Latest NSE4_FGT-7.2 Pass Guaranteed Exam Dumps Certification Sample Questions [Q44-Q65]

Share

Latest NSE4_FGT-7.2 Pass Guaranteed Exam Dumps Certification Sample Questions

New NSE4_FGT-7.2 Test Materials & Valid NSE4_FGT-7.2 Test Engine


Fortinet NSE4_FGT-7.2 certification exam is suitable for network security professionals, including network administrators, security administrators, and system engineers. It is also ideal for IT professionals who want to demonstrate their expertise in Fortinet network security solutions. Fortinet NSE 4 - FortiOS 7.2 certification exam is designed to validate the abilities of professionals to deploy and manage Fortinet security solutions in complex network environments.

 

NEW QUESTION # 44
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

  • A. It limits the scanning of application traffic to the application category only.
  • B. It limits the scanning of application traffic to the DNS protocol only.
  • C. It limits the scanning of application traffic to use parent signatures only.
  • D. It limits the scanning of application traffic to the browser-based technology category only.

Answer: D

Explanation:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-mode


NEW QUESTION # 45
If Internet Service is already selected as Destination in a firewall policy, which other configuration object can be selected for the Destination field of a firewall policy?

  • A. IP address
  • B. No other object can be added
  • C. FQDN address
  • D. User or User Group

Answer: B

Explanation:
FortiGate Security 7.2 Study Guide (p.59): "When configuring your firewall policy, you can use Internet Service as the destination in a firewall policy, which contains all the IP addresses, ports, and protocols used by that service. For the same reason, you cannot mix regular address objects with ISDB objects, and you cannot select services on a firewall policy. The ISDB objects already have services information, which is hardcoded." This is true because Internet Service is a special type of destination object that can only be used alone in a firewall policy. Internet Service is a feature that allows FortiGate to identify and filter traffic based on the internet service or application that it belongs to, such as Facebook, YouTube, Skype, etc. Internet Service uses a database of IP addresses and ports that are associated with each internet service or application, and updates it regularly from FortiGuard. When Internet Service is selected as the destination in a firewall policy, FortiGate will match the traffic to the corresponding internet service or application, and apply the appropriate action and security profiles to it. However, Internet Service cannot be combined with any other destination object, such as IP address, FQDN address, user or user group, etc., as this would create a conflict or ambiguity in the firewall policy. Therefore, no other object can be added if Internet Service is already selected as the destination in a firewall policy


NEW QUESTION # 46
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)

  • A. auth-on-demand
  • B. soft-timeout
  • C. Idle-timeout
  • D. new-session
  • E. hard-timeout

Answer: C,D,E

Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221


NEW QUESTION # 47
If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy?

  • A. Once Internet Service is selected, no other object can be added
  • B. IP address
  • C. FQDN address
  • D. User or User Group

Answer: A


NEW QUESTION # 48
How does FortiGate act when using SSL VPN in web mode?

  • A. FortiGate acts as router.
  • B. FortiGate acts as an HTTP reverse proxy.
  • C. FortiGate acts as an FDS server.
  • D. FortiGate acts as DNS server.

Answer: B


NEW QUESTION # 49
Refer to the exhibit.

Based on the raw log, which two statements are correct? (Choose two.)

  • A. Log severity is set to error on FortiGate.
  • B. Traffic is blocked because Action is set to DENY in the firewall policy.
  • C. Traffic belongs to the root VDOM.
  • D. This is a security log.

Answer: B,D


NEW QUESTION # 50
Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)

  • A. Extended authentication (XAuth) for faster authentication because fewer packets are exchanged
  • B. No certificate is required on the remote peer when you set the certificate signature as the authentication method
  • C. Extended authentication (XAuth) to request the remote peer to provide a username and password
  • D. Pre-shared key and certificate signature as authentication methods

Answer: C,D

Explanation:
B) Extended authentication (XAuth) to request the remote peer to provide a username and password This is true because extended authentication (XAuth) is a feature that allows FortiGate to request the remote peer to provide a username and password during the IPsec IKEv1 authentication process. XAuth is an extension of the IKEv1 protocol that adds an additional authentication step after the main mode or aggressive mode exchange. XAuth can be used with either pre-shared key or certificate signature as the primary authentication method, and it can provide stronger security and granular access control for IPsec VPNs12 D) Pre-shared key and certificate signature as authentication methods This is true because pre-shared key and certificate signature are two authentication methods that are supported by FortiGate for IPsec IKEv1 VPNs. Pre-shared key is a method where both peers share a secret key that is used to authenticate each other during the IKEv1 exchange. Certificate signature is a method where both peers have digital certificates that are used to verify each other's identity and public key during the IKEv1 exchange. Both methods can be combined with XAuth for additional authentication


NEW QUESTION # 51
Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. Traffic matching the signature will be allowed and logged.
  • B. The signature setting includes a group of other signatures.
  • C. The signature setting uses a custom rating threshold.
  • D. Traffic matching the signature will be silently dropped and logged.

Answer: D

Explanation:
Select Block to silently drop traffic matching any of the signatures included in the entry. So, while the default action would be 'Pass' for this signature the administrator is specifically overriding that to set the Block action. To use the default action the setting would have to be 'Default'.
Action is drop, signature default action is listed only in the signature, it would only match if action was set to default.


NEW QUESTION # 52
An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)

  • A. Set the TTL value to never under config system-ttl
  • B. Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
  • C. Create a new service object for HTTP service and set the session TTL to never
  • D. Set the session TTL on the HTTP policy to maximum

Answer: A,C


NEW QUESTION # 53
Refer to the exhibit.

The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem .
With this configuration, which statement is true?

  • A. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
  • B. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
  • C. A static route is required on the To_Internet VDOM to allow LAN users to access the internet.
  • D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.

Answer: A


NEW QUESTION # 54
Which three criteria can a FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)

  • A. Source defined as Internet Services in the firewall policy.
  • B. Highest to lowest priority defined in the firewall policy.
  • C. Destination defined as Internet Services in the firewall policy.
  • D. Services defined in the firewall policy.
  • E. Lowest to highest policy ID number.

Answer: A,C,D

Explanation:
When a packet arrives, how does FortiGate find a matching policy? Each policy has match criteria, which you can define using the following objects:
* Incoming Interface
* Outgoing Interface
* Source: IP address, user, internet services
* Destination: IP address or internet services
* Service: IP protocol and port number
* Schedule: Applies during configured times


NEW QUESTION # 55
Refer to the exhibit.

Based on the raw log, which two statements are correct? (Choose two.)

  • A. Log severity is set to error on FortiGate.
  • B. Traffic is blocked because Action is set to DENY in the firewall policy.
  • C. Traffic belongs to the root VDOM.
  • D. This is a security log.

Answer: B,D


NEW QUESTION # 56
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?

  • A. get system arp
  • B. get system status
  • C. diagnose sys top
  • D. get system performance status

Answer: A

Explanation:
Explanation
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."


NEW QUESTION # 57
An administrator must disable RPF check to investigate an issue.
Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?

  • A. Enable asymmetric routing at the interface level.
  • B. Disable the RPF check at the FortiGate interface level for the source check.
  • C. Disable the RPF check at the FortiGate interface level for the reply check .
  • D. Enable asymmetric routing, so the RPF check will be bypassed.

Answer: B


NEW QUESTION # 58
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.

Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)

  • A. On both FortiGate devices, set Dead Peer Detection to On Demand.
  • B. On HQ-FortiGate, disable Diffie-Helman group 2.
  • C. On Remote-FortiGate, set port2 as Interface.
  • D. On HQ-FortiGate, set IKE mode to Main (ID protection).

Answer: C,D

Explanation:
"In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: main, and aggressive mode. Settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel."


NEW QUESTION # 59
Which scanning technique on FortiGate can be enabled only on the CLI?

  • A. Heuristics scan
  • B. Trojan scan
  • C. Ransomware scan
  • D. Antivirus scan

Answer: A


NEW QUESTION # 60
Refer to the exhibit.

The exhibit contains a network diagram, virtual IP, IP pool, and firewall policies configuration.
The WAN (port1) interface has the IP address 10.200. 1. 1/24.
The LAN (port3) interface has the IP address 10 .0.1.254. /24.
The first firewall policy has NAT enabled using IP Pool.
The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0. 1. 10?

  • A. 10.200. 1. 1
  • B. 10.200. 1. 100
  • C. 10.200.3. 1
  • D. 10.200. 1. 10

Answer: B

Explanation:
Explanation
Policy 1 is applied on outbound (LAN-WAN) and policy 2 is applied on inbound (WAN-LAN). question is asking SNAT for outbound traffic so policy 1 will take place and NAT overload is in effect.


NEW QUESTION # 61
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

  • A. It limits the scope of application control to scan application traffic using parent signatures only
  • B. It limits the scope of application control to scan application traffic based on application category only.
  • C. It limits the scope of application control to the browser-based technology category only.
  • D. It limits the scope of application control to scan application traffic on DNS protocol only.

Answer: B


NEW QUESTION # 62
Which timeout setting can be responsible for deleting SSL VPN associated sessions?

  • A. SSL VPN http-request-body-timeout
  • B. SSL VPN idle-timeout
  • C. SSL VPN login-timeout
  • D. SSL VPN dtls-hello-timeout

Answer: B

Explanation:
Reference:
The SSL VPN idle-timeout setting determines how long an SSL VPN session can be inactive before it is terminated. When an SSL VPN session becomes inactive (for example, if the user closes the VPN client or disconnects from the network), the session timer begins to count down. If the timer reaches the idle-timeout value before the user reconnects or sends any new traffic, the session will be terminated and the associated resources (such as VPN tunnels and virtual interfaces) will be deleted.


NEW QUESTION # 63
Which statement correctly describes the use of reliable logging on FortiGate?

  • A. Reliable logging prevents the loss of logs when the local disk is full.
  • B. Reliable logging is required to encrypt the transmission of logs.
  • C. Reliable logging can be configured only using the CLI.
  • D. Reliable logging is enabled by default in all configuration scenarios.

Answer: A

Explanation:
Explanation
On a FortiGate device, reliable logging is a feature that helps to prevent the loss of log messages when the local disk is full. When reliable logging is enabled, the FortiGate will store log messages in a buffer until they can be written to the local disk. This helps to ensure that log messages are not lost due to a full disk, allowing administrators to maintain an accurate record of activity on the network. Reliable logging is not enabled by default in all configuration scenarios, and it does not encrypt the transmission of logs or require the use of the CLI to be configured. However, it is a useful feature to enable in order to maintain a comprehensive record of activity on the network and help with troubleshooting and security analysis.


NEW QUESTION # 64
Refer to the exhibit.

Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)

  • A. The port3 default route has the lowest metric.
  • B. The port1 and port2 default routes are active in the routing table.
  • C. The port3 default route has the highest distance.
  • D. There will be eight routes active in the routing table.

Answer: B,C


NEW QUESTION # 65
......

NSE4_FGT-7.2 Sample with Accurate & Updated Questions: https://www.exam4labs.com/NSE4_FGT-7.2-practice-torrent.html

NSE4_FGT-7.2 Updated Exam Dumps [2023] Practice Valid Exam Dumps Question: https://drive.google.com/open?id=16zGy8NXBd7_XyFIOsC-2e-B2ShCkIZfH