Fortinet NSE4_FGT-7.0 Practice Test Questions and Exam Dumps Part 19 Q361-380

View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps

 

Question 361. Which FortiGate feature allows administrators to configure a secondary FortiGate to take over when the primary unit fails?

  1. High Availability
  2. Traffic shaping
  3. Web Filter
  4. DNS Filter

Correct Answer: 1. High Availability

Explanation :-

FortiGate High Availability provides redundancy by allowing multiple FortiGate units to operate as an HA cluster. The FortiGate Cluster Protocol (FGCP) coordinates cluster operation, including heartbeat communication and failover behavior. If the active unit becomes unavailable, another suitable cluster member can assume the active role according to the configured HA settings. Traffic shaping, Web Filter, and DNS Filter provide traffic-control or security functions and do not provide appliance-level redundancy. HA is therefore the appropriate feature when continuous firewall availability is required.

Question 362. Which FortiGate command displays the device model, serial number, firmware version, and other basic system information?

  1. diagnose sys session list
  2. get system status
  3. execute ping
  4. show firewall policy

Correct Answer: 2. get system status

Explanation :-

The get system status command displays important system information about the FortiGate, including device identification and the installed FortiOS version. It is commonly used as an initial diagnostic command when administrators need to establish which device and firmware release they are working with. The session-list command displays active sessions, ping tests connectivity, and firewall-policy output displays policy configuration. Therefore, get system status is the appropriate command for obtaining basic system and firmware information.

Question 363. Which FortiGate feature can inspect DNS requests and block domains according to configured categories or reputation information?

  1. DNS Filter
  2. IPsec VPN
  3. ECMP
  4. Traffic shaping

Correct Answer: 1. DNS Filter

Explanation :-

DNS Filter evaluates DNS queries and can apply controls based on configured rules, domain categories, and available reputation information. It can help prevent clients from resolving domains associated with unwanted or potentially harmful content. IPsec VPN provides encrypted tunnels, ECMP manages multiple equal-cost routes, and traffic shaping controls bandwidth. DNS Filter is therefore the appropriate FortiGate security feature when administrators need to control domain resolution based on category or reputation.

Question 364. An administrator wants to allow HTTPS management on an interface but prevent HTTP management on the same interface. Which configuration should be changed?

  1. Firewall service object
  2. Interface administrative access
  3. Web Filter profile
  4. IP pool

Correct Answer: 2. Interface administrative access

Explanation :-

Interface administrative access determines which management protocols are enabled on a FortiGate interface. HTTPS and HTTP are separate management options, so an administrator can enable HTTPS while leaving HTTP disabled. Firewall service objects control forwarded traffic rather than direct administrative access to the interface. Web Filter controls web traffic passing through the firewall, while IP pools support source NAT. Therefore, interface administrative access is the correct configuration area for controlling HTTP and HTTPS management availability.

Question 365. Which FortiGate feature can use a group of public addresses for source NAT instead of using only the outgoing interface address?

  1. IP pool
  2. Address group
  3. Virtual server
  4. Loopback interface

Correct Answer: 1. IP pool

Explanation :-

An IP pool contains one or more addresses that FortiGate can use for source NAT. When configured appropriately in a firewall policy, translated sessions can use addresses from the pool instead of relying solely on the outgoing interface address. Address groups organize network objects, virtual servers support inbound server access and load balancing, and loopback interfaces provide logical endpoints. An IP pool is therefore appropriate when administrators need control over the public source addresses used by translated outbound connections.

Question 366. Which FortiGate feature can identify applications such as BitTorrent even when the traffic does not use the application’s commonly associated port?

  1. Application Control
  2. Static route
  3. DHCP server
  4. NTP

Correct Answer: 1. Application Control

Explanation :-

Application Control identifies applications using signatures and traffic characteristics rather than depending solely on well-known port numbers. This allows FortiGate to recognize applications that may use alternate ports or dynamically change their communication patterns. Static routes determine forwarding paths, DHCP servers assign network parameters, and NTP synchronizes system time. Application Control is therefore the appropriate feature when administrators need to identify and control applications independently of their expected port numbers.

Question 367. Which FortiGate setting determines the amount of time an authenticated user can remain active before authentication is required again?

  1. Authentication timeout
  2. Administrative distance
  3. Session TTL
  4. Route metric

Correct Answer: 1. Authentication timeout

Explanation :-

Authentication timeout determines how long a user’s authentication state remains valid before the user must authenticate again, according to the applicable FortiGate authentication configuration. This is different from route-selection values such as administrative distance and route metrics, which affect routing decisions. Session lifetime settings relate to traffic sessions rather than the validity of user authentication itself. Therefore, when administrators need to control how long authenticated users remain authenticated, the relevant authentication timeout configuration should be reviewed.

Question 368. Which FortiGate feature can prevent an administrator from making configuration changes beyond the permissions assigned to that account?

  1. Administrator profile
  2. IP pool
  3. Service group
  4. Traffic shaper

Correct Answer: 1. Administrator profile

Explanation :-

An administrator profile defines the level of access and permissions available to a FortiGate administrator. Profiles can restrict access to specific configuration areas or operations, helping organizations implement role-based administration and least-privilege access. IP pools control source NAT addresses, service groups organize service definitions, and traffic shapers manage bandwidth. Therefore, administrator profiles should be configured when different administrative accounts require different permissions and some users should not be allowed to modify certain FortiGate settings.

Question 369. Which FortiGate feature allows administrators to inspect and control traffic based on the authenticated identity of a user?

  1. Identity-based policy
  2. Static route
  3. IP pool
  4. Virtual IP

Correct Answer: 1. Identity-based policy

Explanation :-

Identity-based policies allow firewall access decisions to use authenticated user or user-group information. This enables administrators to provide different access privileges to different users even when those users share the same network infrastructure or source subnet. Static routes determine forwarding, IP pools provide source NAT addresses, and virtual IPs provide destination NAT functionality. Identity-based policies are therefore appropriate when network access needs to be controlled according to authenticated user identity rather than only IP address.

Question 370. Which FortiGate component can store and analyze logs received from multiple FortiGate devices?

  1. FortiAnalyzer
  2. FortiGate DHCP Server
  3. Virtual IP
  4. Interface zone

Correct Answer: 1. FortiAnalyzer

Explanation :-

FortiAnalyzer is designed for centralized log collection, storage, analysis, and reporting across Fortinet environments. Multiple FortiGate devices can forward their logs to FortiAnalyzer, allowing administrators to investigate events and security activity from a central location. DHCP Server provides network configuration to clients, virtual IPs support address translation, and interface zones group interfaces. FortiAnalyzer is therefore the appropriate component when centralized analysis of logs from multiple FortiGate devices is required.

Question 371. Which FortiGate route selection factor generally makes a route more preferred when two otherwise comparable routes have different administrative distances?

  1. Lower administrative distance
  2. Higher administrative distance
  3. Higher destination IP address
  4. Larger source port

Correct Answer: 1. Lower administrative distance

Explanation :-

Administrative distance indicates the preference of a route source. When comparable routes toward the same destination are learned from different routing sources, a lower administrative distance is generally preferred. Destination IP addresses and source ports are traffic attributes rather than administrative-distance values. Therefore, when comparing routes with different administrative distances, administrators should normally expect the route with the lower administrative distance to be preferred, subject to the complete route-selection process and applicable configuration.

Question 372. Which FortiGate feature can provide a logical interface that remains available independently of the physical status of individual Ethernet ports?

  1. Loopback interface
  2. Virtual IP
  3. Service group
  4. IP pool

Correct Answer: 1. Loopback interface

Explanation :-

A loopback interface is a logical interface that is not directly dependent on the operational state of a particular physical port. Its address can provide a stable endpoint for management, routing protocols, monitoring, or other services. A virtual IP performs address translation, a service group combines services, and an IP pool supplies addresses for source NAT. A loopback interface is therefore useful when FortiGate requires a persistent logical address that can remain available despite changes in physical interface status.

Question 373. Which FortiGate feature can distribute incoming connections between several backend servers according to configured load-balancing behavior?

  1. Virtual server
  2. DNS Filter
  3. Address group
  4. NTP

Correct Answer: 1. Virtual server

Explanation :-

A FortiGate virtual server can present a virtual destination to clients and distribute incoming connections among configured backend servers. Depending on the configuration, FortiGate can use load-balancing methods and health checks to determine how connections should be forwarded. DNS Filter controls DNS requests, address groups organize network objects, and NTP provides time synchronization. A virtual server is therefore the appropriate feature when FortiGate needs to distribute incoming application connections across multiple backend servers.

Question 374. Which FortiGate feature can preserve a specific client’s IP address across DHCP renewals by associating the address with the client’s MAC address?

  1. DHCP reservation
  2. Policy route
  3. IPsec Phase 1
  4. Traffic shaper

Correct Answer: 1. DHCP reservation

Explanation :-

A DHCP reservation associates a specific IP address with a client’s identifying information, commonly its MAC address. This allows the client to continue receiving the same address through DHCP instead of relying on a dynamically selected address from the general pool. Policy routes affect forwarding decisions, IPsec Phase 1 establishes VPN negotiation parameters, and traffic shapers control bandwidth. DHCP reservation is therefore the appropriate feature when a particular DHCP client requires consistent addressing.

Question 375. Which FortiGate diagnostic tool is most useful for determining whether packets are actually arriving on a specific interface?

  1. diagnose sniffer packet
  2. get system status
  3. show firewall policy
  4. execute ping

Correct Answer: 1. diagnose sniffer packet

Explanation :-

The diagnose sniffer packet command provides packet-level visibility on FortiGate interfaces. It can show whether packets are arriving, their source and destination information, protocol details, and other packet characteristics. This is particularly useful when troubleshooting situations where an administrator is unsure whether traffic is reaching the firewall at all. System status displays device information, firewall-policy output displays configuration, and ping generates ICMP traffic. Packet sniffing is therefore the most direct choice for observing packets entering an interface.

Question 376. Which FortiGate security profile is designed to identify known network attacks and exploit attempts?

  1. IPS
  2. Web Filter
  3. DNS Filter
  4. Antivirus

Correct Answer: 1. IPS

Explanation :-

The Intrusion Prevention System is designed to detect and respond to network attacks, exploits, and suspicious patterns using intrusion-prevention signatures and related detection mechanisms. Depending on configuration, FortiGate can log or block detected threats. Web Filter controls website access, DNS Filter evaluates DNS requests, and Antivirus focuses primarily on malicious content. IPS is therefore the appropriate security profile when the objective is to detect and prevent known network attacks and exploit attempts.

Question 377. Which FortiGate configuration is most directly responsible for determining whether outbound client traffic is translated to the public IP of the outgoing interface?

  1. Firewall policy NAT configuration
  2. Web Filter category
  3. Administrator profile
  4. NTP configuration

Correct Answer: 1. Firewall policy NAT configuration

Explanation :-

Source NAT for outbound traffic is controlled through the applicable firewall policy’s NAT configuration. When NAT is enabled, FortiGate can translate the source address, commonly using the outgoing interface address unless an IP pool or another applicable NAT configuration changes the behavior. Web Filter controls website access, administrator profiles control management permissions, and NTP synchronizes system time. Therefore, the firewall policy NAT setting should be checked first when troubleshooting whether outbound client traffic is being translated.

Question 378. Which FortiGate feature allows several service definitions, such as HTTP, HTTPS, and DNS, to be referenced as one object in a policy?

  1. Service group
  2. Address group
  3. Interface zone
  4. User group

Correct Answer: 1. Service group

Explanation :-

A service group combines multiple service objects into a single reusable collection. For example, HTTP, HTTPS, and other configured services can be grouped so that a firewall policy can reference the group rather than each service separately. Address groups organize network addresses, interface zones group interfaces, and user groups organize authenticated identities. A service group is therefore the appropriate object when multiple protocols or ports need to be handled together in firewall policy configuration.

Question 379. Which FortiGate feature can provide a central dashboard for viewing traffic, applications, bandwidth usage, and security events?

  1. FortiView
  2. DHCP relay
  3. Static route
  4. IP pool

Correct Answer: 1. FortiView

Explanation :-

FortiView provides graphical visibility into FortiGate traffic and security activity. Depending on the available views, administrators can examine applications, sources, destinations, bandwidth consumption, interfaces, threats, and other operational information. DHCP relay forwards DHCP requests, static routes define forwarding paths, and IP pools provide addresses for source NAT. FortiView is therefore the appropriate monitoring capability when administrators need a consolidated dashboard for observing network traffic and security activity without manually examining individual sessions.

Question 380. An administrator has changed several FortiGate settings and wants to return the device to a previously saved configuration state. Which capability should be used?

  1. Configuration revision or backup
  2. Application Control
  3. DNS Filter
  4. Traffic shaping

Correct Answer: 1. Configuration revision or backup

Explanation :-

Configuration revisions and backups provide recovery points for FortiGate configuration. If a series of changes produces an unwanted result, an administrator can use an appropriate saved configuration to restore a previous known-good state, subject to the specific FortiOS workflow and deployment requirements. Application Control, DNS Filter, and traffic shaping affect traffic processing and do not provide configuration recovery. Therefore, saved configuration revisions or backups are the appropriate mechanism for returning FortiGate to an earlier configuration state.