🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 81-93
|
|
Título del Test:
![]() 🛡️ Fortinet NSE4 – FGT_AD-7.6 | Preguntas 81-93 Descripción: Fortinet NSE4. |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Refer to the exhibit. Why did the FortiGate device drop the packet?. It matched the default implicit firewall policy. It failed the RPF check. It matched an explicitly configured firewall policy with the action DENY. It cannot reach the next-hop IP. An administrator wanted to configure an IPS sensor to block traffic that triggers the signature set number of times during a specific time period. How can the administrator achieve the objective?. Use IPS group signatures, set rate-mode 60. Use IPS packet logging option with periodical filter option. Use IPS signatures, rate-mode periodical option. Use IPS filter, rate-mode periodical option. An administrator wants to address shadow IT visibility challenges and prevent users from sending sensitive files outside the organization without proper approval. Which FortiSASE method should the administrator implement to achieve these goals? (Choose one answer). Secure SD-WAN access (SSD-WAN). Secure private access (SPA). Secure SaaS access (SSA). Secure internet access (SIA). You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab. and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?. FortiGuard category ratings. Network Protocol Enforcement. Replacement Messages for UDP-based Applications. Application and Filter Overrides. Which three statements about SD-WAN performance SLAs are true? (Choose three.). They rely on session loss and jitter. They monitor the state of the FortiGate device. All the SLA targets can be configured. They are applied in a SD-WAN rule lowest cost strategy. They can be measured actively or passively. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. You cannot access any of the Google applications, but you are able to access www.fortinet.com . What would you do to resolve this issue?. Change the Inspection mode to Proxy-based. Set SSL inspection to deep-content-inspection. Move up Google in the Application and Filter Overrides section to set its priority to 1. Add Google .com to the URL category in the security profile. A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is not part of the expected process?. The DC agent sends login event data directly to FortiGate. FortiGate determines user identity based on the IP address in the FSSO list. The collector agent forwards login event data to FortiGate. The user logs into the windows domain. An administrator creates a new address object on the root FortiGate (HQ-NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW). What must the administrator do to synchronize the address object?. Change the csf setting on HQ-ISFW (downstream) to set configuration-sync local. Change the csf setting on HQ-ISFW (downstream) to set saml-configuration-sync default. Change the csf setting on HQ-NGFW-1 (root) to set fabric-object-unification default. Change the csf setting on both devices to set downstream-access enable. Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three answers). Lowest Cost (SLA) without load balancing. Manual with load balancing. Lowest Quality (SLA) with load balancing. Lowest Cost (SLA) with load balancing. Best Quality with load balancing. A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad. Which VPN Wizard template must the administrator apply?. Remote Access. Hub-and-Spoke. Site-to-Site. Dial-up User. FortiGate is integrated with FortiAnalyzer and FortiManager. When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?. Universally Unique Identifier. Policy ID. Sequence ID. Log ID. You have configured the below commands on a FortiGate. What would be the impact of this configuration on FortiGate?. FortiGate will enable strict RPF on all its interfaces and porti will be exempted from RPF checks. FortiGate will enable strict RPF on all its interfaces and porti will be enable for asymmetric routing. The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces. Port1 will be enabled with flexible RPF. and all other interfaces will be enabled for strict RPF. Refer to the exhibit. Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.). FortiGate drops new sessions requiring inspection. Administrators must restart FortiGate to allow new sessions. Administrators cannot change the configuration. FortiGate skips quarantine actions. |





