View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 281
Which FortiGate feature can be used to verify whether the device has valid FortiGuard service connectivity and licensing information?
- FortiGuard status
- Policy lookup
- Traffic shaping
- Session pickup
Correct Answer: 1
Explanation
FortiGuard status provides information about the FortiGate’s connectivity to FortiGuard services and the status of supported subscriptions. Administrators can use this information when troubleshooting features that depend on FortiGuard services, such as web ratings, security updates, and other threat intelligence. Policy lookup determines which firewall policy matches traffic, traffic shaping controls bandwidth, and session pickup relates to HA session synchronization. Checking FortiGuard status is therefore useful when administrators need to verify whether required FortiGuard services are reachable and properly available.
Question 282
Which FortiGate feature allows an administrator to define a collection of IP addresses and networks for reuse in firewall policies?
- Service object
- Address group
- Schedule
- Traffic shaper
Correct Answer: 2
Explanation
An address group combines multiple address objects into a single reusable object. Administrators can use an address group as a source or destination in firewall policies when several networks or hosts require the same security treatment. This simplifies configuration and reduces the need to repeatedly select individual address objects. Service objects define protocols and ports, schedules control when policies operate, and traffic shapers manage bandwidth. Therefore, Address group is the correct feature when several IP addresses or networks need to be referenced together in firewall policies.
Question 283
Which FortiGate feature can inspect traffic for known intrusion signatures and take a configured action when a match occurs?
- Web Filter
- DNS Filter
- IPS
- DHCP Server
Correct Answer: 3
Explanation
The Intrusion Prevention System, or IPS, uses signatures and inspection mechanisms to identify network traffic associated with known attacks or suspicious behavior. When an IPS signature matches traffic, FortiGate can take an action according to the configured IPS profile. Web Filter controls website access, DNS Filter evaluates DNS requests, and DHCP Server provides network configuration to clients. IPS is therefore the security feature specifically designed to detect and respond to network-based attacks using intrusion signatures and related detection techniques.
Question 284
Which FortiGate feature is used to define a reusable set of TCP or UDP ports for use in firewall policies?
- Address object
- User group
- Interface zone
- Service group
Correct Answer: 4
Explanation
A service group combines multiple service objects into one reusable group. Service objects define protocols and ports, such as TCP or UDP destination ports, and grouping them makes firewall-policy configuration easier when several services must receive the same treatment. Address objects identify hosts or networks, user groups organize authenticated identities, and interface zones group interfaces. Therefore, Service group is the correct feature when multiple TCP or UDP services need to be referenced together in firewall policies.
Question 285
Which FortiGate setting determines which management protocols are permitted through a particular interface?
- Trusted hosts
- Administrative access
- Performance SLA
- Address group
Correct Answer: 2
Explanation
Administrative access settings determine which management protocols are enabled on a FortiGate interface. Administrators can permit protocols such as HTTPS, SSH, or other supported management methods according to the security requirements of the interface. Trusted hosts restrict the source locations from which an administrator account can connect, while Performance SLA evaluates network-path quality and address groups organize network objects. Therefore, Administrative access is the correct setting when the objective is to control which management protocols can reach FortiGate through an interface.
Question 286
Which FortiGate feature can determine whether an SD-WAN member remains usable by checking network performance against configured thresholds?
- Address group
- Web Filter
- Performance SLA
- Service object
Correct Answer: 3
Explanation
Performance SLA evaluates the quality and availability of SD-WAN members using measurements such as latency, jitter, and packet loss. Administrators can configure thresholds that define acceptable performance, and FortiGate can use the resulting health information in SD-WAN path-selection decisions. Address groups identify network endpoints, Web Filter controls website access, and service objects define network services. Therefore, Performance SLA is the appropriate feature for determining whether an SD-WAN member continues to satisfy configured performance requirements.
Question 287
Which FortiGate feature can create a logical interface associated with a specific VLAN ID?
- VLAN interface
- IP pool
- Service group
- Performance SLA
Correct Answer: 1
Explanation
A VLAN interface is a logical interface configured with a VLAN identifier and associated with a physical interface or appropriate network connection. It allows FortiGate to communicate with devices on tagged VLAN networks and can have its own IP address and administrative settings. An IP pool provides addresses for NAT, a service group combines service objects, and Performance SLA evaluates network-path quality. Therefore, VLAN interface is the correct feature when FortiGate needs to participate in a specific tagged VLAN.
Question 288
Which FortiGate feature can use an external list of known malicious IP addresses or domains as part of security enforcement?
- Web Filter
- DHCP Server
- External threat feed
- Traffic Shaping
Correct Answer: 3
Explanation
An external threat feed provides FortiGate with externally maintained indicators of compromise, such as malicious IP addresses or domains. These indicators can be incorporated into supported security policies to help identify or block traffic associated with known threats. Web Filter focuses on website access, DHCP Server assigns network configuration, and Traffic Shaping manages bandwidth. External threat feeds are useful when an organization wants to supplement FortiGate’s built-in security intelligence with threat information maintained by another trusted source. Therefore, External threat feed is the correct answer.
Question 289
Which FortiGate HA feature can help preserve supported active sessions after a primary-unit failure?
- Override
- Interface monitoring
- Device priority
- Session pickup
Correct Answer: 4
Explanation
Session pickup allows supported session information to be synchronized between HA cluster members so that sessions can continue more smoothly after a failover. This can reduce disruption for established connections when the primary FortiGate becomes unavailable. Override and device priority influence HA primary-unit selection, while interface monitoring detects failures on selected interfaces. Session pickup does not guarantee preservation of every possible session, because supported session types and configuration determine the behavior. Therefore, Session pickup is the correct HA feature for maintaining supported session state after failover.
Question 290
Which FortiGate feature can restrict administrator access to the device based on the source IP address of the management connection?
- Trusted hosts
- Web Filter
- Antivirus
- SD-WAN rule
Correct Answer: 1
Explanation
Trusted hosts allow an administrator account to be restricted to specific source IP addresses or networks. This means that management access for that account is permitted only when the connection originates from an approved location. This provides an additional security control beyond normal username and password authentication. Web Filter controls website access, Antivirus scans supported content, and SD-WAN rules influence WAN-path selection. Therefore, Trusted hosts is the correct feature for limiting administrator access according to the source IP address of the management connection.
Question 291
Which FortiGate feature can apply different security policies to users based on their authenticated identity?
- Static route
- IP pool
- Identity-based firewall policy
- Service group
Correct Answer: 3
Explanation
An identity-based firewall policy can use authenticated user or user-group information as part of access control. This allows administrators to provide different permissions to different users or groups even when they are accessing the same network resources. Static routes determine packet-forwarding paths, IP pools provide NAT addresses, and service groups combine network services. Identity-based policies are particularly useful in environments where access requirements depend on user roles or directory groups. Therefore, Identity-based firewall policy is the appropriate feature for user-based security enforcement.
Question 292
Which FortiGate feature can control access to domains by evaluating DNS queries against configured filtering categories?
- Antivirus
- DNS Filter
- IPS
- Traffic Shaping
Correct Answer: 2
Explanation
DNS Filter evaluates DNS requests and can apply filtering rules based on configured categories and available security intelligence. It can prevent users from resolving or accessing domains that fall into restricted categories, depending on the configured action. Antivirus focuses on malicious content, IPS detects network attacks, and Traffic Shaping controls bandwidth. DNS Filter operates at the DNS-query level and is therefore useful for controlling access to domains before normal application connections are established. Thus, DNS Filter is the correct security feature for this requirement.
Question 293
Which FortiGate command provides general information about the installed FortiOS version and device status?
- get system status
- diagnose debug flow
- diagnose vpn tunnel list
- get router info routing-table all
Correct Answer: 1
Explanation
The get system status command provides general information about the FortiGate device, including details such as the installed FortiOS version, serial number, hostname, and other system information. It is commonly used during troubleshooting and device administration when an administrator needs to confirm the current firmware and general operational details. diagnose debug flow traces packet processing, diagnose vpn tunnel list provides VPN tunnel information, and the routing-table command displays routing entries. Therefore, get system status is the appropriate command for general system information.
Question 294
Which FortiGate configuration can be used to map an external public IP address and port to an internal server and port?
- Address group
- Service group
- Static route
- Virtual IP with port forwarding
Correct Answer: 4
Explanation
A Virtual IP with port forwarding can map an external public IP address and destination port to a private internal IP address and a different destination port. This configuration is useful when an internal service needs to be published externally while using a different port internally. A firewall policy is normally used alongside the VIP to control permitted inbound traffic. Address groups combine address objects, service groups combine services, and static routes determine forwarding paths. Therefore, Virtual IP with port forwarding is the correct configuration for this type of destination NAT.
Question 295
Which FortiGate feature can authenticate users through a centralized external service that uses the RADIUS protocol?
- LDAP
- RADIUS
- FSSO
- FortiToken
Correct Answer: 2
Explanation
RADIUS provides centralized authentication through an external RADIUS server. FortiGate can send user credentials to the configured RADIUS server, which verifies the credentials and returns the authentication result. This allows organizations to use existing centralized authentication infrastructure rather than maintaining all credentials locally on the FortiGate. LDAP is commonly used for directory-based authentication, FSSO supplies user identity information through supported single sign-on mechanisms, and FortiToken provides token-based authentication. Therefore, RADIUS is the correct authentication method for this scenario.
Question 296
Which FortiGate feature can provide centralized log collection and analysis for multiple security devices?
- FortiView
- FortiGuard
- FortiAnalyzer
- FortiToken
Correct Answer: 3
Explanation
FortiAnalyzer provides centralized log collection, storage, analysis, and reporting for supported Fortinet devices. It allows administrators to investigate traffic, security events, and operational information from a centralized platform. This is especially useful when an organization operates multiple FortiGate devices because logs can be consolidated for easier monitoring and investigation. FortiView provides local visibility on a FortiGate, FortiGuard provides security intelligence and services, and FortiToken supports token-based authentication. Therefore, FortiAnalyzer is the correct solution for centralized log management and analysis.
Question 297
Which FortiGate feature can control which applications are allowed, monitored, or blocked through a firewall policy?
- Web Filter
- Antivirus
- Application Control
- DHCP Server
Correct Answer: 3
Explanation
Application Control identifies applications using FortiGate application signatures and allows administrators to define actions for individual applications or categories. An Application Control profile can be attached to a firewall policy so matching traffic is handled according to the configured settings. Web Filter controls websites, Antivirus detects malware and malicious files, and DHCP Server provides network configuration. Application Control is therefore the appropriate feature when administrators need to control network access according to the application generating the traffic rather than relying only on addresses or ports.
Question 298
Which FortiGate HA feature monitors selected interfaces and can contribute to determining whether a failover should occur?
- Session pickup
- Interface monitoring
- FortiGuard
- Web Filter
Correct Answer: 2
Explanation
Interface monitoring allows an HA configuration to monitor selected interfaces for failures. If an important monitored interface becomes unavailable, FortiGate can use that status as part of its HA failover behavior. This helps prevent a unit with a significant connectivity failure from remaining the active primary unit when another cluster member is available. Session pickup synchronizes supported session information, FortiGuard provides security services, and Web Filter controls website access. Therefore, Interface monitoring is the correct HA feature for monitoring selected interfaces and supporting failover decisions.
Question 299
Which FortiGate feature can evaluate a firewall policy’s source, destination, service, and interface conditions to identify the rule that would handle traffic?
- Policy lookup
- FortiToken
- FortiGuard
- DHCP Server
Correct Answer: 1
Explanation
Policy lookup is designed to help administrators determine which firewall policy matches specified traffic characteristics. By examining conditions such as source, destination, service, and interfaces, administrators can troubleshoot unexpected policy behavior and verify whether traffic is being evaluated against the intended rule. FortiToken provides authentication tokens, FortiGuard supplies security intelligence and services, and DHCP Server provides network configuration. Therefore, Policy lookup is the correct FortiGate feature for identifying the policy that would handle a particular traffic flow.
Question 300
Which FortiGate feature allows administrators to define a logical interface that does not depend directly on a physical interface remaining operational?
- VLAN interface
- IP pool
- Service object
- Loopback interface
Correct Answer: 4
Explanation
A loopback interface is a logical interface that can provide a stable IP endpoint independently of a particular physical interface’s operational state. It can be used for routing, management, or other functions that benefit from a consistent logical address. A VLAN interface is associated with a VLAN identifier, an IP pool provides addresses for NAT, and a service object defines protocols and ports. Because a loopback interface is logical rather than tied directly to a single physical link, it is useful when a stable network endpoint is required. Therefore, Loopback interface is the correct answer.