View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 181
Which FortiGate feature can be used to define a logical interface that remains available independently of a physical interface?
- Loopback interface
- IP pool
- Service group
- VLAN tag
Correct Answer: 1
Explanation
A loopback interface is a logical interface that does not depend directly on a physical interface being operational. It can have its own IP address and can be used for routing, management, or other network functions that benefit from a stable logical endpoint. An IP pool provides addresses for NAT, a service group combines service objects, and a VLAN tag identifies traffic belonging to a VLAN. Because a loopback interface remains logically available regardless of a particular physical port’s status, it is the appropriate choice for this requirement.
Question 182
Which FortiGate feature allows administrators to define different actions for traffic depending on the application that generated it?
- DNS Filter
- Application Control
- DHCP server
- Static route
Correct Answer: 2
Explanation
Application Control allows FortiGate to identify applications and apply configured actions based on their detected application signatures. Administrators can create profiles that allow, monitor, or block selected applications or application categories and then apply those profiles through firewall policies. This provides application-aware control even when applications use different ports or protocols. DNS Filter focuses on DNS requests, DHCP assigns network settings, and static routes control packet forwarding. Therefore, Application Control is the appropriate feature when traffic treatment must depend on the application generating the traffic.
Question 183
Which FortiGate component is responsible for storing information about destinations and next hops used during packet forwarding?
- Firewall policy
- Security profile
- Routing table
- User group
Correct Answer: 3
Explanation
The routing table contains the routes FortiGate uses to determine how packets should be forwarded toward their destinations. Entries can come from connected networks, static routes, or dynamic routing protocols, depending on the configuration. FortiGate evaluates available routes and selects the appropriate path according to its routing process. Firewall policies determine whether traffic is allowed, security profiles inspect permitted traffic, and user groups organize authenticated identities. Therefore, the Routing table is the correct component for storing and evaluating destination and next-hop routing information.
Question 184
Which FortiGate feature can provide additional protection by requiring users to complete an authentication step before accessing a network?
- Static routing
- Traffic shaping
- Address group
- Captive portal
Correct Answer: 4
Explanation
A captive portal can require users to authenticate before they are granted access through a configured network interface or policy. It is commonly used for guest networks, wireless access, and environments where administrators want users to complete a web-based authentication process before receiving network access. Static routing controls forwarding paths, traffic shaping manages bandwidth, and address groups organize network address objects. A captive portal adds an identity-based access step before normal network access is provided. Therefore, Captive portal is the correct FortiGate feature for this requirement.
Question 185
Which FortiGate setting identifies the network from which traffic originates in a firewall policy?
- Destination
- Source
- Service
- Schedule
Correct Answer: 2
Explanation
The Source field in a FortiGate firewall policy identifies the source interface and source addresses or address groups from which traffic originates. FortiGate evaluates this information together with destination, service, schedule, and other policy criteria when determining whether traffic matches the policy. Destination identifies where traffic is going, Service identifies supported protocols or ports, and Schedule determines when the policy is active. Therefore, Source is the correct firewall-policy field for identifying the network or address from which traffic originates.
Question 186
Which FortiGate feature can distribute outbound traffic across a pool of public IP addresses for source NAT?
- Virtual IP
- DNS Filter
- IP pool
- Loopback interface
Correct Answer: 3
Explanation
An IP pool provides one or more public IP addresses that FortiGate can use when performing source NAT for outbound connections. Instead of translating all internal clients to only the outgoing interface address, FortiGate can use addresses from the configured pool according to the NAT configuration. A Virtual IP is generally used for destination NAT, DNS Filter controls DNS requests, and a loopback interface is a logical interface. Therefore, IP pool is the appropriate feature when multiple public addresses are required for source NAT.
Question 187
Which FortiGate feature allows an administrator to monitor system resources such as CPU and memory usage from the graphical interface?
- System dashboard
- Service group
- IPsec Phase 2
- Address group
Correct Answer: 1
Explanation
The system dashboard provides an overview of FortiGate health and resource utilization through the graphical interface. Depending on the configured dashboard widgets and FortiOS version, administrators can view CPU usage, memory utilization, sessions, interface activity, and other system information. Service groups organize services, IPsec Phase 2 establishes security associations for VPN data traffic, and address groups combine address objects. Therefore, the System dashboard is the appropriate feature for monitoring general CPU, memory, and device-resource information through the GUI.
Question 188
Which FortiGate feature is used to create an encrypted IPsec tunnel after the initial peer relationship has been established?
- Phase 1
- Firewall policy
- Phase 2
- Static route
Correct Answer: 3
Explanation
IPsec Phase 2 establishes the security associations used to protect actual data traffic after the initial IKE relationship has been established during Phase 1. Phase 2 negotiates parameters such as encryption, authentication, and traffic selectors for the protected networks. A firewall policy determines whether traffic is permitted through FortiGate, while a static route determines the forwarding path. Phase 1 establishes the initial secure peer relationship, whereas Phase 2 creates the IPsec security associations used for data protection. Therefore, Phase 2 is the correct answer.
Question 189
Which FortiGate feature can identify network attacks by matching traffic against configured intrusion-prevention signatures?
- Web Filter
- DNS Filter
- Antivirus
- IPS
Correct Answer: 4
Explanation
The Intrusion Prevention System, or IPS, uses signatures and related detection mechanisms to identify known network attacks and suspicious traffic patterns. An IPS profile can be applied through a firewall policy so FortiGate can inspect matching traffic and take the configured action. Web Filter controls website access, DNS Filter controls DNS requests, and Antivirus focuses on malware and malicious content. IPS is specifically designed for detecting network-based attacks through intrusion-prevention signatures. Therefore, IPS is the correct security profile for this requirement.
Question 190
Which FortiGate feature can store multiple IP address objects under one name for easier firewall-policy configuration?
- Service group
- User group
- Address group
- Interface zone
Correct Answer: 3
Explanation
An address group allows administrators to combine multiple IP address objects into one reusable object. This is useful when several hosts or networks need identical firewall-policy treatment. Instead of selecting every address separately in each policy, an administrator can reference the address group as a single source or destination object. Service groups contain service definitions, user groups organize authenticated users, and interface zones group interfaces. Therefore, Address group is the appropriate feature for storing multiple IP address objects under one reusable name.
Question 191
Which FortiGate authentication method can use an external server to verify a user’s credentials through a centralized authentication protocol?
- RADIUS
- Local authentication
- FSSO
- Certificate inspection
Correct Answer: 1
Explanation
RADIUS provides a centralized authentication mechanism in which FortiGate sends authentication requests to an external RADIUS server. The external server validates the user’s credentials and returns the authentication result. This allows organizations to integrate FortiGate with existing authentication infrastructure and avoid maintaining every user credential locally. Local authentication uses accounts stored on FortiGate, FSSO provides identity information through supported single sign-on mechanisms, and certificate inspection evaluates certificate information. Therefore, RADIUS is the appropriate authentication method for centralized external credential verification.
Question 192
Which FortiGate feature can identify users based on authentication information collected from a supported directory environment?
- Static route
- FSSO
- IP pool
- Traffic shaper
Correct Answer: 2
Explanation
Fortinet Single Sign-On, or FSSO, provides FortiGate with user identity information obtained through supported directory and authentication environments. This information can then be used in identity-based firewall policies to apply access controls according to authenticated users or groups. Static routes control packet forwarding, IP pools provide addresses for source NAT, and traffic shapers manage bandwidth. FSSO is particularly useful when organizations want user-aware policy enforcement without requiring repeated direct authentication to FortiGate. Therefore, FSSO is the correct feature for this scenario.
Question 193
Which FortiGate feature allows administrators to configure a recurring period during which a firewall policy is permitted to operate?
- Address object
- Service group
- Schedule
- User group
Correct Answer: 3
Explanation
A Schedule determines when a firewall policy is active. Administrators can configure recurring schedules for specific days and times and then assign them to firewall policies. This allows access to services or destinations to be limited to defined operational periods. Address objects identify networks or hosts, service groups combine protocol and port definitions, and user groups organize authenticated identities. For example, an organization can configure a policy to permit a particular service only during business hours. Therefore, Schedule is the correct configuration for controlling when a policy operates.
Question 194
Which FortiGate feature can collect logs from multiple FortiGate devices and provide centralized analysis and reporting?
- FortiView
- FortiGuard
- FortiToken
- FortiAnalyzer
Correct Answer: 4
Explanation
FortiAnalyzer is designed to collect and analyze logs from Fortinet devices and provide centralized reporting and investigation capabilities. In environments containing multiple FortiGate devices, it can provide a consolidated view of traffic, security events, and other logged information. FortiView provides local graphical visibility on FortiGate, FortiGuard provides security intelligence and related services, and FortiToken supports authentication. Centralized log management is useful for monitoring and investigating activity across multiple devices. Therefore, FortiAnalyzer is the correct solution for centralized FortiGate log analysis.
Question 195
Which FortiGate feature can inspect a web connection’s certificate information without performing full content decryption?
- Certificate inspection
- Deep inspection
- Application Control
- Traffic Shaping
Correct Answer: 1
Explanation
Certificate inspection examines information contained in SSL/TLS certificates without fully decrypting and inspecting the underlying encrypted content. It can allow FortiGate to evaluate certificate-related information and make supported security decisions while avoiding the full proxying and certificate-generation process associated with deep inspection. Deep inspection decrypts supported encrypted traffic for content inspection, Application Control identifies applications, and Traffic Shaping controls bandwidth. Therefore, Certificate inspection is the correct method when certificate information needs to be examined without decrypting the complete session.
Question 196
Which FortiGate feature can control access to websites according to URL categories and configured filtering actions?
- Antivirus
- Web Filter
- IPS
- DHCP
Correct Answer: 2
Explanation
Web Filter controls access to websites according to configured URL categories, ratings, and other supported filtering criteria. FortiGate can use FortiGuard web-rating information to classify websites and then apply actions such as allow, block, monitor, or warning. Antivirus focuses on malicious content, IPS detects network attacks, and DHCP provides IP configuration to clients. Web filtering can therefore help organizations enforce acceptable-use policies and reduce access to unwanted or potentially harmful websites. Therefore, Web Filter is the correct security profile for category-based website control.
Question 197
Which FortiGate feature can evaluate latency, jitter, and packet loss to determine whether an SD-WAN path meets configured requirements?
- Static route
- Firewall policy
- Performance SLA
- Service group
Correct Answer: 3
Explanation
Performance SLA measures the quality of SD-WAN paths using criteria such as latency, jitter, and packet loss. Administrators can configure thresholds that define acceptable path performance, and FortiGate can use the resulting status when applying SD-WAN rules. This allows traffic to be directed toward paths that satisfy the configured service requirements. Static routes provide forwarding information, firewall policies control access, and service groups organize network services. Therefore, Performance SLA is the correct feature for evaluating SD-WAN path performance against defined criteria.
Question 198
Which FortiGate HA feature can synchronize supported session information so that traffic can continue more smoothly after a failover?
- Override
- Interface monitoring
- Session pickup
- Device priority
Correct Answer: 3
Explanation
Session pickup allows supported session information to be synchronized between HA cluster members so that sessions can continue more smoothly after a failover. Without appropriate session synchronization, existing connections may be interrupted when the primary unit changes. The exact behavior depends on the configured HA options and the types of sessions being synchronized. Override and device priority influence primary-unit selection, while interface monitoring observes selected interfaces for failures. Therefore, Session pickup is the appropriate HA feature for preserving supported session state during failover.
Question 199
Which FortiGate feature can restrict management access to an administrator account based on specific source IP addresses?
- Administrative access
- Trusted hosts
- Address group
- Service object
Correct Answer: 2
Explanation
Trusted hosts can restrict an administrator account so that management access is accepted only from specified source IP addresses or networks. This provides an additional security layer beyond username and password authentication and can reduce exposure to unauthorized management attempts from untrusted locations. Administrative access controls which management protocols are enabled on an interface, address groups organize IP address objects, and service objects define network services. Therefore, Trusted hosts is the correct feature for restricting an administrator account according to source IP addresses.
Question 200
Which FortiGate feature can automatically select an appropriate WAN path according to configured traffic rules and link-performance conditions?
- SD-WAN
- DHCP client
- Web Filter
- Antivirus
Correct Answer: 1
Explanation
SD-WAN allows FortiGate to manage multiple WAN paths and select traffic paths according to configured SD-WAN rules and performance conditions. Administrators can define SD-WAN members, performance SLAs, and rules that determine how specific traffic should use available connections. This enables FortiGate to respond to path-quality changes and apply different forwarding decisions for different types of traffic. DHCP clients obtain network configuration, Web Filter controls website access, and Antivirus scans supported content. Therefore, SD-WAN is the correct feature for dynamic WAN-path selection.