Pass the Fortinet Fortinet Network Security Expert FCP_FGT_AD-7.4 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which three statements explain a flow-based antivirus profile? (Choose three.)

Options:

A.

Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection


B.

Flow-based inspection optimizes performance compared to proxy-based inspection


C.

FortiGate buffers the whole file but transmits to the client at the same time.


D.

If a virus is detected, the last packet is delivered to the client.


E.

The IPS engine handles the process as a standalone.


Expert Solution
Questions # 22:

FortiGate is integrated with FortiAnalyzer and FortiManager.

When a firewall policy is created, which attribute is added to the policy to improve functionality and to support recording logs to FortiAnalyzer or FortiManager?

Options:

A.

Log ID


B.

Policy ID


C.

Sequence ID


D.

Universally Unique Identifier


Expert Solution
Questions # 23:

Which three methods are used by the collector agent for AD polling? (Choose three.)

Options:

A.

WinSecLog


B.

WMI


C.

NetAPI


D.

FSSO REST API


E.

FortiGate polling


Expert Solution
Questions # 24:

Which three statements about SD-WAN zones are true? (Choose three.)

Options:

A.

An SD-WAN zone can contain physical and logical interfaces


B.

You can use an SD-WAN zone in static route definitions


C.

You can define up to three SD-WAN zones per FortiGate device


D.

An SD-WAN zone must contains at least two members


E.

An SD-WAN zone is a logical grouping of members


Expert Solution
Questions # 25:

An administrator has configured a strict RPF check on FortiGate.

How does strict RPF check work?

Options:

A.

Strict RPF checks the best route back to the source using the incoming interface.


B.

Strict RPF allows packets back to sources with all active routes.


C.

Strict RPF checks only for the existence of at least one active route back to the source using the incoming interface.


D.

Strict RPF check is run on the first sent and reply packet of any new session.


Expert Solution
Questions # 26:

Refer to the exhibit.

Question # 26

The exhibit shows theFortiGuard Category Based Filtersection of a corporate web filter profile.

An administrator must block access todownload.com, which belongs to theFreeware and Software Downloadscategory. The administrator must also allow other websites in the same category.

What are two solutions for satisfying the requirement? (Choose two.)

Options:

A.

Configure a separate firewall policy with action Deny and an FQDN address object for *. download, com as destination address.


B.

Set the Freeware and Software Downloads category Action to Warning


C.

Configure a web override rating for download, com and select Malicious Websites as the subcategory.


D.

Configure a static URL filter entry for download, com with Type and Action set to Wildcard and Block, respectively.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions