🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 71-80
|
|
Título del Test:
![]() 🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 71-80 Descripción: Fortinet NSE4. |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Refer to the exhibit. An administrator has created a new firewall address to use as the destination for a static route. Why is the administrator not able to select the new address in the Destination field of the new static route? (Choose one answer). A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled. A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled. A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled. A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled. Refer to the exhibit to view the firewall policy. Why would the firewall policy not block a well-known virus, for example EICAR? (Choose one answer). The action on the firewall policy is not set to DENY. Web filter is not enabled, so the firewall policy does not complement the antivirus profile. The firewall policy is not configured in proxy-based inspection mode. The firewall policy does not apply deep content inspection. Refer to the exhibits. A diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device are shown. Two PCs. PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet. Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.). In the system settings, set Multiple Interface Policies to enable. in the IP pool configuration, set end ipto 100.65.0.112. In the firewall policy, set match-vip to enable using CLI. In the IP pool configuration, set type to overload. Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.). FortiSASE Firewall-as-a-Service (FWaaS). The proxy auto-configuration (PAC) file. VPN policies. FortiExtender. Which two statements are correct when FortiGate enters conserve mode? (Choose two answers). FortiGate continues to run critical security actions, such as quarantine. FortiGate refuses to accept configuration changes. FortiGate halts complete system operation and requires a reboot to regain available resources. FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled. Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.). On HQ-NGFW, disable Diffie-Hellman group 2. On HQ-NGFW, set IKE mode to Main (ID protection). On BR1-FGT, set port2 to Interface. On both FortiGate devices, set Dead Peer Detection to On Demand. Which two statements are true about an HA cluster? (Choose two answers). An HA cluster cannot have both in-band and out-of-band management interfaces at the same time. Link failover triggers a failover if the administrator sets the interface down on the primary device. When sniffing the heartbeat interface, the administrator must see the IP address 169.254.0.2. HA incremental synchronization includes FIB entries and IPsec SAs. Which three methods are used by the collector agent for AD polling? (Choose three answers). NetAPI. WMI. WinSecLog. DNS reverse lookup. FSSO REST API. What are two features of collector agent advanced mode? (Choose two.). In advanced mode, security profiles can be applied only to user groups, not individual users. In advanced mode. FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate. Advanced mode uses the Windows convention—NetBios: Domain\Username. Advanced mode supports nested or inherited groups. An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about this scenario are correct? (Choose two.). The administrator must use a policy route instead of a static route for add-route to work properly. The administrator must ensure phase 2 is successfully established. The administrator must define the remote network correctly in the phase 2 selectors. The administrator must enable a dynamic routing protocol on the dialup interface. |





