Fortinet NSE4_FGT-7.0 Practice Test Questions and Exam Dumps Part 20 Q381-400

View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps

 

Question 381. Which FortiGate feature allows administrators to configure multiple virtual firewall instances on a single physical FortiGate device?

  1. VDOM
  2. IP pool
  3. Service group
  4. Traffic shaper

Correct Answer: 1. VDOM

Explanation :-

Virtual Domains, or VDOMs, allow a FortiGate appliance to be divided into multiple logical firewall environments. Each VDOM can maintain its own routing, firewall policies, interfaces, and other configuration elements according to the deployment. This allows organizations to separate networks or administrative domains while using the same physical appliance. IP pools provide source NAT addresses, service groups organize service objects, and traffic shapers control bandwidth. VDOMs are therefore the appropriate feature when multiple independent firewall environments are required on one FortiGate.

Question 382. Which FortiGate command provides a detailed view of the routes currently installed in the routing table?

  1. execute ping
  2. get router info routing-table all
  3. show firewall policy
  4. get system status

Correct Answer: 2. get router info routing-table all

Explanation :-

The get router info routing-table all command displays the routes currently known to FortiGate, including destination networks, routing sources, next hops, and interfaces where applicable. It is particularly useful for determining whether FortiGate has a route to a particular destination and which path may be selected. execute ping tests connectivity, show firewall policy displays firewall configuration, and get system status provides general device information. Therefore, the routing-table command is appropriate when detailed route information is required.

Question 383. Which FortiGate feature can authenticate users against an external RADIUS server?

  1. RADIUS server configuration
  2. Address group
  3. Virtual IP
  4. Traffic shaping

Correct Answer: 1. RADIUS server configuration

Explanation :-

FortiGate can act as a RADIUS client and communicate with an external RADIUS server to validate user credentials. This allows organizations to use centralized authentication infrastructure rather than maintaining every user account locally on FortiGate. Address groups organize network objects, virtual IPs provide destination NAT functionality, and traffic shaping controls bandwidth. RADIUS configuration is therefore the appropriate mechanism when FortiGate needs to authenticate users through an external RADIUS service.

Question 384. Which FortiGate feature can prevent a firewall policy from being used outside specified days and times?

  1. Service group
  2. Schedule
  3. Address group
  4. IP pool

Correct Answer: 2. Schedule

Explanation :-

A firewall policy schedule defines when that policy is active. Administrators can configure recurring schedules for specific days and times, allowing network access to follow business hours, maintenance windows, or other operational requirements. Service groups combine services, address groups combine network objects, and IP pools provide source NAT addresses. Therefore, a schedule is the appropriate configuration when a firewall policy must only apply during specified time periods.

Question 385. Which FortiGate security feature can identify applications based on application signatures rather than relying solely on TCP or UDP port numbers?

  1. Application Control
  2. Static routing
  3. DHCP server
  4. NTP

Correct Answer: 1. Application Control

Explanation :-

Application Control uses FortiGate application signatures and traffic characteristics to identify applications. This allows administrators to control application traffic even when an application uses ports that differ from its commonly associated ports. Static routing determines forwarding paths, DHCP servers provide network configuration, and NTP synchronizes time. Application Control is therefore the appropriate feature when administrators need application-aware visibility and enforcement rather than relying solely on port-based identification.

Question 386. Which FortiGate feature can inspect encrypted HTTPS traffic by decrypting it so that security profiles can inspect the underlying content?

  1. Certificate inspection
  2. Deep inspection
  3. Traffic shaping
  4. Static routing

Correct Answer: 2. Deep inspection

Explanation :-

Deep inspection decrypts supported SSL/TLS traffic so FortiGate can inspect the underlying content with security profiles such as Antivirus, Web Filter, and other inspection technologies. Because FortiGate acts as an inspection point for the encrypted connection, appropriate certificate deployment and client trust configuration may be required. Certificate inspection provides visibility into certificate and session information without performing the same level of content decryption. Traffic shaping manages bandwidth, while static routing controls forwarding. Deep inspection is therefore appropriate for full encrypted-content inspection.

Question 387. Which FortiGate feature provides a logical grouping of several physical or logical interfaces for use in firewall policies?

  1. Interface zone
  2. IP pool
  3. User group
  4. Service group

Correct Answer: 1. Interface zone

Explanation :-

An interface zone allows multiple interfaces to be grouped logically so that firewall policies can reference the collection rather than listing each interface individually. This can simplify policy administration when several interfaces should receive the same access treatment. IP pools provide source NAT addresses, user groups organize authenticated users, and service groups combine service definitions. Interface zones are therefore useful when administrators want to manage several interfaces collectively within firewall policies.

Question 388. Which FortiGate feature can record information about traffic processed by firewall policies for later investigation?

  1. Firewall policy logging
  2. DHCP reservation
  3. Loopback interface
  4. Static route

Correct Answer: 1. Firewall policy logging

Explanation :-

Firewall policy logging allows FortiGate to record information about sessions and traffic handled by policies according to the configured logging options. These logs can assist with troubleshooting, monitoring, auditing, and security investigations. DHCP reservations provide predictable client addresses, loopback interfaces provide logical endpoints, and static routes determine packet forwarding. Therefore, when administrators need records of traffic processed by firewall policies, the policy’s logging configuration should be reviewed and appropriately enabled.

Question 389. Which FortiGate feature can provide centralized visibility and reporting for security and traffic logs?

  1. FortiAnalyzer
  2. DHCP relay
  3. Virtual IP
  4. ECMP

Correct Answer: 1. FortiAnalyzer

Explanation :-

FortiAnalyzer provides centralized log collection, analysis, reporting, and historical visibility for supported Fortinet devices. FortiGate can forward logs to FortiAnalyzer, allowing administrators to investigate security events and network activity from a central platform. DHCP relay forwards DHCP requests, virtual IPs provide destination NAT functionality, and ECMP manages multiple equal-cost routes. FortiAnalyzer is therefore the appropriate solution when an organization needs centralized analysis and reporting of FortiGate security and traffic logs.

Question 390. Which FortiGate diagnostic command displays active sessions currently tracked by the firewall?

  1. diagnose sys session list
  2. execute ping
  3. get system status
  4. show system interface

Correct Answer: 1. diagnose sys session list

Explanation :-

The diagnose sys session list command displays active sessions tracked by FortiGate. The output can help administrators examine source and destination information, protocols, interfaces, session states, and other details associated with current traffic. execute ping performs an ICMP connectivity test, get system status displays device information, and show system interface displays interface configuration. Therefore, the session-list command is particularly useful when investigating an existing connection or determining how FortiGate is tracking a traffic flow.

Question 391. Which FortiGate feature can restrict administrative access so that a particular administrator account is usable only from approved source networks?

  1. Trusted hosts
  2. Web Filter
  3. Service group
  4. Security profile group

Correct Answer: 1. Trusted hosts

Explanation :-

Trusted hosts allow administrators to restrict the source IP addresses or networks from which a specific administrator account can access FortiGate. This adds an important layer of protection to administrative authentication because access can be limited to known management networks or workstations. Web Filter controls web traffic, service groups organize services, and security profile groups combine inspection profiles. Trusted hosts are therefore the appropriate configuration when management access must be restricted according to the administrator’s source network.

Question 392. Which FortiGate routing mechanism can direct traffic matching specific criteria through a selected interface or gateway instead of relying only on the standard routing table?

  1. Policy-based routing
  2. Antivirus
  3. DNS Filter
  4. Application Control

Correct Answer: 1. Policy-based routing

Explanation :-

Policy-based routing allows FortiGate to make forwarding decisions according to configured traffic criteria. This can be useful when traffic from a particular source, toward a particular destination, or matching other supported conditions must use a specific gateway or interface. Antivirus, DNS Filter, and Application Control are security inspection features and do not primarily determine the forwarding path. Policy-based routing is therefore appropriate when selected traffic requires a forwarding path different from the normal destination-based routing decision.

Question 393. Which FortiGate feature allows a public IP address to be mapped to an internal server for inbound connections?

  1. Virtual IP
  2. IP pool
  3. Address group
  4. Loopback interface

Correct Answer: 1. Virtual IP

Explanation :-

A Virtual IP, or VIP, maps an external address to an internal address and can also support port forwarding. It is commonly used when an internal server must be reachable from an external network through a public IP address. An IP pool is primarily used for source NAT, an address group organizes network addresses, and a loopback interface provides a logical endpoint. Therefore, a VIP is the appropriate feature when inbound connections need to be translated to an internal server.

Question 394. Which FortiGate security profile is primarily used to detect malicious files and other malware in inspected traffic?

  1. Antivirus
  2. Web Filter
  3. IPS
  4. DNS Filter

Correct Answer: 1. Antivirus

Explanation :-

The Antivirus security profile examines supported traffic for malicious content using Fortinet’s malware detection technologies. When applied to an appropriate firewall policy, it can identify and block malware according to the configured inspection and action settings. Web Filter focuses on website access, IPS detects network attacks and exploits, and DNS Filter evaluates DNS requests. Antivirus is therefore the most appropriate security profile when the primary objective is detecting and preventing malicious files or malware within inspected traffic.

Question 395. Which FortiGate feature can provide a stable logical IP endpoint for routing protocols or management services?

  1. Loopback interface
  2. Virtual IP
  3. Service group
  4. IP pool

Correct Answer: 1. Loopback interface

Explanation :-

A loopback interface provides a logical network endpoint that is not directly tied to the operational state of a single physical interface. Because its address can remain stable, it can be useful for routing protocols, management, monitoring, and other services that benefit from a persistent endpoint. Virtual IPs provide address translation, service groups organize service definitions, and IP pools provide source NAT addresses. A loopback interface is therefore suitable when a stable logical address is required.

Question 396. Which FortiGate feature can use FortiGuard categorization to control access to websites based on categories such as social media or malicious sites?

  1. Web Filter
  2. ECMP
  3. Static route
  4. DHCP server

Correct Answer: 1. Web Filter

Explanation :-

Web Filter can use FortiGuard web categorization and reputation information to classify websites and apply configured actions. Administrators can permit, block, monitor, or otherwise control categories according to organizational requirements. ECMP manages equal-cost routing paths, static routes determine forwarding, and DHCP servers provide client network configuration. Web Filter is therefore the appropriate security feature when website access needs to be controlled based on FortiGuard categories or web reputation.

Question 397. Which FortiGate feature can synchronize the device clock with an external time source?

  1. NTP
  2. LDAP
  3. DHCP relay
  4. Application Control

Correct Answer: 1. NTP

Explanation :-

Network Time Protocol allows FortiGate to synchronize its system clock with configured time servers. Accurate time is important for security logs, certificate validation, scheduled policies, authentication events, and troubleshooting. LDAP provides directory authentication, DHCP relay forwards DHCP requests, and Application Control identifies applications. NTP is therefore the appropriate service to configure when FortiGate needs to maintain accurate time based on an external time source.

Question 398. Which FortiGate feature can distribute incoming client connections among backend servers while using health checks to avoid unavailable servers?

  1. Virtual server with health checks
  2. Address group
  3. DNS Filter
  4. Traffic shaper

Correct Answer: 1. Virtual server with health checks

Explanation :-

A FortiGate virtual server can distribute incoming connections among configured backend servers. Health checks can monitor backend server availability so FortiGate can avoid forwarding new connections to servers that are not responding according to the configured health-check criteria. Address groups organize network objects, DNS Filter controls DNS requests, and traffic shapers manage bandwidth. Therefore, a virtual server combined with appropriate health checks is suitable for maintaining reliable load balancing across multiple backend servers.

Question 399. Which FortiGate feature can preserve the same IP address for a DHCP client by associating that address with the client’s MAC address?

  1. DHCP reservation
  2. Policy-based routing
  3. Virtual IP
  4. Traffic shaping

Correct Answer: 1. DHCP reservation

Explanation :-

DHCP reservation allows an administrator to associate a specific IP address with a DHCP client’s identifier, commonly its MAC address. When the client requests an address, the DHCP server can provide the reserved address rather than assigning an arbitrary address from the general pool. Policy-based routing controls forwarding, virtual IPs provide address translation for inbound traffic, and traffic shaping manages bandwidth. DHCP reservation is therefore the appropriate feature when a particular client needs predictable IP addressing while continuing to use DHCP.

Question 400. An administrator has confirmed that a firewall policy permits traffic but wants to determine exactly how FortiGate processes a packet through routing and policy decisions. Which diagnostic tool should be used?

  1. diagnose debug flow
  2. execute ping
  3. get system status
  4. show firewall address

Correct Answer: 1. diagnose debug flow

Explanation :-

diagnose debug flow provides detailed information about FortiGate packet processing. It can show how the device performs routing lookups, evaluates firewall policies, creates or finds sessions, and handles packets during processing. This makes it particularly useful when traffic appears to match an expected policy but does not behave as anticipated. execute ping provides a basic connectivity test, get system status shows device information, and address output displays configuration objects. Debug flow is therefore the appropriate tool for detailed packet-processing troubleshooting.