Pass the Fortinet Fortinet Network Security Expert FCP_FGT_AD-7.4 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit, which shows a partial configuration from the remote authentication server.

Question # 11

Why does the FortiGate administrator need this configuration?

Options:

A.

To authenticate only the Training user group.


B.

To set up a RADIUS server Secret


C.

To authenticate and match the Training OU on the RADIUS server.


D.

To authenticate Any FortiGate user groups.


Expert Solution
Questions # 12:

Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?

Options:

A.

Internet Service Database (ISDB) engine


B.

Intrusion prevention system engine


C.

Antivirus engine


D.

Application control engine


Expert Solution
Questions # 13:

Refer to the exhibits, which show the system performance output and the default configuration of high memory usage thresholds in a FortiGate.

Question # 13

Question # 13

Based on the system performance output, what can be the two possible outcomes? (Choose two.)

Options:

A.

FortiGate will start sending all files to FortiSandbox for inspection.


B.

FortiGate has entered conserve mode.


C.

Administrators cannot change the configuration.


D.

Administrators can access FortiGate onlythrough the console port.


Expert Solution
Questions # 14:

What are two features of collector agent advanced mode? (Choose two.)

Options:

A.

In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.


B.

Advanced mode supports nested or inherited groups.


C.

In advanced mode, security profiles can be applied only to user groups, not individual users.


D.

Advanced mode uses the Windows convention —NetBios: Domain\Username.


Expert Solution
Questions # 15:

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy.

When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the

and does not block the file allowing it to be downloaded.

The administrator confirms that the traffic matches the configured firewall policy.

What are two reasons for the failed virus detection by FortiGate? (Choose two.)

Options:

A.

The selected SSL inspection profile has certificate inspection enabled


B.

The browser does not trust the FortiGate self-siqned CA certificate


C.

The EICAR test file exceeds the protocol options oversize limit


D.

The website is exempted from SSL inspection


Expert Solution
Questions # 16:

A network administrator has configured an SSL/SSH inspection profile defined for full SSL inspection and set with a private CA certificate. The firewall policy that allows the traffic uses this profile for SSL inspection and performs web filtering. When visiting any HTTPS websites, the browser reports certificate warning errors.

What is the reason for the certificate warning errors?

Options:

A.

The SSL cipher compliance option is not enabled on the SSL inspection profile. This setting is required when the SSL inspection profile is defined with a private CA certificate.


B.

The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.


C.

The browser does not recognize the certificate in use as signed by a trusted CA.


D.

With full SSL inspection it is not possible to avoid certificate warning errors at the browser level.


Expert Solution
Questions # 17:

Refer to the exhibits, which show a diagram of a FortiGate device connected to the network. VIP object configuration, and the firewall policy configuration.

Question # 17

Question # 17

Question # 17

TheWAN (port1)interface has the IP address10.200.1.1/24. TheLAN (port3)interface has the IP address10.0.1.254/24.

If the host10.200.3.1sends a TCP SYN packet on port 8080 to10.200.1.10, what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination?

Options:

A.

10.0.1.254, 10.200.1.10, and 8080, respectively


B.

10.0.1.254, 10.0.1.10, and 80, respectively


C.

10.200.3.1, 10.0.1.10, and 80, respectively


D.

10.200.3.1, 10.0.1.10, and 8080, respectively


Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.

What is the most likely reason for this situation?

Options:

A.

The Service DNS is required in the firewall policy.


B.

The user is using an incorrect user name.


C.

The Remote-users group is not added to the Destination.


D.

No matching user account exists for this user.


Expert Solution
Questions # 19:

Which statement about the deployment of the Security Fabric in a multi-VDOM environment is true?

Options:

A.

Downstream devices can connect to the upstream device from any of their VDOMs


B.

Each VDOM in the environment can be part of a different Security Fabric


C.

VDOMs without ports with connected devices are not displayed in the topology


D.

Security rating reports can be run individually for each configured VDOM


Expert Solution
Questions # 20:

Which two statements are correct when FortiGate enters conserve mode? (Choose two.)

Options:

A.

FortiGate halts complete system operation and requires a reboot to regain available resources


B.

FortiGate refuses to accept configuration changes


C.

FortiGate continues to run critical security actions, such as quarantine.


D.

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions