Pass the Fortinet NSE4 NSE4_FGT-7.2 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which statements best describe auto discovery VPN (ADVPN). (Choose two.)

Options:

A.

It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes.


B.

ADVPN is only supported with IKEv2.


C.

Tunnels are negotiated dynamically between spokes.


D.

Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.


Expert Solution
Questions # 32:

Refer to the exhibits.

Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration.

The WAN (port1) interface has the IP address 10.200.1.1/24.

The LAN (port3) interface has the IP address 10.0.1.254/24.

Question # 32

Question # 32

If the host 10.200.3.1 sends a TCP SYN packet on port 10443 to 10.200.1.10, what will the source address, destination address, and destination port of the packet be, after FortiGate forwards the packet to the destination?

Options:

A.

10.0.1.254, 10.0.1.10, and 443, respectively


B.

10.0.1.254, 10.200.1.10, and 443, respectively


C.

10.200.3.1, 10.0.1.10, and 443, respectively


D.

10.0.1.254, 10.0.1.10, and 10443, respectively


Expert Solution
Questions # 33:

Refer to the exhibit.

Question # 33

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up.

Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?

Options:

A.

On HQ-FortiGate, enable Auto-negotiate.


B.

On Remote-FortiGate, set Seconds to 43200.


C.

On HQ-FortiGate, enable Diffie-Hellman Group 2.


D.

On HQ-FortiGate, set Encryption to AES256.


Expert Solution
Questions # 34:

An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel.

Which DPD mode on FortiGate will meet the above requirement?

Options:

A.

Disabled


B.

On Demand


C.

Enabled


D.

On Idle


Expert Solution
Questions # 35:

Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

Options:

A.

FortiGate points the collector agent to use a remote LDAP server.


B.

FortiGate uses the AD server as the collector agent.


C.

FortiGate uses the SMB protocol to read the event viewer logs from the DCs.


D.

FortiGate queries AD by using the LDAP to retrieve user group information.


Expert Solution
Questions # 36:

Refer to the exhibit.

Question # 36

Which contains a session diagnostic output. Which statement is true about the session diagnostic output?

Options:

A.

The session is in SYN_SENT state.


B.

The session is in FIN_ACK state.


C.

The session is in FTN_WAIT state.


D.

The session is in ESTABLISHED state.


Expert Solution
Questions # 37:

Refer to the exhibit.

Question # 37

Based on the ZTNA tag, the security posture of the remote endpoint has changed.

What will happen to endpoint active ZTNA sessions?

Options:

A.

They will be re-evaluated to match the endpoint policy.


B.

They will be re-evaluated to match the firewall policy.


C.

They will be re-evaluated to match the ZTNA policy.


D.

They will be re-evaluated to match the security policy.


Expert Solution
Questions # 38:

7

An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)

Options:

A.

Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.


B.

Create a new service object for HTTP service and set the session TTL to never


C.

Set the TTL value to never under config system-ttl


D.

Set the session TTL on the HTTP policy to maximum


Expert Solution
Questions # 39:

Examine this FortiGate configuration:

Question # 39

How does the FortiGate handle web proxy traffic coming from the IP address 10.2.1.200 that requires authorization?

Options:

A.

It always authorizes the traffic without requiring authentication.


B.

It drops the traffic.


C.

It authenticates the traffic using the authentication scheme SCHEME2.


D.

It authenticates the traffic using the authentication scheme SCHEME1.


Expert Solution
Questions # 40:

46

Which two types of traffic are managed only by the management VDOM? (Choose two.)

Options:

A.

FortiGuard web filter queries


B.

PKI


C.

Traffic shaping


D.

DNS


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions