When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
Fortinet ยท NSE4_FGT-7.2
NSE4_FGT-7.2 questions and answers
Review the question wording, option layout, and available explanations before choosing a study plan.
|
Single choice
Multiple choice
Refer to the exhibit. ![]() Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)
Single choice
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?
Multiple choice
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)
Multiple choice
FortiGuard categories can be overridden and defined in different categories. To create a web rating Which two syntaxes are correct to configure web rating for the home page? (Choose two.)
Single choice
Examine this output from a debug flow: ![]() Why did the FortiGate drop the packet?
Multiple choice
Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)
Multiple choice
Which two statements ate true about the Security Fabric rating? (Choose two.)
Multiple choice
Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network and the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. ![]() Based on the information shown in the exhibit, which three configuration changes should the administrator make to fix the connectivity issue for PC3? (Choose three.)
Single choice
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
Multiple choice
FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface. In this scenario, what are two requirements for the VLAN ID? (Choose two.)
Multiple choice
What are two functions of the ZTNA rule? (Choose two.)
Single choice
Refer to the exhibit. ![]() Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
Single choice
Refer to the exhibit to view the firewall policy. ![]() Why would the firewall policy not block a well-known virus, for example eicar?
Single choice
An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. What must the administrator do to achieve this objective?
Single choice
Which of statement is true about SSL VPN web mode?
Single choice
Refer to the exhibit. ![]() Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
Single choice
Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router. When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output. ![]() Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?
Single choice
Refer to the exhibit. The exhibit shows the output of a diagnose command. ![]() What does the output reveal about the policy route?
Single choice
Refer to the exhibit. ![]() ![]() ![]() ![]() The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port3) interface has the IP address 10.0. 1.254/24. A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.
Multiple choice
Refer to the exhibits. The exhibits show a network diagram and firewall configurations. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. ![]() ![]() In this scenario, which two changes can the administrator make to deny Webserver access for Remote- User2? (Choose two.)
Multiple choice
View the exhibit. ![]() Which of the following statements are correct? (Choose two.)
Single choice
Refer to the web filter raw logs. ![]() Based on the raw logs shown in the exhibit, which statement is correct?
Single choice
Which statement is correct regarding the security fabric?
Single choice
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. ![]() Based on the phase 2 configuration shown in the exhibit, which configuration change will bring phase 2 up?
Single choice
Refer to the exhibits. Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The administrator disabled the WebServer firewall policy. ![]() ![]() Which IP address will be used to source NAT the traffic, if a user with address 10.0.1.10 connects over SSH to the host with address 10.200.3.1?
Single choice
What is a reason for triggering IPS fail open?
Multiple choice
What are two scanning techniques supported by FortiGate? (Choose two.) |


















