Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Exhibits:

Question # 11

You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS.

While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS.

What could be the cause?

Options:

A.

The feature set in the antivirus profile is not set to Flow-based.


B.

Web filter is not enabled on the firewall policy to complement the antivirus profile.


C.

The action on the firewall policy is not set to deny.


D.

The SSL inspection mode in the firewall policy is not deep content inspection.


Expert Solution
Questions # 12:

An administrator creates a new address object on the root FortiGate (HQ-NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW).

Question # 12

Question # 12

What must the administrator do to synchronize the address object?

Options:

A.

Change the csf setting on HQ-ISFW (downstream) to set configuration-sync local.


B.

Change the csf setting on HQ-ISFW (downstream) to set saml-configuration-sync default.


C.

Change the csf setting on HQ-NGFW-1 (root) to set fabric-object-unification default.


D.

Change the csf setting on both devices to set downstream-access enable.


Expert Solution
Questions # 13:

What are three key routing principles in SD-WAN? (Choose three answers)

Options:

A.

By default, SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination.


B.

SD-WAN rules have precedence over any other type of routes.


C.

Regular policy routes have precedence over SD-WAN rules.


D.

By default, SD-WAN rules are skipped if only one route to the destination is available.


E.

By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.


Expert Solution
Questions # 14:

Refer to the exhibit.

Question # 14

The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name

FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows

What could be the reason?

Options:

A.

SD-WAN rule names do not appear immediately. The administrator must refresh the page.


B.

There is no application control profile applied to the firewall policy.


C.

Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled.


D.

FortiGate load balanced the traffic according to the implicit SD-WAN rule.


Expert Solution
Questions # 15:

Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.)

Options:

A.

FortiSASE Firewall-as-a-Service (FWaaS)


B.

The proxy auto-configuration (PAC) file


C.

VPN policies


D.

FortiExtender


Expert Solution
Questions # 16:

Refer to the exhibit to view the firewall policy.

Question # 16

Why would the firewall policy not block a well-known virus, for example EICAR? (Choose one answer)

Options:

A.

The action on the firewall policy is not set to DENY.


B.

Web filter is not enabled, so the firewall policy does not complement the antivirus profile.


C.

The firewall policy is not configured in proxy-based inspection mode.


D.

The firewall policy does not apply deep content inspection.


Expert Solution
Questions # 17:

Refer to the exhibit.

Question # 17

Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?

Options:

A.

Antivirus scan is disabled under System - > Feature visibility


B.

None of the inspected protocols are active in this profile.


C.

The Feature Set for the profile is Flow-based but it must be Proxy-based


D.

FortiGate. with less than 2 GB RAM. does not support the Antivirus scan feature.


Expert Solution
Questions # 18:

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

Options:

A.

On Demand


B.

Enabled


C.

On Idle


D.

Usabled


Expert Solution
Questions # 19:

The FortiGate device HQ-NGFW-1 with the IP address 10.0.13.254 sends logs to the FortiAnalyzer device with the IP address 10.0.13.125. The administrator wants to verify that reliable logging is enabled on HQ-NGFW-1.

Which exhibit helps with the verification?

A)

Question # 19

B)

Question # 19

C)

Question # 19

D)

Question # 19

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 20:

FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)

Options:

A.

Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.


B.

Both interfaces must have the interface role assigned.


C.

Both interfaces must have directly connected routes on the routing table.


D.

Both interfaces must have IP addresses assigned.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions