NSE4_FGT_AD-7.6 Exam Questions
115 real NSE4_FGT_AD-7.6 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51
Refer to the exhibits. The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details. Based on the configuration, what will happen to...
- Question #52
Based on the provided Application override and Filter override configurations, which statement about FaceTime traffic is true?
- Question #53
Refer to the exhibits. An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access Facebook...
- Question #54
Refer to the exhibit. Which two statements are true about the routing entries in this database table? (Choose two.)
- Question #55
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
- Question #56
Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)
- Question #57
What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device? (Choose two.)
- Question #58
Refer to the exhibits. An administrator added a configuration for a new RADIUS server. While configuring, the administrator enabled Include in every user group. What is the impact...
- Question #59
Based on the provided security fabric configurations for HQ-NGFW-1 and HQ-ISFW, which of the following changes is correct?
- Question #60
Refer to the exhibit showing a debug flow output. Which two conclusions can you make from the debug flow output? (Choose two.)
- Question #61
Which action FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate. Which three actions are valid actions that Forti...
- Question #62
You want to ensure that an SSL VPN user's authenticated session does not remain active after they disconnect from the VPN. Which configuration will ensure this?
- Question #63
Refer to the exhibit, which shows a firewall policy to enable active authentication. When attempting to access an external website using an active authentication method, the user i...
- Question #64
Refer to the exhibit. Why did the FortiGate device drop the packet?
- Question #65
Refer to the exhibit, which shows a routing table. An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only. What...
- Question #66
Refer to the exhibit. Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?
- Question #67
An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about th...
- Question #68
An administrator configured a FortiGate device to act as a collector for agentless polling mode. What must the administrator add to the FortiGate device to retrieve AD user group i...
- Question #69
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
- Question #70
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visit...
- Question #71
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tu...
- Question #72
An administrator wants to form an HA cluster using the FGCP protocol. Which two requirements must the administrator ensure both members fulfill? (Choose two.)
- Question #73
FortiGate is integrated with FortiAnalyzer and FortiManager. When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log...
- Question #74
Refer to the exhibit. An administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD- WAN Rule Name. Fort...
- Question #75
An administrator manages a FortiGate model that supports NTurbo. How does NTurbo acceleration enhance antivirus performance?
- Question #76
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Lo...
- Question #77
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate devic...
- Question #78
Refer to the exhibit. Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)
- Question #79
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
- Question #80
Refer to the exhibits. An administrator configured both members of an HA cluster at the same time. After one week of monitoring, the administrator wants to verify the HA failover p...
- Question #81
An administrator needs to analyze and resolve port conflicts between SSL VPN and HTTPS administrative access on the same interface. In which two ways can this be done? (Choose two....
- Question #82
Refer to the exhibit. What can you conclude from the log shown in the exhibit?
- Question #83
A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?
- Question #84
Which two of the following actions would resolve an issue where an IP pool configured for One-to-One NAT is exhausted, preventing new internal hosts from accessing the internet?
- Question #85
Refer to the exhibit. Which two statements about the FortiGuard connection are true? (Choose two.)
- Question #86
Refer to the exhibits. You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS. While testing, you are successful with HTTP and FTP protoc...
- Question #87
Refer to the exhibit. Which statement about this firewall policy list is true?
- Question #88
Refer to the exhibit showing a FortiGuard connection debug output. Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
- Question #89
An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable...
- Question #90
Which two statements describe how the RPF check is used? (Choose two.)
- Question #91
Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)
- Question #92
A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad. Which IPsec Wizard template must the administrator apply?
- Question #93
The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to the SSL VPN?
- Question #94
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has als...
- Question #95
The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2,...
- Question #96
Which statement is a characteristic of automation stitches?
- Question #97
Which three methods are used by the collector agent for AD polling? (Choose three.)
- Question #98
Why is the user unable to receive a block replacement message when downloading an infected file for the first time?
- Question #99
An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
- Question #100
FortiGate is integrated with FortiAnalyzer and FortiManager. When a firewall policy is created, which attribute is added to the policy to improve functionality and to support recor...