View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 141
Which FortiGate feature allows an administrator to define a collection of IP addresses as a single reusable object?
- Service group
- Address group
- User group
- Interface zone
Correct Answer: 2
Explanation
An address group combines multiple address objects into one logical object that can be referenced by firewall policies and other supported configurations. This simplifies administration when several hosts or networks require the same access rules. Instead of selecting each address individually in multiple policies, an administrator can create an address group and use it as a single policy object. Service groups organize services, user groups organize authenticated users, and interface zones group interfaces. Therefore, an Address group is the appropriate choice for combining IP address objects into one reusable object.
Question 142
Which FortiGate setting determines whether an administrator can access the device through SSH on a particular interface?
- Firewall schedule
- Administrative access
- Security profile
- Address object
Correct Answer: 2
Explanation
The Administrative access settings on a FortiGate interface determine which management protocols can be used to access the device through that interface. SSH can be enabled or disabled along with other supported administrative services such as HTTPS, PING, or SNMP, depending on the interface and configuration. Firewall schedules control policy availability, security profiles inspect traffic, and address objects represent network destinations or sources. Therefore, Administrative access is the correct setting for controlling whether SSH management is available through a specific interface.
Question 143
Which FortiGate protocol is commonly used to exchange routing information within an enterprise network?
- BGP
- DHCP
- OSPF
- DNS
Correct Answer: 3
Explanation
OSPF, or Open Shortest Path First, is a dynamic routing protocol commonly used to exchange routing information within an organization’s network. It allows routers and FortiGate devices participating in the OSPF domain to dynamically learn network routes and respond to topology changes. BGP is primarily designed for routing between autonomous systems, DHCP provides IP configuration, and DNS resolves domain names. OSPF is therefore the appropriate choice when an enterprise needs dynamic internal route exchange and automatic adaptation to network changes.
Question 144
Which FortiGate component can provide centralized security intelligence and services such as web categorization and antivirus updates?
- FortiAnalyzer
- FortiView
- FortiToken
- FortiGuard
Correct Answer: 4
Explanation
FortiGuard provides various security intelligence and update services used by Fortinet products. Depending on the licensed services, FortiGuard can provide resources such as web-rating information, antivirus updates, application information, and other security intelligence. FortiAnalyzer focuses on centralized logging and analysis, FortiView provides local visibility into traffic and security activity, and FortiToken supports authentication. Therefore, FortiGuard is the appropriate Fortinet service for security intelligence and update-related functions used by FortiGate.
Question 145
Which FortiGate feature can automatically assign IP addresses to devices connected to a network interface?
- DHCP server
- DHCP client
- Static route
- DNS Filter
Correct Answer: 1
Explanation
A DHCP server assigns IP addresses and other network configuration information to clients on a network. FortiGate can provide DHCP services on supported interfaces, allowing connected devices to receive parameters such as IP addresses, subnet masks, default gateways, and DNS server information. A DHCP client instead obtains an address from an upstream DHCP server, while static routes determine packet forwarding and DNS Filter controls DNS requests. Therefore, DHCP server is the correct feature when FortiGate needs to automatically assign network configuration to connected clients.
Question 146
Which FortiGate inspection approach uses a proxy mechanism to process and inspect supported traffic?
- Flow-based inspection
- Certificate inspection
- Proxy-based inspection
- DNS inspection
Correct Answer: 3
Explanation
Proxy-based inspection uses a proxy mechanism to process supported traffic before forwarding it toward its destination. This inspection approach can provide detailed content inspection and supports security functions that require proxy processing. Flow-based inspection examines traffic as it passes through the device without using the same full proxy model. Certificate inspection focuses primarily on certificate information, while DNS inspection handles DNS traffic. The appropriate mode depends on the required security controls and performance considerations. Therefore, Proxy-based inspection is the correct answer.
Question 147
Which FortiGate object can represent TCP or UDP ports such as HTTP, HTTPS, or DNS for use in firewall policies?
- Address object
- User group
- Service object
- IP pool
Correct Answer: 3
Explanation
A service object represents network protocols and ports that can be referenced by firewall policies. For example, service definitions can identify TCP ports used by HTTP or HTTPS and UDP ports commonly used by DNS. Administrators can select these service objects when defining which types of traffic a firewall policy should match. Address objects represent IP addresses and networks, user groups organize authenticated users, and IP pools provide addresses for source NAT. Therefore, Service object is the correct configuration for representing TCP or UDP services.
Question 148
Which FortiGate feature can help an administrator identify the firewall policy that would process traffic between a specified source and destination?
- Policy lookup
- FortiGuard
- FortiToken
- DHCP monitor
Correct Answer: 1
Explanation
Policy lookup can help administrators determine which firewall policy matches specific traffic based on factors such as source, destination, service, and interfaces. This is useful when troubleshooting policy behavior because FortiGate processes policies according to its policy-matching logic and sequence. Administrators can use policy lookup to identify the relevant policy without manually inspecting every policy in the configuration. FortiGuard provides security intelligence, FortiToken supports authentication, and DHCP monitoring focuses on address assignments. Therefore, Policy lookup is the correct troubleshooting feature.
Question 149
Which FortiGate feature can use an external LDAP directory to authenticate users?
- Local users
- RADIUS
- FSSO
- LDAP server
Correct Answer: 4
Explanation
An LDAP server configuration allows FortiGate to communicate with an external LDAP directory for user authentication and directory lookups. This enables organizations to use existing directory accounts instead of creating every user directly on FortiGate. LDAP can be used with appropriate user groups and authentication configurations to control access to supported services and policies. Local users are stored on FortiGate, RADIUS uses a RADIUS server, and FSSO provides identity information through supported single sign-on mechanisms. Therefore, LDAP server is the correct answer.
Question 150
Which FortiGate feature can detect when a monitored WAN link experiences excessive latency or packet loss?
- Static route
- Performance SLA
- Address group
- Service object
Correct Answer: 2
Explanation
A Performance SLA can monitor WAN-path quality using measurements such as latency, jitter, and packet loss. Administrators configure thresholds that define acceptable performance, and FortiGate can use the resulting health information in SD-WAN path-selection decisions. This allows traffic to be moved away from a path that no longer satisfies the required performance conditions, depending on the configured SD-WAN rules. Static routes control forwarding, address groups organize IP addresses, and service objects identify network services. Therefore, Performance SLA is the correct feature for monitoring WAN-link quality.
Question 151
Which FortiGate command is useful for checking general device information such as the FortiOS version and serial number?
- diagnose sys session list
- diagnose vpn tunnel list
- get system status
- get router info routing-table all
Correct Answer: 3
Explanation
The get system status command displays important general information about the FortiGate device. The output can include the hostname, serial number, FortiOS version, firmware build, and other system details. This makes the command useful at the beginning of troubleshooting or when confirming the software version before performing configuration or upgrade tasks. The session command displays active sessions, the VPN command provides tunnel information, and the routing-table command displays routing information. Therefore, get system status is the correct command for basic system identification.
Question 152
Which FortiGate feature can control access to applications by allowing or blocking specific application categories?
- Web Filter
- Antivirus
- IPS
- Application Control
Correct Answer: 4
Explanation
Application Control allows administrators to identify applications and apply configured actions to individual applications or application categories. This provides more granular control than simply filtering by IP address or TCP/UDP port. For example, an administrator can create rules affecting categories of applications or selected application signatures. Web Filter focuses on websites, Antivirus detects malicious content, and IPS identifies network attacks. Therefore, Application Control is the correct security profile when the goal is to allow, monitor, or block applications according to their detected identity.
Question 153
Which FortiGate feature can store logs locally on the device when local logging is enabled?
- Local disk
- FortiToken
- IP pool
- Performance SLA
Correct Answer: 1
Explanation
Local disk logging allows FortiGate to store supported log information on its local storage when the platform and configuration support this capability. Local logging can provide administrators with access to device-generated traffic, event, and security information without requiring an external logging server. FortiAnalyzer and syslog provide external or centralized logging options, while FortiToken supports authentication and IP pools support NAT. Therefore, Local disk is the correct option when logs need to be stored directly on the FortiGate device.
Question 154
Which FortiGate feature allows an administrator to define a logical network interface associated with a specific VLAN ID?
- Software switch
- VLAN interface
- IP pool
- Service group
Correct Answer: 2
Explanation
A VLAN interface is a logical interface associated with a specific VLAN ID and is commonly used when FortiGate connects to a switch through a VLAN trunk. Each VLAN interface can have its own IP configuration and can participate in routing and firewall policies. A software switch combines interfaces for switching purposes, an IP pool provides addresses for NAT, and a service group combines service objects. Therefore, VLAN interface is the correct choice when an administrator needs to create a logical interface for a particular VLAN.
Question 155
Which FortiGate feature can help protect administrative accounts by requiring a one-time verification code in addition to a password?
- Static route
- Web Filter
- FortiView
- Multi-factor authentication
Correct Answer: 4
Explanation
Multi-factor authentication requires more than one authentication factor before access is granted. When configured with an appropriate authentication mechanism such as FortiToken, an administrator may need to provide a password along with a temporary verification code. This reduces reliance on a single password and can improve protection against credential compromise. Static routes control network forwarding, Web Filter controls website access, and FortiView provides traffic visibility. Therefore, Multi-factor authentication is the correct feature for requiring an additional verification code alongside a password.
Question 156
Which FortiGate feature can be used to define a reusable group containing several TCP and UDP service objects?
- Service group
- Address group
- User group
- Interface zone
Correct Answer: 1
Explanation
A service group combines multiple service objects into a single reusable configuration object. Administrators can include several TCP or UDP services in the group and then reference the group from firewall policies. This reduces repetitive configuration when the same collection of services is required by multiple policies. Address groups contain IP address objects, user groups contain authenticated identities, and interface zones organize interfaces. Therefore, Service group is the correct object for grouping multiple TCP and UDP services into one policy reference.
Question 157
Which FortiGate feature can provide a detailed record of individual network sessions for troubleshooting and security analysis?
- System dashboard
- Traffic logs
- Firmware manager
- DHCP server
Correct Answer: 2
Explanation
Traffic logs provide detailed records of network sessions processed by FortiGate. Depending on the logging configuration, entries can include source and destination addresses, ports, interfaces, policy identifiers, actions, timestamps, and traffic volumes. This information is useful for investigating connectivity problems, verifying firewall-policy behavior, and reviewing security activity. The system dashboard provides general device information, firmware management handles software updates, and DHCP servers assign network configuration. Therefore, Traffic logs are the most appropriate feature for reviewing individual network sessions.
Question 158
Which FortiGate feature can provide automatic firmware upgrade functionality when a supported upgrade path and appropriate configuration are available?
- Web Filter
- Application Control
- Firmware upgrade
- Traffic Shaping
Correct Answer: 3
Explanation
Firmware upgrade functionality allows administrators to update FortiGate to a newer supported FortiOS version. Before upgrading, administrators should verify compatibility, supported upgrade paths, configuration requirements, and available backups. FortiOS upgrades can introduce new features, security improvements, and bug fixes, but using an unsupported upgrade path can create operational problems. Web Filter controls website access, Application Control manages applications, and Traffic Shaping manages bandwidth. Therefore, Firmware upgrade is the correct feature for updating the FortiGate operating system when a supported upgrade path is available.
Question 159
Which FortiGate feature can use a wildcard domain pattern to match multiple hostnames under a domain?
- IP pool
- Service group
- FQDN address
- Traffic shaper
Correct Answer: 3
Explanation
An FQDN address object can represent a fully qualified domain name and can be used in supported firewall-policy configurations. Wildcard FQDN capabilities can allow administrators to match multiple hostnames under a specified domain according to the configured pattern and FortiOS support. This can simplify policies when numerous destinations belong to the same domain structure. IP pools are used for NAT, service groups contain service objects, and traffic shapers manage bandwidth. Therefore, FQDN address is the appropriate feature for domain-based address matching.
Question 160
Which FortiGate feature can automatically distribute traffic across multiple available WAN links according to configured SD-WAN rules?
- SD-WAN
- DHCP server
- Web Filter
- Antivirus
Correct Answer: 1
Explanation
SD-WAN allows FortiGate to manage multiple WAN connections and distribute or steer traffic according to configured rules and path-performance requirements. Administrators can define SD-WAN members, performance SLAs, and rules that determine how traffic should use available paths. This can improve WAN utilization and provide more flexible path selection than relying only on a single static route. DHCP provides network addressing, Web Filter controls website access, and Antivirus inspects supported content for malware. Therefore, SD-WAN is the correct feature for managing traffic across multiple WAN links.