Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part1 Q1-20

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 21

Which FortiGate feature provides centralized security intelligence, signatures, and reputation services to FortiGate devices?

  1. FortiManager
  2. FortiGuard
  3. FortiAnalyzer
  4. FortiSwitch

Correct Answer: 2

Explanation

FortiGuard provides Fortinet security services and threat intelligence that can be used by FortiGate devices. These services include security updates, application and web-filtering information, antivirus signatures, and other threat intelligence services, depending on the subscribed services and configuration. FortiManager is primarily used for centralized management of Fortinet devices, while FortiAnalyzer focuses on logging, analysis, and reporting. FortiSwitch provides switching functionality. Therefore, FortiGuard is the appropriate Fortinet service for delivering security intelligence and regularly updated security information to FortiGate devices.

Question 22

An administrator wants to upgrade FortiGate firmware while preserving the existing configuration. Which approach is appropriate?

  1. Factory reset the device first
  2. Delete the current configuration
  3. Perform a supported firmware upgrade
  4. Replace all firewall policies

Correct Answer: 3

Explanation

A supported firmware upgrade allows administrators to move FortiGate to a newer compatible firmware version while normally retaining the existing configuration. Before performing the upgrade, administrators should verify compatibility, review the release notes, and create a configuration backup. A factory reset or deleting policies would unnecessarily remove the existing configuration. Replacing firewall policies is also not a standard requirement for a firmware upgrade. Therefore, the appropriate approach is to perform a supported firmware upgrade after completing the recommended preparation and backup procedures.

Question 23

Which FortiGate log type records information about allowed and denied network traffic processed by firewall policies?

  1. Traffic logs
  2. Event logs
  3. System logs
  4. Security rating logs

Correct Answer: 1

Explanation

Traffic logs record information about network sessions processed by FortiGate firewall policies. Depending on the configured logging settings, these records can include source and destination addresses, ports, interfaces, policy identifiers, actions, bytes, and session information. Event logs focus on administrative and system-related events, while security rating information is associated with security assessment capabilities. System logs provide information about system operations and activities. Therefore, when an administrator needs to investigate whether traffic was allowed or denied by a firewall policy, traffic logs are the most relevant log type.

Question 24

Which FortiGate setting determines whether an administrator can access the GUI through a particular interface?

  1. Administrative distance
  2. Interface administrative access
  3. Security profile
  4. Session TTL

Correct Answer: 2

Explanation

Interface administrative access controls which management protocols are permitted on a FortiGate interface. Depending on the configuration, protocols such as HTTPS, SSH, PING, or other supported management services can be enabled or disabled. This setting helps administrators restrict management access to trusted interfaces and reduce unnecessary exposure. Administrative distance is related to route selection, security profiles inspect traffic, and session TTL controls session lifetime. Therefore, interface administrative access is the setting that determines whether administrators can use the GUI or other management protocols through a particular interface.

Question 25

Which FortiGate HA mode is designed to provide device redundancy by electing one unit as primary while another remains available for failover?

  1. Active-passive
  2. Load balance
  3. Transparent
  4. Standalone

Correct Answer: 1

Explanation

An active-passive HA configuration uses one FortiGate unit as the primary device while another unit remains available to take over if the primary fails. The cluster uses FGCP mechanisms to monitor members and determine which device should provide active traffic processing. During a failover, the secondary unit can become primary according to the configured HA behavior. Load balancing describes traffic distribution rather than the standard active-passive model, while transparent and standalone are not HA modes that describe this redundancy relationship. Therefore, active-passive is correct.

Question 26

Which FortiGate feature can restrict access to websites based on categories such as social networking, gambling, or malicious sites?

  1. Web Filter
  2. Antivirus
  3. IPS
  4. Traffic Shaping

Correct Answer: 1

Explanation

Web Filter can control access to websites according to URL categories, ratings, domains, and other web-related criteria. FortiGate can use FortiGuard web-filtering services to classify websites into categories and then apply actions such as allow, block, monitor, or warning according to the configured profile. Antivirus is primarily focused on malware detection, IPS protects against network attacks, and Traffic Shaping manages bandwidth usage. Therefore, Web Filter is the appropriate security profile when administrators need to control website access based on categories.

Question 27

Which FortiGate authentication method uses a one-time password delivered through a FortiToken?

  1. LDAP authentication
  2. Local authentication
  3. Two-factor authentication
  4. Certificate authentication

Correct Answer: 3

Explanation

Two-factor authentication can combine a user’s primary authentication method, such as a password, with a one-time password generated by or delivered through a FortiToken. This provides an additional verification factor beyond the user’s password and can significantly strengthen administrative or user authentication. LDAP and local authentication primarily identify users through stored or directory-based credentials, while certificate authentication relies on digital certificates. Therefore, two-factor authentication using FortiToken is the appropriate method when a one-time password is required as an additional authentication factor.

Question 28

Which FortiGate object groups multiple IP addresses or subnet objects so they can be referenced together in a firewall policy?

  1. Service group
  2. Address group
  3. IP pool
  4. Virtual IP

Correct Answer: 2

Explanation

An address group allows administrators to combine multiple address objects into a single logical group. The group can then be referenced in firewall policies and other configurations instead of selecting every individual address separately. This makes policy management easier, especially in environments containing many networks or hosts. A service group combines service objects such as TCP or UDP ports, an IP pool provides addresses for source NAT, and a Virtual IP is commonly used for destination NAT. Therefore, an address group is the correct object.

Question 29

Which FortiGate firewall policy setting determines whether traffic matching the policy is permitted or denied?

  1. Action
  2. Schedule
  3. Service
  4. Log setting

Correct Answer: 1

Explanation

The Action setting determines what FortiGate does with traffic that matches a firewall policy. Common actions include Accept and Deny. When the action is Accept, FortiGate permits the traffic and can apply configured security profiles, NAT, logging, and other processing. When the action is Deny, the matching traffic is blocked. Schedule controls when a policy is active, Service identifies protocols or ports, and logging controls whether relevant events are recorded. Therefore, Action is the setting that determines whether matching traffic is permitted or denied.

Question 30

Which authentication server protocol is commonly used to authenticate users against Microsoft Active Directory through a directory service?

  1. RADIUS
  2. TACACS+
  3. LDAP
  4. SNMP

Correct Answer: 4

Explanation

LDAP is a directory access protocol commonly used to communicate with directory services such as Microsoft Active Directory. FortiGate can be configured with an LDAP server and use directory information for supported authentication scenarios. LDAP can provide access to users and groups stored in a centralized directory. RADIUS and TACACS+ are authentication protocols with different architectures and common use cases, while SNMP is primarily intended for network monitoring and management. Therefore, LDAP is the appropriate protocol when FortiGate needs to communicate directly with a directory service.

Question 31

Which FortiGate setting controls the maximum amount of time a TCP session can remain idle before it is removed from the session table?

  1. Session TTL
  2. Administrative distance
  3. IP pool
  4. Firewall priority

Correct Answer: 1

Explanation

Session TTL, or time-to-live, controls how long a session can remain in the FortiGate session table according to the relevant timeout settings. When a session remains inactive beyond its configured timeout, FortiGate can remove it from the session table. This helps manage session resources and prevents inactive sessions from remaining indefinitely. Administrative distance is used in route selection, IP pools provide addresses for NAT, and firewall policy priority affects policy matching order. Therefore, Session TTL is the setting associated with session timeout behavior.

Question 32

Which FortiGate feature provides detailed reports and analysis based on logs collected from FortiGate devices?

  1. FortiToken
  2. FortiAnalyzer
  3. FortiSwitch
  4. FortiExtender

Correct Answer: 2

Explanation

FortiAnalyzer is designed to collect, store, analyze, and report on logs generated by Fortinet devices such as FortiGate. It provides centralized visibility into traffic, security events, system activity, and other logged information. Administrators can use FortiAnalyzer to investigate events and create reports based on collected data. FortiToken is used for authentication, FortiSwitch provides switching capabilities, and FortiExtender can provide connectivity and WAN extension functionality. Therefore, FortiAnalyzer is the appropriate solution for centralized log analysis and reporting.

Question 33

Which firewall policy field specifies the source network or address from which traffic is allowed or denied?

  1. Source
  2. Destination
  3. Service
  4. Action

Correct Answer: 1

Explanation

The Source field in a FortiGate firewall policy identifies the originating address, network, or address group that the policy should match. Administrators can use source address objects to control which hosts or networks are permitted to access a destination. The Destination field identifies where the traffic is going, Service defines protocols and ports, and Action determines whether matching traffic is accepted or denied. Therefore, the Source field is the correct choice when a policy needs to match traffic originating from a specific network or address.

Question 34

Which routing protocol is commonly used to exchange routing information dynamically between routers within an enterprise network?

  1. BGP
  2. RIP
  3. OSPF
  4. DHCP

Correct Answer: 3

Explanation

OSPF is a dynamic interior gateway routing protocol commonly used within enterprise networks. It allows routers and FortiGate devices to exchange information about reachable networks and automatically calculate appropriate paths. OSPF uses areas and link-state information to build a view of the network topology. BGP is commonly used for inter-domain routing and large-scale network connectivity, while RIP is an older distance-vector protocol. DHCP provides IP configuration rather than dynamic routing. Therefore, OSPF is the appropriate choice for dynamic routing within many enterprise networks.

Question 35

Which FortiGate VPN component defines the parameters used to establish an IPsec tunnel, including authentication and encryption settings?

  1. Firewall policy
  2. Phase 1 configuration
  3. Address group
  4. Static route

Correct Answer: 4

Explanation

An IPsec VPN uses Phase 1 and Phase 2 configurations to establish and secure the tunnel. Phase 1 defines parameters used to establish the initial secure association, including authentication, encryption, and key-exchange settings. Phase 2 defines the parameters for the IPsec security associations that protect actual traffic. A firewall policy controls permitted traffic, an address group organizes address objects, and a static route determines forwarding. Therefore, the correct answer is Phase 1 configuration, which establishes the initial IPsec negotiation parameters.

Question 36

Which FortiGate feature can limit the bandwidth available to specific types of network traffic?

  1. Traffic Shaping
  2. Web Filter
  3. Application Control
  4. DHCP

Correct Answer: 3

Explanation

Traffic Shaping controls bandwidth consumption by applying configured limits or priorities to network traffic. It can be used to prevent particular applications, services, or traffic categories from consuming excessive bandwidth and affecting other users. Web Filter controls website access, Application Control identifies and manages applications, and DHCP provides IP configuration to clients. Traffic shaping policies can be associated with firewall policies and configured according to organizational bandwidth requirements. Therefore, Traffic Shaping is the appropriate FortiGate feature for controlling available bandwidth.

Question 37

Which FortiGate log storage option stores logs locally on the FortiGate device when supported by the platform?

  1. FortiAnalyzer
  2. Syslog server
  3. Local disk
  4. FortiManager

Correct Answer: 2

Explanation

A Syslog server is an external log destination that receives log messages from FortiGate over the network. Local disk, when supported by the FortiGate model, provides local storage for logs directly on the device. FortiAnalyzer is a dedicated platform for centralized log storage and analysis, while FortiManager is primarily focused on centralized device management and configuration. Therefore, the correct answer is Local disk, which is option 3. Administrators should verify the specific FortiGate model and available storage options when configuring local logging.

Question 38

Which FortiGate feature allows different administrative users to receive different permissions for managing the device?

  1. Administrator profiles
  2. IPsec Phase 2
  3. Security profiles
  4. Service groups

Correct Answer: 4

Explanation

Administrator profiles define the permissions and access levels available to FortiGate administrators. Different profiles can provide varying privileges for system settings, firewall configuration, monitoring, VPN configuration, and other administrative functions. This supports the principle of least privilege by ensuring administrators receive only the permissions required for their responsibilities. IPsec Phase 2 defines VPN security associations, security profiles inspect network traffic, and service groups organize protocol and port objects. Therefore, administrator profiles are the appropriate mechanism for controlling administrative permissions.

Question 39

Which FortiGate feature can automatically select a route based on configured performance requirements for an SD-WAN service?

  1. SD-WAN rule
  2. Address object
  3. DHCP relay
  4. Security profile

Correct Answer: 1

Explanation

An SD-WAN rule determines how FortiGate selects SD-WAN members for matching traffic. Rules can use configured criteria and performance information such as latency, jitter, or packet loss when performance-based steering is configured. This allows applications or services to use WAN links according to defined requirements rather than relying solely on conventional routing. Address objects identify network endpoints, DHCP relay forwards DHCP requests, and security profiles inspect traffic. Therefore, an SD-WAN rule is the appropriate feature for selecting paths based on configured SD-WAN requirements.

Question 40

Which FortiGate feature can provide a graphical representation of interfaces, routes, policies, and other network information for troubleshooting?

  1. CLI console
  2. Network topology
  3. Packet capture
  4. Policy package

Correct Answer: 1

Explanation

The CLI console provides administrators with direct command-line access to FortiGate configuration and troubleshooting commands. It can be used to inspect interfaces, routing information, firewall policies, sessions, and many other operational details. Network topology provides a visual representation of connected network elements, but it is not the primary command-line troubleshooting interface. Packet capture focuses specifically on captured network packets, while a policy package is a collection of policies managed in centralized environments. Therefore, the CLI console is the appropriate choice among these options for direct troubleshooting and inspection.