option
Cuestiones
ayuda
daypo
buscar.php

🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 11-20

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 11-20

Descripción:
Fortinet NSE4.

Fecha de Creación: 2026/09/17

Categoría: Informática

Número Preguntas: 10

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows What could be the reason?. SD-WAN rule names do not appear immediately. The administrator must refresh the page. There is no application control profile applied to the firewall policy. Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled. FortiGate load balanced the traffic according to the implicit SD-WAN rule.

An administrator has observed the performance status outputs on an HA cluster for 55 seconds. Which FortiGate is the primary?. HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting. HQ-NGFW-2 with the parameter priority setting. HQ-NGFW-1 with the parameter override setting. HQ-NGFW-2 with the parameter memory-failover-threshold setting.

When configuring a FortiGate in a multi-WAN setup, why would an administrator enable session preservation on an interface? (Choose one answer). To allow the FortiGate to dynamically change interfaces for all active sessions when a WAN link fails. To make sure all sessions without source NAT enabled always use the primary WAN link. To improve security by forcing users to authenticate again when the WAN link changes. To ensure that existing SSL VPN connections remain on the same interface even if route changes occur.

When configuring firewall policies which of the following is true regarding the policy ID? (Choose two.). A firewall policy ID identifies the order of policy execution in firewall policies. A policy ID cannot be modified once a policy is created. You can create a policy in CLI with policy ID 0. It is mandatory to provide a policy ID while creating a firewall policy regardless of GUI or CLI.

The system performance output and default configuration of high memory usage thresholds on a FortiGate device are shown. Administrators can access FortiGate only through the console port. FortiGate has entered conserve mode. FortiGate drops new sessions. Administrators can change the configuration.

You have created a web filter profile named restrictmedia-profile with a daily category usage quota. When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down. What could be the reason?. The web filter profile is already referenced in another firewall policy. The firewall policy is in no-inspection mode instead of deep-inspection. The naming convention used in the web filter profile is restricting it in the firewall policy. The inspection mode in the firewall policy is not matching with web filter profile feature set.

You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS. During the deployment, which components must the FortiGate CNF create to handle traffic from the EC2 instance?. A. The customer VPC and GWLBe. B. The gateway load balancer endpoint (GWLBe) in the customer virtual private cloud (VPC). C. The CNF VPC. customer VPC. and GWLB. D. The GWLB. GWLBe, and the internet gateway (IGW) in the customer VPC.

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. You cannot access any of the Google applications, but you are able to access www.fortinet.com. Which two actions would you take to resolve the issue? (Choose two.). Set SSL inspection to deep-content inspection. Move up Google in the Application and Filter Overrides section to set its priority lot. Add " Google " .com to the URL category in the security profile. Change the Inspection mode to Flow-based. Set the action for Google in the Application and Filter Overrides section to Allow.

Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.). No certificate is required on the remote peer when you set the certificate signature as the authentication method. Extended authentication (XAuth) for faster authentication because fewer packets are exchanged. Extended authentication (XAuth) to request the remote peer to provide a username and password. Pre-shared key and certificate signature as authentication methods.

Which two statements about the FortiGuard connection are true? (Choose two.). The weight increases as the number of failed packets rises. You can configure unreliable protocols to communicate with FortiGuard Server. FortiGate identified the FortiGuard Server using DNS lookup. FortiGate is using the default port for FortiGuard communication.

Denunciar Test