Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is the primary FortiGate election process when the HA override setting is enabled? (Choose one answer)

Options:

A.

Connected monitored ports > Priority > HA uptime > FortiGate serial number


B.

Connected monitored ports > Priority > System uptime > FortiGate serial number


C.

Connected monitored ports > HA uptime > Priority > FortiGate serial number


D.

Connected monitored ports > System uptime > Priority > FortiGate serial number


Questions # 12:

You have configured an application control profile, set peer-o-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, you peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?

Options:

A.

Replacement Messages for UDP-based Applications


B.

Network Protocol Enforcement


C.

Application and Filter Overrides


D.

FortiGuard category ratings


Questions # 13:

Refer to the exhibit.

Question # 13

An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times.

Why are there no logs generated under security logs for ABC.Com?

Options:

A.

The ABC Com is hitting the category Excessive-Bandwidth.


B.

The ABC.Com Type is set as Application instead of Filter.


C.

The ABC.Com is configured under application profile, which must be configured as a web filter profile.


D.

The ABC Com Action is set to Allow


Questions # 14:

Refer to the exhibit.

Question # 14

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.

Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)

Options:

A.

On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.


B.

On HQ-NGFW. enable Diffie-Hellman Group 2.


C.

On BR1-FGT. set Seconds to 43200


D.

On HQ-NGFW. set Encryption to AES256.


Questions # 15:

Refer to the exhibit

A firewall policy to enable active authentication is shown.

Question # 15

When attempting to access an external website using an active authentication method, the user is not presented with a login prompt. What is the most likely reason for this situation?

Options:

A.

No matching user account exists for this user.


B.

The Remote-users group must be set up correctly in the FSSO configuration.


C.

The Remote-users group is not added to the Destination


D.

The Service DNS is required in the firewall policy.


Questions # 16:

Which three statements about SD-WAN performance SLAs are true? (Choose three.)

Options:

A.

They rely on session loss and jitter.


B.

They monitor the state of the FortiGate device.


C.

All the SLA targets can be configured.


D.

They are applied in a SD-WAN rule lowest cost strategy.


E.

They can be measured actively or passively.


Questions # 17:

Refer to the exhibit.

Question # 17

Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)

Options:

A.

A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.


B.

A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.


C.

A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.


D.

A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.


Questions # 18:

Refer to the exhibit.

Question # 18

The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team?

Options:

A.

Increase the admintimeout value under config system accprofile noc Access.


B.

increase the of line value of the override idle Timeout parameter in the NOC_Access admin profile.


C.

Move NOC_Access to the top of the list to ensure all profile settings take effect.


D.

Ensure that all NOC_Access users are assigned the super_admin role to guarantee access.


Questions # 19:

What are two features of FortiGate FSSO agentless polling mode? (Choose two.)

Options:

A.

FortiGate uses the AD server as the collector agent.


B.

FortiGate uses the SMB protocol to read the event viewer logs from the DCs.


C.

FortiGate does not support workstation check.


D.

FortiGate directs the collector agent to use a remote LDAP server.


Questions # 20:

Refer to the exhibit.

Question # 20

Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)

Options:

A.

FortiGate drops new sessions requiring inspection.


B.

Administrators must restart FortiGate to allow new sessions.


C.

Administrators cannot change the configuration.


D.

FortiGate skips quarantine actions.


Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions