Real NSE4_FGT-7.2 Exam PDF Test Engine Practice Test Questions [Q54-Q72]

Share

Real NSE4_FGT-7.2 Exam PDF Test Engine Practice Test Questions

Fortinet NSE4_FGT-7.2 Real 2024 Braindumps Mock Exam Dumps

NEW QUESTION # 54
Which statement is correct regarding the security fabric?

  • A. FortiGate Cloud cannot be used for logging purposes.
  • B. A minimum of two Fortinet devices is required.
  • C. FortiManager is one of the required member devices.
  • D. FortiGate devices must be operating in NAT mode.

Answer: D

Explanation:
FortiGate Security 7.2 Study Guide (p.428): "You must have a minimum of two FortiGate devices at the core of the Security Fabric, plus one FortiAnalyzer or cloud logging solution. FortiAnalyzer Cloud or FortiGate Cloud can act as the cloud logging solution. The FortiGate devices must be running in NAT mode."


NEW QUESTION # 55
Refer to the exhibit.

Which contains a network diagram and routing table output.
The Student is unable to access Webserver.
What is the cause of the problem and what is the solution for the problem?

  • A. The first reply packet for Student failed the RPF check .
    This issue can be resolved by adding a static route to 203.0. 114.24/32 through port3.
  • B. The first packet sent from Student failed the RPF check.
    This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.
  • C. The first packet sent from Student failed the RPF check.
    This issue can be resolved by adding a static route to 203.0. 114.24/32 through port3.
  • D. The first reply packet for Student failed the RPF check.
    This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.

Answer: C


NEW QUESTION # 56
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?

  • A. A subordinate CA
  • B. A root CA
  • C. A person
  • D. A CRL

Answer: B


NEW QUESTION # 57
Refer to the exhibit.

The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem .
With this configuration, which statement is true?

  • A. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
  • B. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
  • C. A static route is required on the To_Internet VDOM to allow LAN users to access the internet.
  • D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.

Answer: A


NEW QUESTION # 58
In which two ways can RPF checking be disabled? (Choose two )

  • A. Disable strict-arc-check under system settings.
  • B. Enable anti-replay in firewall policy.
  • C. Disable the RPF check at the FortiGate interface level for the source check
  • D. Enable asymmetric routing.

Answer: A,D


NEW QUESTION # 59
Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

  • A. FortiGate queries AD by using the LDAP to retrieve user group information.
  • B. FortiGate points the collector agent to use a remote LDAP server.
  • C. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
  • D. FortiGate uses the AD server as the collector agent.

Answer: A,C

Explanation:
Explanation
Fortigate Infrastructure 7.0 Study Guide P.272-273
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732


NEW QUESTION # 60
Which two statements are true about the FGCP protocol? (Choose two.)

  • A. FGCP elects the primary FortiGate device.
  • B. FGCP runs only over the heartbeat links.
  • C. FGCP is used to discover FortiGate devices in different HA groups.
  • D. FGCP is not used when FortiGate is in transparent mode.

Answer: A,B

Explanation:
Explanation
The FGCP (FortiGate Clustering Protocol) is a protocol that is used to manage high availability (HA) clusters of FortiGate devices. It performs several functions, including the following:
FGCP elects the primary FortiGate device: In an HA cluster, FGCP is used to determine which FortiGate device will be the primary device, responsible for handling traffic and making decisions about what to allow or block. FGCP uses a variety of factors, such as the device's priority, to determine which device should be the primary.
FGCP runs only over the heartbeat links: FGCP communicates between FortiGate devices in the HA cluster using the heartbeat links. These are dedicated links that are used to exchange status and control information between the devices. FGCP does not run over other types of links, such as data links.


NEW QUESTION # 61
Which three criteria can a FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)

  • A. Source defined as Internet Services in the firewall policy.
  • B. Destination defined as Internet Services in the firewall policy.
  • C. Services defined in the firewall policy.
  • D. Highest to lowest priority defined in the firewall policy.
  • E. Lowest to highest policy ID number.

Answer: A,B,C

Explanation:
When a packet arrives, how does FortiGate find a matching policy? Each policy has match criteria, which you can define using the following objects:
* Incoming Interface
* Outgoing Interface
* Source: IP address, user, internet services
* Destination: IP address or internet services
* Service: IP protocol and port number
* Schedule: Applies during configured times


NEW QUESTION # 62
Refer to the exhibits.
The exhibits show the firewall policies and the objects used in the firewall policies.
The administrator is using the Policy Lookup feature and has entered the search criteria shown in the exhibit.

Which policy will be highlighted, based on the input criteria?

  • A. Policies with ID 2 and 3.
  • B. Policy with ID 4.
  • C. Policy with ID 5.
  • D. Policy with ID 4.

Answer: C

Explanation:
Reference:
We are looking for a policy that will allow or deny traffic from the source interface Port3 and source IP address 10.1.1.10 (LOCAL_CLIENT) to facebook.com TCP port 443 (HTTPS). There are only two policies that will match this traffic, policy ID 2 and 5. In FortiGate, firewall policies are evaluated from top to bottom. This means that the first policy that matches the traffic is applied, and subsequent policies are not evaluated. Based on the Policy Lookup criteria, Policy ID 5 will be highlighted


NEW QUESTION # 63
Refer to the exhibits.
The exhibits show a network diagram and firewall configurations.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. Remote-User1 must be able to access the Webserver. Remote-User2 must not be able to access the Webserver.


In this scenario, which two changes can the administrator make to deny Webserver access for Remote-User2? (Choose two.)

  • A. Set the Destination address as Deny_IP in the Allow-access policy.
  • B. Set the Destination address as Web_server in the Deny policy.
  • C. Enable match vip in the Deny policy.
  • D. Disable match-vip in the Deny policy.

Answer: B,C

Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Firewall-does-not-block-incoming-WAN-to-LAN/ta-p/189641


NEW QUESTION # 64
Which statement about video filtering on FortiGate is true?

  • A. Otis available only on a proxy-based firewall policy.
  • B. It does not require a separate FortiGuard license.
  • C. Video filtering FortiGuard categories are based on web filter FortiGuard categories.
  • D. Full SSL inspection is not required.

Answer: B


NEW QUESTION # 65
An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels.
The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel.
Which DPD mode on FortiGate will meet the above requirement?

  • A. On Idle
  • B. On Demand
  • C. Disabled
  • D. Enabled

Answer: A


NEW QUESTION # 66
Which scanning technique on FortiGate can be enabled only on the CLI?

  • A. Trojan scan
  • B. Antivirus scan
  • C. Ransomware scan
  • D. Heuristics scan

Answer: D


NEW QUESTION # 67
Which two statements ate true about the Security Fabric rating? (Choose two.)

  • A. The Security Fabric rating is a free service that comes bundled with alt FortiGate devices.
  • B. It provides executive summaries of the four largest areas of security focus.
  • C. The Security Fabric rating must be run on the root FortiGate device in the Security Fabric.
  • D. Many of the security issues can be fixed immediately by clicking Apply where available.

Answer: C,D


NEW QUESTION # 68
How does FortiGate act when using SSL VPN in web mode?

  • A. FortiGate acts as router.
  • B. FortiGate acts as an FDS server.
  • C. FortiGate acts as DNS server.
  • D. FortiGate acts as an HTTP reverse proxy.

Answer: D


NEW QUESTION # 69
How can you disable RPF checking?

  • A. Disable src-check on the interface level settings
  • B. Disable fail-detect on the interface level settings.
  • C. Disable strict-src-check under system settings.
  • D. Unset fail-alert-interfaces on the interface level settings.

Answer: A


NEW QUESTION # 70
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

  • A. The operation mode is transparent.
  • B. The interface is a member of a zone.
  • C. The interface is a member of a virtual wire pair.
  • D. The interface has been configured for one-arm sniffer.
  • E. Captive portal is enabled in the interface.

Answer: A,C,D

Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm


NEW QUESTION # 71
What are two functions of ZTNA? (Choose two.)

  • A. ZTNA provides a security posture check.
  • B. ZTNA provides role-based access.
  • C. ZTNA manages access for remote users only.
  • D. ZTNA manages access through the client only.

Answer: A,B


NEW QUESTION # 72
......

Prepare For The NSE4_FGT-7.2 Question Papers In Advance: https://www.examprepaway.com/Fortinet/braindumps.NSE4_FGT-7.2.ete.file.html

Released Fortinet NSE4_FGT-7.2 Updated Questions PDF: https://drive.google.com/open?id=1zHgQDeGYOtrl3EpMHliNgu9JOWTJGNvH