Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 341

Which FortiGate feature can synchronize configuration and session information between members of a high-availability cluster?

  1. HA synchronization
  2. Performance SLA
  3. FortiAnalyzer
  4. Traffic Shaping

Correct Answer: 1

Explanation

HA synchronization allows FortiGate devices operating in a high-availability cluster to maintain consistent configuration and, where supported, session information between cluster members. This helps the secondary device remain prepared to take over if the primary unit fails. Performance SLA measures network-path quality, FortiAnalyzer provides centralized logging, and Traffic Shaping manages bandwidth. Proper synchronization is important because differences between cluster members can cause unexpected behavior during failover. Therefore, HA synchronization is the correct feature for maintaining consistency across FortiGate HA members.

Question 342

Which FortiGate component determines the order in which firewall policies are evaluated for matching traffic?

  1. Policy lookup
  2. Policy sequence
  3. Service object
  4. Schedule

Correct Answer: 2

Explanation

The policy sequence determines the order in which firewall policies are evaluated. FortiGate generally evaluates applicable policies from the top of the policy list downward, and the first matching policy is used for the traffic. Therefore, placing a more specific policy above a broader rule can be important when controlling access. Policy lookup helps identify which policy matches traffic, while service objects define protocols and ports and schedules control policy timing. The policy sequence is therefore essential when policy-order behavior needs to be understood.

Question 343

Which FortiGate inspection mode examines traffic as it passes through the device without buffering the complete content before inspection?

  1. Proxy-based inspection
  2. Certificate inspection
  3. Flow-based inspection
  4. Deep inspection

Correct Answer: 3

Explanation

Flow-based inspection examines network traffic as it passes through FortiGate rather than requiring the complete content to be buffered before processing. This approach can provide efficient inspection with relatively low processing overhead while still allowing supported security profiles to analyze traffic. Proxy-based inspection handles traffic through a proxy architecture, certificate inspection focuses on certificate information, and deep inspection can decrypt encrypted traffic for more detailed analysis. Therefore, Flow-based inspection is the correct mode when traffic should be inspected in transit without full proxy-style buffering.

Question 344

Which FortiGate feature can allow an administrator to temporarily change the action of a web-filter category for a specific user or group?

  1. Traffic Shaping
  2. Application Control
  3. IPS
  4. Web Filter Override

Correct Answer: 4

Explanation

Web Filter Override allows administrators to create controlled exceptions to normal web-filtering behavior for authorized users or groups. This can be useful when a category is normally blocked or restricted but specific users require access for legitimate business purposes. The override can be configured according to the organization’s access-control requirements. Traffic Shaping manages bandwidth, Application Control manages application traffic, and IPS detects network attacks. Therefore, Web Filter Override is the appropriate feature when specific users need an exception to standard web-filtering rules.

Question 345

Which FortiGate feature can define a reusable object representing a specific TCP or UDP port and protocol?

  1. Service Object
  2. Address Group
  3. User Group
  4. Interface Zone

Correct Answer: 1

Explanation

A Service Object defines a network service using parameters such as protocol and port number. These objects can then be selected in firewall policies to control traffic for specific services. For example, an administrator can create a service object for a particular TCP port and reuse it across multiple policies. Address Groups combine address objects, User Groups organize authenticated identities, and Interface Zones group interfaces. Therefore, Service Object is the correct configuration when a reusable definition of a specific network service is required.

Question 346

Which FortiGate feature can determine whether a configured route is preferred over another route to the same destination?

  1. Schedule
  2. Administrative distance
  3. Web Filter
  4. Service Group

Correct Answer: 2

Explanation

Administrative distance is used to establish the preference of routes learned from different sources when multiple routes to the same destination are available. Generally, a route with a lower administrative distance is preferred over a route with a higher value, assuming other relevant routing conditions are satisfied. Schedule controls firewall-policy timing, Web Filter controls website access, and Service Group combines service objects. Therefore, Administrative distance is the appropriate routing parameter for comparing the preference of routes from different sources.

Question 347

Which FortiGate feature can inspect the certificate information of encrypted HTTPS traffic without decrypting the full content?

  1. Deep Inspection
  2. Flow-based Inspection
  3. Certificate Inspection
  4. Traffic Shaping

Correct Answer: 3

Explanation

Certificate Inspection examines information contained in SSL/TLS certificates without performing full content decryption of the encrypted session. It can provide visibility into certificate-related information while avoiding the broader privacy and compatibility considerations associated with deep inspection. Deep Inspection decrypts supported sessions for content-level inspection, Flow-based Inspection describes a traffic-processing approach, and Traffic Shaping manages bandwidth. Therefore, Certificate Inspection is the correct option when the administrator needs to evaluate certificate information without fully decrypting the HTTPS content.

Question 348

Which FortiGate feature can provide automatic failover between two or more WAN paths when one path becomes unavailable?

  1. Address Group
  2. Service Object
  3. Antivirus
  4. SD-WAN

Correct Answer: 4

Explanation

SD-WAN can provide path selection and failover across multiple WAN connections. By combining SD-WAN members with Performance SLA monitoring and appropriate SD-WAN rules, FortiGate can detect when a path no longer satisfies configured requirements and select another available path. Address Groups organize network addresses, Service Objects define network services, and Antivirus protects against malicious files. Therefore, SD-WAN is the appropriate feature for managing multiple WAN paths and providing automated path selection or failover based on configured conditions.

Question 349

Which FortiGate feature can provide detailed graphical visibility into traffic, applications, users, and security activity on the appliance?

  1. FortiView
  2. FortiToken
  3. DHCP Server
  4. RADIUS

Correct Answer: 1

Explanation

FortiView provides graphical and interactive visibility into network activity observed by FortiGate. Depending on the available data and configuration, administrators can use FortiView to examine traffic, applications, users, sources, destinations, and security-related information. FortiToken provides authentication tokens, DHCP Server assigns network configuration, and RADIUS supports centralized authentication. FortiView is therefore the correct feature when an administrator needs an operational overview of network and security activity directly from the FortiGate management interface.

Question 350

Which FortiGate feature can authenticate a user against a local database maintained on the FortiGate?

  1. RADIUS
  2. LDAP
  3. Local Authentication
  4. FSSO

Correct Answer: 3

Explanation

Local Authentication uses user accounts configured directly on the FortiGate for authentication. This can be useful for smaller environments or situations where local accounts are appropriate for specific administrative or network-access requirements. RADIUS authenticates through an external RADIUS server, LDAP communicates with an external directory service, and FSSO provides user identity information through supported single sign-on mechanisms. Therefore, Local Authentication is the correct choice when FortiGate itself maintains the user credentials used for authentication.

Question 351

Which FortiGate security profile is primarily responsible for identifying malicious files and malware in inspected traffic?

  1. Antivirus
  2. Web Filter
  3. Application Control
  4. DNS Filter

Correct Answer: 1

Explanation

The Antivirus security profile is designed to detect malicious files and malware within supported inspected traffic. It can be applied through firewall policies so matching traffic is scanned according to the configured antivirus settings. Web Filter controls access to websites, Application Control identifies applications, and DNS Filter controls domain-based access using DNS-related security policies. Therefore, Antivirus is the correct security profile when the primary objective is to identify and handle malware or malicious files passing through FortiGate.

Question 352

Which FortiGate feature can resolve a domain name into an address object for use in firewall policies?

  1. IP Pool
  2. FQDN Address
  3. Service Group
  4. Loopback Interface

Correct Answer: 2

Explanation

An FQDN address object allows administrators to define an address using a fully qualified domain name rather than only a fixed IP address. FortiGate can resolve the domain name and use the resulting address information for supported policy decisions. IP Pools provide source NAT addresses, Service Groups combine service objects, and Loopback Interfaces provide logical interfaces. Therefore, FQDN Address is the correct feature when a firewall policy needs to reference a destination using its domain name.

Question 353

Which FortiGate feature can protect management interfaces by limiting access to approved protocols such as HTTPS and SSH?

  1. Administrative Access
  2. Address Group
  3. Performance SLA
  4. Traffic Shaping

Correct Answer: 1

Explanation

Administrative Access controls which management protocols can be used through a FortiGate interface. Administrators can enable required protocols, such as HTTPS or SSH, and disable unnecessary services to reduce the management exposure of the device. Address Groups organize network addresses, Performance SLA evaluates SD-WAN link performance, and Traffic Shaping controls bandwidth. Therefore, Administrative Access is the correct setting when the goal is to determine which management protocols can reach a particular FortiGate interface.

Question 354

Which FortiGate feature can provide redundancy by allowing a secondary device to take over when the primary device fails?

  1. SD-WAN
  2. FortiAnalyzer
  3. FGCP HA
  4. Web Filter

Correct Answer: 3

Explanation

FortiGate Clustering Protocol, or FGCP HA, allows multiple FortiGate devices to operate as a high-availability cluster. In an active-passive configuration, one unit normally handles traffic while another remains available to take over if the primary unit fails. This improves service availability and reduces the impact of hardware or system failures. SD-WAN manages WAN paths, FortiAnalyzer handles centralized logging, and Web Filter controls website access. Therefore, FGCP HA is the correct feature for providing FortiGate device redundancy and failover.

Question 355

Which FortiGate configuration can specify the IP address range used when source NAT assigns addresses from a pool?

  1. IP Pool
  2. Virtual IP
  3. Service Group
  4. User Group

Correct Answer: 1

Explanation

An IP Pool defines one or more public or translated IP addresses that FortiGate can use for source NAT. Instead of relying only on the outgoing interface address, a firewall policy can be configured to use an IP pool when translated traffic requires specific source addresses. Virtual IP performs destination NAT, Service Groups combine service objects, and User Groups organize authenticated users. Therefore, IP Pool is the correct configuration when specific addresses need to be assigned to translated source traffic.

Question 356

Which FortiGate feature can identify applications such as social media, file sharing, or streaming services within network traffic?

  1. Web Filter
  2. IPS
  3. Application Control
  4. DHCP Server

Correct Answer: 3

Explanation

Application Control identifies applications within network traffic using FortiGate application signatures and related identification mechanisms. Administrators can configure actions for individual applications or categories and apply the profile through firewall policies. Web Filter primarily controls websites and URL categories, IPS identifies network attacks, and DHCP Server assigns network configuration to clients. Therefore, Application Control is the appropriate feature when the objective is to identify and control applications such as streaming, social media, or file-sharing services.

Question 357

Which FortiGate feature can collect information about security events and traffic for later centralized reporting?

  1. Local User
  2. FortiAnalyzer
  3. Service Object
  4. VLAN Interface

Correct Answer: 2

Explanation

FortiAnalyzer can collect logs from FortiGate devices and provide centralized storage, analysis, investigation, and reporting. This allows administrators to review security events and network activity over time instead of relying only on information available locally on one FortiGate. Local User provides an authentication account, Service Object defines protocols and ports, and VLAN Interface provides connectivity for a VLAN. Therefore, FortiAnalyzer is the appropriate solution when logs need to be centrally collected and used for analysis or reporting.

Question 358

Which FortiGate feature can assign different authentication requirements to users based on configured authentication rules?

  1. Firewall Address
  2. DHCP Server
  3. Authentication Rule
  4. Traffic Shaping

Correct Answer: 3

Explanation

Authentication Rules allow FortiGate to determine how users should be authenticated based on configured matching conditions and authentication settings. They can be used to support controlled access to resources where user authentication is required. Firewall addresses identify network endpoints, DHCP Server provides IP configuration, and Traffic Shaping manages bandwidth. Therefore, Authentication Rule is the correct feature when administrators need to define and apply specific authentication behavior based on configured conditions.

Question 359

Which FortiGate feature can monitor the status of an IPsec VPN tunnel and help identify whether the tunnel is established?

  1. VPN monitoring
  2. Web Filter
  3. Address Group
  4. Service Group

Correct Answer: 1

Explanation

VPN monitoring provides visibility into the operational status of configured IPsec VPN tunnels. Administrators can use VPN-related monitoring information to determine whether a tunnel is established and investigate connectivity problems when the expected VPN state is not present. Web Filter controls website access, Address Groups organize network addresses, and Service Groups combine service objects. Therefore, VPN monitoring is the appropriate feature for checking the operational condition of IPsec VPN connections and supporting VPN troubleshooting.

Question 360

Which FortiGate feature can create a logical interface that carries traffic for a specific VLAN over a physical interface?

  1. Loopback Interface
  2. Software Switch
  3. VLAN Interface
  4. IP Pool

Correct Answer: 3

Explanation

A VLAN Interface creates a logical interface associated with a specific VLAN identifier and can carry tagged VLAN traffic over a physical or suitable parent interface. It allows FortiGate to provide Layer 3 connectivity and apply firewall policies to traffic belonging to that VLAN. A Loopback Interface is a logical endpoint independent of a physical interface, a Software Switch combines interfaces, and an IP Pool provides addresses for NAT. Therefore, VLAN Interface is the correct configuration for handling traffic belonging to a specific VLAN.