🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 1-10
|
|
Título del Test:
![]() 🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 1-10 Descripción: Fortinet NSE4. |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Refer to the exhibits. The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device. Based on the system performance output, what are the two possible outcomes? (Choose two.). FortiGate drops new sessions. Administrators can access FortiGate only through the console port. Administrators can change the configuration. FortiGate has entered conserve mode. Refer to the exhibit. A RADIUS server configuration is shown. An administrator added a configuration for a new RADIUS server While configuring, the administrator enabled Include in every user group What is the impact of enabling Include in every user group in a RADIUS configuration?. This option places the RADIUS server, and all users who can authenticate against that server, into every FortiGate user group. This option places all FortiGate users and groups required to authenticate into the RADIUS server, which, in this case, is FortiAuthenticator. This option places the RADIUS server, and all users who can authenticate against that server, into every RADIUS group. This option places all users into every RADIUS user group, including groups that are used for the LDAP server on FortiGate. Refer to the exhibit. The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team?. Increase the admintimeout value under config system accprofile noc Access. Increase the of line value of the override idle Timeout parameter in the NOC_Access admin profile. Move NOC_Access to the top of the list to ensure all profile settings take effect. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access. Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. Which two factors can you observe from these configurations? (Choose two.). YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings. Facebook access is blocked based on the category filter settings. Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings. YouTube search is allowed based on the Google Application and Filter override settings. Which three statements explain a flow-based antivirus profile? (Choose three answers). FortiGate buffers the whole file but transmits to the client at the same time. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection. If a virus is detected, the last packet is delivered to the client. Flow-based inspection optimizes performance compared to proxy-based inspection. The IPS engine handles the process as a standalone. An administrator has configured the following settings. (Choose two.). The number of logs generated by denied traffic is reduced. A session for denied traffic is created. Denied users are blocked for 30 minutes. Session helpers are disabled for denied traffic. Which two statements are correct when the FortiGate device enters conserve mode? (Choose two.). FortiGate refuses to accept configuration changes. FortiGate halts complete system operation and requires a reboot to regain available resources. FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled. FortiGate continues to run critical security actions, such as quarantine. There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels. Which phase 1 setting you can configure to match the user to the tunnel?. Local Gateway. Dead Peer Detection. Peer ID. IKE Mode Config. An administrator manages a FortiGate model that supports NTurbo. How does NTurbo acceleration enhance antivirus performance?. For flow-based inspection. NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces. For flow-based inspection. NTurbo creates two inspection sessions on the FortiGate device. For proxy-based inspection. NTurbo offloads traffic to the content processor. For proxy-based inspection. NTurbo buffers the whole file and then sends it to the antivirus engine. A web filter profile configuration and firewall policy configuration are shown. You are trying to access www. facebook.com, but you are redirected to a FortiGuard web filtering block page. Based on the exhibits, what is the possible cause of the issue?. The web rating override configuration is incorrect. The web filter profile feature set is configured incorrectly. The firewall policy inspection mode is incorrect. For www. facebook. com. the URL filter action is incorrect. |





