC
B,C correct
upvoted 1 times
...
caleidoscopio
7 months, 3 weeks ago
Answer: A, C
upvoted 1 times
...
[Removed]
8 months ago
Selected Answer: AC
Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 61/399
upvoted 1 times
...
certifi46
8 months ago
Selected Answer: AC
A and C
upvoted 1 times
...
kashir
9 months, 2 weeks ago
Selected Answer A,C https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/194558/conserve-mode
upvoted 1 times
...
HSilver
9 months, 2 weeks ago
Selected Answer: BC
B & C https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/194558/conserve-mode
upvoted 2 times
HSilver
9 months, 1 week ago
I WRONG, CORRECT A & C.
upvoted 2 times
...
...
BoostBoris
9 months, 3 weeks ago
Selected Answer: AC
A because av-failopen pass is the default setting in config system global C because fail-open disable is default in config ips global Command set ips fail-over does not exist
upvoted 3 times
...
Seph1
11 months ago
Selected Answer: AC
A & C - are correct. set fail-open for IPS set av-failopen pass|off are correct commands, but the pass is the Default so "off" is correct.
upvoted 1 times
...
klapek
1 year ago
Selected Answer: BC
B and C are correct Fail-open for IPS is configured as follows: 'config ips global set fail-open enable'
upvoted 3 times
klapek
12 months ago
A and C are correct as AV default is 'pass'
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago