wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Post Test NSE4 Basic Training

Total questions: 45

Worksheet time: 26mins

Name
Class
Date
1.

An administrator is investigating a report of users having intermittent issues with browsing the web. The administrator ran diagnostics and received the output shown in the exhibit.

a)

NAT port exhaustion

b)

High CPU usage

c)

High memory usage

d)

High session timeout value

2.

Which statement about FortiGuard services for FortiGate is true?

a)

The web filtering database is downloaded locally on FortiGate.

b)

Antivirus signatures are downloaded locally on FortiGate.

c)

FortiGate downloads IPS updates using UDP port 53 or 8888.

d)

FortiAnalyzer can be configured as a local FDN to provide antivirus and IPS updates.

3.

Which of the following services can be inspected by the DLP prof ile? (Choose three.)

a)

IMAP

b)

ClFS

c)

FTP

d)

HTTP-POST

e)

NFS

4.

Which of the following statements about virtual domains(VDOMs) are true? (Choose two.)

a)

Each VDOM maintains its own routing table.

b)

A FortiGate device has 64 VDOMs, created by default.

c)

Each VDOM maintains its own system time.

d)

The root VDOM is the management VDOM by default.

5.

What FortiGate components are tested during the hardware test? (Choose three.)

a)

Hard disk

b)

HAheartbeat

c)

CPU

d)

Network interfaces

e)

Administrativeaccess

6.

Which one of the following processes is involved in updating IPS from FortiGuard?

a)

FortiGate IPS update requests are sent using UDP port 443.

b)

Protocol decoder update requests are sent to service. fortiguard.net.

c)

IPS engine updates can only be obtained using push updates.

d)

IPS signature update requests are sent to update. fortiguard.net.

7.

Which of the following statements about Conserve mode are true? (Choose two.)

a)

FortiGate stops doing RPF checks over incoming packets

b)

Administrators cannot change the configuration

c)

Administrators can access the FortiGate only through the console port.

d)

FortiGate stops sending f iles to FortiSandbox for inspection.

8.

Given the FortiGate CLI output, why is the administrator getting the error shown in the exhibit?

a)

The administrator must first enter the command edit global.

b)

The administrator admin does not have the privileges required to configure global settings.

c)

The command config system global does not exist in FortiGate.

d)

The global settings cannot be configured from the root VDOM context.

9.

Examine the network diagram and the existing FGTI routing table shown in the exhibit, and then answer the following question:An administrator has added the following static route on FGTI.

Since the change, the new static route is not showing up in the routing table. Given the information provided, which of the following describes the cause of this problem?

a)

The new route's destination subnet overlaps an existing route.

b)

The new route's Distance value should be higher than 10.

c)

The Gateway IP address is not in the same subnet as port1.

d)

The Priority is 0, which means that this route will remain inactive.

10.

Which users and user groups are allowed access to the network through captive portal?

a)

Users and groups defined in the firewall policy.

b)

Only individual users "" not groups "" defined in the captive portal configuration

c)

Groups defined in the captive portal configuration

d)

All users

11.

NGFW mode allows policy-based configuration for most inspection rules. Which security profile's configuration does not change when you enable policy-based inspection?

a)

Web filtering

b)

Antivirus

c)

Web proxy

d)

Application control

12.

During the digital verification process, comparing the original and fresh hash results satisfies which security requirement?

a)

Non-repudiation.

b)

Data integrity.

c)

Signature verification.

d)

Authentication.

13.

Why must you use aggressive mode when a local FortiGate lPSec gateway hosts multiple dialup tunnels?

a)

In aggressive mode, the remote peers are able to provide their peer IDs in the first message.

b)

FortiGate is able to handle NATed connections only in aggressive mode.

c)

FortiClient only supports aggressive mode.

d)

Main mode does not support XAuth for user authentication.

14.

In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit.
What should the administrator do next to troubleshoot the problem?

a)

Run a sniffer on the web server.

b)

Capture the traffic using an external sniffer connected to port1.

c)

Execute another sniffer in the FortiGate, this time with the filter "host 10.0.1.10"

d)

Execute a debug flow.

15.

Which of the following statements are best practices for troubleshooting FSSO? (Choose two.)

a)

Include the group of guest users in a policy.

b)

Extend timeout timers.

c)

Guarantee at least 34 Kbps bandwidth between FortiGate and domain controllers.

d)

Ensure all firewalls allow the FSSO required ports.

16.

If Internet Service is already selected as Destination in a firewall policy, which other configuration objects can be selected for the Destination field of a firewall policy?

a)

IP address

b)

User or User Group

c)

No other object can be added

d)

FQDN address

17.

Which statements about HA for FortiGate devices are true? (Choose two.)

a)

Sessions handled by proxy-based security profiles cannot be synchronized.

b)

Virtual clustering can be configured between two FortiGate devices that have multiple VDOMs.

c)

HA management interface settings are synchronized between cluster members.

d)

Heartbeat interfaces are not required on the primary device.

18.

An administrator has configured a route-based IPsec VPN between two FortiGate devices.
Which statement about this IPsec VPN configuration is true?

a)

A phase 2 configuration is not required.

b)

This VPN cannot be used as part of a hub-and-spoke topology.

c)

A virtual IPsec interface is automatically created after the phase 1 configuration is completed.

d)

The IPsec firewall policies must be placed at the top of the list.

19.

What settings must you configure to ensure FortiGate generates logs for web filter activity on a firewall policy called Full Access? (Choose two.)

a)

Enable Event Logging

b)

Enable Log Allowed Traff ic on the Full Access firewall policy

c)

Enable a web filer security profile on the Full Access f irewall policy

d)

Enable disk logging.

20.

Based on the configuration shown in the exhibit, what statements about application control behavior are true? (Choose two.)

a)

Access to all unknown applications will be allowed.

b)

Access to browser-based Social.Media applications will be blocked.

c)

Access to mobile social media applications will be blocked.

d)

Access to all applications in Social.Media category will be blocked.

21.

HTTP Public Key Pinning (HPKP) can be an obstacle to implementing full SSL inspection. What solutions could resolve this problem? (Choose two.)

a)

Enable Allow Invalid SSL Certificates for the relevant security profile.

b)

Change web browsers to one that does not support HPKP.

c)

Exempt those web sites that use HPKP from full SSL inspection.

d)

Install the CA certificate (that is required to verify the web server certificate) stores of users' computers.

22.

Examine the routing database shown in the exhibit, and then answer the following question:

Which of the following statements are correct? (Choose two.)

a)

The port3 default route has the highest distance.

b)

The port3 default route has the lowest metric.

c)

There will be eight routes active in the routing table.

d)

The port1 and port2 default routes are active in the routing table.

23.

Which of the following features is supported by web filter in flow-based inspection mode with NGFW mode set to profile-based? (choose two)

a)

FortiGuard Quotas

b)

Static URL Filter

c)

Search engines

d)

Rating option

24.

Examine the exhibit, which contains a virtual IP and firewall policy configuration.

The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?

a)

10.200.1.10

b)

Any available IP address in the WAN (port1) subnet 10.200.1.0/24

c)

10.200.1.1

d)

10.0.1.254

25.

By default, when logging to disk, when does FortiGate delete logs?

a)

1 year

b)

7 days

c)

Never

d)

30 days

26.

When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?

a)

The public IP address of the FortiGate device

b)

remote user's public IP address

c)

The remote user's virtual IP address

d)

The internal IP address of the FortiGate device

27.

A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not.
Which configuration option is the most effective way to support this request?

a)

Implement web filter authentication for the specified website

b)

Implement DNS f ilter for the specified website.

c)

Implement a web filter category override for the specified website

d)

Implement web filter quotas for the specif ied website.

28.

Which two statements about antivirus scanning mode are true? (Choose two.)

a)

In proxy-based inspection mode, files bigger than the buffer size are scanned

b)

In full scan flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.

c)

In quick scan mode, you can conf igure antivirus prof iles to use any of the available antivirus signature databases.

d)

In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.

29.

Which is the correct description of a hash result as it relates to digital certificates?

a)

An encrypted output value used to safe-guard the input data

b)

An output value that is used to identify the person or deduce that authored the input data.

c)

An obfuscation used to mask the input data.

d)

A unique value used to verify the input data

30.

On a FortiGate with a hard disk, how frequently can you upload logs to FortiAnalyzer or FortiManager? (Choose two.)

a)

every 5 minutes

b)

hourly

c)

on demand

d)

real-time

31.

Which statement about DLP on FortiGate is true?

a)

Files can be sent to FortiSandbox for detecting DLP threats

b)

It can be applied to a firewall policy in a flow-based VDOM

c)

It can archive files and messages

d)

Traffic shaping can be applied to DLP sensors.

32.

Which statements are true regarding firewall policy NAT using the outgoing interface IP address with fixed port disabled? (Choose two.)

a)

This is known as many-to-one NAT.

b)

Source IP is translated to the outgoing interface IP.

c)

Connections are tracked using source port and source MAC address.

d)

Port address translation is not used.

33.

What criteria does FortiGate use to look for a matching firewall policy to process traff ic? (Choose two.)

a)

Services defined in the firewall policy

b)

Highest to lowest priority defined in the firewall policy.

c)

Lowest to highest policy ID number.

d)

Incoming and outgoing interfaces

34.

An administrator wants to configure a FortiGate as a DNS server. FotiGate must use a DNS database first, and then relay all irresolvable queries to an external
DNS server. Which of the following DNS methods must you use?

a)

Recursive

b)

Non-recursive

c)

Forward to primary and secondary DNS

d)

Forward to system DNS

35.

To complete the final step of a Security Fabric configuration, an administrator must authorize all the devices on which device?

a)

Downstream FortiGate

b)

FortiAnalyzer

c)

FortiManager

d)

Root FortiGate

36.

An administrator wants to block HTTP uploads. Examine the exhibit, which contains the proxy address created for that purpose.

Where must the proxy address be used?

a)

As the source in a firewall policy.

b)

As the source in a proxy policy.

c)

As the destination in a firewall policy.

d)

As the destination in a proxy policy.

37.

An administrator has configured two VLAN interfaces:

A DHCP server is connected to the VLAN10 interface. A DHCP client is connected to the VLAN5 interface. However, the DHCP client cannot get a dynamic IP address from the DHCP server. What is the cause of the problem?

a)

Both interfaces must belong to the same forward domain.

b)

The role of the VLAN10 interface must be set to server.

c)

Both interfaces must have the same VLAN ID.

d)

Both interfaces must be in different VDOMs.

38.

Which three statements correctly describe transparent mode operation? (Choose three.)

a)

The transparent FortiGate is visible to network hosts in an IP traceroute.

b)

FortiGate acts as a transparent bridge and forwards traffic at Layer 2.

c)

Ethernet packets are forwarded based on destination MAC addresses, not IP addresses.

d)

It permits inline traffic inspection and firewalling without changing the IP scheme of the network.

e)

All interfaces on the transparent mode FortiGate device must be on different IP subnets.

39.

Given to the static routes shown in the exhibit, which statements are correct? (Choose two.)

a)

This is a redundant IPsec setup.

b)

This setup requires at least two firewall policies with the action set to IPsec

c)

Dead peer detection must be disabled to support this type of IPsec setup.

d)

The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.

40.

Which statement about the exhibit is true? (Choose two.)

a)

Broadcast traffic received in port1-VLAN10 will not be forwarded to port2-VLAN10.

b)

port-VLAN1 is the native VLAN for the port1 physical interface.

c)

port1-VLAN10 and port2-VLAN10 can be assigned to different VDOMs.

d)

Traffic between port1-VLAN1 and port2-VLAN1 is allowed by default.

41.

Given the network diagram shown in the exhibit, which route is the best candidate route for FGT1 to route traffic from the workstation to the webserver?

a)

172.16.32.0/24 is directly connected, port1

b)

172.16.0.0/16 [50/0] via 10.4.200.2, port2 [5/0]

c)

10.4.200.0/30 is directly connected, port2

d)

0.0.0.0/0 [20/0] via 10.4.200.2, port2

42.

A firewall administrator must configure equal cost multipath (ECMP) routing on FGT1 to ensure both port1 and port3 links are used at the same time for all traffic destined for 172.20.2.0/24. Which of the following static routes will satisfy this requirement on FGT1? (Choose two.)

a)

172.20.2.0/24 (1/0) via 10.10.1.2, port1 [0/0]

b)

172.20.2.0/24 (25/0) via 10.10.3.2, port3 [5/0]

c)

172.20.2.0/24 (1/150) via 10.10.3.2, port3 [10/0]

d)

172.20.2.0/24 (25/0) via 10.10.3.2, port3 [5/0]

43.

Which of the following are valid actions for FortiGuard category based filter in a web filter profile ui proxy-based inspection mode? (Choose two.)

a)

Warning

b)

Exempt

c)

Allow

d)

Learn

44.

Which two static routes are not maintained in the routing table? (Choose two.)

a)

Dynamic routes

b)

Policy routes

c)

ISDB routes

d)

Named Address routes

45.

What will happen to unauthenticated users when an active authentication policy is followed by a fall through policy without authentication?

a)

The user must log in again to authenticate.

b)

The user will be denied access to resources without authentication.

c)

The user will not be prompted for authentication.

d)

User authentication happens at an interface level.