Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

What are two features of collector agent advanced mode? (Choose two.)

Options:

A.

In advanced mode, security profiles can be applied only to user groups, not individual users.


B.

In advanced mode. FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.


C.

Advanced mode uses the Windows convention—NetBios: Domain\Username.


D.

Advanced mode supports nested or inherited groups.


Expert Solution
Questions # 22:

Refer to the exhibit.

Question # 22

Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)

Options:

A.

FortiGate drops new sessions requiring inspection.


B.

Administrators must restart FortiGate to allow new sessions.


C.

Administrators cannot change the configuration.


D.

FortiGate skips quarantine actions.


Expert Solution
Questions # 23:

Refer to the exhibits.

Question # 23

Question # 23

Question # 23

An administrator has observed the performance status outputs on an HA cluster for 55 seconds.

Which FortiGate is the primary?

Options:

A.

HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting


B.

HQ-NGFW-2 with the parameter priority setting


C.

HQ-NGFW-1 with the parameter override setting


D.

HQ-NGFW-2 with the parameter memory-failover-threshold setting


Expert Solution
Questions # 24:

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two answers)

Options:

A.

The selected SSL inspection profile has certificate inspection enabled.


B.

The website is exempted from SSL inspection.


C.

The EICAR test file exceeds the protocol options oversize limit.


D.

The browser does not trust the FortiGate self-signed CA certificate.


Expert Solution
Questions # 25:

There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels.

Which phase 1 setting you can configure to match the user to the tunnel?

Options:

A.

Local Gateway


B.

Dead Peer Detection


C.

Peer ID


D.

IKE Mode Config


Expert Solution
Questions # 26:

Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)

Options:

A.

No certificate is required on the remote peer when you set the certificate signature as the authentication method


B.

Extended authentication (XAuth) for faster authentication because fewer packets are exchanged


C.

Extended authentication (XAuth) to request the remote peer to provide a username and password


D.

Pre-shared key and certificate signature as authentication methods


Expert Solution
Questions # 27:

When configuring firewall policies which of the following is true regarding the policy ID? (Choose two.)

Options:

A.

A firewall policy ID identifies the order of policy execution in firewall policies.


B.

A policy ID cannot be modified once a policy is created.


C.

You can create a policy in CLI with policy ID 0


D.

It is mandatory to provide a policy ID while creating a firewall policy regardless of GUI or CLI.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions