Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

A routing table is shown

Question # 1

An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only. What are the two criteria that the administrator can use to achieve this objective? (Choose two.)

Options:

A.

The new static route must have the priority set to 3.


B.

The new static route must have the metric set to 1.


C.

The existing static route through port3 must have the distance set to 11.


D.

The new static route must have the distance set to 9


Expert Solution
Questions # 2:

An administrator manages a FortiGate model that supports NTurbo

How does NTurbo acceleration enhance antivirus performance?

Options:

A.

For flow-based inspection. NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces.


B.

For flow-based inspection. NTurbo creates two inspection sessions on the FortiGate device.


C.

For proxy-based inspection. NTurbo offloads traffic to the content processor.


D.

For proxy-based inspection. NTurbo buffers the whole file and then sends it to the antivirus engine.


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times.

Why are there no logs generated under security logs for ABC.Com?

Options:

A.

The ABC Com is hitting the category Excessive-Bandwidth.


B.

The ABC.Com Type is set as Application instead of Filter.


C.

The ABC.Com is configured under application profile, which must be configured as a web filter profile.


D.

The ABC Com Action is set to Allow


Expert Solution
Questions # 4:

Which two statements are correct when FortiGate enters conserve mode? (Choose two answers)

Options:

A.

FortiGate continues to run critical security actions, such as quarantine.


B.

FortiGate refuses to accept configuration changes.


C.

FortiGate halts complete system operation and requires a reboot to regain available resources.


D.

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.


Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team?

Options:

A.

Increase the admintimeout value under config system accprofile noc Access.


B.

increase the of line value of the override idle Timeout parameter in the NOC_Access admin profile.


C.

Move NOC_Access to the top of the list to ensure all profile settings take effect.


D.

Ensure that all NOC_Access users are assigned the super_admin role to guarantee access.


Expert Solution
Questions # 6:

A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad.

Which VPN Wizard template must the administrator apply?

Options:

A.

Remote Access


B.

Hub-and-Spoke


C.

Site-to-Site


D.

Dial-up User


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name

FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows

What could be the reason?

Options:

A.

SD-WAN rule names do not appear immediately. The administrator must refresh the page.


B.

There is no application control profile applied to the firewall policy.


C.

Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled.


D.

FortiGate load balanced the traffic according to the implicit SD-WAN rule.


Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

An intrusion prevention system (IPS) profile signature setting is shown.

What can you conclude about the signature when adding the FTP.Login.Failed signature to the IPS Sensor profile?

Options:

A.

The signature setting uses a custom rating threshold.


B.

FortiGate allows this low severity signature packet and creates a log.


C.

FortiGate stores a local copy of the packet that matches the signature.


D.

The signature setting includes a group of other signatures.


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit What could be the possible reason of the diagnose output shown in the exhibit?

Options:

A.

There is a no firewall policy configured with an IPS security profile.


B.

Administrator entered the command diagnose test application ipsmonitor 5.


C.

FortiGate entered into IPS fail open state.


D.

Administrator entered the command diagnose test application ipsmonitor 99.


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

Options:

A.

FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.


B.

FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.


C.

FortiGate will close the connection if the SNI does not match the CN or SAN fields.


D.

FortiGate will close the connection if the SNI does not match the CN and SAN fields


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions