Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 361

Which FortiGate feature can identify unusually high CPU usage caused by an IPS sensor or security inspection process?

  1. System diagnostics
  2. Web Filter
  3. Address Group
  4. Service Object

Correct Answer: 1

Explanation

System diagnostics can help administrators investigate resource usage and identify conditions such as unusually high CPU utilization. When security inspection features such as IPS contribute to increased processing demand, administrators can review system resources and diagnostic information to determine the source of the load. Web Filter controls website access, Address Groups combine address objects, and Service Objects define network services. Therefore, System diagnostics is the appropriate starting point for investigating high CPU usage and determining whether a security process may be contributing to the problem.

Question 362

Which FortiGate component provides security intelligence and subscription-based services such as antivirus and web-rating updates?

  1. FortiAnalyzer
  2. FortiGuard
  3. FortiView
  4. FortiToken

Correct Answer: 2

Explanation

FortiGuard provides security intelligence and subscription-based services that support several FortiGate security functions. These services can include antivirus updates, web-rating information, application-related intelligence, and other threat intelligence depending on the licensed services. FortiAnalyzer provides centralized log management, FortiView provides local visibility into network activity, and FortiToken supports token-based authentication. Therefore, FortiGuard is the correct component when FortiGate needs current security intelligence and related service updates.

Question 363

Which FortiGate setting can prevent a management service from being reachable through an interface when that service is disabled?

  1. Administrative Access
  2. Performance SLA
  3. Service Group
  4. IP Pool

Correct Answer: 1

Explanation

Administrative Access controls which management services are enabled on a FortiGate interface. If a protocol such as HTTPS or SSH is not enabled for administrative access on that interface, the corresponding management service is not normally available through it. Performance SLA evaluates WAN-link performance, Service Groups combine service objects, and IP Pools provide addresses for source NAT. Therefore, Administrative Access is the correct setting when an administrator needs to prevent a specific management service from being reachable through an interface.

Question 364

Which FortiGate feature can combine physical interfaces into a single logical interface for simplified policy configuration?

  1. VLAN Interface
  2. Loopback Interface
  3. IP Pool
  4. Software Switch

Correct Answer: 4

Explanation

A Software Switch combines multiple physical or logical interfaces into a single logical interface. This can simplify network configuration by allowing the grouped interfaces to be treated as one interface for appropriate networking and firewall-policy purposes. A VLAN Interface provides Layer 3 connectivity for a VLAN, a Loopback Interface provides a logical endpoint, and an IP Pool supplies addresses for NAT. Therefore, Software Switch is the correct feature when multiple interfaces need to be combined into a logical interface.

Question 365

Which FortiGate feature can save the current configuration so it can be restored later if required?

  1. Configuration Backup
  2. Performance SLA
  3. Application Control
  4. Web Filter

Correct Answer: 1

Explanation

Configuration Backup allows administrators to save FortiGate configuration information for later recovery or restoration. Maintaining current backups is important before major changes such as firmware upgrades, policy modifications, or other system maintenance. Performance SLA monitors network-path quality, Application Control identifies applications, and Web Filter manages website access. A backup provides a recovery point if a configuration change causes unexpected behavior or if the device needs to be restored. Therefore, Configuration Backup is the appropriate feature for preserving the current FortiGate configuration.

Question 366

Which FortiGate feature can allow administrators to restore a previously saved configuration file?

  1. FortiView
  2. Configuration Restore
  3. Traffic Shaping
  4. Application Control

Correct Answer: 2

Explanation

Configuration Restore allows administrators to load a previously saved FortiGate configuration and return the device to an earlier configuration state. This can be useful after an unsuccessful configuration change, during recovery procedures, or when moving a known configuration to an appropriate device or environment. FortiView provides operational visibility, Traffic Shaping manages bandwidth, and Application Control identifies applications. Before restoring a configuration, administrators should verify that the file is appropriate for the device and FortiOS environment. Therefore, Configuration Restore is the correct feature.

Question 367

Which FortiGate component can provide centralized event and traffic-log analysis from several FortiGate devices?

  1. FortiToken
  2. FortiView
  3. FortiAnalyzer
  4. FortiGuard

Correct Answer: 3

Explanation

FortiAnalyzer is designed to receive and centrally analyze logs from supported Fortinet devices. It can store traffic, event, and security information and provide reporting and investigation capabilities across multiple FortiGate appliances. FortiToken provides authentication tokens, FortiView provides local visibility on a FortiGate, and FortiGuard provides security intelligence and subscription services. Centralized logging is particularly useful when administrators need to investigate activity across several devices from one location. Therefore, FortiAnalyzer is the correct component for centralized log analysis.

Question 368

Which FortiGate feature can reduce the risk of unauthorized administrative access by restricting an administrator account to known source networks?

  1. Trusted Hosts
  2. Service Group
  3. DNS Filter
  4. Traffic Shaping

Correct Answer: 1

Explanation

Trusted Hosts restrict an administrator account so that management access is accepted only from specified source IP addresses or networks. This provides an additional control beyond username and password authentication and can significantly reduce exposure to unauthorized management attempts from unapproved locations. Service Groups combine network services, DNS Filter controls domain-based access, and Traffic Shaping manages bandwidth. Therefore, Trusted Hosts is the appropriate feature when administrator accounts need to be limited to known management networks.

Question 369

Which FortiGate feature can determine whether traffic should use one SD-WAN member instead of another based on configured conditions?

  1. Performance SLA
  2. SD-WAN Rule
  3. Static Route
  4. Address Group

Correct Answer: 2

Explanation

An SD-WAN Rule determines how FortiGate selects among available SD-WAN members for matching traffic. Rules can use criteria such as source, destination, application, service, and link-quality information to influence path selection. Performance SLA measures path health, but the SD-WAN rule uses those conditions when deciding how traffic should be handled. Static Routes provide routing entries, while Address Groups combine address objects. Therefore, SD-WAN Rule is the correct feature for controlling which SD-WAN member should be selected for matching traffic.

Question 370

Which FortiGate routing feature can provide a backup path when the preferred static route becomes unavailable?

  1. Web Filter
  2. Service Object
  3. Static routes with different priorities
  4. Application Control

Correct Answer: 3

Explanation

Static routes with different priorities can provide route redundancy. When multiple routes exist for the same destination, the route with the preferred routing attributes can be selected while another route remains available as a backup. If the preferred route becomes unavailable, FortiGate can use the alternate route when the routing conditions allow it. Web Filter, Service Object, and Application Control are unrelated to route selection. Therefore, configuring static routes with different priorities is an appropriate method for creating a primary and backup routing path.

Question 371

Which FortiGate security profile can identify applications even when multiple applications use commonly shared network ports?

  1. Application Control
  2. Static Route
  3. DHCP Server
  4. IP Pool

Correct Answer: 1

Explanation

Application Control uses application signatures and inspection techniques to identify applications within network traffic rather than relying only on destination port numbers. This is useful because multiple applications can use common ports such as TCP 80 or TCP 443. Static Routes determine packet-forwarding paths, DHCP Server assigns network configuration, and IP Pools provide addresses for NAT. Therefore, Application Control is the appropriate security profile when administrators need application-level identification and control beyond simple port-based filtering.

Question 372

Which FortiGate feature can detect and block network attacks using configured intrusion-prevention signatures?

  1. Web Filter
  2. IPS
  3. DNS Filter
  4. Traffic Shaping

Correct Answer: 2

Explanation

IPS uses intrusion-prevention signatures and inspection mechanisms to identify known malicious patterns and network attacks. An IPS profile can be applied to firewall policies and configured with appropriate actions, such as blocking or monitoring matching traffic. Web Filter controls website access, DNS Filter manages domain-based access, and Traffic Shaping manages bandwidth. Therefore, IPS is the correct FortiGate security feature when the objective is to detect and prevent network attacks using intrusion-prevention signatures.

Question 373

Which FortiGate feature can provide domain-based filtering by evaluating DNS requests?

  1. Web Filter
  2. Antivirus
  3. DNS Filter
  4. IP Pool

Correct Answer: 3

Explanation

DNS Filter controls access based on domain names by evaluating DNS-related requests and applying configured filtering actions. It can be used to block or allow domains according to categories, reputation, or administrator-defined settings supported by the FortiGate configuration. Web Filter operates primarily on web traffic and URL filtering, Antivirus focuses on malicious content, and IP Pool provides addresses for NAT. Therefore, DNS Filter is the appropriate security profile when administrators need to control access at the domain-resolution level.

Question 374

Which FortiGate feature can authenticate users against a directory service using the LDAP protocol?

  1. LDAP Server
  2. Performance SLA
  3. Virtual IP
  4. Traffic Shaping

Correct Answer: 1

Explanation

LDAP Server configuration allows FortiGate to communicate with an external LDAP directory for user authentication and related directory operations. Administrators can configure the server address, connection parameters, and appropriate directory settings so FortiGate can validate user credentials against the organization’s directory service. Performance SLA measures SD-WAN path quality, Virtual IP provides destination NAT, and Traffic Shaping manages bandwidth. Therefore, LDAP Server is the correct configuration when user authentication needs to be performed through an LDAP-compatible directory.

Question 375

Which FortiGate feature can provide two-factor authentication by requiring a password and a one-time token?

  1. FortiAnalyzer
  2. FortiGuard
  3. FortiToken
  4. FortiView

Correct Answer: 3

Explanation

FortiToken provides one-time-password authentication that can be used as an additional factor alongside a password. This creates a multi-factor authentication process in which possession of the token is required in addition to knowledge of the password. FortiAnalyzer is used for centralized logging, FortiGuard provides security intelligence and services, and FortiView provides network visibility. Therefore, FortiToken is the correct Fortinet component when administrators need to implement token-based two-factor authentication.

Question 376

Which FortiGate feature can control traffic sent to services running directly on the FortiGate itself?

  1. Firewall Policy
  2. Local-in Policy
  3. SD-WAN Rule
  4. Service Group

Correct Answer: 2

Explanation

A Local-in Policy controls traffic destined for the FortiGate itself rather than traffic passing through the appliance between other networks. It can be used to restrict access to services and management functions exposed by FortiGate according to configured source, destination, interface, service, and action criteria. Firewall policies generally control transit traffic, SD-WAN rules influence WAN path selection, and Service Groups combine service objects. Therefore, Local-in Policy is the appropriate feature for controlling traffic addressed directly to FortiGate.

Question 377

Which FortiGate feature can provide visibility into the current state of IPsec VPN tunnels for troubleshooting?

  1. FortiView
  2. VPN Monitoring
  3. Web Filter
  4. DHCP Server

Correct Answer: 2

Explanation

VPN Monitoring provides information about configured VPN connections and can help administrators determine whether IPsec tunnels are operational. When a tunnel is not established or traffic is not passing as expected, VPN monitoring information can be useful as part of the troubleshooting process. FortiView provides broader activity visibility, Web Filter controls website access, and DHCP Server provides client network configuration. Therefore, VPN Monitoring is the appropriate feature for checking the operational state of IPsec VPN tunnels.

Question 378

Which FortiGate feature can capture packets passing through an interface for detailed network troubleshooting?

  1. Packet Capture
  2. FortiToken
  3. Address Group
  4. Schedule

Correct Answer: 1

Explanation

Packet Capture allows administrators to capture network packets for detailed troubleshooting and analysis. Captured traffic can help identify whether packets are arriving at the expected interface, determine whether responses are being generated, and investigate protocol-level connectivity problems. FortiToken provides authentication tokens, Address Groups combine network objects, and Schedule controls when firewall policies are active. Packet captures should normally be filtered appropriately so that the resulting information remains focused on the traffic under investigation. Therefore, Packet Capture is the correct troubleshooting feature.

Question 379

Which FortiGate feature can provide a reusable collection of authenticated users for use in access-control policies?

  1. Address Group
  2. Service Group
  3. User Group
  4. Interface Zone

Correct Answer: 3

Explanation

A User Group combines configured or externally authenticated users so they can be referenced together in authentication and identity-based access-control configurations. This simplifies administration when several users require the same access permissions. Address Groups combine network address objects, Service Groups combine service objects, and Interface Zones group interfaces. User Groups are therefore appropriate when firewall or authentication policies need to apply the same treatment to multiple users without configuring each identity separately.

Question 380

Which FortiGate feature can use a DNS name rather than a fixed IP address when defining a destination address object?

  1. IP Pool
  2. Service Object
  3. FQDN Address
  4. Static Route

Correct Answer: 3

Explanation

An FQDN Address object uses a fully qualified domain name as the address definition. FortiGate can resolve the configured domain name and use the resulting address information in supported firewall-policy decisions. This can be useful for destinations whose IP addresses may change while their DNS name remains consistent. IP Pools provide source NAT addresses, Service Objects define protocols and ports, and Static Routes determine forwarding paths. Therefore, FQDN Address is the correct feature when a destination needs to be represented by a DNS name rather than a fixed IP address.