View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 121
Which FortiGate feature can prevent unauthorized devices from accessing a network by requiring authentication before access is granted?
- Static route
- Traffic shaper
- Address group
- Captive portal
Correct Answer: 4
Explanation
A captive portal can require users to authenticate before they are permitted to access network resources through a configured FortiGate interface or policy. This is commonly used on guest or wireless networks where users must provide credentials or accept an access requirement before receiving network access. Static routes determine forwarding paths, traffic shapers control bandwidth, and address groups organize IP address objects. Therefore, Captive portal is the appropriate feature when FortiGate needs to require user authentication before granting network access.
Question 122
Which FortiGate configuration determines which physical or logical interface receives traffic for a directly connected network?
- Firewall policy
- Routing table
- Security profile
- Service group
Correct Answer: 2
Explanation
The routing table contains the routes FortiGate uses to determine where packets should be forwarded. Directly connected networks are normally represented as connected routes associated with the relevant interface. When traffic is destined for such a network, FortiGate uses the routing information to select the appropriate outgoing interface. Firewall policies then determine whether the traffic is allowed, while security profiles inspect permitted traffic and service groups organize services. Therefore, the Routing table is the correct configuration for determining the forwarding interface for a connected destination.
Question 123
Which FortiGate feature can group several users together so the same firewall policy can be applied to all of them?
- User group
- Address group
- Service group
- Interface zone
Correct Answer: 1
Explanation
A user group allows multiple user accounts to be grouped together and referenced as a single object in supported authentication and firewall-policy configurations. This is useful when different users require the same access permissions. Instead of creating separate policies for every individual user, administrators can assign users to a group and reference that group in an identity-based policy. Address groups contain IP address objects, service groups contain service definitions, and interface zones group interfaces. Therefore, User group is the correct choice for grouping users for common policy enforcement.
Question 124
Which FortiGate security profile can block DNS requests to domains categorized as malicious or inappropriate?
- Antivirus
- IPS
- DNS Filter
- Application Control
Correct Answer: 3
Explanation
DNS Filter can inspect DNS requests and apply configured filtering actions based on domains, categories, and other supported criteria. It can help prevent users from resolving or accessing domains that are classified as malicious, inappropriate, or otherwise restricted. Antivirus is intended to detect malicious content, IPS detects network attacks, and Application Control identifies applications. DNS filtering operates at the domain-resolution stage and can provide an additional layer of protection before a connection to the destination is established. Therefore, DNS Filter is the correct security profile.
Question 125
Which FortiGate configuration can allow a public-facing server to be accessed through a specific external TCP port?
- Traffic shaping
- Virtual IP with port forwarding
- Static route
- Address group
Correct Answer: 1
Explanation
A Virtual IP with port forwarding can map a specific external TCP port to a selected internal server and port. This is useful when administrators need to expose only a particular service rather than making every port on the internal server accessible. The VIP can define the external address and port and translate it to the appropriate internal destination. Traffic shaping controls bandwidth, static routes determine packet forwarding, and address groups organize address objects. Therefore, the appropriate configuration is a Virtual IP with port forwarding for controlled inbound service publishing.
Question 126
Which FortiGate feature can monitor whether an SD-WAN path meets configured latency, jitter, and packet-loss requirements?
- Firewall policy
- Address group
- Service group
- Performance SLA
Correct Answer: 4
Explanation
A Performance SLA monitors the quality of SD-WAN paths using configured performance criteria such as latency, jitter, and packet loss. FortiGate can use these measurements to determine whether a network path satisfies the required service-level conditions. SD-WAN rules can then use the results to influence path selection according to the configured design. Firewall policies control permitted traffic, address groups organize IP addresses, and service groups organize services. Therefore, Performance SLA is the correct feature for monitoring SD-WAN path quality against defined performance requirements.
Question 127
Which FortiGate inspection mode examines traffic as it passes through the device without using full proxy processing for every session?
- Proxy-based inspection
- Flow-based inspection
- Certificate inspection
- DNS inspection
Correct Answer: 2
Explanation
Flow-based inspection examines traffic as it passes through FortiGate and generally avoids the full proxy processing model used by proxy-based inspection. It can provide security inspection with lower processing overhead for supported security functions and traffic types. Proxy-based inspection instead uses proxy processing to handle and inspect traffic, while certificate inspection focuses on certificate information and DNS inspection focuses on DNS traffic. The appropriate inspection mode depends on the organization’s security requirements and the supported security profiles. Therefore, Flow-based inspection is correct.
Question 128
Which FortiGate feature can detect and block web requests based on a URL category received from FortiGuard?
- IPS
- Antivirus
- Web Filter
- Traffic Shaping
Correct Answer: 3
Explanation
Web Filter can use FortiGuard web-rating information to categorize websites and apply configured actions to requests. Administrators can create policies that block or allow categories according to organizational requirements. For example, categories associated with malicious, inappropriate, or unwanted websites can be restricted while business-related categories remain accessible. IPS focuses on network attacks, Antivirus scans supported content for malware, and Traffic Shaping manages bandwidth. Therefore, Web Filter is the correct FortiGate security profile for controlling web requests according to FortiGuard URL categories.
Question 129
Which FortiGate command can display the list of active sessions currently tracked by the firewall?
- diagnose sys session list
- get system status
- diagnose vpn tunnel list
- get router info routing-table all
Correct Answer: 1
Explanation
The diagnose sys session list command displays information about active sessions tracked by FortiGate. It can provide details such as source and destination addresses, ports, interfaces, and session states, making it useful for troubleshooting connectivity and session-related issues. get system status provides general device information, diagnose vpn tunnel list focuses on IPsec VPN tunnels, and the routing-table command displays routing information. Therefore, diagnose sys session list is the appropriate command when an administrator needs to inspect active firewall sessions.
Question 130
Which FortiGate feature can identify a user’s identity based on information received from a Windows domain environment without requiring repeated authentication prompts?
- RADIUS
- LDAP
- FSSO
- Local users
Correct Answer: 3
Explanation
Fortinet Single Sign-On, or FSSO, can provide FortiGate with user identity information from supported Windows domain environments. This allows identity-based policies to use information about authenticated users without requiring users to repeatedly enter credentials directly into FortiGate for every access request. RADIUS provides centralized authentication, LDAP allows directory-based authentication and user lookup, and local users are stored directly on FortiGate. FSSO is specifically designed to integrate user identity information into Fortinet security policies. Therefore, FSSO is the correct answer.
Question 131
Which FortiGate setting controls how long an established session can remain active when no traffic is exchanged?
- Administrative timeout
- Session TTL
- Firewall schedule
- Route priority
Correct Answer: 2
Explanation
Session TTL, or Time To Live, determines how long a firewall session can remain in the session table according to the relevant timeout configuration. When a session remains inactive for the applicable period, FortiGate can remove it from the session table. This helps manage firewall resources and ensures that stale sessions do not remain indefinitely. Administrative timeout controls management sessions, firewall schedules determine when policies operate, and route priority influences routing decisions. Therefore, Session TTL is the correct setting for controlling firewall session lifetime.
Question 132
Which FortiGate feature can be used to organize several network interfaces under a single logical interface for configuration purposes?
- Software switch
- IP pool
- Service group
- User group
Correct Answer: 1
Explanation
A software switch can combine multiple interfaces into a single logical switching interface. This allows connected devices to participate in the same Layer 2 network according to the configured design. Administrators can then apply relevant interface and network settings to the logical switch rather than treating every member interface as an entirely separate network. IP pools provide addresses for NAT, service groups combine services, and user groups organize authenticated users. Therefore, Software switch is the correct feature for grouping interfaces into one logical switching interface.
Question 133
Which FortiGate feature allows an administrator to specify a preferred outgoing interface when multiple network paths are available?
- Web Filter
- Antivirus profile
- Static route
- User group
Correct Answer: 3
Explanation
A static route allows an administrator to define a specific destination network, next-hop gateway, and outgoing interface. This provides direct control over how FortiGate forwards traffic toward a particular destination. When multiple paths exist, route-selection attributes determine which route is preferred. Web Filter and Antivirus are security profiles, while User groups organize authenticated identities. Static routes are particularly useful for manually defining network paths when dynamic routing is unnecessary or when a specific forwarding path is required. Therefore, Static route is the correct answer.
Question 134
Which FortiGate feature can synchronize configuration information between HA cluster members?
- Traffic shaping
- Web filtering
- DNS filtering
- HA synchronization
Correct Answer: 4
Explanation
HA synchronization keeps relevant configuration information consistent between members of a FortiGate HA cluster. Synchronization helps ensure that a secondary unit has the necessary configuration to take over if the primary unit fails. Without appropriate synchronization, cluster members could have inconsistent configurations that could affect failover behavior. Traffic Shaping, Web Filtering, and DNS Filtering are unrelated to HA configuration synchronization. Therefore, HA synchronization is the correct feature for maintaining consistent configuration information across members of an HA cluster.
Question 135
Which FortiGate authentication source stores user accounts directly on the FortiGate device?
- Local users
- RADIUS
- LDAP
- FSSO
Correct Answer: 1
Explanation
Local users are accounts created and stored directly on the FortiGate device. Administrators can configure usernames, passwords, and supported authentication settings for these accounts and then use them in appropriate user groups and authentication policies. RADIUS and LDAP rely on external authentication or directory services, while FSSO obtains identity information through supported single sign-on mechanisms. Local authentication can be useful for administrative accounts or smaller deployments where an external identity service is not required. Therefore, Local users is the correct authentication source.
Question 136
Which FortiGate feature can protect a network by blocking traffic that matches known malicious IP addresses supplied by an external feed?
- Traffic Shaping
- External threat feed
- Service group
- DHCP server
Correct Answer: 2
Explanation
An external threat feed can provide FortiGate with indicators such as known malicious IP addresses. These indicators can then be referenced by supported security configurations and policies to help block or otherwise control traffic associated with known threats. This allows organizations to incorporate external threat intelligence into their security controls. Traffic Shaping manages bandwidth, service groups organize protocol and port definitions, and DHCP servers provide IP configuration to clients. Therefore, External threat feed is the appropriate feature for incorporating malicious IP indicators into security enforcement.
Question 137
Which FortiGate feature can display real-time information about traffic volume, applications, and network users through a graphical interface?
- Static route
- DHCP server
- FortiView
- Service group
Correct Answer: 3
Explanation
FortiView provides graphical visibility into network traffic and security activity. Administrators can use available FortiView dashboards to examine traffic volume, applications, users, destinations, sources, and other relevant information. This can help identify unusual traffic patterns and understand how network resources are being used. Static routes control packet forwarding, DHCP servers provide network addressing, and service groups organize service definitions. Therefore, FortiView is the correct feature for obtaining graphical visibility into traffic and security information.
Question 138
Which FortiGate authentication protocol commonly uses directory information from an LDAP server to verify users?
- LDAP
- RADIUS
- FSSO
- Local authentication
Correct Answer: 2
Explanation
RADIUS is a widely used authentication protocol that can allow FortiGate to verify users through an external RADIUS server. The RADIUS server can integrate with an organization’s existing authentication infrastructure and return authentication results to FortiGate. LDAP is a directory protocol and can also be configured directly as an authentication server, while FSSO provides user identity information through supported single sign-on mechanisms. Local authentication uses accounts stored on FortiGate. Therefore, RADIUS is the correct protocol among the listed options for external authentication.
Question 139
Which FortiGate feature allows an administrator to restrict management access by defining trusted source addresses for administrative connections?
- Trusted hosts
- Service group
- IP pool
- SD-WAN rule
Correct Answer: 1
Explanation
Trusted hosts can restrict administrative access to FortiGate accounts by specifying source IP addresses or networks that are allowed to use the account for management access. This provides an additional security control because even if valid credentials are obtained, administrative access can be restricted based on the originating address. Service groups organize services, IP pools are used for NAT, and SD-WAN rules control traffic path selection. Therefore, Trusted hosts is the appropriate feature for restricting administrative access based on trusted source addresses.
Question 140
Which FortiGate feature can automatically select among multiple WAN paths based on configured application, destination, and performance criteria?
- DHCP server
- Firewall address
- Service group
- SD-WAN
Correct Answer: 4
Explanation
SD-WAN allows FortiGate to manage multiple WAN paths and select an appropriate path based on configured rules and performance requirements. Administrators can use SD-WAN rules and performance measurements to influence how traffic is distributed across available members. This can help organizations use multiple internet connections while applying different path-selection requirements to applications or destinations. DHCP servers provide network addressing, firewall addresses define network objects, and service groups organize services. Therefore, SD-WAN is the correct feature for intelligent path selection across multiple WAN connections.