View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 101
Which FortiGate feature can identify and control applications by using application signatures?
- Application Control
- DNS Filter
- IPS
- DHCP
Correct Answer: 1
Explanation
Application Control identifies network applications using application signatures and related detection mechanisms. Administrators can create an Application Control profile and apply actions to selected applications or categories through firewall policies. This allows FortiGate to control applications even when they do not consistently use a single network port. DNS Filter focuses on DNS requests, IPS detects network attacks, and DHCP provides IP configuration. Therefore, Application Control is the appropriate FortiGate feature when an administrator needs to identify and control network applications based on their signatures.
Question 102
Which FortiGate feature allows administrators to save a copy of the current configuration for later restoration?
- FortiView
- Configuration backup
- Traffic shaping
- Web Filter
Correct Answer: 2
Explanation
Configuration backup allows administrators to save the FortiGate configuration so it can be restored later if necessary. Backups are particularly useful before firmware upgrades, major configuration changes, or troubleshooting activities because they provide a recovery point. FortiView displays traffic and security information, Traffic Shaping manages bandwidth, and Web Filter controls web access. A properly maintained configuration backup can help reduce recovery time after an unexpected configuration problem. Therefore, Configuration backup is the correct feature for preserving the current FortiGate configuration.
Question 103
Which FortiGate routing value is used to determine the preference of routes learned from different routing sources?
- Administrative distance
- Session TTL
- Priority queue
- Firewall action
Correct Answer: 1
Explanation
Administrative distance is used to determine the preference of routes learned from different routing sources. When multiple routes to the same destination are available through different routing mechanisms, FortiGate uses routing attributes including administrative distance as part of the route-selection process. A route with a more preferred administrative distance can be selected over another route to the same destination, subject to the routing process. Session TTL controls session lifetime, priority queues relate to traffic handling, and firewall action controls policy decisions. Therefore, Administrative distance is the correct answer.
Question 104
Which FortiGate object is used to represent a collection of IP addresses that can be referenced in a firewall policy?
- Service group
- Address group
- User group
- Interface zone
Correct Answer: 2
Explanation
An address group combines multiple address objects into one logical object that can be referenced by firewall policies and other supported configurations. This makes policy management easier because administrators can manage several related networks or hosts through one reusable object. Service groups contain service definitions, user groups organize authenticated users, and interface zones group interfaces. For example, several internal server addresses can be combined into an address group and used as the destination in a policy. Therefore, Address group is the correct answer.
Question 105
Which FortiGate security feature can use FortiGuard services to classify websites according to content categories?
- Application Control
- IPS
- Web Filter
- Antivirus
Correct Answer: 3
Explanation
Web Filter can use FortiGuard web-rating services to classify websites into categories and apply configured actions to web requests. Administrators can allow, block, monitor, or otherwise handle websites based on their assigned categories and filtering configuration. Application Control focuses on applications, IPS detects network attacks, and Antivirus scans supported traffic for malicious content. FortiGuard categorization can help organizations enforce acceptable-use policies and reduce exposure to unwanted or harmful websites. Therefore, Web Filter is the appropriate feature for category-based website classification and control.
Question 106
Which FortiGate authentication method can verify users against an external RADIUS server?
- Local authentication
- RADIUS
- FSSO
- Certificate inspection
Correct Answer: 2
Explanation
RADIUS allows FortiGate to authenticate users against an external RADIUS server. This can centralize authentication and allow FortiGate to use an existing authentication infrastructure rather than maintaining all user credentials locally. The RADIUS server receives authentication requests and returns the appropriate response based on its configuration. Local authentication uses accounts stored directly on FortiGate, FSSO provides user identity information through supported single sign-on mechanisms, and certificate inspection handles certificate-related traffic inspection. Therefore, RADIUS is the correct authentication method for an external RADIUS server.
Question 107
Which FortiGate troubleshooting tool provides detailed information about how packets are processed by firewall policies and routing?
- Debug flow
- FortiView
- Traffic log
- System dashboard
Correct Answer: 1
Explanation
Debug flow provides detailed information about packet processing inside FortiGate. It can help administrators determine how traffic is routed, which firewall policy is matched, and why a packet may be accepted or denied. This makes it especially useful when normal logs do not provide enough detail to diagnose a connectivity problem. FortiView provides visual traffic information, traffic logs record session information, and the system dashboard displays general device status. Therefore, Debug flow is the appropriate troubleshooting tool for examining detailed packet-processing decisions.
Question 108
Which FortiGate feature allows administrators to define a destination NAT mapping from a public IP address to an internal server?
- IP pool
- Virtual IP
- Service group
- Loopback interface
Correct Answer: 2
Explanation
A Virtual IP, commonly called a VIP, defines a destination NAT mapping that can translate an external address to an internal address. VIPs are frequently used when internal servers must be reachable through selected public IP addresses or ports. They can also be configured for port forwarding when only specific services should be exposed. IP pools are primarily associated with source NAT, service groups combine service objects, and loopback interfaces provide logical interfaces. Therefore, Virtual IP is the correct FortiGate feature for destination NAT to an internal server.
Question 109
Which FortiGate feature can provide centralized log storage, analysis, and reporting for multiple Fortinet devices?
- FortiView
- FortiAnalyzer
- FortiToken
- FortiGuard
Correct Answer: 2
Explanation
FortiAnalyzer provides centralized log collection, analysis, reporting, and related management capabilities for Fortinet devices. Organizations can use it to consolidate logs from multiple FortiGate devices and analyze security or traffic events from a central location. FortiView provides visibility directly on FortiGate, FortiToken supports multi-factor authentication, and FortiGuard provides various security and intelligence services. Centralized log management can make investigations and reporting more efficient when many devices are deployed. Therefore, FortiAnalyzer is the correct solution for centralized Fortinet log storage and analysis.
Question 110
Which FortiGate HA mode uses one primary unit to actively process traffic while another unit is available to take over after a failure?
- Active-active
- Load-balanced mode
- Active-passive
- Standalone
Correct Answer: 3
Explanation
In an active-passive HA configuration, one FortiGate unit operates as the primary device and processes network traffic, while another unit remains available to take over when the primary unit fails. This provides redundancy and helps maintain network availability during hardware or system problems. Active-active HA can involve multiple units processing traffic depending on the configuration and platform capabilities. Load-balanced mode is not the standard FortiGate HA mode name, while standalone means the device is not operating as part of an HA cluster. Therefore, Active-passive is correct.
Question 111
Which FortiGate feature allows administrators to define a recurring time period during which a firewall policy is active?
- Schedule
- Service group
- Address group
- IP pool
Correct Answer: 1
Explanation
A firewall policy schedule determines when the policy is active. Administrators can configure schedules such as always-active or recurring time periods and then assign them to firewall policies. This allows organizations to restrict certain types of access to particular hours, days, or operational periods. Service groups combine protocol and port definitions, address groups combine address objects, and IP pools provide addresses for source NAT. Therefore, Schedule is the correct feature when a firewall policy needs to operate only during specified recurring periods.
Question 112
Which FortiGate feature can enforce bandwidth limits on selected traffic?
- Web Filter
- Antivirus
- Traffic Shaping
- DNS Filter
Correct Answer: 3
Explanation
Traffic Shaping controls the amount of bandwidth available to selected traffic. Administrators can use traffic-shaping policies or profiles to manage bandwidth consumption and help ensure that important applications or users receive appropriate network resources. This can be useful when high-bandwidth applications might otherwise consume excessive capacity. Web Filter controls web access, Antivirus scans for malicious content, and DNS Filter controls DNS requests. Therefore, Traffic Shaping is the appropriate FortiGate feature for controlling or limiting bandwidth consumption for selected traffic.
Question 113
Which FortiGate VPN component establishes the security associations used to protect actual user data?
- Phase 1
- IKE negotiation
- Phase 2
- Firewall policy
Correct Answer: 3
Explanation
IPsec Phase 2 establishes the security associations used to protect the actual data traffic passing through the VPN tunnel. During Phase 2 negotiation, the peers agree on parameters such as encryption, authentication, and traffic selectors for the IPsec security association. Phase 1 establishes the initial secure IKE relationship between the peers. Firewall policies determine whether traffic is permitted through FortiGate, while IKE negotiation encompasses the broader key-management process. Therefore, Phase 2 is the correct component for establishing the security associations that protect user data.
Question 114
Which FortiGate setting can determine the preference between multiple routes that have the same destination and routing protocol?
- Session timeout
- Route priority
- Web category
- Security action
Correct Answer: 2
Explanation
Route priority is used as part of FortiGate’s route-selection process when comparing routes that meet the relevant destination criteria. Administrators can configure route attributes so that one available path is preferred over another when multiple routes exist. Session timeout controls the duration of sessions, web categories are used by web filtering, and security action determines how inspected traffic is handled. Understanding route preference is important when troubleshooting situations where FortiGate appears to select a path different from the one expected. Therefore, Route priority is the correct answer.
Question 115
Which FortiGate feature can authenticate administrators or users using a digital certificate?
- Certificate-based authentication
- Traffic shaping
- DNS filtering
- Static routing
Correct Answer: 1
Explanation
Certificate-based authentication uses digital certificates to verify the identity of a user or system. Certificates can provide a stronger authentication mechanism by relying on cryptographic credentials rather than only passwords. The certificate must be issued and trusted according to the configured certificate infrastructure and authentication requirements. Traffic Shaping controls bandwidth, DNS Filtering controls DNS requests, and static routing determines network paths. Therefore, Certificate-based authentication is the appropriate choice when digital certificates are used as the authentication mechanism.
Question 116
Which FortiGate feature can detect malicious or suspicious network traffic using intrusion prevention signatures?
- Web Filter
- Antivirus
- IPS
- DHCP
Correct Answer: 3
Explanation
The Intrusion Prevention System, or IPS, uses signatures and other detection mechanisms to identify known network attacks and suspicious traffic patterns. An IPS profile can be applied through a firewall policy so that matching traffic is inspected and handled according to configured actions. Web Filter controls website access, Antivirus focuses on malicious files and supported content, and DHCP assigns network configuration. IPS is therefore the appropriate FortiGate security feature when the goal is to detect network-based attacks using intrusion prevention signatures and related inspection mechanisms.
Question 117
Which FortiGate command is commonly used to display the routing table and help verify the routes currently known to the device?
- get system status
- get router info routing-table all
- diagnose vpn tunnel list
- diagnose debug flow
Correct Answer: 2
Explanation
The get router info routing-table all command displays the FortiGate routing table and provides information about routes known to the device. It is useful for troubleshooting connectivity problems and verifying whether a destination has an appropriate route. Administrators can use the output to inspect route sources, destination networks, gateways, interfaces, and related routing information. get system status displays general system information, diagnose vpn tunnel list focuses on VPN tunnels, and debug flow examines packet processing. Therefore, the routing-table command is correct.
Question 118
Which FortiGate feature can provide multi-factor authentication by requiring an additional authentication factor beyond a password?
- Web Filter
- FortiView
- FortiToken
- Traffic Shaping
Correct Answer: 3
Explanation
FortiToken can be used as an additional authentication factor in supported FortiGate authentication configurations. Multi-factor authentication improves account security by requiring users to provide another verification factor in addition to their primary credentials. This can help reduce the impact of compromised passwords. Web Filter controls web access, FortiView provides visibility into traffic and security activity, and Traffic Shaping manages bandwidth. Therefore, FortiToken is the appropriate choice when an administrator needs an additional authentication factor for supported FortiGate access.
Question 119
Which FortiGate inspection method can decrypt and inspect HTTPS traffic by using a FortiGate-generated certificate for the destination?
- Certificate inspection
- Flow-based inspection
- Deep inspection
- DNS inspection
Correct Answer: 3
Explanation
Deep inspection can decrypt supported HTTPS traffic so FortiGate can inspect the underlying content using security profiles. During this process, FortiGate can generate certificates for inspected destinations, and client devices must trust the appropriate certificate authority to avoid certificate warnings. Certificate inspection examines certificate information without fully decrypting the protected content, while flow-based inspection refers to a broader inspection approach and DNS inspection focuses on DNS traffic. Therefore, Deep inspection is the appropriate method when encrypted HTTPS content must be decrypted and inspected.
Question 120
Which FortiGate feature provides a graphical view of traffic activity, top applications, users, destinations, and security information?
- FortiView
- DHCP monitor
- CLI console
- Static route
Correct Answer: 1
Explanation
FortiView provides graphical visibility into traffic and security activity on FortiGate. Depending on the available views and configuration, administrators can examine information such as top applications, users, destinations, sources, bandwidth usage, and security events. This makes FortiView useful for quickly identifying traffic patterns and investigating unusual activity through an interactive interface. DHCP monitoring focuses on address assignments, the CLI console provides command-line access, and static routes control packet forwarding. Therefore, FortiView is the correct feature for graphical traffic and security visibility.