NSE4_FGT_AD-7.6 Exam Questions
115 real NSE4_FGT_AD-7.6 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Security Profiles
Which three statements explain a flow-based antivirus profile? (Choose three.)
flow-based inspectionantivirus profileproxy-based inspectionIPS engine - Question #2Security Profiles
Refer to the exhibit. An administrator has configured an Application Overrides for the ABC.com application signature and set the Action to Allow. The application control profile is...
application controlapplication overrideloggingallow action - Question #3System Configuration
Which two statements describe characteristics of automation stitches? (Choose two.)
automation stitchesSecurity Fabrictriggersparallel actions - Question #4Network Configuration
Which three statements about SD-WAN performance SLAs are true? (Choose three.)
SD-WANperformance SLASLA targetsSD-WAN rules - Question #5High Availability
Which two statements are true about an HA cluster? (Choose two.)
HA clusterlink failoverheartbeat interfaceHA synchronization - Question #6Routing
Refer to the exhibit. An administrator has created a new firewall address to use as the destination for a static route. Why is the administrator not able to select the new address...
static routefirewall addressrouting configurationnamed address - Question #7Network Configuration
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected phys...
NAT modeinterface configurationdirectly connected routesIP addressing - Question #8Network Configuration
When configuring a FortiGate in a multi-WAN setup, why would an administrator enable session preservation on an interface?
multi-WANsession preservationWAN link failoverSSL VPN - Question #9VPN
You are analyzing connectivity problems caused by intermediate devices blocking traffic in SSL VPN environment. In which two ways can you effectively resolve the problem? (Choose t...
SSL VPNDTLSIPsecfragmentation - Question #10Firewall Policies
Refer to the exhibit. FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles. Which action must the ad...
firewall policymultiple interface policiespolicy consolidationinterface selection - Question #11Security Profiles
ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?
application controlnetwork protocol enforcementtraffic blockingUDP ports - Question #12Firewall Policies
When configuring firewall policies which of the following is true regarding the policy ID? (Choose two.)
firewall policypolicy IDCLI configurationpolicy creation - Question #13Troubleshooting and Monitoring
Which two statements are correct when FortiGate enters conserve mode? (Choose two.)
conserve modememory managementIPS fail-opensystem resources - Question #14VPN
A remote user reports slow SSL VPN performance and frequent disconnections. The user is located in an area with poor internet connectivity. What setting should the administrator ad...
SSL VPNDTLS timeouthigh latencyperformance tuning - Question #15VPN
An administrator wants to analyze and manage digital certificates to prevent browser warnings when users connect to the SSL VPN portal. Which two statements describe how to correct...
SSL VPNdigital certificatesCA certificateself-signed certificate - Question #16Troubleshooting and Monitoring
An administrator suspects that the Collector Agent is not forwarding login events to FortiGate. What is the most effective troubleshooting step?
FSSOCollector AgentTCP port 8000DC agent - Question #17VPN
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phas...
IPsecphase 2encryption mismatchproxy ID - Question #18High Availability
Refer to the exhibits. An administrator has observed the performance status outputs on an HA cluster for 55 seconds. Which FortiGate is the primary?
HA clusterprimary electionmemory failover thresholdHA priority - Question #19System Configuration
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
FSSONetAPI pollingNetSessionEnumuser logout tracking - Question #20Troubleshooting and Monitoring
You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied. What should the administrator check first?
FSSOAD group membershipactive users listinternet access - Question #21Routing
What are three key routing principles in SD-WAN? (Choose three.)
SD-WAN rulesrouting prioritypolicy routesSD-WAN members - Question #22Network Configuration
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port2)...
SNATIP poolNATfirewall policy - Question #23Firewall Policies
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with defau...
deny policyVIP matchingdestination addressmatch-vip - Question #24Troubleshooting and Monitoring
Refer to the exhibits. The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device. Based on the system performa...
conserve modememory usagesystem performancesession drops - Question #25High Availability
Refer to the exhibits. Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibit. What would...
HA clusteroverridepriorityfailover - Question #26High Availability
Which of the following statements is true regarding the FortiGate cluster?
HA clusteroverride enablepriority electionprimary unit - Question #27Troubleshooting and Monitoring
Refer to the exhibits. An administrator wants to add HQ-ISFW-2 in the Security Fabric. HQ-ISFW-2 is in the same subnet as HQ-ISFW. After configuring the Security Fabric settings on...
Security Fabricupstream FortiGatepending statusauthorization - Question #28Security Profiles
Refer to the exhibit. The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which be...
web filterstatic URL filterFortiGuard categoryURL block - Question #29VPN
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbo...
IPsec VPNdead peer detectionDPD modesOn Demand - Question #30Routing
Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)
ECMPload balancingSD-WANrouting algorithm - Question #31Security Profiles
You have created a web filter profile named restrict_media-profile with a daily category usage quotas. When you are adding the profile to the firewall policy, the restrict_media-pr...
web filter profileinspection modefeature setproxy vs flow - Question #32Troubleshooting and Monitoring
Refer to the exhibit. As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit. What coul...
IPS profilediagnose outputfirewall policyIPS fail open - Question #33System Configuration
Refer to the exhibit. The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early in inactivity....
admin profileidle timeoutGUI sessionaccprofile - Question #34Troubleshooting and Monitoring
Refer to the exhibit. Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
conserve modememory thresholdssession inspectionconfiguration access - Question #35Security Profiles
A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus...
antivirusSSL inspectioncertificate inspectionHTTPS scanning - Question #36Routing
You have configured the below commands on a FortiGate. config system settings set strict-src-check enable end config system interface edit port1 set src-check disable next end What...
RPFstrict-src-checkasymmetric routinginterface RPF - Question #37Security Profiles
Refer to the exhibit. What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?
SSL inspectionSNI checkserver certificateCN/SAN validation - Question #38System Configuration
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?
FSSODC agent modecollector agentuser authentication - Question #39Firewall Policies
A network administrator is reviewing firewall policies in both Interface Pair View and By Sequence View. The policies appear in a different order in each view. Why is the policy or...
firewall policyInterface Pair ViewBy Sequence Viewpolicy order - Question #40VPN
An administrator notices that some users are unable to establish SSL VPN connections, while others can connect without any issues. What should the administrator check first?
SSL VPNport numberVPN troubleshootingconnection failure - Question #41Network Configuration
Refer to the exhibits. Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)...
SNATIP poolsNAT policysource NAT - Question #42Security Profiles
A network administrator has configured an SSL/SSH inspection profile defined for full SSL inspection and set with a private CA certificate. The firewall policy allows the traffic u...
SSL inspectionCA certificateHTTPS inspectioncertificate trust - Question #43System Configuration
What are two features of collector agent advanced mode? (Choose two.)
collector agentadvanced modeLDAPuser groups - Question #44VPN
You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two.)
IPsecNAT traversalESPUDP encapsulation - Question #45Network Configuration
Refer to the exhibit. Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
SD-WANtraffic distributiondefault ruleload balancing - Question #46Troubleshooting and Monitoring
Refer to the exhibit. In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the...
snifferdebug flowpacket captureconnectivity troubleshooting - Question #47Network Configuration
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?
SD-WAN zonesvirtual-wan-linkinterface membersSD-WAN configuration - Question #48High Availability
Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.)
HA clusterconfiguration syncincremental syncprimary device - Question #49Firewall Policies
What are two features of the NGFW profile-based mode? (Choose two.)
NGFW profile-based modeinspection modefirewall policyapplication control - Question #50Security Profiles
Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. Which two factors can you observe from these conf...
application sensorfilter overrideapplication controltraffic policy