Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE4_FGT_AD-7.6 Dumps

Fortinet NSE 4 - FortiOS 7.6 Administrator Questions and Answers

Question 1

Refer to the exhibit.

as

Which two ways can you view the log messages shown in the exhibit? (Choose two.)

Options:

A.

By right clicking the implicit deny policy

B.

Using the FortiGate CLI command diagnose log test

C.

By filtering by policy universally unique identifier (UUID) and application name in the log entry

D.

In the Forward Traffic section

Question 2

Which statement correctly describes NetAPI polling mode for the FSSO collector agent?

Options:

A.

The collector agent uses a Windows API to query DCs for user logins.

B.

The NetSessionEnum function is used to track user logouts.

C.

NetAPI polling can increase bandwidth usage in large networks.

D.

The collector agent must search Windows application event logs.

Question 3

An administrator creates a new address object on the root FortiGate (HQ-NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW).

as

as

What must the administrator do to synchronize the address object?

Options:

A.

Change the csf setting on HQ-ISFW (downstream) to set configuration-sync local.

B.

Change the csf setting on HQ-ISFW (downstream) to set saml-configuration-sync default.

C.

Change the csf setting on HQ-NGFW-1 (root) to set fabric-object-unification default.

D.

Change the csf setting on both devices to set downstream-access enable.

Question 4

Refer to the exhibit.

as

A partial cloud topology is shown.

You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS for FortiGate CNF policy enforcement for EC2 instance traffic. Which path does the EC2 traffic take from the EC2 instance to the internet?

Options:

A.

EC2 instance → GWLBe → FortiGate CNF → GWLBe → IGW → internet

B.

EC2 instance → Internet Gateway (IGW) → Gateway Load Balancer (GWLB) → FortiGate CNF → internet

C.

EC2 instance → FortiGate CNF → GWLB → GWLBe → IGW → internet

D.

EC2 instance → GWLB endpoint (GWLBe) → FortiGate CNF → IGW → internet

Question 5

Refer to the exhibit.

as

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category. What are two solutions for satisfying the requirement? (Choose two answers)

Options:

A.

Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.

B.

Configure a web override rating for download.com and select Malicious Websites as the subcategory.

C.

Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.

D.

Set the Freeware and Software Downloads category Action to Warning.

Question 6

Which three methods are used by the collector agent for AD polling? (Choose three answers)

Options:

A.

NetAPI

B.

WMI

C.

WinSecLog

D.

DNS reverse lookup

E.

FSSO REST API

Question 7

Refer to the exhibits.

as

The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device.

Based on the system performance output, what are the two possible outcomes? (Choose two.)

Options:

A.

FortiGate drops new sessions.

B.

Administrators can access FortiGate only through the console port.

C.

Administrators can change the configuration.

D.

FortiGate has entered conserve mode.

Question 8

Refer to the exhibit.

as

What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

Options:

A.

FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.

B.

FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.

C.

FortiGate will close the connection if the SNI does not match the CN or SAN fields.

D.

FortiGate will close the connection if the SNI does not match the CN and SAN fields

Question 9

Refer to the exhibit.

as

Which two statements about the FortiGuard connection are true? (Choose two.)

Options:

A.

The weight increases as the number of failed packets rises

B.

You can configure unreliable protocols to communicate with FortiGuard Server.

C.

FortiGate identified the FortiGuard Server using DNS lookup.

D.

FortiGate is using the default port for FortiGuard communication.

Question 10

An administrator manages a FortiGate model that supports NTurbo

How does NTurbo acceleration enhance antivirus performance?

Options:

A.

For flow-based inspection. NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces.

B.

For flow-based inspection. NTurbo creates two inspection sessions on the FortiGate device.

C.

For proxy-based inspection. NTurbo offloads traffic to the content processor.

D.

For proxy-based inspection. NTurbo buffers the whole file and then sends it to the antivirus engine.

Question 11

FortiGate is integrated with FortiAnalyzer and FortiManager.

When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

Options:

A.

Universally Unique Identifier

B.

Policy ID

C.

Sequence ID

D.

Log ID

Question 12

When configuring a FortiGate in a multi-WAN setup, why would an administrator enable session preservation on an interface? (Choose one answer)

Options:

A.

To allow the FortiGate to dynamically change interfaces for all active sessions when a WAN link fails

B.

To make sure all sessions without source NAT enabled always use the primary WAN link

C.

To improve security by forcing users to authenticate again when the WAN link changes

D.

To ensure that existing SSL VPN connections remain on the same interface even if route changes occur

Question 13

A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad.

Which VPN Wizard template must the administrator apply?

Options:

A.

Remote Access

B.

Hub-and-Spoke

C.

Site-to-Site

D.

Dial-up User

Question 14

You have created a web filter profile named restrictmedia-profile with a daily category usage quota.

When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.

What could be the reason?

Options:

A.

The web filter profile is already referenced in another firewall policy.

B.

The firewall policy is in no-inspection mode instead of deep-inspection.

C.

The naming convention used in the web filter profile is restricting it in the firewall policy.

D.

The inspection mode in the firewall policy is not matching with web filter profile feature set.

Question 15

Which two statements describe characteristics of automation stitches? (Choose two answers)

Options:

A.

Actions involve only devices included in the Security Fabric.

B.

An automation stitch can have multiple triggers.

C.

Multiple actions can run in parallel.

D.

Triggers can involve external connectors.

Question 16

You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two answers)

Options:

A.

You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 or 4500).

B.

You can turn on fragmentation to fix large certificate negotiation problems.

C.

You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP ports.

D.

You should use the protocol IKEv2.

Question 17

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

Options:

A.

On Demand

B.

Enabled

C.

On Idle

D.

Usabled

Question 18

A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is not part of the expected process?

Options:

A.

The DC agent sends login event data directly to FortiGate.

B.

FortiGate determines user identity based on the IP address in the FSSO list.

C.

The collector agent forwards login event data to FortiGate.

D.

The user logs into the windows domain.

Question 19

FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)

Options:

A.

Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.

B.

Both interfaces must have the interface role assigned.

C.

Both interfaces must have directly connected routes on the routing table.

D.

Both interfaces must have IP addresses assigned.

Question 20

Refer to the exhibits.

as

The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver? (Choose one answer)

Options:

A.

Disable match-vip in the Allow_access policy.

B.

Configure a One-to-One IP Pool object in a new policy.

C.

Set the Destination address as Webserver in the Deny policy.

D.

Set the Destination address as Deny_IP in the Allow_access policy.

Question 21

Which two statements are correct when the FortiGate device enters conserve mode? (Choose two.)

Options:

A.

FortiGate refuses to accept configuration changes.

B.

FortiGate halts complete system operation and requires a reboot to regain available resources.

C.

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.

D.

FortiGate continues to run critical security actions, such as quarantine.

Question 22

Refer to the exhibit showing a debug flow output.

as

Which two conclusions can you make from the debug flow output? (Choose two answers)

Options:

A.

The default gateway is configured on port2.

B.

The RPF check fails.

C.

The debug flow is for UDP traffic.

D.

The matching firewall policy denies the traffic.

Question 23

Refer to the exhibit.

as

What can you conclude from the log shown in the exhibit?

Options:

A.

The IPS socket buffer is full and IPS engine needs more memory to create new sessions.

B.

The IPS socket buffer is full and IPS engine cannot decode a packet.

C.

The IPS scan is paused by the IPS diagnostic command with bypass mode option 5.

D.

The IPS session scan is paused and reevaluating the packet because of a dirty flag.

Question 24

Exhibits:

as

You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS.

While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS.

What could be the cause?

Options:

A.

The feature set in the antivirus profile is not set to Flow-based.

B.

Web filter is not enabled on the firewall policy to complement the antivirus profile.

C.

The action on the firewall policy is not set to deny.

D.

The SSL inspection mode in the firewall policy is not deep content inspection.

Question 25

You have configured the below commands on a FortiGate.

as

What would be the impact of this configuration on FortiGate?

Options:

A.

FortiGate will enable strict RPF on all its interfaces and porti will be exempted from RPF checks.

B.

FortiGate will enable strict RPF on all its interfaces and porti will be enable for asymmetric routing.

C.

The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces.

D.

Port1 will be enabled with flexible RPF. and all other interfaces will be enabled for strict RPF

Question 26

What is the primary FortiGate election process when the HA override setting is enabled? (Choose one answer)

Options:

A.

Connected monitored ports > Priority > HA uptime > FortiGate serial number

B.

Connected monitored ports > Priority > System uptime > FortiGate serial number

C.

Connected monitored ports > HA uptime > Priority > FortiGate serial number

D.

Connected monitored ports > System uptime > Priority > FortiGate serial number

Question 27

Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two answers)

Options:

A.

If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.

B.

If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.

C.

If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.

D.

If SD-WAN is disabled, you configure the load balancing algorithm in config system settings.

Question 28

Refer to the exhibits.

as

The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details. Based on the configuration, what will happen to Apple FaceTime if there are only a few calls originating or incoming? (Choose one answer)

Options:

A.

Apple FaceTime will be allowed, based on the Video/Audio category configuration.

B.

Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration.

C.

Apple FaceTime will be allowed, based on the Apple filter configuration.

D.

Apple FaceTime will be allowed only if the Apple filter in Application and Filter Overrides is set to Allow.

Page: 1 / 10
Total 95 questions