Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)

Options:

A.

A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.


B.

A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.


C.

A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.


D.

A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

Options:

A.

FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.


B.

FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.


C.

FortiGate will close the connection if the SNI does not match the CN or SAN fields.


D.

FortiGate will close the connection if the SNI does not match the CN and SAN fields


Expert Solution
Questions # 13:

Refer to the exhibits.

Question # 13

Question # 13

The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects.

The WAN (port2) interface has the IP address

100.65.0.101/24.

The LAN (port4) interface has the IP address

10.0.11.254/24.

Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)?

Options:

A.

100.65.0.101


B.

100.65.0.49


C.

100.65.0.149


D.

100.65.0.99


Expert Solution
Questions # 14:

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

Options:

A.

On Demand


B.

Enabled


C.

On Idle


D.

Usabled


Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?

Options:

A.

Antivirus scan is disabled under System -> Feature visibility


B.

None of the inspected protocols are active in this profile.


C.

The Feature Set for the profile is Flow-based but it must be Proxy-based


D.

FortiGate. with less than 2 GB RAM. does not support the Antivirus scan feature.


Expert Solution
Questions # 16:

Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.)

Options:

A.

FortiSASE Firewall-as-a-Service (FWaaS)


B.

The proxy auto-configuration (PAC) file


C.

VPN policies


D.

FortiExtender


Expert Solution
Questions # 17:

Refer to the exhibit.

Question # 17

The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team? (Choose one answer)

Options:

A.

Move NOC_Access to the top of the list to ensure all profile settings take effect.


B.

Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.


C.

Ensure that all NOC_Access users are assigned the super_admin role to guarantee access.


D.

Increase the admintimeout value under config system accprofile NOC_Access.


Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit For which two reasons are these web categories exempted? (Choose two.)

Options:

A.

The resources utilization is optimized because these websites are in the trusted domain list on FortiGate.


B.

The legal regulation aims to prioritize user privacy and protect sensitive information for these websites.


C.

These websites are in an allowlist of reputable domain names maintained by FortiGuard.


D.

The FortiGate temporary certificate denies the browser's access to websites that use HTTP Strict Transport Security.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions