Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE4_FGT_AD-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

FortiGate is integrated with FortiAnalyzer and FortiManager.

When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

Options:

A.

Universally Unique Identifier


B.

Policy ID


C.

Sequence ID


D.

Log ID


Expert Solution
Questions # 22:

Refer to the exhibit showing a debug flow output.

Question # 22

Which two conclusions can you make from the debug flow output? (Choose two answers)

Options:

A.

The default gateway is configured on port2.


B.

The RPF check fails.


C.

The debug flow is for UDP traffic.


D.

The matching firewall policy denies the traffic.


Expert Solution
Questions # 23:

When configuring the connection between FortiGate and FortiAnalyzer, which option indicates that reliable traffic is enabled? (Choose one answer)

Options:

A.

The connection status shows a green check icon


B.

The interface status is set to up


C.

A padlock icon appears in the connection settings


D.

The logging mode is set to real-time


Expert Solution
Questions # 24:

Refer to the exhibit.

Question # 24

FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles.

Which action must the administrator perform to consolidate the two policies into one?

Options:

A.

Select port1 and port2 subnets in a single firewall policy.


B.

Create an Aggregate interface that includes port1 and port2 to create a single firewall policy.


C.

Replace port1 and port2 with the any interface in a single firewall policy.


D.

Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy.


Expert Solution
Questions # 25:

An administrator creates a new address object on the root FortiGate (HQ-NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW).

Question # 25

Question # 25

What must the administrator do to synchronize the address object?

Options:

A.

Change the csf setting on HQ-ISFW (downstream) to set configuration-sync local.


B.

Change the csf setting on HQ-ISFW (downstream) to set saml-configuration-sync default.


C.

Change the csf setting on HQ-NGFW-1 (root) to set fabric-object-unification default.


D.

Change the csf setting on both devices to set downstream-access enable.


Expert Solution
Questions # 26:

An administrator has configured the following settings.

config system settings

set ses-denied-traffic enable

end

config system global

set block-session-timer 30

end

What are the two results of this configuration? (Choose two.)

Options:

A.

The number of logs generated by denied traffic is reduced.


B.

A session for denied traffic is created.


C.

Denied users are blocked for 30 minutes.


D.

Session helpers are disabled for denied traffic.


Expert Solution
Questions # 27:

Refer to the exhibits.

Question # 27

Question # 27

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.

Which two factors can you observe from these configurations? (Choose two.)

Options:

A.

YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings.


B.

Facebook access is blocked based on the category filter settings.


C.

Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings.


D.

YouTube search is allowed based on the Google Application and Filter override settings.


Expert Solution
Questions # 28:

Refer to the exhibit to view the firewall policy.

Question # 28

Why would the firewall policy not block a well-known virus, for example EICAR? (Choose one answer)

Options:

A.

The action on the firewall policy is not set to DENY.


B.

Web filter is not enabled, so the firewall policy does not complement the antivirus profile.


C.

The firewall policy is not configured in proxy-based inspection mode.


D.

The firewall policy does not apply deep content inspection.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions