New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.)

Options:

A.

FortiSASE Firewall-as-a-Service (FWaaS)


B.

The proxy auto-configuration (PAC) file


C.

VPN policies


D.

FortiExtender


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit For which two reasons are these web categories exempted? (Choose two.)

Options:

A.

The resources utilization is optimized because these websites are in the trusted domain list on FortiGate.


B.

The legal regulation aims to prioritize user privacy and protect sensitive information for these websites.


C.

These websites are in an allowlist of reputable domain names maintained by FortiGuard.


D.

The FortiGate temporary certificate denies the browser's access to websites that use HTTP Strict Transport Security.


Expert Solution
Questions # 13:

Which two statements are correct when the FortiGate device enters conserve mode? (Choose two.)

Options:

A.

FortiGate refuses to accept configuration changes.


B.

FortiGate halts complete system operation and requires a reboot to regain available resources.


C.

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.


D.

FortiGate continues to run critical security actions, such as quarantine.


Expert Solution
Questions # 14:

Refer to the exhibits.

Question # 14

Question # 14

Question # 14

Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibits.

What would be the expected outcome in the HA cluster?

Options:

A.

HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.


B.

HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority


C.

The HA cluster will become out of sync because the override setting must match on all HA members.


D.

HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.


Expert Solution
Questions # 15:

How does FortiExtender connect to FortiSASE in a site-based, remote internet access method?

Options:

A.

FortiExtender uses a Virtual Extensible LAN (VXLAN)-over-IPsec connection.


B.

FortiExtender establishes a secure SSL connection using FortiClient.


C.

FortiExtender first connects to a FortiGate LAN extension through a secure web gateway (SWG).


D.

FortiExtender uses the proxy auto-configuration


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions