Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Which two statements about the FortiGuard connection are true? (Choose two.)

Options:

A.

The weight increases as the number of failed packets rises


B.

You can configure unreliable protocols to communicate with FortiGuard Server.


C.

FortiGate identified the FortiGuard Server using DNS lookup.


D.

FortiGate is using the default port for FortiGuard communication.


Questions # 2:

FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)

Options:

A.

Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.


B.

Both interfaces must have the interface role assigned.


C.

Both interfaces must have directly connected routes on the routing table.


D.

Both interfaces must have IP addresses assigned.


Questions # 3:

You have configured the below commands on a FortiGate.

Question # 3

What would be the impact of this configuration on FortiGate?

Options:

A.

FortiGate will enable strict RPF on all its interfaces and porti will be exempted from RPF checks.


B.

FortiGate will enable strict RPF on all its interfaces and porti will be enable for asymmetric routing.


C.

The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces.


D.

Port1 will be enabled with flexible RPF. and all other interfaces will be enabled for strict RPF


Questions # 4:

Refer to the exhibits.

Question # 4

Question # 4

The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects.

The WAN (port2) interface has the IP address

100.65.0.101/24.

The LAN (port4) interface has the IP address

10.0.11.254/24.

Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)?

Options:

A.

100.65.0.101


B.

100.65.0.49


C.

100.65.0.149


D.

100.65.0.99


Questions # 5:

Which three methods are used by the collector agent for AD polling? (Choose three answers)

Options:

A.

NetAPI


B.

WMI


C.

WinSecLog


D.

DNS reverse lookup


E.

FSSO REST API


Questions # 6:

Which two statements are true about an HA cluster? (Choose two answers)

Options:

A.

An HA cluster cannot have both in-band and out-of-band management interfaces at the same time.


B.

Link failover triggers a failover if the administrator sets the interface down on the primary device.


C.

When sniffing the heartbeat interface, the administrator must see the IP address 169.254.0.2.


D.

HA incremental synchronization includes FIB entries and IPsec SAs.


Questions # 7:

An administrator wants to address shadow IT visibility challenges and prevent users from sending sensitive files outside the organization without proper approval. Which FortiSASE method should the administrator implement to achieve these goals? (Choose one answer)

Options:

A.

Secure SD-WAN access (SSD-WAN)


B.

Secure private access (SPA)


C.

Secure SaaS access (SSA)


D.

Secure internet access (SIA)


Questions # 8:

Which three methods are used by the collector agent for AD polling? (Choose three answers)

Options:

A.

NetAPI


B.

WMI


C.

WinSecLog


D.

DNS reverse lookup


E.

FSSO REST API


Questions # 9:

An administrator wants to form an HA cluster using the FGCP protocol. Which two requirements must the administrator ensure both members fulfill? (Choose two answers)

Options:

A.

They must have the same HA group ID.


B.

They must have the heartbeat interfaces in the same subnet.


C.

They must have the same number of configured VDOMs.


D.

They must have the same hard drive configuration.


Questions # 10:

Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two answers)

Options:

A.

If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.


B.

If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.


C.

If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.


D.

If SD-WAN is disabled, you configure the load balancing algorithm in config system settings.


Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions