Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

Options:

A.

On Demand


B.

Enabled


C.

On Idle


D.

Usabled


Expert Solution
Questions # 12:

You have created a web filter profile named restrictmedia-profile with a daily category usage quota.

When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.

What could be the reason?

Options:

A.

The web filter profile is already referenced in another firewall policy.


B.

The firewall policy is in no-inspection mode instead of deep-inspection.


C.

The naming convention used in the web filter profile is restricting it in the firewall policy.


D.

The inspection mode in the firewall policy is not matching with web filter profile feature set.


Expert Solution
Questions # 13:

Which three methods are used by the collector agent for AD polling? (Choose three answers)

Options:

A.

NetAPI


B.

WMI


C.

WinSecLog


D.

DNS reverse lookup


E.

FSSO REST API


Expert Solution
Questions # 14:

There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels.

Which phase 1 setting you can configure to match the user to the tunnel?

Options:

A.

Local Gateway


B.

Dead Peer Detection


C.

Peer ID


D.

IKE Mode Config


Expert Solution
Questions # 15:

A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is not part of the expected process?

Options:

A.

The DC agent sends login event data directly to FortiGate.


B.

FortiGate determines user identity based on the IP address in the FSSO list.


C.

The collector agent forwards login event data to FortiGate.


D.

The user logs into the windows domain.


Expert Solution
Questions # 16:

Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.)

Options:

A.

FortiSASE Firewall-as-a-Service (FWaaS)


B.

The proxy auto-configuration (PAC) file


C.

VPN policies


D.

FortiExtender


Expert Solution
Questions # 17:

Which two statements describe characteristics of automation stitches? (Choose two answers)

Options:

A.

Actions involve only devices included in the Security Fabric.


B.

An automation stitch can have multiple triggers.


C.

Multiple actions can run in parallel.


D.

Triggers can involve external connectors.


Expert Solution
Questions # 18:

What are two features of FortiGate FSSO agentless polling mode? (Choose two.)

Options:

A.

FortiGate uses the AD server as the collector agent.


B.

FortiGate uses the SMB protocol to read the event viewer logs from the DCs.


C.

FortiGate does not support workstation check.


D.

FortiGate directs the collector agent to use a remote LDAP server.


Expert Solution
Questions # 19:

You are onboarding an agentless, secure web gateway (SWG) endpoint for secure internet access (SIA). What will happen to the user ' s nonweb traffic? (Choose one answer)

Options:

A.

All the nonweb traffic will bypass FortiSASE.


B.

The endpoint will use split tunneling to redirect nonweb traffic to FortiSASE.


C.

FortiSASE will use Firewall-as-a-Service (FWaaS) to redirect nonweb traffic.


D.

FortiSASE will use SWG to redirect nonweb traffic to FortiExtender.


Expert Solution
Questions # 20:

What are three key routing principles in SD-WAN? (Choose three answers)

Options:

A.

By default, SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination.


B.

SD-WAN rules have precedence over any other type of routes.


C.

Regular policy routes have precedence over SD-WAN rules.


D.

By default, SD-WAN rules are skipped if only one route to the destination is available.


E.

By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions