option
Cuestiones
ayuda
daypo
buscar.php

🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 51-60

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 51-60

Descripción:
Fortinet NSE4.

Fecha de Creación: 2026/09/17

Categoría: Informática

Número Preguntas: 10

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

What are three key routing principles in SD-WAN? (Choose three answers). By default, SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination. SD-WAN rules have precedence over any other type of routes. Regular policy routes have precedence over SD-WAN rules. By default, SD-WAN rules are skipped if only one route to the destination is available. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device? (Choose two.). Heartbeat IP addresses are used to distinguish between cluster members. The heartbeat interface of the primary device in the cluster is always assigned IP address 169.254.0.1. A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster. Heartbeat interfaces have virtual IP addresses that are manually assigned.

What are two features of FortiGate FSSO agentless polling mode? (Choose two.). FortiGate uses the AD server as the collector agent. FortiGate uses the SMB protocol to read the event viewer logs from the DCs. FortiGate does not support workstation check. FortiGate directs the collector agent to use a remote LDAP server.

Which statement correctly describes NetAPI polling mode for the FSSO collector agent?. The collector agent uses a Windows API to query DCs for user logins. The NetSessionEnum function is used to track user logouts. NetAPI polling can increase bandwidth usage in large networks. The collector agent must search Windows application event logs.

What is the primary FortiGate election process when the HA override setting is enabled? (Choose one answer). Connected monitored ports > Priority > HA uptime > FortiGate serial number. Connected monitored ports > Priority > System uptime > FortiGate serial number. Connected monitored ports > HA uptime > Priority > FortiGate serial number. Connected monitored ports > System uptime > Priority > FortiGate serial number.

Refer to the exhibits The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver? (Choose one answer). Disable match-vip in the Allow_access policy. Configure a One-to-One IP Pool object in a new policy. Set the Destination address as Webserver in the Deny policy. Set the Destination address as Deny_IP in the Allow_access policy.

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.). On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0. On HQ-NGFW. enable Diffie-Hellman Group 2. On BR1-FGT. set Seconds to 43200. On HQ-NGFW. set Encryption to AES256.

Refer to the exhibit The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team? (Choose one answer). Move NOC_Access to the top of the list to ensure all profile settings take effect. Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access. Increase the admintimeout value under config system accprofile NOC_Access.

Refer to the exhibit Which two ways can you view the log messages shown in the exhibit? (Choose two.). By right clicking the implicit deny policy. Using the FortiGate CLI command diagnose log test. By filtering by policy universally unique identifier (UUID) and application name in the log entry. In the Forward Traffic section.

FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.). Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned. Both interfaces must have the interface role assigned. Both interfaces must have directly connected routes on the routing table. Both interfaces must have IP addresses assigned.

Denunciar Test