Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part16 Q301-320

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 301

Which FortiGate feature can be used to verify the current firmware version before performing an upgrade?

  1. get system status
  2. diagnose sys session list
  3. diagnose vpn tunnel list
  4. get router info routing-table all

Correct Answer: 1

Explanation

The get system status command displays general system information, including the installed FortiOS firmware version. Verifying the current firmware version is an important step before performing an upgrade because administrators need to confirm the existing release and determine whether the planned upgrade path is appropriate. The session command displays active sessions, the VPN command provides tunnel information, and the routing-table command displays available routes. Therefore, get system status is the appropriate command for checking the currently installed FortiOS version before an upgrade.

Question 302

Which FortiGate feature can automatically assign IP addresses to devices connected to a configured network interface?

  1. IP pool
  2. DHCP server
  3. Virtual IP
  4. Static route

Correct Answer: 2

Explanation

A DHCP server automatically assigns IP addresses and other network configuration parameters to clients on a configured network. FortiGate can provide clients with information such as the assigned IP address, subnet mask, default gateway, and DNS server. An IP pool provides addresses for NAT operations, a Virtual IP is generally used for destination NAT, and a static route determines a forwarding path. Therefore, the DHCP server is the correct feature when FortiGate needs to automatically configure network clients with IP addressing information.

Question 303

Which FortiGate feature can apply a security profile that detects malicious files in supported network traffic?

  1. Web Filter
  2. Application Control
  3. Antivirus
  4. SD-WAN

Correct Answer: 3

Explanation

The Antivirus security profile scans supported network traffic for malicious files, malware, and other threats using FortiGate’s antivirus inspection capabilities. It can be applied through a firewall policy so matching traffic receives the configured antivirus treatment. Web Filter controls website access, Application Control identifies applications, and SD-WAN manages WAN-path selection. Antivirus inspection is therefore the appropriate security function when the objective is to identify and handle malicious content transmitted through supported protocols. Administrators can configure the profile according to the desired detection and response behavior.

Question 304

Which FortiGate feature can provide a centralized location for analyzing logs generated by multiple FortiGate devices?

  1. FortiView
  2. FortiGuard
  3. FortiToken
  4. FortiAnalyzer

Correct Answer: 4

Explanation

FortiAnalyzer provides centralized collection, storage, analysis, and reporting for logs generated by supported Fortinet devices. In a multi-FortiGate environment, administrators can send logs to FortiAnalyzer and investigate traffic, security events, and operational information from a central platform. FortiView provides local visibility on an individual FortiGate, FortiGuard supplies security intelligence and services, and FortiToken supports authentication. Therefore, FortiAnalyzer is the appropriate solution when multiple FortiGate devices need centralized log analysis and reporting.

Question 305

Which FortiGate configuration determines when a firewall policy is active?

  1. Source address
  2. Schedule
  3. Service
  4. Destination address

Correct Answer: 2

Explanation

The Schedule setting determines when a firewall policy is active. Administrators can create schedules that specify recurring days and time periods and then assign them to firewall policies. This allows network access to be controlled according to business hours or other operational requirements. Source address identifies where traffic originates, destination address identifies where it is going, and service specifies protocols or ports. Therefore, Schedule is the correct firewall-policy setting when access needs to be restricted to specific days or times.

Question 306

Which FortiGate feature can restrict access to a management account based on approved source IP addresses?

  1. Administrative access
  2. Interface zone
  3. Address group
  4. Trusted hosts

Correct Answer: 4

Explanation

Trusted hosts allow administrators to restrict an individual administrator account to specific source IP addresses or networks. This adds an additional security control because the account cannot be used for management access from unauthorized source locations even when valid credentials are supplied. Administrative access determines which management protocols are enabled on an interface, interface zones group interfaces, and address groups combine address objects. Therefore, Trusted hosts is the appropriate feature for limiting administrator access based on approved source IP addresses.

Question 307

Which FortiGate feature can combine several network interfaces into a logical group for use in firewall policies?

  1. Interface zone
  2. IP pool
  3. Service object
  4. User group

Correct Answer: 1

Explanation

An interface zone allows multiple FortiGate interfaces to be grouped logically and referenced together in firewall policies. This simplifies policy configuration when several interfaces require the same access-control rules. Instead of repeatedly selecting individual interfaces, an administrator can reference the zone as a logical interface group. IP pools provide NAT addresses, service objects define protocols and ports, and user groups organize authenticated identities. Therefore, Interface zone is the correct feature for grouping multiple network interfaces for policy configuration.

Question 308

Which FortiGate feature can determine whether an SD-WAN link meets configured latency, jitter, and packet-loss requirements?

  1. Static route
  2. Traffic shaper
  3. Performance SLA
  4. Address group

Correct Answer: 3

Explanation

Performance SLA evaluates SD-WAN path quality using measurements such as latency, jitter, and packet loss. Administrators can define thresholds for acceptable performance and use the resulting health information when configuring SD-WAN path-selection behavior. Static routes determine forwarding paths, traffic shapers control bandwidth, and address groups combine network address objects. Performance SLA is therefore the appropriate mechanism for monitoring SD-WAN link quality and determining whether a path satisfies configured performance requirements.

Question 309

Which FortiGate configuration is used to translate an external public IP address to an internal private server address?

  1. Service group
  2. Address group
  3. Static route
  4. Virtual IP

Correct Answer: 4

Explanation

A Virtual IP, or VIP, performs destination NAT by mapping an external public address to an internal private address. It is commonly used to publish internal servers such as web or mail servers to external users. A corresponding firewall policy normally controls whether the translated traffic is permitted. Service groups combine service objects, address groups combine address objects, and static routes determine packet-forwarding paths. Therefore, Virtual IP is the correct configuration when an external public IP needs to be mapped to an internal server address.

Question 310

Which FortiGate diagnostic command can display currently active sessions handled by the firewall?

  1. diagnose sys session list
  2. get system status
  3. diagnose vpn tunnel list
  4. get router info routing-table all

Correct Answer: 1

Explanation

The diagnose sys session list command displays information about active sessions tracked by FortiGate. Administrators can use this information when troubleshooting connectivity, examining source and destination addresses, checking ports, and understanding current session states. The get system status command provides general system information, diagnose vpn tunnel list provides VPN tunnel information, and get router info routing-table all displays routing entries. Therefore, diagnose sys session list is the appropriate command for examining active firewall sessions.

Question 311

Which FortiGate feature can identify users through supported single sign-on mechanisms without requiring repeated direct authentication to FortiGate?

  1. LDAP
  2. RADIUS
  3. FSSO
  4. FortiToken

Correct Answer: 3

Explanation

Fortinet Single Sign-On, or FSSO, provides FortiGate with user identity information obtained through supported authentication and directory environments. This allows FortiGate to associate network activity with authenticated users and use that identity information in appropriate firewall policies. LDAP provides directory-based authentication, RADIUS uses centralized authentication servers, and FortiToken provides token-based authentication. FSSO is particularly useful when an organization wants identity-aware firewall policies while minimizing repeated user authentication prompts. Therefore, FSSO is the correct feature for this scenario.

Question 312

Which FortiGate feature can control which websites users are permitted to access based on URL categories?

  1. Antivirus
  2. Web Filter
  3. IPS
  4. Traffic Shaping

Correct Answer: 2

Explanation

Web Filter controls website access using URL categories, ratings, and configured filtering actions. FortiGate can use available web-rating information to classify websites and then allow, block, monitor, or warn users according to the configured policy. Antivirus focuses on malware detection, IPS identifies network attacks, and Traffic Shaping controls bandwidth. Therefore, Web Filter is the correct security profile when administrators need to control website access based on URL categories or related web-classification information.

Question 313

Which FortiGate feature can use application signatures to identify and control applications within firewall traffic?

  1. Application Control
  2. DHCP server
  3. Static route
  4. IP pool

Correct Answer: 1

Explanation

Application Control identifies applications using FortiGate application signatures and allows administrators to configure actions for specific applications or application categories. The profile can be applied to a firewall policy to control matching traffic. This provides application-aware security that can operate beyond simple IP-address and port filtering. DHCP server provides network configuration, static routes determine forwarding paths, and IP pools provide addresses for NAT. Therefore, Application Control is the correct feature for identifying and controlling applications through firewall traffic.

Question 314

Which FortiGate feature can be used to group several service objects so they can be selected together in a firewall policy?

  1. Address group
  2. User group
  3. Service group
  4. Interface zone

Correct Answer: 3

Explanation

A service group combines multiple service objects into a single reusable configuration object. Each service object can define protocols and ports, and grouping them allows administrators to apply the same firewall-policy treatment to several services at once. Address groups contain address objects, user groups organize authenticated identities, and interface zones group interfaces. Service groups can simplify policy administration when multiple services are repeatedly used in similar rules. Therefore, Service group is the correct feature for combining several service objects.

Question 315

Which FortiGate feature can provide a logical interface with a stable IP address that is not directly dependent on a physical interface?

  1. VLAN interface
  2. Loopback interface
  3. IP pool
  4. Service object

Correct Answer: 2

Explanation

A loopback interface is a logical interface that can provide a stable IP address independently of a specific physical interface’s operational state. It can be useful for routing, management, and other network functions that require a consistent logical endpoint. A VLAN interface is associated with a VLAN identifier, an IP pool provides addresses for NAT, and a service object defines protocols and ports. Therefore, Loopback interface is the appropriate configuration when a stable logical network endpoint is required.

Question 316

Which FortiGate feature can control traffic destined directly to services running on the FortiGate itself?

  1. Firewall policy
  2. SD-WAN rule
  3. Authentication rule
  4. Local-in policy

Correct Answer: 4

Explanation

A local-in policy controls traffic destined for the FortiGate itself rather than traffic passing through the firewall between different networks. It can be used to restrict access to services hosted on FortiGate, including certain management or network services, according to configured criteria. Regular firewall policies primarily control transit traffic, SD-WAN rules influence WAN path selection, and authentication rules support authentication behavior. Therefore, Local-in policy is the appropriate configuration when administrators need to control traffic directed at the FortiGate itself.

Question 317

Which FortiGate feature can provide a second authentication factor using a one-time password token?

  1. FortiToken
  2. FortiView
  3. FortiGuard
  4. FortiAnalyzer

Correct Answer: 1

Explanation

FortiToken provides token-based authentication using one-time passwords and can be used as an additional authentication factor. This strengthens account security by requiring more than just a username and password. FortiView provides graphical visibility into device activity, FortiGuard provides security intelligence and related services, and FortiAnalyzer provides centralized logging and analysis. FortiToken is therefore the appropriate Fortinet component when administrators need to implement token-based multi-factor authentication for supported users or administrative accounts.

Question 318

Which FortiGate feature can determine the path selected for traffic by evaluating configured source, destination, service, and interface conditions against firewall policies?

  1. Traffic Shaping
  2. FortiGuard
  3. Policy lookup
  4. DHCP server

Correct Answer: 3

Explanation

Policy lookup helps administrators identify which firewall policy matches specified traffic conditions. By checking factors such as source, destination, service, and interfaces, it can help explain why traffic is handled by a particular policy. This is especially useful when troubleshooting policy order or unexpected access results. Traffic Shaping manages bandwidth, FortiGuard provides security services and intelligence, and DHCP server provides client network configuration. Therefore, Policy lookup is the correct feature for determining which firewall policy matches a particular traffic flow.

Question 319

Which FortiGate feature can provide centralized authentication by communicating with an external directory using LDAP?

  1. RADIUS
  2. LDAP server
  3. FSSO
  4. FortiToken

Correct Answer: 2

Explanation

An LDAP server configuration allows FortiGate to communicate directly with an LDAP-compatible directory and authenticate users using credentials maintained by that directory. It can also support directory-based groups for appropriate authentication and policy configurations. RADIUS uses a different authentication protocol, FSSO provides user identity information through supported single sign-on mechanisms, and FortiToken provides token-based authentication. Therefore, LDAP server is the correct configuration when FortiGate needs to authenticate users against an external LDAP directory.

Question 320

Which FortiGate feature can provide centralized collection, storage, and analysis of traffic and security logs?

  1. FortiView
  2. FortiGuard
  3. Local Disk
  4. FortiAnalyzer

Correct Answer: 4

Explanation

FortiAnalyzer provides centralized collection, storage, analysis, and reporting of logs from supported Fortinet devices. It can receive logs from FortiGate appliances and provide tools for investigating traffic, security events, and operational activity. FortiView provides local graphical visibility, FortiGuard supplies security intelligence and related services, and Local Disk stores logs directly on a supported FortiGate appliance. Therefore, FortiAnalyzer is the correct solution when centralized log collection and analysis are required.