152 Exam Questions for NSE4_FGT-7.2 Updated Versions With Test Engine
Pass NSE4_FGT-7.2 Exam with Updated NSE4_FGT-7.2 Exam Dumps PDF 2023
Fortinet NSE4_FGT-7.2 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
NEW QUESTION 14
Refer to the exhibit.
Which contains a network diagram and routing table output.
The Student is unable to access Webserver.
What is the cause of the problem and what is the solution for the problem?
- A. The first packet sent from Student failed the RPF check.
This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1. - B. The first packet sent from Student failed the RPF check.
This issue can be resolved by adding a static route to 203.0. 114.24/32 through port3. - C. The first reply packet for Student failed the RPF check.
This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1. - D. The first reply packet for Student failed the RPF check .
This issue can be resolved by adding a static route to 203.0. 114.24/32 through port3.
Answer: B
NEW QUESTION 15
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL Inspection? (Choose two.)
- A. The CA extension must be set to TRUE.
- B. The keyUsage extension must be set to keyCertSign.
- C. The common name on the subject field must use a wildcard name.
- D. The issuer must be a public CA.
Answer: A,B
Explanation:
"In order for FortiGate to act in these roles, its CA certificate must have the basic constraints extension set to cA=True and the value of the keyUsage extension set to keyCertSign."
NEW QUESTION 16
An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)
- A. Set the session TTL on the HTTP policy to maximum
- B. Create a new service object for HTTP service and set the session TTL to never
- C. Set the TTL value to never under config system-ttl
- D. Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
Answer: B,C
NEW QUESTION 17
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?
- A. A subordinate CA
- B. A CRL
- C. A root CA
- D. A person
Answer: C
NEW QUESTION 18
Which three methods are used by the collector agent for AD polling? (Choose three.)
- A. FortiGate polling
- B. WinSecLog
- C. Novell API
- D. WMI
- E. NetAPI
Answer: B,D,E
NEW QUESTION 19
Refer to the exhibit.
Which contains a session list output. Based on the information shown in the exhibit, which statement is true?
- A. Port block allocation IP pool is used in the firewall policy.
- B. Destination NAT is disabled in the firewall policy.
- C. One-to-one NAT IP pool is used in the firewall policy.
- D. Overload NAT IP pool is used in the firewall policy.
Answer: C
Explanation:
FortiGate_Security_6.4 page 155 . In one-to-one, PAT is not required.
NEW QUESTION 20
If the Services field is configured in a Virtual IP (VIP), which statement is true when central NAT is used?
- A. The Services field prevents multiple sources of traffic from using multiple services to connect to a single computer.
- B. The Services field removes the requirement to create multiple VIPs for different services.
- C. The Services field prevents SNAT and DNAT from being combined in the same policy.
- D. The Services field is used when you need to bundle several VIPs into VIP groups.
Answer: B
NEW QUESTION 21
Which two statements are true when FortiGate is in transparent mode? (Choose two.)
- A. FortiGate forwards frames without changing the MAC address.
- B. By default, all interfaces are part of the same broadcast domain.
- C. The existing network IP schema must be changed when installing a transparent mode.
- D. Static routes are required to allow traffic to the next hop.
Answer: A,B
Explanation:
Reference:
attachID=Fortigate_Transparent_Mode_Technical_Guide_FortiOS_4_0_version1.2.pdf&documentID=FD33113
NEW QUESTION 22
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which configuration change will bring phase 2 up?
- A. On HQ-FortiGate, enable Diffie-Hellman Group 2.
- B. On HQ-FortiGate, enable Auto-negotiate.
- C. On Remote-FortiGate, set Seconds to 43200.
- D. On HQ-FortiGate, set Encryption to AES256.
Answer: D
NEW QUESTION 23
Refer to the exhibit.
The exhibit shows the IPS sensor configuration.
If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)
- A. The sensor will reset all connections that match these signatures.
- B. The sensor will block all attacks aimed at Windows servers.
- C. The sensor will gather a packet log for all matched traffic.
- D. The sensor will allow attackers matching the Microsoft Windows.iSCSI.Target.DoS signature.
Answer: B,D
NEW QUESTION 24
Why does FortiGate keep TCP sessions in the session table for some seconds even after both sides (client and server) have terminated the session?
- A. To generate logs
- B. To allow for out-of-order packets that could arrive after the FIN/ACK packets.
- C. To remove the NAT operation.
- D. To finish any inspection operations.
Answer: B
NEW QUESTION 25
Refer to the web filter raw logs.
Based on the raw logs shown in the exhibit, which statement is correct?
- A. Social networking web filter category is configured with the action set to authenticate.
- B. Access to the social networking web filter category was explicitly blocked to all users.
- C. The action on firewall policy ID 1 is set to warning.
- D. The name of the firewall policy is all_users_web.
Answer: A
NEW QUESTION 26
What are two benefits of flow-based inspection compared to proxy-based inspection? (Choose two.)
- A. FortiGate allocates two sessions per connection.
- B. FortiGate uses fewer resources.
- C. FortiGate performs a more exhaustive inspection on traffic.
- D. FortiGate adds less latency to traffic.
Answer: B,D
NEW QUESTION 27
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?
- A. On HQ-FortiGate, enable Diffie-Hellman Group 2.
- B. On HQ-FortiGate, enable Auto-negotiate.
- C. On Remote-FortiGate, set Seconds to 43200.
- D. On HQ-FortiGate, set Encryption to AES256.
Answer: D
Explanation:
Reference:
:
Encryption and authentication algorithm needs to match in order for IPSEC be successfully established.
NEW QUESTION 28
Refer to the exhibits.

Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default configuration of high memory usage thresholds. Based on the system performance output, which two statements are correct? (Choose two.)
- A. Administrators can access FortiGate only through the console port.
- B. Administrators cannot change the configuration.
- C. FortiGate has entered conserve mode.
- D. FortiGate will start sending all files to FortiSandbox for inspection.
Answer: B,C
Explanation:
Reference:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Conserve-mode-changes/ta-p/198502 configurable thresholds Though it is recommended to keep the default memory threshold, a new CLI command has been added to allow administrators to adjust the thresholds.
Default values are :
- red : 88% of total memory is considered "used memory"
- extreme : 95% of total memory is considered "used memory"
- green : 82% of total memory is considered "used memory"
NEW QUESTION 29
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On HQ-FortiGate, set IKE mode to Main (ID protection).
- B. On both FortiGate devices, set Dead Peer Detection to On Demand.
- C. On HQ-FortiGate, disable Diffie-Helman group 2.
- D. On Remote-FortiGate, set port2 as Interface.
Answer: A,D
NEW QUESTION 30
Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)
- A. NTP
- B. DNS
- C. FortiGate hostname
- D. FortiGuard web filter cache
Answer: A,B
NEW QUESTION 31
Which three criteria can a FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)
- A. Highest to lowest priority defined in the firewall policy.
- B. Services defined in the firewall policy.
- C. Source defined as Internet Services in the firewall policy.
- D. Destination defined as Internet Services in the firewall policy.
- E. Lowest to highest policy ID number.
Answer: B,C,D
Explanation:
When a packet arrives, how does FortiGate find a matching policy? Each policy has match criteria, which you can define using the following objects:
* Incoming Interface
* Outgoing Interface
* Source: IP address, user, internet services
* Destination: IP address or internet services
* Service: IP protocol and port number
* Schedule: Applies during configured times
NEW QUESTION 32
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings.
What is true about the DNS connection to a FortiGuard server?
- A. It uses UDP 8888.
- B. It uses UDP 53.
- C. It uses DNS overTLS.
- D. It uses DNS over HTTPS.
Answer: B
NEW QUESTION 33
Refer to the exhibit.
An administrator added a configuration for a new RADIUS server. While configuring, the administrator selected the Include in every user group option.
What is the impact of using the Include in every user group option in a RADIUS configuration?
- A. This option places all users into every RADIUS user group, including groups that are used for the LDAP server on FortiGate.
- B. This option places the RADIUS server, and all users who can authenticate against that server, into every RADIUS group.
- C. This option places all FortiGate users and groups required to authenticate into the RADIUS server, which, in this case, is FortiAuthenticator.
- D. This option places the RADIUS server, and all users who can authenticate against that server, into every FortiGate user group.
Answer: D
NEW QUESTION 34
Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)
- A. FortiCloud
- B. FortiSIEM
- C. FortiAnalyzer
- D. FortiSandbox
- E. FortiCache
Answer: A,B,C
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/265052/logging-and-reporting-overview
NEW QUESTION 35
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?
- A. Interface Pair view will be disabled.
- B. By Sequence view will be disabled.
- C. Policy lookup will be disabled.
- D. Search option will be disabled
Answer: A
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47821
NEW QUESTION 36
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. diagnose sys top
- B. get system status
- C. get system arp
- D. get system performance status
Answer: C
Explanation:
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."
NEW QUESTION 37
......
NSE4_FGT-7.2 Exam Dumps - Free Demo & 365 Day Updates: https://www.actualtestsquiz.com/NSE4_FGT-7.2-test-torrent.html
Free Sales Ending Soon - Use Real NSE4_FGT-7.2 PDF Questions: https://drive.google.com/open?id=1OdOXr6vg-J-3qQeOyRVR9L7cccWs4rzY

