
FortinetNSE 7 - Enterprise Firewall Administrator
Domain 3Objective 1
Manage SSL/SSH Inspection Profiles, Based on a Scenario NSE7-ENTERPRISE-FIREWALL-ADMINISTRATOR Practice Questions (Page 1)
Part of the Security Profiles domain, which makes up ~23% of our current practice bank. Fortinet does not publish an official question count, but from its 70-minute exam (~30–45 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
Questions 1–5
- 1
Which action does a certificate inspection profile perform on a server certificate that fails validation?
Select an answer first - 2
A company has deployed full SSL inspection in a transparent proxy mode. Users report that some HTTPS sites fail to load, while others work fine. The administrator checks the FortiGate logs and sees 'SSL handshake failure' errors for the failing sites. The failing sites include a banking portal and a software update service. The administrator has already added the banking portal to the exemption list, but the issue persists. What is the most likely cause and the best next step?
Select an answer first - 3
A hospital wants to validate that all outbound HTTPS traffic from its finance department is destined for legitimate banking domains, but the compliance team prohibits decryption of financial transactions. The security team needs to verify the certificate chain and detect expired or untrusted certificates without seeing the payload. Which inspection mode should the administrator configure?
Select an answer first - 4
A company is using certificate inspection and users report that some HTTPS sites are being blocked. The administrator checks the logs and sees 'certificate validation failed' errors for these sites. The sites are legitimate and use certificates from well-known CAs. What is the most likely cause?
Select an answer first - 5
A retail company is deploying full SSL inspection for all employee web traffic. The security administrator has created a full inspection profile and selected the internal CA certificate. However, employees are reporting browser certificate warnings when visiting https://www.vendor-portal.com. The administrator wants to exclude this specific domain from inspection while keeping full inspection for all other traffic. What is the most efficient way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE7-ENTERPRISE-FIREWALL-ADMINISTRATOR” is a trademark of its owner, used for identification only.