exam questions

Exam NSE7_EFW-7.0 All Questions

View all questions & answers for the NSE7_EFW-7.0 exam

Exam NSE7_EFW-7.0 topic 1 question 47 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 47
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which shows the output of a real-time debug.

Which statement about this output is true?

  • A. The requested URL belongs to category ID 255.
  • B. The server hostname was extracted from the SNI in the client request, or from the CN in the server certificate.
  • C. FortiGate found the requested URL in its local cache.
  • D. This web request was inspected using the ftgd-allow web filter profile.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
theklee
Highly Voted 10 months, 2 weeks ago
B - Study guide page 365
upvoted 7 times
...
JackeD
Highly Voted 11 months, 2 weeks ago
Selected Answer: B
b seems right "IPS and WAD will only send request to urlfilter daemon when cache is missed. "
upvoted 7 times
...
luismanzanero
Most Recent 1 month, 4 weeks ago
Selected Answer: B
B is correct
upvoted 1 times
...
Malasxd
2 months, 3 weeks ago
Selected Answer: B
B for sure
upvoted 1 times
...
Bob_Oso
4 months ago
Selected Answer: B
B Enterprise_Firewall_7.0_Study_Guide-Online.pdf page 365
upvoted 1 times
...
nse_student
6 months, 3 weeks ago
Selected Answer: B
Only B is valid.
upvoted 2 times
...
Dayvey
7 months, 3 weeks ago
Indeed B, however I came to this answer because the request TO the filter is cat=255=unknown and the lookup is cat=52, so it had to do a lookup somewhere else. But indeed the urlfilter is only used when the local cache doesn't have the info and the debug output will only show something IF the urlfiler is actually used.
upvoted 2 times
...
certifi46
8 months ago
Selected Answer: B
B Study guide page 365
upvoted 2 times
...
Seph1
9 months ago
Selected Answer: B
B is correct. This exact example is in the study guide. It is forwarding the request to WAD.
upvoted 2 times
...
mader
9 months, 3 weeks ago
Selected Answer: C
should be msg="Cache miss" if no local cache
upvoted 2 times
...
Seph1
9 months, 4 weeks ago
Selected Answer: C
I think the answer is C: Example log for no local cache case: #id=93000 msg="pid=57 urlfilter_main-723 in main.c received pkt:count=91 "IPS and WAD will only send request to urlfilter daemon when cache is missed. " So the WAD process by itself found the URL rating in the local cache and didn`t ask for help from the URL process as in the example. B - we can`t know anything about CN or SNI in this debug. It is more SSL-inspection field.
upvoted 1 times
Seph1
9 months ago
No, the answer is B. This exact example is in the study guide. It is forwarding the request to WAD. Sorry, the correct answer is B.
upvoted 2 times
...
...
kashir
10 months ago
All choices except B are incorrect. The debug output should say something like this "fetched from local cache" if local cache is used.
upvoted 2 times
...
saudiboy
10 months ago
Selected Answer: C
c is the answer
upvoted 1 times
...
jjejje
11 months, 2 weeks ago
Selected Answer: C
answer
upvoted 1 times
...
racdab
11 months, 3 weeks ago
Selected Answer: C
we don't see msg= miss cache for me C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago