wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Exam Questions NSE4_FGT-7.0 Fortinet NSE 4 - FortiOS 7.0

Total questions: 22

Worksheet time: 6hrs 30mins

Name
Class
Date
1.

An administrator wants to configure timeouts for users. Regardless of the user€™s behavior, the timer should start as soon as the user authenticates and expire after the configured value. Which timeout option should be configured on FortiGate?

a)

auth-on-demand

b)

soft-timeout

c)

idle-timeout

d)

new-session

e)

hard-timeout

2.

Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)

a)

FortiCache

b)

FortiSIEM

c)

FortiAnalyzer

d)

FortiSandbox

e)

FortiCloud

3.

Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)

a)

System time

b)

FortiGuaid update servers

c)

Operating mode

d)

NGFW mode

4.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

a)

The signature setting uses a custom rating threshold.

b)

The signature setting includes a group of other signatures.

c)

Traffic matching the signature will be allowed and logged.

d)

Traffic matching the signature will be silently dropped and logged

5.

Which statement correctly describes NetAPI polling mode for the FSSO collector agent?

a)

The collector agent uses a Windows API to query DCs for user logins.

b)

NetAPI polling can increase bandwidth usage in large networks.

c)

The collector agent must search security event logs.

d)

The NetSession Enum function is used to track user logouts

6.

An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel. Which DPD mode on FortiGate will meet the above requirement?

a)

Disabled

b)

On Demand

c)

Enabled

d)

On Idle

7.

An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic. Why is FortiGate not sending probes to 4.2.2.2 and 4.2.2.1 servers? (Choose two.)

a)

The Detection Mode setting is not set to Passive.

b)

Administrator didn't configure a gateway for the SD-WAN members, or configured gateway is not valid.

c)

The configured participants are not SD-WAN members.

d)

The Enable probe packets setting is not enabled.

8.

An administrator has configured a strict RPF check on FortiGate. Which statement is true about the strict RPF check?

a)

The strict RPF check is run on the first sent and reply packet of any new session.

b)

Strict RPF checks the best route back to the source using the incoming interface

c)

Strict RPF checks only for the existence of at cast one active route back to the source using the incoming interface.

d)

Strict RPF allows packets back to sources with all active routes

9.

The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?

a)

Change password

b)

Enable restrict access to trusted hosts

c)

Change Administrator profile

d)

Enable two-factor authentication

10.

Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?

a)

Antivirus engine

b)

Intrusion prevention system engine

c)

Flow engine

d)

Detection engine

11.

An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?

a)

Policy lookup will be disabled.

b)

By Sequence view will be disabled

c)

Search option will be disabled

d)

Interface Pair view will be disabled.

12.

Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?

a)

get system status

b)

get system performance status

c)

diagnose sys top

d)

get system arp

13.

An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?

a)

Add the support of NTLM authentication

b)

Add user accounts to Active Directory (AD).

c)

Add user accounts to the FortiGate group fitter

d)

Add user accounts to the Ignore User List.

14.

Which contains a session list output. Based on the information shown in the exhibit, which statement is true?

a)

Destination NAT is disabled in the firewall policy.

b)

One-to-one NAT IP pool is used in the firewall policy.

c)

Overload NAT IP pool is used in the firewall policy

d)

Port block allocation IP pool is used in the firewall policy

15.

An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24. Which subnet must the administrator configure for the local quick mode selector for site B?

a)

192.168.1.0/24

b)

192.168.0.0/24

c)

192.168.2.0/24

d)

192.168.3.0/24

16.

Which two statements are true about the FGCP protocol? (Choose two.)

a)

Not used when FortiGate is in Transparent mode

b)

Elects the primary FortiGate device

c)

Runs only over the heartbeat links

d)

Is used to discover FortiGate devices in different HA groups

17.

How does FortiGate act when using SSL VPN in web mode?

a)

FortiGate acts as an FDS server

b)

FortiGate acts as an HTTP reverse proxy.

c)

FortiGate acts as DNS server.

d)

FortiGate acts as router.

18.

Which two statements about SSL VPN between two FortiGate devices are true? (Choose two.)

a)

The client FortiGate requires a client certificate signed by the CA on the server FortiGate

b)

The client FortiGate requires a manually added route to remote subnets.

c)

The client FortiGate uses the SSL VPN tunnel interface type to connect SSL VPN.

d)

Server FortiGate requires a CA certificate to verify the client FortiGate certificate.

19.

A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded. What is the reason for the failed virus detection by FortiGate?

a)

Application control is not enabled

b)

SSL/SSH Inspection profile is incorrect

c)

Antivirus profile configuration is incorrect

d)

Antivirus definitions are not up to date

20.

An administrator is configuring an Ipsec between site A and siteB. The Remotes Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.16.1.0/24 and the remote quick mode selector is 192.16.2.0/24. How must the administrator configure the local quick mode selector for site B?

a)

192.168.3.0/24

b)

192.168.2.0/24

c)

192.168.1.0/24

d)

192.168.0.0/8

21.

Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

a)

FortiGate points the collector agent to use a remote LDAP server.

b)

FortiGate uses the AD server as the collector agent.

c)

FortiGate uses the SMB protocol to read the event viewer logs from the DCs.

d)

FortiGate queries AD by using the LDAP to retrieve user group information.

22.

Which of the following are purposes of NAT traversal in IPsec? (Choose two.)

a)

To detect intermediary NAT devices in the tunnel path.

b)

To dynamically change phase 1 negotiation mode aggressive mode

c)

To encapsulation ESP packets in UDP packets using port 4500.

d)

To force a new DH exchange with each phase 2 rekey.