exam questions

Exam NSE7_EFW-7.0 All Questions

View all questions & answers for the NSE7_EFW-7.0 exam

Exam NSE7_EFW-7.0 topic 1 question 28 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 28
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which contains the output of a debug command.

If the default settings are in place, what can be concluded about the conserve mode shown in the exhibit?

  • A. FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings due to high memory use.
  • B. FortiGate is currently allowing new sessions that require flow-based or proxy-based content inspection but is not performing inspection on those sessions.
  • C. FortiGate is currently blocking new sessions that require flow-based or proxy-based content inspection.
  • D. FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pcbbj
Highly Voted 1 year, 4 months ago
I'd say that there is no correct answer, as the command says that the FortiGate is running with default settings. The correct would be: "FortiGate is currently ALLOWING new sessions that require PROXY-based content inspection and BLOCKING sessions that require FLOW-based content inspection." References: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Conserve-mode-changes/ta-p/198502 https://docs.fortinet.com/document/fortigate/6.2.12/cookbook/194558/conserve-mode Agree?
upvoted 7 times
klapek
1 year, 4 months ago
No, I don't agree. By default av-failopen-session is disabled and that particular option is responsible for new session behavior in proxy mode. The new sessions are blocked. By default fail-open is disabled --> new sessions in flow-based inspection mode are blocked too.
upvoted 3 times
manimal666
1 year, 4 months ago
By default, set av-failopen mode is pass not disable which means pcbbj looks legit.
upvoted 2 times
racdab
1 year, 4 months ago
by default fortinet bloacks new session( av-failopen-session disable )
upvoted 5 times
...
...
...
...
k3rnelpanicpj
Highly Voted 1 year, 4 months ago
Based on this https://docs.fortinet.com/document/fortigate/6.2.12/cookbook/194558/conserve-mode Proxy-based have default pass (no inspection) Flow-based have default disable (drop sessions) None of answers are correct
upvoted 6 times
...
tuky88
Most Recent 1 day, 7 hours ago
Selected Answer: B
Only extreme threshold drops sessions, red will allow but perform no inspection.
upvoted 1 times
...
Yusraaa
5 months, 3 weeks ago
correct answer is C
upvoted 1 times
...
alwayz
6 months, 1 week ago
av-failopen-session kicks in not during a high memory situation (conserve mode) , but when a proxy on FortiGate runs out of available sockets to process more proxy-based inspected traffic. So, none of answers are correct!
upvoted 1 times
...
talos_2002
10 months, 2 weeks ago
When memory usage becomes extreme, all new sessions are dropped. threshold extreme = 2887 threshold extreme = memory used + freeable memory used + freeable = 2706 + 334 = 3034 3034 > 2887 The unit is in extreme mode, dropping all new sessions.
upvoted 3 times
mikerss
7 months, 4 weeks ago
your calculation does not make sense. The "allowing" answers are not correct. Therefore my assumption is that it went to extreme mode at some stage, however it did not reach green state yet. Therefore the correct answer is C - block new proxy and flow sessions.
upvoted 1 times
mikerss
7 months, 3 weeks ago
Default setting are: (1) "av-failopen-session" is disabled by default. This block all proxy mode traffic (2) "av-failopen" is "pass" by default. However since (1) is disable it is irrelevant. For it to work (1) must be enabled (3) "set fail-open" is disabled by defualt and drops all new sessions that require flow-based insepction. Therefore by default in conserve mode all proxy/flow traffic is blocked. Hence only C is valid. set av-failopen pass
upvoted 1 times
...
...
...
FORTIGOD
10 months, 2 weeks ago
Selected Answer: B
Correct answer is indeed B. av-failopen-session is to address a connection pool issue, av-failopen is to address conserve mode (the topic at hand). One condition can exists without the other and as the documentation notes, where both are occuring av-failopen is used to resolve any discrepancies (since it takes into account an entire system, not a single connection pool).
upvoted 1 times
...
mau_80
11 months ago
Selected Answer: A
FGT is in extreme mode (89%) so why not A?
upvoted 2 times
mikerss
6 months, 4 weeks ago
it is not in extreme mode. to be in extreme mode it needs to be >95%
upvoted 1 times
...
...
[Removed]
1 year, 1 month ago
Selected Answer: C
Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 61/62
upvoted 3 times
mau_80
10 months, 4 weeks ago
FGT is in extreme mode (89%) so why not A?
upvoted 1 times
...
...
certifi46
1 year, 1 month ago
Selected Answer: C
default settings
upvoted 2 times
...
kachbfe
1 year, 2 months ago
Selected Answer: C
NSE7 Page 61,62 Proxy Inspection While in Conserve Mode Note that antivirus is only an example, this applies to all proxy-based inspections. Antivirus failopen governs FortiGate behavior for proxy-based inspection while in conserve mode config system global set av-failopen {off | one-shot | pass} set av-pailopen-session {enable | disable} end set av-failopen-session – Enable or disable failopen Default is disable set av-failopen – Configure how sesions failopen Pass – Stops inspecting new sessions. Inspection is automatically restarted when exiting conserve mode Flow Inspection while in Conserve Mode IPS failopen governs FortiGate behavior for flow-based inspection while in conserve mode config ips global set fail-open {enable | disable} end By default, IPS fail-open is disabled, which means the IPS engine drops all new sessions that require flow-based inspection, but tries to process all existing sessions.If IPS fail-open is enabled, the IPS engine does not perform any scan, but allows new packets.
upvoted 4 times
...
LeeRoy9912
1 year, 3 months ago
Selected Answer: C
C is correct.
upvoted 1 times
...
Seph1
1 year, 3 months ago
Selected Answer: C
C is correct.
upvoted 1 times
...
akukaracia
1 year, 3 months ago
av-failopen (pass) doesn't matter, because av-failopen-session is disabled by default. When it is disabled, FG blocks new sessions. Study guide 61p
upvoted 2 times
akukaracia
1 year, 3 months ago
C is correct
upvoted 1 times
...
...
dosoriomartins
1 year, 4 months ago
Selected Answer: C
agree with klapek2
upvoted 1 times
...
klapek
1 year, 5 months ago
Selected Answer: C
With default settings C is correct
upvoted 4 times
racdab
1 year, 4 months ago
C correct the are two settings av-failopen-session and av-failopen.when you enable av-failopen-session fortinet applies the action configured in av-failopen by default fortinet bloacks new session( av-failopen-session disable )
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago