Which three statements about SD-WAN zones are true? (Choose three.)
A. An SD-WAN zone can contain physical and logical interfaces B. You can use an SD-WAN zone in static route definitions C. You can define up to three SD-WAN zones per FortiGate device D. An SD-WAN zone must contains at least two members E. An SD-WAN zone is a logical grouping of members
A. An SD-WAN zone can contain physical and logical interfaces B. You can use an SD-WAN zone in static route definitions E. An SD-WAN zone is a logical grouping of members explanation: An SD-WAN zone can contain physical and logical interfaces SD-WAN zones can include both physical and logical interfaces, allowing flexible configuration for different network types. You can use an SD-WAN zone in static route definitions SD-WAN zones can be referenced in static routes, enabling dynamic path selection based on SD-WAN rules. An SD-WAN zone is a logical grouping of members An SD-WAN zone is a logical grouping of interfaces (members), used to simplify the management and application of SD-WAN rules.
Question 2:
Refer to the exhibit.
Which statement about this firewall policy list is true?
A. The Implicit group can include more than one deny firewall policy. B. The firewall policies are listed by ID sequence view. C. The firewall policies are listed by ingress and egress interfaces pairing view. D. LAN to WAN. WAN to LAN. and Implicit are sequence grouping view lists.
D. LAN to WAN. WAN to LAN. and Implicit are sequence grouping view lists.
Question 3:
Which statement is a characteristic of automation stitches?
A. They can be run only on devices in the Security Fabric. B. They can be created only on downstream devices in the fabric. C. They can have one or more triggers. D. They can run multiple actions at the same time.
D. They can run multiple actions at the same time. explanation: Explanation Explanation/Reference: "To create an automation stitch, A TRIGGER EVENT (singular) and a response action or ACTIONS (plural) are selected." See the documentation:https://docs.fortinet.com/document/fortigate/7.4.0/administration- guide/351998
Question 4:
Refer to the exhibit.
FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles. Which action must the administrator perform to consolidate the two policies into one?
A. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy B. Create an Interface Group that includes port1 and port2 to create a single firewall policy C. Select port1 and port2 subnets in a single firewall policy. D. Replace port1 and port2 with the any interface in a single firewall policy.
A. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy explanation: Explanation Explanation/Reference: To consolidate the two separate firewall policies for Sales and Engineering departments accessing the same web server, you can create an Interface Group that includes bothport1(Sales) andport2(Engineering). Once the Interface Group is created, you can use this group as a single incoming interface in a single firewall policy. This approach reduces the number of policies, making management more efficient. References: FortiOS 7.4.1 Administration Guide: Firewall Policy Configuration
Question 5:
A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad. Which IPsec Wizard template must the administrator apply?
A. Remote Access B. Site to Site C. Dial up User D. iHub-and-Spoke
A. Remote Access explanation: Explanation For configuring an IPsec VPN tunnel for a sales employee traveling abroad, the "Remote Access" template is the most appropriate choice. This template is designed to allow remote users to securely connect to the internal network of an organization from any location using FortiClient or a compatible client. The other options, such as "Site to Site," "Dial up User," and "iHub-and-Spoke," are used for connecting different networks or sites, not individual remote users. References: FortiOS 7.4.1 Administration Guide: IPsec Wizard Template Types
Question 6:
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
A. The NetSessionEnum function is used to track user logouts. B. NetAPI polling can increase bandwidth usage in large networks. C. The collector agent must search Windows application event logs. D. The collector agent uses a Windows API to query DCs for user logins.
A. The NetSessionEnum function is used to track user logouts.
Question 7:
Refer to the exhibits.
The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy. and the sniffer CLI output on the FortiGate device.
The WAN (port1) interface has the IP address 10.200.1.1 /24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The webserver host (10. 0.1. 10) must use its VIP external IP address as the source NAT (SNAT) when It pings remote server (10.200.3.1).
Which two statements are valid to achieve this goal? (Choose two.)
A. Enable NAT on the Allow_access firewall policy. B. Create a new firewall policy before lnternet_Access for the webserver and apply the IP pool. C. Disable NAT on the lnternet_Access firewall policy. D. Disable port forwarding on the VIP object.
A. Enable NAT on the Allow_access firewall policy. D. Disable port forwarding on the VIP object. explanation: Explanation Explanation/Reference: Enable NAT on the Allow_access firewall policy (A): Disable port forwarding on the VIP object (D): Why other options are not correct: B. Create a new firewall policy before Internet_Access for the webserver and apply the IP pool: C. Disable NAT on the Internet_Access firewall policy: Thus, enabling NAT on the Allow_access policy and disabling port forwarding on the VIP configuration are the valid steps to achieve the goal.
Question 8:
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
A. On Remote-FortiGate, set Seconds to 43200. B. On HQ-FortiGate, enable Diffie-Hellman Group 2. C. On HQ-FortiGate, set Encryption to AES256. D. On Remote-FortiGate, set Remote Address to 10.0.1.0/255.255.255.0.
C. On HQ-FortiGate, set Encryption to AES256. D. On Remote-FortiGate, set Remote Address to 10.0.1.0/255.255.255.0.
Question 9:
A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?
A. SSL VPN dcls-hello-timeout B. SSL VPN http-request-header-timeout C. SSL VPN login-timeout D. SSL VPN idle-timeout
B. SSL VPN http-request-header-timeout explanation: Explanation Explanation/Reference: The SSL VPN http-request-header-timeout timer is used to mitigate denial of service (DoS) attacks by limiting the amount of time the FortiGate waits for the client to send an HTTP request header after a connection is established. This helps reduce the attack surface by preventing potential attacks that exploit prolonged connection times without fully completing requests.
Question 10:
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. Which order must FortiGate use when the web filter profile has features such as safe search enabled?
A. FortiGuard category filter and rating filter B. Static domain filter, SSL inspection filter, and external connectors filters C. DNS-based web filter and proxy-based web filter D. Static URL filter, FortiGuard category filter, and advanced filters
D. Static URL filter, FortiGuard category filter, and advanced filters explanation: Explanation Explanation/Reference:When multiple web filtering features are enabled in FortiGate, the HTTP inspection process follows a specific sequence: Static URL Filter: This filter checks URLs against a predefined list of allowed or blocked URLs. FortiGuard Category Filter: This checks the category of the website using the FortiGuard database. Advanced Filters: These include features like -> "Safe Search"
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Fortinet exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your FCP_FGT_AD-7.4 exam preparations
and Fortinet certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.