Fortinet NSE4_FGT-7.0 Practice Test Questions and Exam Dumps Part 2 Q21-40

View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps

 

Question 21. A FortiGate administrator needs to inspect the routing decision for a packet based on its source and destination addresses. Which troubleshooting tool is most appropriate?

  1. FortiView
  2. Packet capture
  3. IPsec monitor
  4. Policy route lookup

Correct Answer: 4. Policy route lookup

Explanation :-

Policy route lookup can help an administrator determine how FortiGate evaluates routing information for a particular traffic flow. It is useful when troubleshooting situations where policy-based routing, static routes, or other routing decisions affect packet forwarding. FortiView provides traffic visibility, packet capture displays packets observed on interfaces, and the IPsec monitor focuses on VPN status. When the primary concern is determining the routing decision for specific source and destination information, route lookup is the appropriate troubleshooting approach.

Question 22. Which FortiGate feature allows an administrator to define alternate forwarding behavior based on source address, destination address, incoming interface, or other matching criteria?

  1. Policy-based routing
  2. Antivirus
  3. Web filtering
  4. DHCP relay

Correct Answer: 1. Policy-based routing

Explanation :-

Policy-based routing, or PBR, allows FortiGate to make forwarding decisions based on configured traffic criteria rather than relying solely on the normal routing-table lookup. Administrators can use matching conditions such as source address, destination address, protocol, or incoming interface to direct traffic through a particular gateway or interface. Antivirus and web filtering provide security inspection, while DHCP relay forwards DHCP requests. PBR is therefore appropriate when traffic requires a forwarding decision based on specific policy conditions.

Question 23. Which FortiGate command is commonly used to display the routing table from the CLI?

  1. diagnose debug application ipsmonitor
  2. get router info routing-table all
  3. diagnose vpn tunnel list
  4. execute ping-options

Correct Answer: 2. get router info routing-table all

Explanation :-

The get router info routing-table all command displays the routing table and provides useful information about routes known to the FortiGate. Administrators commonly use routing-table commands when troubleshooting connectivity and forwarding problems. diagnose debug application ipsmonitor relates to IPS debugging, diagnose vpn tunnel list provides VPN tunnel information, and execute ping-options configures options for ping testing. Reviewing the routing table is an important troubleshooting step when determining how FortiGate will forward traffic.

Question 24. An administrator wants to allow only HTTPS access from a specific internal subnet to the internet. Which firewall policy configuration is most appropriate?

  1. Service set to ALL with no source restriction
  2. Service set to DNS only
  3. Source set to the internal subnet and service set to HTTPS
  4. Destination set to the internal subnet and service set to HTTP

Correct Answer: 3. Source set to the internal subnet and service set to HTTPS

Explanation :-

A FortiGate firewall policy can restrict traffic by source address and service. To allow HTTPS access from a particular internal subnet, the source should identify that subnet and the service should be HTTPS. Using ALL would allow more services than required, DNS would not provide HTTPS access, and reversing the source and destination addressing would not represent the intended outbound flow. Restricting policies to the required sources and services follows the principle of allowing only the traffic necessary for the business requirement.

Question 25. Which FortiGate feature provides visibility into applications, users, destinations, and traffic activity through graphical dashboards and statistics?

  1. FortiView
  2. Virtual IP
  3. DHCP server
  4. IPsec Phase 1

Correct Answer: 1. FortiView

Explanation :-

FortiView provides graphical visibility into network activity and can present information about traffic, applications, users, sources, destinations, and other monitored activity depending on the FortiGate configuration and available logging. A virtual IP performs destination NAT, a DHCP server provides IP configuration to clients, and IPsec Phase 1 establishes VPN negotiation parameters. FortiView is therefore the appropriate feature when an administrator needs an interactive view of network activity for monitoring and troubleshooting.

Question 26. Which FortiGate component can provide DNS filtering by blocking domains associated with unwanted or malicious categories?

  1. FortiGuard DNS Filtering
  2. Traffic shaping
  3. IPsec Phase 2
  4. Static routing

Correct Answer: 1. FortiGuard DNS Filtering

Explanation :-

FortiGuard DNS Filtering can use domain categorization and security intelligence to control DNS requests. Depending on configuration, administrators can block domains associated with malicious or unwanted categories before users establish connections to those destinations. Traffic shaping controls bandwidth, IPsec Phase 2 defines protected VPN traffic, and static routing determines forwarding paths. DNS filtering is therefore particularly useful when an organization wants to enforce domain-based access controls through DNS requests.

Question 27. A FortiGate administrator needs to authenticate users against an external directory service before allowing access to protected resources. Which configuration can provide centralized user authentication?

  1. Static route
  2. LDAP server configuration
  3. IP pool
  4. Traffic shaper

Correct Answer: 2. LDAP server configuration

Explanation :-

FortiGate can integrate with LDAP directory services for centralized user authentication. An LDAP server configuration allows FortiGate to communicate with an external directory and verify user credentials according to the configured authentication process. Static routes determine packet forwarding, IP pools provide source addresses for NAT, and traffic shapers manage bandwidth. LDAP integration is therefore appropriate when authentication needs to be performed against an organization’s existing directory service rather than maintaining every user account locally on FortiGate.

Question 28. Which FortiGate feature can restrict access to websites based on categories such as social networking, gambling, or malware?

  1. Application Control
  2. Web Filter
  3. IPsec VPN
  4. Static NAT

Correct Answer: 2. Web Filter

Explanation :-

FortiGate Web Filter can control web access using URL categories and FortiGuard web-rating information. Administrators can create web-filter profiles and apply actions such as allowing, monitoring, or blocking selected categories. Application Control focuses on identifying and controlling applications, IPsec VPN provides encrypted connectivity, and static NAT performs address translation. Web Filter therefore directly addresses a requirement to control websites according to content or security categories.

Question 29. Which FortiGate inspection profile is used to identify and control applications such as peer-to-peer software, streaming services, or business applications?

  1. Antivirus
  2. Web Filter
  3. Application Control
  4. DNS Filter

Correct Answer: 3. Application Control

Explanation :-

Application Control identifies applications in network traffic using application signatures and related classification mechanisms. Administrators can use Application Control profiles to monitor, allow, block, or otherwise manage application traffic according to organizational policies. Antivirus focuses on malware detection, Web Filter controls web access, and DNS Filter evaluates DNS requests and domain categories. Application Control is therefore the appropriate FortiGate security profile when traffic needs to be managed according to application identity.

Question 30. Which protocol is commonly used by FortiGate to provide secure command-line management over a network?

  1. Telnet
  2. FTP
  3. HTTP
  4. SSH

Correct Answer: 4. SSH

Explanation :-

SSH provides encrypted remote command-line access to network devices and is commonly used for secure FortiGate CLI administration. Unlike Telnet, SSH protects the management session through encryption. FTP is primarily used for file transfers, while HTTP is an unencrypted web protocol. Using secure management protocols is important because administrative credentials and configuration activity should be protected from interception while traversing a network.

Question 31. A FortiGate administrator wants to prevent users from downloading files containing known malware through web traffic. Which security profile should be applied to the relevant firewall policy?

  1. Antivirus
  2. Traffic Shaping
  3. Application Control
  4. Static Route

Correct Answer: 1. Antivirus

Explanation :-

The FortiGate Antivirus security profile is designed to inspect supported traffic for malware and other malicious content. When applied to an appropriate firewall policy, antivirus inspection can help detect and block malicious files according to the configured protection settings. Traffic Shaping manages bandwidth, Application Control identifies applications, and Static Routes determine packet forwarding. Antivirus is therefore the security profile most directly associated with preventing users from receiving known malicious files through inspected traffic.

Question 32. Which FortiGate VPN component defines the traffic selectors and security parameters used to protect actual user data between IPsec peers?

  1. Phase 2
  2. Phase 1
  3. Firewall policy order
  4. DHCP configuration

Correct Answer: 1. Phase 2

Explanation :-

IPsec Phase 2 establishes the security associations used to protect the actual data traffic across an IPsec VPN. It includes settings such as encryption and authentication proposals and traffic selectors that identify the networks or traffic to be protected. Phase 1 establishes and authenticates the IKE relationship between the peers. Firewall policy order controls policy matching, while DHCP provides address configuration. Phase 2 is therefore the component most directly associated with protecting the VPN’s data traffic.

Question 33. Which FortiGate log type is most useful for determining which firewall policy handled a network session?

  1. System event log
  2. Traffic log
  3. VPN event log
  4. Authentication server log

Correct Answer: 2. Traffic log

Explanation :-

FortiGate traffic logs provide information about network sessions and can include details such as source and destination addresses, services, interfaces, actions, bytes, and the policy identifier associated with the session. This makes traffic logs useful when determining which firewall policy processed a connection. System event logs focus on administrative and system events, VPN event logs focus on VPN activity, and authentication logs focus on authentication events. Traffic logs are therefore the most relevant source for investigating firewall-policy handling of network sessions.

Question 34. Which FortiGate feature can automatically block or monitor traffic from clients whose behavior matches configured IPS signatures?

  1. DHCP server
  2. IPS
  3. DNS forwarding
  4. Static routing

Correct Answer: 2. IPS

Explanation :-

FortiGate IPS examines network traffic for known attack patterns and signatures. Depending on the configured IPS profile and action, matching traffic can be blocked, monitored, or handled according to the security policy. DHCP provides IP addressing, DNS forwarding handles DNS requests, and static routing determines forwarding paths. IPS is therefore the security feature intended to identify network intrusion attempts and apply configured responses to matching malicious traffic.

Question 35. A FortiGate has a default route through ISP-A and another through ISP-B. The administrator wants selected traffic to use ISP-B based on its source subnet. Which feature is appropriate?

  1. Antivirus profile
  2. Policy-based routing
  3. Web Filter
  4. Virtual IP

Correct Answer: 2. Policy-based routing

Explanation :-

Policy-based routing allows FortiGate to make forwarding decisions using criteria beyond the normal destination-based routing lookup. An administrator can define a policy that matches a particular source subnet and directs matching traffic toward the desired interface or gateway, such as ISP-B. Antivirus and Web Filter inspect traffic, while a virtual IP performs destination NAT. PBR is therefore appropriate when selected traffic needs to use a particular WAN path based on source or other traffic characteristics.

Question 36. Which FortiGate mechanism can group multiple address objects so that a single firewall policy can reference them collectively?

  1. Address group
  2. IPsec Phase 1
  3. Session helper
  4. Traffic shaper

Correct Answer: 1. Address group

Explanation :-

An address group allows multiple FortiGate address objects to be referenced collectively. This simplifies firewall-policy configuration when several hosts, networks, or other address objects should receive the same policy treatment. IPsec Phase 1 handles VPN negotiation, session helpers support certain application protocols, and traffic shapers control bandwidth. Address groups therefore provide a practical way to organize related addresses and reduce the need to create separate policies for every individual address object.

Question 37. Which FortiGate feature can identify whether a user has authenticated and then use the identity in security-policy decisions?

  1. Identity-based policy
  2. Static route
  3. IP pool
  4. Virtual IP

Correct Answer: 1. Identity-based policy

Explanation :-

Identity-based policies allow FortiGate to incorporate authenticated user identity into access-control decisions. This can enable administrators to apply different policies to users or user groups rather than relying exclusively on IP addresses. Static routes determine forwarding paths, IP pools provide addresses for NAT, and virtual IPs provide destination address translation. Identity-based policies are therefore useful when access control needs to be associated with authenticated users or groups.

Question 38. An administrator wants FortiGate to send DHCP requests from a local network to a DHCP server located on another network. Which feature should be configured?

  1. DHCP relay
  2. Web Filter
  3. IPsec Phase 2
  4. Application Control

Correct Answer: 1. DHCP relay

Explanation :-

DHCP relay allows a FortiGate interface to forward DHCP client requests toward a DHCP server located on another network. This is useful when the DHCP server is centralized and clients reside on different subnets. Web Filter controls web access, IPsec Phase 2 protects VPN data traffic, and Application Control identifies applications. DHCP relay therefore provides the forwarding function needed to allow clients on one network to obtain DHCP configuration from a server on another network.

Question 39. Which FortiGate feature allows an administrator to inspect encrypted HTTPS traffic so security profiles can examine the decrypted content according to the configured inspection method?

  1. SSL/SSH inspection
  2. Static routing
  3. DHCP relay
  4. IP pool

Correct Answer: 1. SSL/SSH inspection

Explanation :-

SSL/SSH inspection provides FortiGate with mechanisms for handling encrypted traffic so applicable security inspection can be performed according to the configured inspection mode and certificate settings. This is particularly relevant for HTTPS traffic because the content is encrypted between the client and destination. Static routing determines forwarding paths, DHCP relay forwards DHCP requests, and IP pools provide addresses for source NAT. SSL/SSH inspection is therefore the feature associated with inspecting supported encrypted sessions.

Question 40. Which FortiGate command is commonly used to test basic IP connectivity to a remote destination from the FortiGate CLI?

  1. diagnose debug flow
  2. get system status
  3. execute ping
  4. diagnose vpn ike gateway list

Correct Answer: 3. execute ping

Explanation :-

The execute ping command can be used from the FortiGate CLI to test basic IP connectivity to a specified destination. It is useful as an initial troubleshooting step when determining whether the FortiGate can reach a remote IP address. diagnose debug flow is used for detailed traffic-flow troubleshooting, get system status displays system information, and diagnose vpn ike gateway list provides VPN gateway information. Ping is therefore the straightforward CLI tool for basic reachability testing.