Fortinet NSE4_FGT-7.0 Practice Test Questions and Exam Dumps Part 1 Q1-20

View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps

 

Question 1. A FortiGate administrator needs to allow internal users to access the internet while translating their private source addresses to the FortiGate’s outgoing interface address. Which configuration should be used?

  1. Destination NAT using a virtual IP
  2. Source NAT enabled on the firewall policy
  3. IPsec phase 2 selector
  4. Static routing with a blackhole route

Correct Answer: 2. Source NAT enabled on the firewall policy

Explanation :-

Source NAT changes the source address of traffic leaving the FortiGate. In a typical internet-access policy, enabling NAT allows private internal addresses to be translated before traffic is sent toward the external interface. Destination NAT, commonly implemented with a virtual IP, is instead used to translate incoming traffic toward an internal destination. IPsec phase 2 selectors define protected traffic for an IPsec VPN, while a blackhole route is used to discard matching traffic. FortiOS 7.0 documentation shows source NAT as an option in firewall policies for outbound traffic.

Question 2. Which FortiGate component determines whether traffic is allowed or denied based on source, destination, service, interface, schedule, and action?

  1. Firewall policy
  2. Static route
  3. DNS database
  4. IPsec phase 2

Correct Answer: 1. Firewall policy

Explanation :-

A FortiGate firewall policy defines how matching traffic should be handled. Policy parameters can include incoming and outgoing interfaces, source and destination addresses, schedule, services, security profiles, NAT, and the action to take. A static route determines the forwarding path but does not by itself provide the same security-policy decision. DNS provides name resolution, while IPsec phase 2 defines protected traffic selectors for a VPN. Firewall policies are therefore central to controlling permitted network traffic.

Question 3. A FortiGate has two possible routes to the same destination. Which routing attribute can be used to prefer one static route over another when their destinations are otherwise equivalent?

  1. Security profile
  2. Firewall policy action
  3. Administrative distance
  4. SSL inspection mode

Correct Answer: 3. Administrative distance

Explanation :-

Administrative distance is used by FortiGate when comparing routes learned from different sources or configured route entries. When appropriate routes have the same destination prefix, the route with the lower administrative distance is generally preferred. Security profiles inspect traffic rather than select routes, firewall policy actions determine how matching sessions are handled, and SSL inspection controls inspection of encrypted traffic. Understanding administrative distance is therefore important when troubleshooting why FortiGate selects one available route instead of another.

Question 4. Which FortiGate feature allows an administrator to publish an internal server through a public IP address by translating incoming traffic to the server’s private address?

  1. IP pool
  2. Policy route
  3. Security profile
  4. Virtual IP

Correct Answer: 4. Virtual IP

Explanation :-

A FortiGate virtual IP, or VIP, can provide destination NAT for incoming traffic. A public or external address can be mapped to an internal server address, allowing clients on an external network to reach the published service. An IP pool is generally associated with source NAT, while a policy route influences forwarding decisions and a security profile provides traffic inspection. FortiOS documentation includes static virtual IPs and port-forwarding VIPs as destination NAT mechanisms.

Question 5. Which inspection mode examines traffic as it passes through FortiGate without requiring the entire content to be buffered before inspection?

  1. Flow-based inspection
  2. Proxy-based inspection
  3. Offline inspection
  4. Route-only inspection

Correct Answer: 1. Flow-based inspection

Explanation :-

Flow-based inspection analyzes traffic as it flows through the FortiGate rather than operating as a full proxy for the traffic. This approach can provide efficient security inspection while allowing the traffic stream to continue through the security engine. Proxy-based inspection uses a different architecture in which FortiGate acts as an intermediary for supported traffic and can buffer content as required by particular security functions. FortiOS 7.0 documentation identifies flow mode and proxy mode as distinct inspection approaches.

Question 6. An administrator wants to establish a site-to-site encrypted connection between two FortiGate devices. Which technology is designed for this requirement?

  1. DHCP relay
  2. IPsec VPN
  3. DNS forwarding
  4. Traffic shaping

Correct Answer: 2. IPsec VPN

Explanation :-

IPsec VPN provides encrypted network connectivity between sites. A common FortiGate deployment uses an IPsec tunnel between two gateways so that traffic between protected networks can traverse an untrusted network securely. DHCP relay forwards DHCP requests, DNS forwarding handles name-resolution requests, and traffic shaping controls bandwidth behavior. FortiOS 7.0 includes site-to-site IPsec VPN configuration with phase 1, phase 2, authentication, and VPN security policies.

Question 7. Which FortiGate feature can identify applications in network traffic and allow an administrator to control them through a security policy?

  1. Application Control
  2. Static routing
  3. DHCP server
  4. IPsec phase 1

Correct Answer: 1. Application Control

Explanation :-

Application Control is a FortiGate security feature used to identify applications and apply controls based on application signatures and categories. It can be associated with firewall policies to control application traffic according to organizational requirements. Static routing determines forwarding paths, DHCP provides address configuration, and IPsec phase 1 establishes and negotiates VPN parameters. Application Control is therefore the appropriate feature when the requirement is to identify and control specific applications.

Question 8. A remote employee needs secure access to internal corporate resources through an encrypted connection from an untrusted network. Which FortiGate technology is appropriate?

  1. Web filtering
  2. VLAN trunking
  3. SSL VPN
  4. DNS filtering

Correct Answer: 3. SSL VPN

Explanation :-

FortiGate SSL VPN can provide remote users with secure access to internal resources through an encrypted VPN connection. It is designed for remote-access scenarios where users connect from external or untrusted networks. Web filtering controls access to websites, VLAN trunking transports VLAN traffic, and DNS filtering focuses on domain-resolution controls. FortiOS 7.0 documentation includes SSL VPN remote-access configurations such as split tunneling and FortiClient VPN connectivity.

Question 9. Which FortiGate object represents a network, host, IP range, or other destination that can be referenced by firewall policies?

  1. Address object
  2. Session helper
  3. Route monitor
  4. IPS engine

Correct Answer: 1. Address object

Explanation :-

FortiGate address objects represent network destinations such as individual IP addresses, subnets, IP ranges, and supported dynamic address types. These objects can then be referenced by firewall policies instead of repeatedly entering addressing information. Session helpers assist with certain protocol sessions, the route monitor displays routing information, and the IPS engine performs intrusion prevention inspection. FortiOS 7.0 supports several address-object types, including subnet, IP range, FQDN, and address groups.

Question 10. During IPsec VPN establishment, which phase is primarily responsible for negotiating the secure IKE management connection and authenticating the peers?

  1. Phase 2
  2. Firewall policy processing
  3. Phase 1
  4. Application Control

Correct Answer: 3. Phase 1

Explanation :-

IPsec VPN Phase 1 establishes the initial IKE security association between the VPN peers. It negotiates parameters used to create the secure management relationship and authenticates the peers using configured authentication methods. Phase 2 subsequently establishes the IPsec security associations used to protect the actual data traffic. Firewall policies control traffic after it reaches the policy-processing stage, while Application Control identifies applications. FortiOS 7.0 documentation separates IPsec configuration into Phase 1 and Phase 2 settings.

Question 11. Which FortiGate security profile is primarily designed to detect and block malicious files and malware?

  1. Web Filter
  2. Antivirus
  3. Application Control
  4. Traffic Shaping

Correct Answer: 2. Antivirus

Explanation :-

The FortiGate Antivirus security profile is designed to detect and block malware and other malicious content according to its configured inspection capabilities. It can be attached to appropriate firewall policies so that traffic matching those policies receives antivirus inspection. Web Filter focuses on web access and URL categories, Application Control identifies and controls applications, and Traffic Shaping manages bandwidth behavior. Antivirus is therefore the security profile most directly associated with malware and malicious-file detection.

Question 12. An administrator needs to troubleshoot why traffic is being denied by a FortiGate policy. Which FortiGate capability can help identify the policy that would match particular traffic?

  1. Policy lookup
  2. DHCP relay
  3. IPsec phase 1
  4. DNS cache

Correct Answer: 1. Policy lookup

Explanation :-

FortiGate policy lookup can help administrators determine which firewall policy would match specified traffic. This is useful when troubleshooting policy ordering, source and destination objects, interfaces, services, and other matching criteria. DHCP relay handles DHCP forwarding, IPsec phase 1 establishes VPN negotiation parameters, and DNS caching relates to name resolution. FortiOS 7.0 includes policy views and policy lookup functionality specifically for examining policy matching and troubleshooting policy behavior.

Question 13. Which routing protocol can FortiGate use to exchange routes dynamically with neighboring routers in an enterprise network?

  1. SMTP
  2. FTP
  3. OSPF
  4. SNMP

Correct Answer: 3. OSPF

Explanation :-

OSPF is a dynamic routing protocol that FortiGate can use to exchange routing information with neighboring routers. Instead of manually configuring every route, administrators can use OSPF to dynamically learn and advertise network prefixes within an OSPF domain. SMTP is an email protocol, FTP is used for file transfer, and SNMP is primarily used for network monitoring and management. FortiOS 7.0 provides OSPF configuration and troubleshooting capabilities as part of its routing features.

Question 14. Which FortiGate feature can restrict users from accessing websites based on URL categories or web-rating classifications?

  1. Traffic shaping
  2. Web Filter
  3. Static route
  4. IPsec VPN

Correct Answer: 2. Web Filter

Explanation :-

FortiGate Web Filter can control web access based on URL categories and related web-rating information. Administrators can configure web-filter profiles and attach them to appropriate firewall policies to control access to websites. Traffic shaping controls bandwidth, static routes determine forwarding paths, and IPsec VPN provides encrypted connectivity. Web Filter is therefore the appropriate security feature when an organization needs to restrict access according to website categories or ratings.

Question 15. A FortiGate administrator wants to create a rule that gives higher priority to a specific type of business traffic when multiple applications compete for limited bandwidth. Which feature should be considered?

  1. Traffic shaping
  2. DNS server
  3. Address group
  4. Virtual IP

Correct Answer: 1. Traffic shaping

Explanation :-

Traffic shaping can be used to control and prioritize network bandwidth according to configured policies or traffic classes. An administrator can use traffic-shaping features to manage how available bandwidth is allocated when multiple types of traffic compete for network resources. A DNS server provides name resolution, address groups organize address objects, and virtual IPs provide destination NAT. FortiOS 7.0 includes traffic-shaping policies and traffic-shaping profiles as part of its policy and object capabilities.

Question 16. Which FortiGate component provides centralized configuration separation so different virtual firewalls can operate independently on the same physical device?

  1. VDOM
  2. IP pool
  3. Security profile
  4. FortiGuard category

Correct Answer: 1. VDOM

Explanation :-

Virtual domains, or VDOMs, allow a FortiGate device to be divided into separate logical firewall environments. Each VDOM can maintain its own policies, interfaces, routing configuration, and other settings, depending on the deployment and permissions. An IP pool is used for address translation, a security profile provides inspection capabilities, and FortiGuard categories support security services such as web classification. VDOMs therefore provide logical separation of firewall environments within a FortiGate.

Question 17. Which FortiGate feature can provide centralized control over source NAT rules when Central SNAT is enabled?

  1. Central SNAT table
  2. Web Filter profile
  3. IPsec Phase 2 selector
  4. DHCP server

Correct Answer: 1. Central SNAT table

Explanation :-

The Central SNAT table provides centralized control over source NAT rules. When Central NAT is enabled, source NAT is handled through the central SNAT configuration rather than the NAT option on individual IPv4 firewall policies. Administrators can define matching conditions and translation behavior through the central SNAT entries. Web Filter controls web access, IPsec Phase 2 defines protected traffic selectors, and DHCP provides address configuration. FortiOS 7.0 documentation specifically describes the Central SNAT table and its relationship to firewall-policy NAT.

Question 18. Which FortiGate security feature is intended to detect and block network-based intrusion attempts using signatures and related inspection techniques?

  1. DHCP
  2. IPS
  3. DNS
  4. NAT

Correct Answer: 2. IPS

Explanation :-

FortiGate Intrusion Prevention System, or IPS, is designed to detect and prevent network attacks by inspecting traffic for known malicious patterns and other indicators. IPS functionality can be applied through security profiles associated with firewall policies. DHCP provides IP configuration, DNS handles name resolution, and NAT translates network addresses. IPS is therefore the appropriate FortiGate security feature when the requirement is to detect and block network-based intrusion attempts.

Question 19. A FortiGate administrator needs to determine the next-hop path FortiGate will use to reach a particular destination. Which information should be examined first?

  1. Routing table
  2. Antivirus profile
  3. Web Filter profile
  4. Application signature database

Correct Answer: 1. Routing table

Explanation :-

The FortiGate routing table contains the routes available to the device and helps determine which path is selected for a destination. Examining the routing table is an important first step when troubleshooting forwarding problems because it can reveal whether an appropriate route exists and which interface or gateway is associated with it. Antivirus, Web Filter, and Application Control provide security inspection rather than determine the fundamental routing path. FortiOS 7.0 documentation includes procedures for verifying routing-table contents and the route selected for traffic.

Question 20. Which configuration is required to allow traffic through a FortiGate when the traffic must be explicitly permitted by a security policy?

  1. A matching firewall policy with an appropriate accept action
  2. A DNS record only
  3. An IPsec Phase 2 selector only
  4. A traffic-shaping profile only

Correct Answer: 1. A matching firewall policy with an appropriate accept action

Explanation :-

FortiGate uses firewall policies to determine whether matching traffic is permitted or denied. A policy must match the relevant interfaces, addresses, schedule, and service, and its action must allow the traffic. A DNS record does not authorize network forwarding, an IPsec Phase 2 selector only defines protected VPN traffic, and a traffic-shaping profile manages bandwidth behavior rather than replacing access control. FortiOS 7.0 examples show firewall policies configured with source, destination, service, schedule, and an ACCEPT action.