Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE4_FGT_AD-7.6 Fortinet NSE 4 - FortiOS 7.6 Administrator Exam Practice Test

Fortinet NSE 4 - FortiOS 7.6 Administrator Questions and Answers

Question 1

An administrator creates a new address object on the root FortiGate (HQ-NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW).

Question # 1

Question # 1

What must the administrator do to synchronize the address object?

Options:

A.

Change the csf setting on HQ-ISFW (downstream) to set configuration-sync local.

B.

Change the csf setting on HQ-ISFW (downstream) to set saml-configuration-sync default.

C.

Change the csf setting on HQ-NGFW-1 (root) to set fabric-object-unification default.

D.

Change the csf setting on both devices to set downstream-access enable.

Question 2

Refer to the exhibits.

Question # 2

Question # 2

Question # 2

A web filter profile configuration and firewall policy configuration are shown.

You are trying to access www. facebook.com, but you are redirected to a FortiGuard web filtering block page.

Based on the exhibits, what is the possible cause of the issue?

Options:

A.

The web rating override configuration is incorrect.

B.

The web filter profile feature set is configured incorrectly.

C.

The firewall policy inspection mode is incorrect.

D.

For www. facebook. com. the URL filter action is incorrect.

Question 3

When configuring firewall policies which of the following is true regarding the policy ID? (Choose two.)

Options:

A.

A firewall policy ID identifies the order of policy execution in firewall policies.

B.

A policy ID cannot be modified once a policy is created.

C.

You can create a policy in CLI with policy ID 0

D.

It is mandatory to provide a policy ID while creating a firewall policy regardless of GUI or CLI.

Question 4

How does FortiExtender connect to FortiSASE in a site-based, remote internet access method?

Options:

A.

FortiExtender uses a Virtual Extensible LAN (VXLAN)-over-IPsec connection.

B.

FortiExtender establishes a secure SSL connection using FortiClient.

C.

FortiExtender first connects to a FortiGate LAN extension through a secure web gateway (SWG).

D.

FortiExtender uses the proxy auto-configuration < PAC) file and an explicit web proxy to connect.

Question 5

An administrator wanted to configure an IPS sensor to block traffic that triggers the signature set number of times during a specific time period. How can the administrator achieve the objective?

Options:

A.

Use IPS group signatures, set rate-mode 60.

B.

Use IPS packet logging option with periodical filter option.

C.

Use IPS signatures, rate-mode periodical option.

D.

Use IPS filter, rate-mode periodical option.

Question 6

Refer to the exhibit

A firewall policy to enable active authentication is shown.

Question # 6

When attempting to access an external website using an active authentication method, the user is not presented with a login prompt. What is the most likely reason for this situation?

Options:

A.

No matching user account exists for this user.

B.

The Remote-users group must be set up correctly in the FSSO configuration.

C.

The Remote-users group is not added to the Destination

D.

The Service DNS is required in the firewall policy.

Question 7

You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab. and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked.

What FortiGate settings should you check to resolve this issue?

Options:

A.

FortiGuard category ratings

B.

Network Protocol Enforcement

C.

Replacement Messages for UDP-based Applications

D.

Application and Filter Overrides

Question 8

Which two statements about the Security Fabric rating are true? (Choose two answers)

Options:

A.

A license is required to obtain an executive summary in the Security Rating section.

B.

The root FortiGate provides executive summaries of all the FortiGate devices in the Security Fabric.

C.

The Security Posture category provides PCI compliance results.

D.

Security Rating Insights are available only in the Security Rating page.

Question 9

Refer to the exhibits.

Question # 9

Question # 9

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.

Which two factors can you observe from these configurations? (Choose two.)

Options:

A.

YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings.

B.

Facebook access is blocked based on the category filter settings.

C.

Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings.

D.

YouTube search is allowed based on the Google Application and Filter override settings.

Question 10

Refer to the exhibit showing a debug flow output.

Question # 10

Which two conclusions can you make from the debug flow output? (Choose two answers)

Options:

A.

The default gateway is configured on port2.

B.

The RPF check fails.

C.

The debug flow is for UDP traffic.

D.

The matching firewall policy denies the traffic.

Question 11

A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is not part of the expected process?

Options:

A.

The DC agent sends login event data directly to FortiGate.

B.

FortiGate determines user identity based on the IP address in the FSSO list.

C.

The collector agent forwards login event data to FortiGate.

D.

The user logs into the windows domain.

Question 12

Which three statements about SD-WAN performance SLAs are true? (Choose three.)

Options:

A.

They rely on session loss and jitter.

B.

They monitor the state of the FortiGate device.

C.

All the SLA targets can be configured.

D.

They are applied in a SD-WAN rule lowest cost strategy.

E.

They can be measured actively or passively.

Question 13

What is the primary FortiGate election process when the HA override setting is enabled? (Choose one answer)

Options:

A.

Connected monitored ports > Priority > HA uptime > FortiGate serial number

B.

Connected monitored ports > Priority > System uptime > FortiGate serial number

C.

Connected monitored ports > HA uptime > Priority > FortiGate serial number

D.

Connected monitored ports > System uptime > Priority > FortiGate serial number

Question 14

What are two features of collector agent advanced mode? (Choose two.)

Options:

A.

In advanced mode, security profiles can be applied only to user groups, not individual users.

B.

In advanced mode. FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.

C.

Advanced mode uses the Windows convention—NetBios: Domain\Username.

D.

Advanced mode supports nested or inherited groups.

Question 15

Refer to the exhibit.

A partial cloud topology is shown.

Question # 15

You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS.

During the deployment, which components must the FortiGate CNF create to handle traffic from the EC2 instance?

Options:

A.

The customer VPC and GWLBe

B.

The gateway load balancer endpoint (GWLBe) in the customer virtual private cloud (VPC)

C.

The CNF VPC. customer VPC. and GWLB

D.

The GWLB. GWLBe, and the internet gateway (IGW) in the customer VPC

Question 16

What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device? (Choose two.)

Options:

A.

Heartbeat IP addresses are used to distinguish between cluster members.

B.

The heartbeat interface of the primary device in the cluster is always assigned IP address 169.254.0.1.

C.

A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster.

D.

Heartbeat interfaces have virtual IP addresses that are manually assigned.

Question 17

Refer to the exhibits.

Question # 17

Question # 17

Question # 17

Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibits.

What would be the expected outcome in the HA cluster?

Options:

A.

HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.

B.

HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority

C.

The HA cluster will become out of sync because the override setting must match on all HA members.

D.

HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.

Question 18

What are two features of FortiGate FSSO agentless polling mode? (Choose two.)

Options:

A.

FortiGate uses the AD server as the collector agent.

B.

FortiGate uses the SMB protocol to read the event viewer logs from the DCs.

C.

FortiGate does not support workstation check.

D.

FortiGate directs the collector agent to use a remote LDAP server.

Question 19

Refer to the exhibits.

Question # 19

The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver? (Choose one answer)

Options:

A.

Disable match-vip in the Allow_access policy.

B.

Configure a One-to-One IP Pool object in a new policy.

C.

Set the Destination address as Webserver in the Deny policy.

D.

Set the Destination address as Deny_IP in the Allow_access policy.

Question 20

You have created a web filter profile named restrictmedia-profile with a daily category usage quota.

When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.

What could be the reason?

Options:

A.

The web filter profile is already referenced in another firewall policy.

B.

The firewall policy is in no-inspection mode instead of deep-inspection.

C.

The naming convention used in the web filter profile is restricting it in the firewall policy.

D.

The inspection mode in the firewall policy is not matching with web filter profile feature set.

Question 21

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

Options:

A.

On Demand

B.

Enabled

C.

On Idle

D.

Usabled

Question 22

Refer to the exhibit.

Question # 22

What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

Options:

A.

FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.

B.

FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.

C.

FortiGate will close the connection if the SNI does not match the CN or SAN fields.

D.

FortiGate will close the connection if the SNI does not match the CN and SAN fields

Question 23

Which two statements describe characteristics of automation stitches? (Choose two answers)

Options:

A.

Actions involve only devices included in the Security Fabric.

B.

An automation stitch can have multiple triggers.

C.

Multiple actions can run in parallel.

D.

Triggers can involve external connectors.

Question 24

Which three methods are used by the collector agent for AD polling? (Choose three answers)

Options:

A.

NetAPI

B.

WMI

C.

WinSecLog

D.

DNS reverse lookup

E.

FSSO REST API

Question 25

There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels.

Which phase 1 setting you can configure to match the user to the tunnel?

Options:

A.

Local Gateway

B.

Dead Peer Detection

C.

Peer ID

D.

IKE Mode Config

Question 26

Refer to the exhibits.

Question # 26

Question # 26

Question # 26

A diagram of a FortiGate device connected to the network VIP object and firewall policy configurations are shown.

The WAN (port2) interface has the IP address

100.65.0.101/24.

The LAN (port4) interface has the IP address

10.0.11.254/24.

If the host 100.65.1.111 sends a TCP SYN packet on port 443 to 100.65.0.200. what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination?

Options:

A.

10.0.11.254, 100.65.0.200. and 443, respectively

B.

10.0.11.254, 10.0.15.50, and 4443. respectively

C.

100.65.1. 111, 10.0.11.50, and 4443. respectively

D.

100.65.1.111, 10.0.11.50. and 443. respectively

Question 27

You have configured an application control profile, set peer-o-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, you peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?

Options:

A.

Replacement Messages for UDP-based Applications

B.

Network Protocol Enforcement

C.

Application and Filter Overrides

D.

FortiGuard category ratings