Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab. and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked.

What FortiGate settings should you check to resolve this issue?

Options:

A.

FortiGuard category ratings


B.

Network Protocol Enforcement


C.

Replacement Messages for UDP-based Applications


D.

Application and Filter Overrides


Questions # 22:

Refer to the exhibits.

Question # 22

Question # 22

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.

You cannot access any of the Google applications, but you are able to access www.fortinet.com.

Which two actions would you take to resolve the issue? (Choose two.)

Options:

A.

Set SSL inspection to deep-content inspection.


B.

Move up Google in the Application and Filter Overrides section to set its priority lot


C.

Add " Google " .com to the URL category in the security profile.


D.

Change the Inspection mode to Flow-based


E.

Set the action for Google in the Application and Filter Overrides section to Allow


Questions # 23:

What are three key routing principles in SD-WAN? (Choose three answers)

Options:

A.

By default, SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination.


B.

SD-WAN rules have precedence over any other type of routes.


C.

Regular policy routes have precedence over SD-WAN rules.


D.

By default, SD-WAN rules are skipped if only one route to the destination is available.


E.

By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.


Questions # 24:

Refer to the exhibit.

Question # 24

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category. What are two solutions for satisfying the requirement? (Choose two answers)

Options:

A.

Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.


B.

Configure a web override rating for download.com and select Malicious Websites as the subcategory.


C.

Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.


D.

Set the Freeware and Software Downloads category Action to Warning.


Questions # 25:

Refer to the exhibit.

A partial cloud topology is shown.

Question # 25

You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS.

During the deployment, which components must the FortiGate CNF create to handle traffic from the EC2 instance?

Options:

A.

The customer VPC and GWLBe


B.

The gateway load balancer endpoint (GWLBe) in the customer virtual private cloud (VPC)


C.

The CNF VPC. customer VPC. and GWLB


D.

The GWLB. GWLBe, and the internet gateway (IGW) in the customer VPC


Questions # 26:

Which two statements are correct when the FortiGate device enters conserve mode? (Choose two.)

Options:

A.

FortiGate refuses to accept configuration changes.


B.

FortiGate halts complete system operation and requires a reboot to regain available resources.


C.

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.


D.

FortiGate continues to run critical security actions, such as quarantine.


Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions