Pass the Fortinet NSE4 NSE4_FGT-7.2 Questions and answers with CertsForce

Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions
Questions # 21:

How does FortiGate act when using SSL VPN in web mode?

Options:

A.

FortiGate acts as an FDS server.


B.

FortiGate acts as an HTTP reverse proxy.


C.

FortiGate acts as DNS server.


D.

FortiGate acts as router.


Expert Solution
Questions # 22:

Refer to the exhibit.

The exhibit shows the output of a diagnose command.

Question # 22

What does the output reveal about the policy route?

Options:

A.

It is an ISDB route in policy route.


B.

It is a regular policy route.


C.

It is an ISDB policy route with an SDWAN rule.


D.

It is an SDWAN rule in policy route.


Expert Solution
Questions # 23:

Which of the following statements is true regarding SSL VPN settings for an SSL VPN portal?

Options:

A.

By default, FortiGate uses WINS servers to resolve names.


B.

By default, the SSL VPN portal requires the installation of a client's certificate.


C.

By default, split tunneling is enabled.


D.

By default, the admin GUI and SSL VPN portal use the same HTTPS port.


Expert Solution
Questions # 24:

17

In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)

Options:

A.

The IP version of the sources and destinations in a firewall policy must be different.


B.

The Incoming Interface. Outgoing Interface. Schedule, and Service fields can be shared with both IPv4 and IPv6.


C.

The policy table in the GUI can be filtered to display policies with IPv4, IPv6 or IPv4 and IPv6 sources and destinations.


D.

The IP version of the sources and destinations in a policy must match.


E.

The policy table in the GUI will be consolidated to display policies with IPv4 and IPv6 sources and destinations.


Expert Solution
Questions # 25:

27

Which feature in the Security Fabric takes one or more actions based on event triggers?

Options:

A.

Fabric Connectors


B.

Automation Stitches


C.

Security Rating


D.

Logical Topology


Expert Solution
Questions # 26:

20

Which two statements are true about the RPF check? (Choose two.)

Options:

A.

The RPF check is run on the first sent packet of any new session.


B.

The RPF check is run on the first reply packet of any new session.


C.

The RPF check is run on the first sent and reply packet of any new session.


D.

RPF is a mechanism that protects FortiGate and your network from IP spoofing attacks.


Expert Solution
Questions # 27:

109

Why does FortiGate keep TCP sessions in the session table for some seconds even after both sides

(client and server) have terminated the session?

Options:

A.

To remove the NAT operation.


B.

To generate logs


C.

To finish any inspection operations.


D.

To allow for out-of-order packets that could arrive after the FIN/ACK packets.


Expert Solution
Questions # 28:

Refer to the exhibits.

Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration.

The WAN (port1) interface has the IP address 10.200.1.1/24.

The LAN (port3) interface has the IP address 10.0.1.254/24.

The administrator disabled the WebServer firewall policy.

Question # 28

Question # 28

Which IP address will be used to source NAT the traffic, if a user with address 10.0.1.10 connects over SSH to the host with address 10.200.3.1?

Options:

A.

10.200.1.10


B.

10.0.1.254


C.

10.200.1.1


D.

10.200.3.1


Expert Solution
Questions # 29:

49

A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.

What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?

Options:

A.

Static IP Address


B.

Dialup User


C.

Dynamic DNS


D.

Pre-shared Key


Expert Solution
Questions # 30:

An administrator is configuring an Ipsec between site A and siteB. The Remotes Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192. 16. 1.0/24 and the remote quick mode selector is 192. 16.2.0/24. How must the administrator configure the local quick mode selector for site B?

Options:

A.

192. 168.3.0/24


B.

192. 168.2.0/24


C.

192. 168. 1.0/24


D.

192. 168.0.0/8


Expert Solution
Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions