View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 41
Which FortiGate feature allows administrators to divide a physical FortiGate into multiple independent virtual firewalls?
- VDOM
- HA
- SD-WAN
- FortiLink
Correct Answer: 1
Explanation
Virtual Domains, or VDOMs, allow a single FortiGate device to be divided into multiple logical firewall instances. Each VDOM can have its own interfaces, routing configuration, firewall policies, administrators, and security settings, depending on the configuration. This is useful when organizations need to separate networks, departments, customers, or security environments while using one physical FortiGate. HA provides device redundancy, SD-WAN manages WAN connectivity, and FortiLink integrates supported FortiSwitch devices. Therefore, VDOM is the correct feature for creating multiple independent virtual firewalls.
Question 42
Which setting determines the order in which FortiGate firewall policies are evaluated for matching traffic?
- Policy ID
- Policy sequence
- Policy comment
- Policy logging
Correct Answer: 2
Explanation
FortiGate evaluates firewall policies according to their sequence in the policy list. When traffic enters an interface, FortiGate evaluates policies from the top toward the bottom and uses the first policy that matches the relevant traffic criteria. Therefore, placing a more specific policy above a broader policy can be important to ensure the intended rule is matched. The policy ID identifies the policy, comments provide administrative information, and logging controls event recording. Therefore, policy sequence is the key factor determining evaluation order.
Question 43
Which FortiGate feature allows administrators to define reusable TCP, UDP, or other protocol and port combinations for firewall policies?
- Address object
- Service object
- IP pool
- Virtual IP
Correct Answer: 2
Explanation
A service object defines network services, protocols, and port information that can be reused in FortiGate firewall policies. For example, administrators can use predefined or custom service objects to permit HTTPS, SSH, DNS, or specific TCP and UDP port ranges. Address objects identify hosts and networks, IP pools provide addresses for source NAT, and Virtual IP objects are commonly used for destination NAT. Using service objects makes firewall policies easier to manage because the same service definition can be referenced by multiple policies. Therefore, Service object is correct.
Question 44
Which FortiGate configuration can prevent an administrator from logging in through an interface using HTTPS?
- Disabled HTTPS administrative access
- Static route
- DNS filter
- IPsec Phase 2
Correct Answer: 1
Explanation
HTTPS is one of the administrative access protocols that can be enabled or disabled separately on FortiGate interfaces. If HTTPS administrative access is disabled on an interface, administrators cannot use the FortiGate GUI through that interface using HTTPS. This provides an important method for limiting management access to trusted interfaces. Static routes control packet forwarding, DNS filters control DNS-based access, and IPsec Phase 2 defines VPN security association parameters. Therefore, disabling HTTPS administrative access is the appropriate configuration when GUI access through an interface must be prevented.
Question 45
Which FortiGate feature can associate a firewall policy with a specific period during which the policy is active?
- Schedule
- Service
- Action
- NAT
Correct Answer: 1
Explanation
A firewall policy Schedule determines when the policy is active. Administrators can use schedules to allow or deny specific types of traffic only during defined periods, such as business hours or maintenance windows. A policy can use predefined schedules or custom schedules depending on the required configuration. Service identifies protocols and ports, Action determines whether matching traffic is accepted or denied, and NAT controls address translation behavior. Therefore, Schedule is the correct firewall policy setting when access needs to be restricted according to time.
Question 46
Which FortiGate feature can provide a second authentication factor for an administrator using a FortiToken Mobile code?
- Local user database
- LDAP
- Two-factor authentication
- RADIUS accounting
Correct Answer: 3
Explanation
Two-factor authentication provides an additional authentication requirement beyond the primary password. When FortiToken Mobile is configured, a user can be required to provide a time-based one-time password in addition to the normal authentication credentials. This reduces the risk associated with compromised passwords because possession of the additional authentication factor is also required. A local user database stores credentials, LDAP provides directory-based authentication, and RADIUS accounting records authentication-related information. Therefore, two-factor authentication is the appropriate mechanism for using FortiToken Mobile codes.
Question 47
Which FortiGate command is commonly used to display the routing table from the CLI?
- get router info routing-table all
- diagnose firewall policy list
- diagnose sys session list
- get system status
Correct Answer: 1
Explanation
The get router info routing-table all command displays the FortiGate routing table and provides information about routes known to the device. It can help administrators determine which routes are available and investigate problems where traffic is not reaching the expected destination. The firewall policy command is used for policy information, session commands display active sessions, and get system status provides general system information. Therefore, get router info routing-table all is the appropriate CLI command when an administrator needs to inspect the routing table.
Question 48
Which FortiGate feature can block websites according to their URL category and FortiGuard classification?
- Application Control
- IPS
- Web Filter
- Antivirus
Correct Answer: 3
Explanation
Web Filter can use URL categories and FortiGuard classification information to control access to websites. Administrators can configure actions such as allow, block, monitor, or warning for different categories depending on organizational requirements. Application Control focuses on identifying and controlling applications, IPS detects network attacks and exploits, and Antivirus detects malicious files or content. Web filtering is therefore the appropriate security profile when website access needs to be controlled based on categories or URL classifications. This profile can be applied through an appropriate firewall policy.
Question 49
Which FortiGate feature can identify applications even when the applications do not use their commonly associated TCP or UDP ports?
- Static routing
- Application Control
- DHCP
- IP pool
Correct Answer: 2
Explanation
Application Control uses application signatures and traffic characteristics to identify supported applications rather than relying exclusively on their commonly associated port numbers. This allows administrators to control applications even when traffic uses unexpected ports or protocols, subject to FortiGate’s inspection capabilities. Static routing determines network paths, DHCP provides network configuration, and IP pools provide addresses for source NAT. Therefore, Application Control is the appropriate FortiGate feature for identifying and controlling network applications based on application signatures and traffic behavior.
Question 50
Which FortiGate inspection method decrypts HTTPS traffic so that the security engine can inspect the actual encrypted payload?
- Certificate inspection
- DNS inspection
- Deep inspection
- Header inspection
Correct Answer: 3
Explanation
Deep inspection decrypts supported SSL/TLS traffic so FortiGate can inspect the underlying content using applicable security profiles. Because encrypted traffic is decrypted and re-encrypted, client devices generally need to trust the appropriate FortiGate certificate authority to avoid certificate warnings. Certificate inspection, in contrast, examines certificate and handshake information without fully decrypting the application payload. DNS inspection operates on DNS traffic rather than decrypting HTTPS content. Therefore, Deep inspection is the appropriate method when the actual encrypted payload needs to be inspected.
Question 51
Which FortiGate feature is used to define users and groups locally on the firewall?
- User & Authentication
- Routing Monitor
- FortiView
- Network Interfaces
Correct Answer: 1
Explanation
The User & Authentication configuration area allows administrators to create and manage local users and user groups on FortiGate. These users can then be associated with authentication methods and referenced by appropriate firewall policies or other security configurations. Routing Monitor is used to inspect routing information, FortiView provides operational visibility and traffic analytics, and Network Interfaces manages interface configuration. Local users are useful when an external authentication service is not required or when specific local accounts are needed. Therefore, User & Authentication is the correct choice.
Question 52
Which FortiGate feature can show real-time information about traffic, applications, threats, and network activity through graphical views?
- CLI
- FortiView
- Static route
- DHCP server
Correct Answer: 2
Explanation
FortiView provides graphical and interactive visibility into traffic, applications, users, destinations, security events, and other operational information available from the FortiGate. It helps administrators quickly investigate current network activity and identify unusual or important traffic patterns. The CLI provides command-line configuration and troubleshooting, while static routes determine forwarding paths and DHCP servers provide network configuration to clients. Therefore, FortiView is the appropriate FortiGate feature for graphical visibility into current traffic and security activity.
Question 53
Which FortiGate function can match traffic against a predefined database of Internet services and destinations?
- Internet Service Database
- DHCP relay
- Address group
- IP pool
Correct Answer: 1
Explanation
The Internet Service Database, or ISDB, contains predefined information about Internet services and destinations that FortiGate can use in firewall policies. Instead of manually maintaining individual IP addresses for supported services, administrators can reference appropriate Internet Service objects when creating policies. This can simplify policy management for well-known Internet services and destinations. DHCP relay forwards DHCP requests, address groups combine address objects, and IP pools provide source addresses for NAT. Therefore, Internet Service Database is the correct feature for matching supported Internet services and destinations.
Question 54
Which FortiGate command is useful for viewing active sessions and their source and destination information?
- diagnose debug application
- diagnose sys session list
- execute reboot
- get system interface
Correct Answer: 4
Explanation
The diagnose sys session list command displays information about active sessions in the FortiGate session table. Administrators can use this information during troubleshooting to examine source and destination addresses, ports, interfaces, policies, and session states. This can help determine whether traffic is creating a session and how FortiGate is processing that traffic. execute reboot restarts the device and should not be used for routine traffic inspection. Therefore, diagnose sys session list is the appropriate command for examining active sessions.
Question 55
Which FortiGate feature can automatically obtain an IP address and other network parameters from an upstream DHCP server?
- DHCP client
- DHCP server
- DNS server
- Static addressing
Correct Answer: 1
Explanation
A DHCP client allows a FortiGate interface to obtain network configuration information automatically from an upstream DHCP server. Depending on the DHCP service, the interface can receive information such as an IP address, subnet mask, default gateway, and DNS information. A DHCP server performs the opposite role by assigning addresses to downstream clients. DNS server functionality handles name-resolution services, while static addressing requires an administrator to configure the values manually. Therefore, DHCP client is the correct choice when an interface must obtain its address dynamically.
Question 56
Which FortiGate VPN component defines the traffic selectors and IPsec security parameters used to protect data through the tunnel?
- Phase 1
- Phase 2
- Static route
- Firewall schedule
Correct Answer: 2
Explanation
IPsec Phase 2 defines the security association parameters used to protect data traffic through an established VPN tunnel. It includes settings such as encryption and authentication algorithms and traffic selectors that determine which traffic is protected. Phase 1 establishes the initial secure association and negotiates the parameters required to create the tunnel. Static routes determine how traffic reaches a destination, while firewall schedules control when policies are active. Therefore, Phase 2 is the correct IPsec component for defining protected traffic and its associated security parameters.
Question 57
Which FortiGate security profile is primarily used to detect malicious files such as viruses and trojans?
- Web Filter
- Application Control
- Antivirus
- IPS
Correct Answer: 3
Explanation
The Antivirus security profile is designed to detect and block malware such as viruses, trojans, worms, and other malicious content within supported traffic. FortiGate uses antivirus engines and signatures to identify known threats and can apply configured actions when suspicious or malicious content is detected. Web Filter controls websites and URLs, Application Control identifies and manages applications, and IPS focuses on network exploits and intrusion attempts. Therefore, Antivirus is the appropriate security profile when the primary requirement is detecting and preventing malicious files.
Question 58
Which FortiGate routing feature can distribute traffic across multiple available paths when configured for load balancing?
- Route redundancy and load balancing
- Web filtering
- Certificate inspection
- User authentication
Correct Answer: 4
Explanation
Route redundancy and load-balancing mechanisms can allow FortiGate to use multiple available paths according to the configured routing design. This can improve resilience and, in appropriate scenarios, distribute traffic among paths instead of relying exclusively on one route. Web filtering controls website access, certificate inspection examines TLS certificate information, and user authentication verifies identities. Routing decisions depend on the available routes and their attributes. Therefore, route redundancy and load balancing is the appropriate choice when multiple paths need to be used for resilient or distributed forwarding.
Question 59
Which FortiGate feature can provide a warning or block users when they attempt to access websites classified under restricted categories?
- Traffic shaping
- Web Filter
- Static routing
- Session helper
Correct Answer: 2
Explanation
Web Filter can apply actions to websites according to their URL or FortiGuard category classification. Depending on the configured profile, FortiGate can allow access, block the request, monitor it, or display a warning to the user. This allows organizations to implement acceptable-use policies and reduce access to inappropriate or risky web destinations. Traffic shaping controls bandwidth, static routing determines packet forwarding, and session helpers support specific protocol handling. Therefore, Web Filter is the appropriate feature for warning or blocking users based on website categories.
Question 60
Which FortiGate feature allows administrators to restore a previously saved configuration after a configuration problem?
- Configuration restore
- Traffic shaping
- Policy lookup
- Application signature update
Correct Answer: 1
Explanation
Configuration restore allows an administrator to load a previously saved FortiGate configuration file when recovery is required. This can be useful after an incorrect configuration change, failed maintenance operation, or other situation where returning to a known configuration is necessary. Administrators should maintain appropriate backups and verify that the backup corresponds to the intended FortiOS version and device environment. Traffic shaping controls bandwidth, policy lookup assists with policy troubleshooting, and application signature updates provide updated application identification information. Therefore, Configuration restore is the correct choice.