View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps
Question 341. Which FortiGate feature allows an administrator to define a default gateway for traffic when no more specific route exists?
- Default route
- Service group
- Security profile group
- IP pool
Correct Answer: 1. Default route
Explanation :-
A default route provides a forwarding path for destinations that do not match a more specific entry in the routing table. In IPv4, it is commonly represented as 0.0.0.0/0. FortiGate uses the default route when no longer-prefix route provides a more specific match. Service groups combine service objects, security profile groups combine inspection profiles, and IP pools provide addresses for source NAT. Therefore, a default route is the appropriate configuration when unknown destinations need to be forwarded toward a designated gateway.
Question 342. An administrator wants FortiGate to accept management connections only through interfaces explicitly configured for HTTPS administration. Which interface setting should be reviewed?
- Security profile
- Administrative access
- DHCP server
- Traffic shaping
Correct Answer: 2. Administrative access
Explanation :-
Administrative access settings determine which management protocols can be used through a FortiGate interface. If HTTPS is enabled on an interface, administrators can use the secure web-based management interface through that interface, subject to other access controls. Security profiles inspect forwarded traffic, DHCP servers assign client configuration, and traffic shaping manages bandwidth. Therefore, when troubleshooting whether HTTPS management is available through a particular interface, the administrator should review the interface’s administrative-access settings.
Question 343. Which FortiGate feature can automatically update security intelligence used by services such as Antivirus, IPS, and Web Filter?
- FortiGuard services
- Static routing
- DHCP relay
- Interface zone
Correct Answer: 1. FortiGuard services
Explanation :-
FortiGuard services provide security intelligence and updates used by several Fortinet security features. Depending on the licensed services and configuration, FortiGuard can provide updated Antivirus signatures, IPS signatures, web-category information, application information, and other security intelligence. Static routing determines packet forwarding, DHCP relay forwards client configuration requests, and interface zones group interfaces. FortiGuard services are therefore important when FortiGate needs current security databases and classification information for its inspection features.
Question 344. Which FortiGate configuration determines whether a firewall policy performs source NAT for matching traffic?
- Destination address
- NAT setting
- Service group
- Policy comment
Correct Answer: 2. NAT setting
Explanation :-
The NAT configuration of a firewall policy determines whether matching traffic is translated before it is forwarded. When source NAT is enabled, FortiGate can use the outgoing interface address or a configured IP pool according to the applicable configuration. Destination addresses determine which destinations match the policy, service groups identify protocols and ports, and comments provide administrative descriptions. Therefore, when troubleshooting whether outbound traffic should be translated, the policy’s NAT configuration should be examined.
Question 345. Which FortiGate feature can combine several network address objects into a single reusable collection?
- Address group
- Service group
- Traffic shaper
- Schedule
Correct Answer: 1. Address group
Explanation :-
An address group combines multiple address objects into one logical collection. Firewall policies and other configurations can reference the group instead of repeatedly specifying individual addresses. Service groups perform a similar organizational function for services rather than network addresses. Traffic shapers control bandwidth, while schedules determine when policies are active. Address groups are therefore useful when multiple hosts, subnets, or address objects should receive the same policy treatment.
Question 346. A FortiGate administrator wants to verify whether an interface has the expected IP address, administrative state, and link information. Which configuration area should be inspected?
- Firewall policy
- System interface configuration
- Security profile group
- FortiGuard settings
Correct Answer: 2. System interface configuration
Explanation :-
The system interface configuration contains important information about FortiGate interfaces, including configured IP addressing, administrative settings, interface roles, and other interface-specific parameters. It is a key area to inspect when troubleshooting connectivity problems involving a particular interface. Firewall policies determine traffic handling, security profile groups control inspection combinations, and FortiGuard settings manage security intelligence services. Therefore, interface configuration should be checked first when the administrator needs to verify an interface’s basic network settings.
Question 347. Which FortiGate feature can allow multiple physical links to operate as a logical interface for increased resilience or aggregate bandwidth?
- Link aggregation
- Web Filter
- Virtual IP
- Captive portal
Correct Answer: 1. Link aggregation
Explanation :-
Link aggregation combines multiple physical links into a logical interface according to the configured aggregation method and supported hardware behavior. It can provide redundancy and, depending on the configuration, aggregate available link capacity. Web Filter controls website access, virtual IPs provide address translation for inbound connections, and captive portals provide web-based authentication. Link aggregation is therefore appropriate when multiple physical network links need to function together as a logical connection.
Question 348. Which FortiGate command is useful for displaying the configured firewall policies from the CLI?
- show firewall policy
- execute ping
- get system performance status
- diagnose sys session list
Correct Answer: 1. show firewall policy
Explanation :-
The show firewall policy command displays the configured firewall policy entries and their relevant settings in the CLI. It is useful when administrators need to inspect policy configuration, compare rules, or verify settings without relying solely on the graphical interface. execute ping tests connectivity, get system performance status displays resource information, and diagnose sys session list shows active sessions. Therefore, show firewall policy is the appropriate command for reviewing firewall policy configuration from the CLI.
Question 349. Which FortiGate feature can provide a separate logical routing and policy environment within the same physical FortiGate appliance?
- VDOM
- IP pool
- Service group
- Address object
Correct Answer: 1. VDOM
Explanation :-
A Virtual Domain, or VDOM, provides a logically separate operating environment within a FortiGate appliance. Depending on the deployment, each VDOM can maintain its own interfaces, routing, firewall policies, and other configuration elements. IP pools provide addresses for source NAT, service groups combine services, and address objects represent network entities. VDOMs are therefore appropriate when multiple independent logical firewall environments must operate on the same physical FortiGate device.
Question 350. Which FortiGate feature can identify traffic according to application signatures even when applications use ports that are not traditionally associated with them?
- Application Control
- Static route
- DHCP reservation
- NTP
Correct Answer: 1. Application Control
Explanation :-
Application Control identifies applications using FortiGate application signatures and traffic characteristics rather than relying exclusively on TCP or UDP port numbers. This allows administrators to create controls for applications that may use nonstandard ports or dynamically change their communication behavior. Static routes determine forwarding paths, DHCP reservations provide predictable client addresses, and NTP synchronizes time. Application Control is therefore the appropriate feature when traffic needs to be controlled based on application identity.
Question 351. Which FortiGate routing attribute is used to prefer one route over another when the routes have the same destination prefix but originate from different routing sources?
- Administrative distance
- Source port
- Security profile
- Policy comment
Correct Answer: 1. Administrative distance
Explanation :-
Administrative distance is used to establish the preference between routes learned from different routing sources when they provide comparable destination information. A lower administrative distance generally represents a more preferred route. Source ports are traffic attributes rather than route-preference values, security profiles inspect traffic, and policy comments provide descriptive information. Administrative distance is therefore an important routing attribute to examine when multiple routing sources provide competing routes toward the same destination.
Question 352. Which FortiGate feature can authenticate administrators using a centralized external authentication server instead of only local FortiGate accounts?
- RADIUS or LDAP authentication
- Traffic shaping
- Virtual IP
- Service group
Correct Answer: 1. RADIUS or LDAP authentication
Explanation :-
FortiGate can integrate with external authentication services such as RADIUS and LDAP for administrator authentication, depending on the configured authentication method and environment. Centralized authentication can simplify account management and allow organizations to use existing identity infrastructure. Traffic shaping controls bandwidth, virtual IPs perform address translation, and service groups organize service definitions. Therefore, RADIUS or LDAP authentication is appropriate when administrators should be authenticated through an external centralized identity service rather than relying exclusively on local accounts.
Question 353. Which FortiGate feature allows a policy to be enabled only during a defined recurring period, such as business hours?
- Schedule
- Address group
- IP pool
- Antivirus profile
Correct Answer: 1. Schedule
Explanation :-
A firewall policy schedule controls when that policy is active. Administrators can create recurring schedules that specify particular days and time periods, allowing access rules to reflect operational requirements such as business hours or maintenance windows. Address groups organize network addresses, IP pools support source NAT, and Antivirus profiles inspect supported content for malware. A schedule is therefore the appropriate mechanism when access controlled by a firewall policy needs to vary according to time.
Question 354. Which FortiGate security profile is primarily designed to inspect web traffic and control access according to website categories?
- Web Filter
- IPS
- Antivirus
- Application Control
Correct Answer: 1. Web Filter
Explanation :-
The Web Filter security profile is designed to control access to websites and web resources according to configured filtering rules and available categorization information. Administrators can allow, block, monitor, or otherwise handle website categories according to organizational requirements. IPS focuses on intrusion and exploit detection, Antivirus focuses on malicious content, and Application Control identifies applications. Therefore, Web Filter is the most directly applicable profile when the requirement is category-based control of web access.
Question 355. Which FortiGate feature can provide a mechanism for sending system and security logs to an external syslog server?
- Syslog configuration
- IPsec Phase 2
- DHCP server
- Address group
Correct Answer: 1. Syslog configuration
Explanation :-
FortiGate can be configured to send supported logs to an external syslog server. This allows organizations to centralize logging with other infrastructure and security monitoring systems. IPsec Phase 2 controls protected VPN traffic, DHCP servers provide client configuration, and address groups organize network objects. Syslog configuration is therefore the appropriate area to review when an administrator needs FortiGate to forward logs to an external logging platform using the syslog protocol.
Question 356. Which FortiGate diagnostic command displays information about active sessions currently tracked by the firewall?
- diagnose sys session list
- show firewall policy
- execute ping
- get router info routing-table all
Correct Answer: 1. diagnose sys session list
Explanation :-
The diagnose sys session list command displays information about sessions currently tracked by FortiGate. It can help administrators examine active connections, source and destination information, protocols, interfaces, and other session details. show firewall policy displays policy configuration, execute ping tests reachability, and the routing-table command displays route information. The session-list command is therefore particularly useful when troubleshooting connections that are already being tracked by the firewall.
Question 357. Which FortiGate feature can inspect encrypted HTTPS traffic by decrypting it for security inspection when appropriately configured?
- Deep inspection
- Certificate inspection
- Static routing
- Traffic shaping
Correct Answer: 1. Deep inspection
Explanation :-
Deep inspection can decrypt supported SSL/TLS traffic so FortiGate security profiles can inspect the underlying content. Because this involves certificate handling and decryption, appropriate certificates and client trust configuration may be required to avoid browser warnings and maintain expected security behavior. Certificate inspection examines certificate and session information without performing the same level of content decryption. Static routing controls forwarding, while traffic shaping manages bandwidth. Deep inspection is therefore the appropriate feature when full encrypted-content inspection is required.
Question 358. Which FortiGate feature can provide a fixed address to a DHCP client based on the client’s hardware or MAC address?
- DHCP reservation
- IP pool
- Virtual IP
- Static route
Correct Answer: 1. DHCP reservation
Explanation :-
A DHCP reservation associates a particular client identifier, commonly its MAC address, with a specified IP address. This allows the client to continue receiving the same address while still using DHCP for configuration. An IP pool is used primarily for source NAT, a virtual IP provides address translation for inbound traffic, and a static route determines packet forwarding. DHCP reservation is therefore the appropriate feature when a specific DHCP client needs predictable addressing.
Question 359. Which FortiGate feature can identify and block known network attacks based on intrusion prevention signatures?
- IPS
- DNS Filter
- DHCP relay
- NTP
Correct Answer: 1. IPS
Explanation :-
The Intrusion Prevention System uses signatures and detection techniques to identify known attacks, exploits, and suspicious network activity. Depending on the configured action, FortiGate can log, block, or otherwise handle detected threats. DNS Filter controls DNS requests, DHCP relay forwards DHCP traffic, and NTP synchronizes system time. IPS is therefore the appropriate security feature when the objective is to detect and prevent network attacks using intrusion-prevention signatures.
Question 360. A FortiGate administrator needs to determine whether a route exists for a specific destination before troubleshooting the firewall policy. Which information should be checked?
- Routing table
- Web Filter categories
- Antivirus signatures
- Administrator profile
Correct Answer: 1. Routing table
Explanation :-
The routing table should be checked to determine whether FortiGate has a valid route toward the destination and which interface or next hop it will use. A firewall policy can permit traffic, but successful forwarding still requires an appropriate routing decision. Web Filter categories and Antivirus signatures relate to security inspection, while administrator profiles control management permissions. Therefore, when troubleshooting a connection and determining whether FortiGate knows how to reach the destination, reviewing the routing table is an essential step.