Fortinet Enterprise Firewall 7.6 FCSS_EFW_AD-7.6 BGP Peering Advertisement Practice Test

 

This practice test focuses on bgp peering advertisement and best path fundamentals through original applied scenarios aligned to the final published Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator 7.6 blueprint. It is intended for study and does not reproduce live exam content. For broader exam preparation, review the Fortinet FCSS_EFW_AD-7.6 Exam Dumps page.

Question 1

A change ticket for Contoso Finance states that administrators must establish an eBGP session with an upstream router. Which choice is correct? The change is taking place in a controlled maintenance window. Only one site is affected; peer sites are healthy.

  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state

Correct answer: E

Explanation

  1. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  4. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  5. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state. A BGP session needs transport reachability plus compatible neighbor and AS configuration.

Question 2

The security team at Litware Logistics wants to advertise an internal prefix only when that exact route exists in the routing table. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The change must be validated on a pilot device before broader rollout.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Set a higher local preference on routes learned from the preferred exit

Correct answer: A

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This directly addresses the stated requirement.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  3. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  4. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  5. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the BGP network statement for the prefix and ensure a matching route is present. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior.

Question 3

An incident at Wide World Importers requires the NOC engineer to prefer one exit for outbound traffic by changing an attribute within the local AS. What should be done first? The answer must address the stated cause rather than a different feature. Existing production IP addressing must remain unchanged.

  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Use the BGP network statement for the prefix and ensure a matching route is present

Correct answer: D

Explanation

  1. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  3. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  4. BGP prefers higher local preference and the value is propagated within the local AS. This directly addresses the stated requirement.
  5. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, set a higher local preference on routes learned from the preferred exit. BGP prefers higher local preference and the value is propagated within the local AS.

Question 4

For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Relecloud, which option correctly addresses the need to influence an external neighbor to prefer one inbound path without changing the local decision process? Preserve the existing design unless the requirement says otherwise. The resulting configuration must remain centrally auditable.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Set a higher local preference on routes learned from the preferred exit
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity

Correct answer: C

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  3. MED and AS-path length can influence how external networks select a path, subject to their policies. This directly addresses the stated requirement.
  4. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  5. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy. MED and AS-path length can influence how external networks select a path, subject to their policies.

Question 5

Adventure Works has verified basic IP reachability. The remaining requirement is to diagnose an Idle or Active peer. Which action should the team take? Prefer a change that is reversible and easy to verify. A known-good rollback point is available before the change.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit

Correct answer: D

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  3. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This directly addresses the stated requirement.
  5. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity. Transport and neighbor identity must be correct before BGP can reach Established state.

Question 6

At Fourth Coffee, the Fortinet administrator must establish an eBGP session with an upstream router. Which action best addresses the requirement? The team needs an auditable result. The design must preserve the current segmentation boundaries.

  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Set a higher local preference on routes learned from the preferred exit

Correct answer: A

Explanation

  1. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This directly addresses the stated requirement.
  2. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  3. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  4. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  5. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state. A BGP session needs transport reachability plus compatible neighbor and AS configuration.

Question 7

During an enterprise firewall change at Coho Winery, the team needs to advertise an internal prefix only when that exact route exists in the routing table. What should it do? Use normal enterprise Fortinet administration practice. The team is not allowed to disable the security feature globally.

  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: C

Explanation

  1. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  3. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This directly addresses the stated requirement.
  4. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the BGP network statement for the prefix and ensure a matching route is present. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior.

Question 8

A production review at Fabrikam Manufacturing identifies this requirement: prefer one exit for outbound traffic by changing an attribute within the local AS. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. The symptom appeared immediately after a planned configuration change.

  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use the BGP network statement for the prefix and ensure a matching route is present

Correct answer: B

Explanation

  1. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  2. BGP prefers higher local preference and the value is propagated within the local AS. This directly addresses the stated requirement.
  3. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  4. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  5. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, set a higher local preference on routes learned from the preferred exit. BGP prefers higher local preference and the value is propagated within the local AS.

Question 9

While troubleshooting at Wingtip Energy, the NOC engineer needs to influence an external neighbor to prefer one inbound path without changing the local decision process. What is the best next step? No unrelated control should be weakened. Logs from the affected traffic are available for verification.

  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Set a higher local preference on routes learned from the preferred exit
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: E

Explanation

  1. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  2. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  3. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy. MED and AS-path length can influence how external networks select a path, subject to their policies.

Question 10

Lucerne Publishing is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to diagnose an Idle or Active peer? The team will validate the result immediately after the change. The equivalent configuration works correctly at a separate site.

  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Use the BGP network statement for the prefix and ensure a matching route is present

Correct answer: B

Explanation

  1. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This directly addresses the stated requirement.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  4. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  5. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity. Transport and neighbor identity must be correct before BGP can reach Established state.

Question 11

A change ticket for Bellows College states that administrators must establish an eBGP session with an upstream router. Which choice is correct? The change is taking place in a controlled maintenance window. The change must be reversible within the same maintenance window.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: B

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This directly addresses the stated requirement.
  3. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  4. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state. A BGP session needs transport reachability plus compatible neighbor and AS configuration.

Question 12

The security team at Tailspin Toys wants to advertise an internal prefix only when that exact route exists in the routing table. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The device is already synchronized with its central-management database.

  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Set a higher local preference on routes learned from the preferred exit

Correct answer: B

Explanation

  1. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  2. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This directly addresses the stated requirement.
  3. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  4. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  5. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the BGP network statement for the prefix and ensure a matching route is present. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior.

Question 13

An incident at Humongous Insurance requires the network operations engineer to prefer one exit for outbound traffic by changing an attribute within the local AS. What should be done first? The answer must address the stated cause rather than a different feature. The current routing table contains the expected connected networks.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: C

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This directly addresses the stated requirement.
  4. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, set a higher local preference on routes learned from the preferred exit. BGP prefers higher local preference and the value is propagated within the local AS.

Question 14

For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Margie Travel, which option correctly addresses the need to influence an external neighbor to prefer one inbound path without changing the local decision process? Preserve the existing design unless the requirement says otherwise. Basic IP reachability to the remote endpoint has already been verified.

  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Use the BGP network statement for the prefix and ensure a matching route is present

Correct answer: D

Explanation

  1. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  4. MED and AS-path length can influence how external networks select a path, subject to their policies. This directly addresses the stated requirement.
  5. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy. MED and AS-path length can influence how external networks select a path, subject to their policies.

Question 15

Northwind Health has verified basic IP reachability. The remaining requirement is to diagnose an Idle or Active peer. Which action should the team take? Prefer a change that is reversible and easy to verify. Hardware replacement is outside the approved change scope.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Set a higher local preference on routes learned from the preferred exit
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state

Correct answer: D

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  2. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This directly addresses the stated requirement.
  5. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity. Transport and neighbor identity must be correct before BGP can reach Established state.

Question 16

At Blue Yonder Airlines, the enterprise firewall engineer must establish an eBGP session with an upstream router. Which action best addresses the requirement? The team needs an auditable result. The requirement applies only to one policy, peer, or managed device group.

  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Set a higher local preference on routes learned from the preferred exit
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use the BGP network statement for the prefix and ensure a matching route is present

Correct answer: B

Explanation

  1. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This directly addresses the stated requirement.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  5. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state. A BGP session needs transport reachability plus compatible neighbor and AS configuration.

Question 17

During an enterprise firewall change at Trey Research, the team needs to advertise an internal prefix only when that exact route exists in the routing table. What should it do? Use normal enterprise Fortinet administration practice. The team must avoid broadening administrative trust or permissions.

  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Set a higher local preference on routes learned from the preferred exit
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: B

Explanation

  1. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  2. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This directly addresses the stated requirement.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  4. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the BGP network statement for the prefix and ensure a matching route is present. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior.

Question 18

A production review at Apex Retail identifies this requirement: prefer one exit for outbound traffic by changing an attribute within the local AS. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. The design must preserve existing centralized logging and telemetry.

  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Set a higher local preference on routes learned from the preferred exit
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: C

Explanation

  1. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  2. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This directly addresses the stated requirement.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, set a higher local preference on routes learned from the preferred exit. BGP prefers higher local preference and the value is propagated within the local AS.

Question 19

While troubleshooting at Proseware Media, the network operations engineer needs to influence an external neighbor to prefer one inbound path without changing the local decision process. What is the best next step? No unrelated control should be weakened. Production subnets cannot be renumbered as part of this change.

  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: E

Explanation

  1. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  2. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  3. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  4. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy. MED and AS-path length can influence how external networks select a path, subject to their policies.

Question 20

City Power & Light is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to diagnose an Idle or Active peer? The team will validate the result immediately after the change. A maintenance window is open, but service interruption must be minimized.

  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Set a higher local preference on routes learned from the preferred exit
  • Use the BGP network statement for the prefix and ensure a matching route is present

Correct answer: B

Explanation

  1. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This directly addresses the stated requirement.
  3. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  4. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  5. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity. Transport and neighbor identity must be correct before BGP can reach Established state.

Question 21

A change ticket for VanArsdel states that administrators must establish an eBGP session with an upstream router. Which choice is correct? The change is taking place in a controlled maintenance window. The team must preserve existing certificate-trust relationships unless the requirement explicitly changes them.

  • Set a higher local preference on routes learned from the preferred exit
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: C

Explanation

  1. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  2. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  3. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This directly addresses the stated requirement.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to establish an eBGP session with an upstream router.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state. A BGP session needs transport reachability plus compatible neighbor and AS configuration.

Question 22

The security team at Woodgrove Bank wants to advertise an internal prefix only when that exact route exists in the routing table. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The change will be reviewed later using the configuration and event audit trail.

  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state

Correct answer: C

Explanation

  1. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  2. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  3. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This directly addresses the stated requirement.
  4. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.
  5. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to advertise an internal prefix only when that exact route exists in the routing table.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the BGP network statement for the prefix and ensure a matching route is present. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior.

Question 23

An incident at Alpine Ski House requires the network security architect to prefer one exit for outbound traffic by changing an attribute within the local AS. What should be done first? The answer must address the stated cause rather than a different feature. The chosen approach must continue to work as additional branch sites are added.

  • Set a higher local preference on routes learned from the preferred exit
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy

Correct answer: A

Explanation

  1. BGP prefers higher local preference and the value is propagated within the local AS. This directly addresses the stated requirement.
  2. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  3. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  4. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.
  5. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prefer one exit for outbound traffic by changing an attribute within the local AS.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, set a higher local preference on routes learned from the preferred exit. BGP prefers higher local preference and the value is propagated within the local AS.

Question 24

For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Datum Corporation, which option correctly addresses the need to influence an external neighbor to prefer one inbound path without changing the local decision process? Preserve the existing design unless the requirement says otherwise. A second engineer will verify the result using independent operational evidence.

  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Set a higher local preference on routes learned from the preferred exit
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity

Correct answer: A

Explanation

  1. MED and AS-path length can influence how external networks select a path, subject to their policies. This directly addresses the stated requirement.
  2. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  3. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  4. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.
  5. Transport and neighbor identity must be correct before BGP can reach Established state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to influence an external neighbor to prefer one inbound path without changing the local decision process.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy. MED and AS-path length can influence how external networks select a path, subject to their policies.

Question 25

Contoso Finance has verified basic IP reachability. The remaining requirement is to diagnose an Idle or Active peer. Which action should the team take? Prefer a change that is reversible and easy to verify. The team requires a deterministic rollback path if validation fails.

  • Configure the neighbor address and remote AS, ensure IP reachability and TCP 179 access, and verify BGP state
  • Use the BGP network statement for the prefix and ensure a matching route is present
  • Set a higher local preference on routes learned from the preferred exit
  • Use an outbound MED or AS-path prepending strategy appropriate to the peer relationship and provider policy
  • Verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity

Correct answer: E

Explanation

  1. A BGP session needs transport reachability plus compatible neighbor and AS configuration. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  2. BGP network origination requires the prefix to exist in the routing information base under normal network-statement behavior. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  3. BGP prefers higher local preference and the value is propagated within the local AS. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  4. MED and AS-path length can influence how external networks select a path, subject to their policies. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to diagnose an Idle or Active peer.
  5. Transport and neighbor identity must be correct before BGP can reach Established state. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify neighbor addressing, remote AS, routing to the peer, source interface or update source, and TCP connectivity. Transport and neighbor identity must be correct before BGP can reach Established state.

Popular posts

img