NSE4_FGT_AD-7.6 Exam Questions
115 real NSE4_FGT_AD-7.6 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Security Profiles
Refer to the exhibits. The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details. Based on the configuration, what will happen to...
application sensorExcessive-Bandwidth filterFaceTimeapplication override - Question #52Security Profiles
Based on the provided Application override and Filter override configurations, which statement about FaceTime traffic is true?
application overridefilter overrideFaceTimeApple filter - Question #53Security Profiles
Refer to the exhibits. An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access Facebook...
web filterstatic URL filterFortiGuard categoriesURL exemption - Question #54Routing
Refer to the exhibit. Which two statements are true about the routing entries in this database table? (Choose two.)
routing databaseadministrative distancestandby routedefault route - Question #55Security Profiles
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
SSL certificate inspectionSNISANserver certificate - Question #56Network Configuration
Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)
SD-WAN rulesmember selection strategyload balancingSLA - Question #57High Availability
What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device? (Choose two.)
HA heartbeatcluster membersheartbeat IPlink-local address - Question #58System Configuration
Refer to the exhibits. An administrator added a configuration for a new RADIUS server. While configuring, the administrator enabled Include in every user group. What is the impact...
RADIUSuser groupsauthenticationinclude in every user group - Question #59System Configuration
Based on the provided security fabric configurations for HQ-NGFW-1 and HQ-ISFW, which of the following changes is correct?
Security Fabricfabric-object-unificationcsf configurationdownstream FortiGate - Question #60Troubleshooting and Monitoring
Refer to the exhibit showing a debug flow output. Which two conclusions can you make from the debug flow output? (Choose two.)
debug flowRPF checkdefault gatewaytraffic analysis - Question #61Security Profiles
Which action FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate. Which three actions are valid actions that Forti...
SSL inspectioninvalid certificatecertificate actionsSSL/SSH profile - Question #62VPN
You want to ensure that an SSL VPN user's authenticated session does not remain active after they disconnect from the VPN. Which configuration will ensure this?
SSL VPNsession timeoutfirewall authenticationsession management - Question #63Troubleshooting and Monitoring
Refer to the exhibit, which shows a firewall policy to enable active authentication. When attempting to access an external website using an active authentication method, the user i...
active authenticationfirewall policyDNS servicelogin prompt - Question #64Troubleshooting and Monitoring
Refer to the exhibit. Why did the FortiGate device drop the packet?
packet dropimplicit denyRPF checkfirewall policy - Question #65Routing
Refer to the exhibit, which shows a routing table. An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only. What...
static routeroute distanceroute priorityroute selection - Question #66Security Profiles
Refer to the exhibit. Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?
antivirus profileflow-based inspectionproxy-based inspectionFTP inspection - Question #67VPN
An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about th...
IPsec VPNdialup VPNadd-routephase 2 selectors - Question #68System Configuration
An administrator configured a FortiGate device to act as a collector for agentless polling mode. What must the administrator add to the FortiGate device to retrieve AD user group i...
FSSOagentless pollingLDAP serverAD integration - Question #69System Configuration
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
FSSOagentless pollingSMB protocolworkstation check - Question #70Security Profiles
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visit...
SSL inspectionCA certificatebrowser trustcertificate warning - Question #71VPN
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tu...
IPsec VPNredundant tunnelsdead peer detectionroute distance - Question #72High Availability
An administrator wants to form an HA cluster using the FGCP protocol. Which two requirements must the administrator ensure both members fulfill? (Choose two.)
FGCPHA clusterHA group IDhard drive configuration - Question #73System Configuration
FortiGate is integrated with FortiAnalyzer and FortiManager. When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log...
UUIDFortiAnalyzerFortiManagerfirewall policy logging - Question #74Troubleshooting and Monitoring
Refer to the exhibit. An administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD- WAN Rule Name. Fort...
SD-WANtraffic logsimplicit SD-WAN ruleSD-WAN rule name - Question #75Security Profiles
An administrator manages a FortiGate model that supports NTurbo. How does NTurbo acceleration enhance antivirus performance?
NTurboantivirusflow-based inspectionhardware acceleration - Question #76Security Profiles
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Lo...
IPSsignaturepacket loggingFTP login - Question #77Firewall Policies
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate devic...
NATIP poolSNATVIP - Question #78Routing
Refer to the exhibit. Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)
RPF checkstrict RPFrouting tablereverse path forwarding - Question #79System Configuration
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
DNSFortiGuardDNS over TLSDNS configuration - Question #80High Availability
Refer to the exhibits. An administrator configured both members of an HA cluster at the same time. After one week of monitoring, the administrator wants to verify the HA failover p...
HA failoverHA clusteroverrideHA uptime - Question #81VPN
An administrator needs to analyze and resolve port conflicts between SSL VPN and HTTPS administrative access on the same interface. In which two ways can this be done? (Choose two....
SSL VPNport conflictHTTPS admin accessinterface configuration - Question #82Troubleshooting and Monitoring
Refer to the exhibit. What can you conclude from the log shown in the exhibit?
IPS enginesocket buffermemorylog analysis - Question #83VPN
A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?
SSL VPNDoS mitigationhttp-request-header-timeoutattack surface - Question #84Network Configuration
Which two of the following actions would resolve an issue where an IP pool configured for One-to-One NAT is exhausted, preventing new internal hosts from accessing the internet?
IP poolNAT overloadone-to-one NATIP exhaustion - Question #85Troubleshooting and Monitoring
Refer to the exhibit. Which two statements about the FortiGuard connection are true? (Choose two.)
FortiGuardconnection debugpacket weightprotocol configuration - Question #86Security Profiles
Refer to the exhibits. You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS. While testing, you are successful with HTTP and FTP protoc...
antivirus profileSSL inspectionHTTPSdeep content inspection - Question #87Firewall Policies
Refer to the exhibit. Which statement about this firewall policy list is true?
firewall policyinterface pairingsequence groupingpolicy list view - Question #88Troubleshooting and Monitoring
Refer to the exhibit showing a FortiGuard connection debug output. Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
FortiGuarddebug outputserver communicationFortiManager - Question #89System Configuration
An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable...
DHCP serverinterface roleGUI configurationFortiGate interface - Question #90Network Configuration
Which two statements describe how the RPF check is used? (Choose two.)
RPF checkIP spoofingreverse path forwardingsession packet - Question #91VPN
Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)
SSL VPNFortiGate-to-FortiGateCA certificatetunnel interface - Question #92VPN
A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad. Which IPsec Wizard template must the administrator apply?
IPsec VPNwizard templateremote accessdial-up - Question #93VPN
The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to the SSL VPN?
SSL VPNconnection failureport configurationclient troubleshooting - Question #94VPN
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has als...
IPsec VPNphase 1IKE modeDH group - Question #95Network Configuration
The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2,...
IP poolNATfirewall policyconnectivity troubleshooting - Question #96System Configuration
Which statement is a characteristic of automation stitches?
automation stitchesSecurity Fabrictriggersactions - Question #97System Configuration
Which three methods are used by the collector agent for AD polling? (Choose three.)
FSSOcollector agentAD pollingWinSecLog - Question #98Security Profiles
Why is the user unable to receive a block replacement message when downloading an infected file for the first time?
flow-based inspectionantivirusblock replacement messageinfected file - Question #99VPN
An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
SSL VPNhigh latencylogin-timeoutnegotiation failure - Question #100Firewall Policies
FortiGate is integrated with FortiAnalyzer and FortiManager. When a firewall policy is created, which attribute is added to the policy to improve functionality and to support recor...
firewall policyUUIDFortiAnalyzerFortiManager