option
Cuestiones
ayuda
daypo
buscar.php

🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 21-30

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 21-30

Descripción:
Fortinet NSE4.

Fecha de Creación: 2026/09/17

Categoría: Informática

Número Preguntas: 10

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

Diagnostics Refer to the exhibit showing a debug flow output. Which two conclusions can you make from the debug flow output? (Choose two answers). The default gateway is configured on port2. The RPF check fails. The debug flow is for UDP traffic. The matching firewall policy denies the traffic.

Exhibits: You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS. While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS. What could be the cause?. The feature set in the antivirus profile is not set to Flow-based. Web filter is not enabled on the firewall policy to complement the antivirus profile. The action on the firewall policy is not set to deny. The SSL inspection mode in the firewall policy is not deep content inspection.

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit For which two reasons are these web categories exempted? (Choose two.). The resources utilization is optimized because these websites are in the trusted domain list on FortiGate. The legal regulation aims to prioritize user privacy and protect sensitive information for these websites. These websites are in an allowlist of reputable domain names maintained by FortiGuard. The FortiGate temporary certificate denies the browser ' s access to websites that use HTTP Strict Transport Security.

An administrator wants to form an HA cluster using the FGCP protocol. Which two requirements must the administrator ensure both members fulfill? (Choose two answers). They must have the same HA group ID. They must have the heartbeat interfaces in the same subnet. They must have the same number of configured VDOMs. They must have the same hard drive configuration.

Refer to the exhibit A firewall policy to enable active authentication is shown. When attempting to access an external website using an active authentication method, the user is not presented with a login prompt. What is the most likely reason for this situation?. No matching user account exists for this user. The Remote-users group must be set up correctly in the FSSO configuration. The Remote-users group is not added to the Destination. The Service DNS is required in the firewall policy.

Refer to the exhibits. The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details. Based on the configuration, what will happen to Apple FaceTime if there are only a few calls originating or incoming? (Choose one answer). Apple FaceTime will be allowed, based on the Video/Audio category configuration. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration. Apple FaceTime will be allowed, based on the Apple filter configuration. Apple FaceTime will be allowed only if the Apple filter in Application and Filter Overrides is set to Allow.

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category. What are two solutions for satisfying the requirement? (Choose two answers). Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively. Configure a web override rating for download.com and select Malicious Websites as the subcategory. Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address. Set the Freeware and Software Downloads category Action to Warning.

An SD-WAN zone configuration on the FortiGate GUI is shown. Based on the exhibit, which statement is true?. The Underlay zone contains no member. The virtual-wan-link and overlay zones can be deleted. The Underlay zone is the zone by default. port2 and port3 are not assigned to a zone.

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two answers). The selected SSL inspection profile has certificate inspection enabled. The website is exempted from SSL inspection. The EICAR test file exceeds the protocol options oversize limit. The browser does not trust the FortiGate self-signed CA certificate.

A network administrator is reviewing firewall policies in both Interface Pair View and By Sequence View. The policies appear in a different order in each view. Why is the policy order different in these two views?. By Sequence View groups policies based on rule priority, while Interface Pair View always follows the order of traffic logs. The firewall dynamically reorders policies in Interface Pair View based on recent traffic patterns, but By Sequence View remains static. Interface Pair View sorts policies based on matching interfaces, while By Sequence View shows the actual processing order of rules. Policies in Interface Pair View are prioritized by security levels, while By Sequence View strictly follows the administrator ' s manual ordering.

Denunciar Test