option
Cuestiones
ayuda
daypo
buscar.php

🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 61-70

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 61-70

Descripción:
Fortinet NSE4.

Fecha de Creación: 2026/09/17

Categoría: Informática

Número Preguntas: 10

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

Refer to the exhibit. A routing table is shown An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only. What are the two criteria that the administrator can use to achieve this objective? (Choose two.). The new static route must have the priority set to 3. The new static route must have the metric set to 1. The existing static route through port3 must have the distance set to 11. The new static route must have the distance set to 9. The new static route must have the priority set to 1.

Refer to the exhibits. An administrator wants to form an HA cluster using the FGCP protocol. Both FortiGate devices are configured with the HA Override option enabled. Which sequence correctly describes the primary FortiGate election process? (Choose one answer.). Connected monitored ports → HA uptime → Priority → FortiGate serial number. Priority → Connected monitored ports → HA uptime → FortiGate serial number. Connected monitored ports → Priority → HA uptime → FortiGate serial number. Connected monitored ports → Priority → FortiGate serial number → HA uptime.

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)?. 100.65.0.101. 100.65.0.49. 100.65.0.149. 100.65.0.99.

Refer to the exhibits. Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibits. What would be the expected outcome in the HA cluster?. HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1. HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority. The HA cluster will become out of sync because the override setting must match on all HA members. HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.

You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two answers). You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 or 4500). You can turn on fragmentation to fix large certificate negotiation problems. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP ports. You should use the protocol IKEv2.

Refer to the exhibit. What can you conclude from the log shown in the exhibit?. The IPS socket buffer is full and IPS engine needs more memory to create new sessions. The IPS socket buffer is full and IPS engine cannot decode a packet. The IPS scan is paused by the IPS diagnostic command with bypass mode option 5. The IPS session scan is paused and reevaluating the packet because of a dirty flag.

You have configured the FortiGate device for FSSO. A user is successful in log-in to Windows, but their access to the internet is denied. What should the administrator check first? (Choose one answer). Whether the user is assigned to the correct AD group. The FortiGate firewall policy settings for SSL decryption. The FortiGate FSSO active users list for user ' s IP address. The Windows event viewer for failed login attempts.

Refer to the exhibit. An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times. Why are there no logs generated under security logs for ABC.Com?. The ABC Com is hitting the category Excessive-Bandwidth. The ABC.Com Type is set as Application instead of Filter. The ABC.Com is configured under application profile, which must be configured as a web filter profile. The ABC Com Action is set to Allow.

A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?. The option invalid SSL certificates is set to allow on the SSL/SSH inspection profile. The matching firewall policy is set to proxy inspection mode. The browser does not trust the certificate used by FortiGate for SSL inspection. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.

Refer to the exhibit. An administrator has created a new firewall address to use as the destination for a static route. Why is the administrator not able to select the new address in the Destination field of the new static route? (Choose one answer). In the new static route, the administrator must select Named Address. In the new firewall address, the FQDN address must first be resolved. In the new static route, the administrator must first set the interface to port2. In the new firewall address, Routing configuration must be enabled.

Denunciar Test