View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 201
Which FortiGate diagnostic command can display information about the current system status, including the FortiOS version?
- get system status
- diagnose debug flow
- get router info routing-table all
- diagnose sys session list
Correct Answer: 1
Explanation
The get system status command provides important information about the FortiGate device, including the FortiOS firmware version, serial number, hostname, operation mode, and other system details. It is commonly used during troubleshooting to verify the installed firmware and general device information. The diagnose debug flow command is used for packet-flow troubleshooting, while get router info routing-table all displays routing information. diagnose sys session list provides information about active sessions. Therefore, get system status is the appropriate command for checking general system status.
Question 202
Which FortiGate feature is primarily used to authenticate users against an external directory service such as Microsoft Active Directory?
- RADIUS
- LDAP
- FortiToken
- FSSO
Correct Answer: 2
Explanation
LDAP allows FortiGate to communicate with an external directory service and authenticate users against directory accounts. It is commonly used with directory environments such as Microsoft Active Directory when organizations need centralized user authentication. FortiGate can also use LDAP groups in authentication and firewall-policy configurations. RADIUS is another external authentication method but uses the RADIUS protocol, while FortiToken provides token-based authentication and FSSO supplies user identity information through supported single sign-on mechanisms. Therefore, LDAP is the appropriate choice for directory-based authentication.
Question 203
What happens when traffic reaches the end of the FortiGate firewall policy list without matching an applicable policy?
- It is forwarded through the default route.
- It is automatically authenticated.
- It is denied by the implicit deny policy.
- It is sent to FortiAnalyzer.
Correct Answer: 3
Explanation
FortiGate uses an implicit deny rule at the end of the firewall policy processing sequence. If traffic does not match any applicable policy, it is denied rather than automatically forwarded. Administrators can create explicit policies to permit required traffic, but unmatched traffic remains subject to the implicit deny behavior. Routing information alone does not authorize traffic through the firewall. Authentication and FortiAnalyzer logging do not replace firewall-policy matching. Therefore, traffic that reaches the end of the policy list without a match is denied by the implicit deny policy.
Question 204
Which configuration is most appropriate when an administrator wants to publish an internal web server to the Internet using a specific public IP address?
- Address group
- Virtual IP
- Traffic shaper
- DNS Filter
Correct Answer: 2
Explanation
A Virtual IP, or VIP, can map a public IP address to an internal server address and is commonly used for destination NAT. For example, an organization can configure a VIP so that connections received on a public address are translated to the private address of an internal web server. A firewall policy can then control whether the inbound connection is permitted. Address groups organize address objects, traffic shapers manage bandwidth, and DNS Filter controls DNS requests. Therefore, a Virtual IP is the appropriate configuration for publishing an internal server through a public IP address.
Question 205
Which FortiGate component can provide updated security intelligence and services used by features such as Web Filter and Antivirus?
- FortiGuard
- FortiView
- FortiAnalyzer
- FortiToken
Correct Answer: 1
Explanation
FortiGuard provides security intelligence and subscription-based services that support several FortiGate security features. Depending on the licensed services, FortiGuard can provide information used by Web Filter, Antivirus, IPS, application identification, and other security functions. FortiView is a visibility and monitoring interface, FortiAnalyzer provides centralized logging and analysis, and FortiToken is associated with authentication. Maintaining valid FortiGuard services can therefore be important for keeping security databases and related services current. Thus, FortiGuard is the correct answer for this requirement.
Question 206
Which FortiGate setting can determine whether traffic matching a firewall policy should be recorded in traffic logs?
- Source address
- Service
- Logging option
- Schedule
Correct Answer: 3
Explanation
Firewall policies include logging options that determine whether traffic matching the policy should generate traffic logs. Administrators can use these settings to record accepted or other relevant traffic according to the available FortiOS logging configuration. Source addresses identify where traffic originates, Service specifies protocols or ports, and Schedule determines when the policy is active. Logging is particularly useful for troubleshooting, auditing, and security investigations because it provides information about matching sessions. Therefore, the Logging option is the setting directly associated with recording traffic handled by a firewall policy.
Question 207
Which FortiGate inspection mode generally buffers and processes content before forwarding it to the destination?
- Flow-based inspection
- Proxy-based inspection
- Certificate inspection
- Route-based inspection
Correct Answer: 2
Explanation
Proxy-based inspection allows FortiGate to act as an intermediary for supported traffic and can buffer content for inspection before forwarding it onward. This approach can provide more extensive inspection capabilities for certain security features because FortiGate processes the content rather than simply examining packets as they pass through. Flow-based inspection generally analyzes traffic as it flows through the device without using the same proxy architecture. Certificate inspection focuses on certificate information, while route-based describes VPN routing behavior rather than content inspection. Therefore, proxy-based inspection is the correct answer.
Question 208
Which FortiGate configuration can limit administrative access on an interface to HTTPS and SSH while disabling less secure management protocols?
- Interface administrative access
- IP pool
- Service group
- Static route
Correct Answer: 1
Explanation
Interface administrative access settings determine which management protocols can be used to access FortiGate through a particular interface. Administrators can enable appropriate protocols such as HTTPS and SSH while disabling unnecessary or less secure management methods. This helps reduce the device’s management attack surface. An IP pool is used primarily for NAT, a service group combines service objects, and a static route determines packet forwarding. Therefore, Interface administrative access is the correct configuration when management protocols need to be explicitly controlled on an interface.
Question 209
Which FortiGate feature allows an administrator to combine several individual service objects into one reusable object?
- Address group
- Service group
- User group
- Interface zone
Correct Answer: 2
Explanation
A service group combines multiple service objects into a single reusable configuration object. This can simplify firewall policies when the same collection of protocols or destination ports must be referenced repeatedly. For example, several TCP and UDP service objects can be grouped and then selected together in a policy. Address groups are used for IP address objects, user groups organize authenticated users, and interface zones combine interfaces for policy purposes. Therefore, Service group is the correct feature for combining multiple individual service objects into one reusable object.
Question 210
Which FortiGate feature can detect when a monitored network interface becomes unavailable and use that information in HA operation?
- Session pickup
- Override
- Interface monitoring
- FortiGuard
Correct Answer: 3
Explanation
Interface monitoring allows FortiGate HA to monitor selected interfaces for failures. If a monitored interface fails, the HA cluster can use the configured monitoring behavior as part of determining whether a failover should occur. This helps ensure that the active unit has functional connectivity through important network interfaces. Session pickup is related to session synchronization, Override influences primary-unit selection behavior, and FortiGuard provides security services. Therefore, Interface monitoring is the correct HA feature for detecting failures on configured network interfaces.
Question 211
Which FortiGate feature can use a health check to determine whether an SD-WAN member is meeting configured connectivity requirements?
- Performance SLA
- Address group
- Local-in policy
- Antivirus
Correct Answer: 1
Explanation
A Performance SLA provides health-check mechanisms for evaluating the quality and availability of SD-WAN paths. It can measure characteristics such as latency, jitter, and packet loss and compare them with configured thresholds. FortiGate can then use the health status when making SD-WAN path-selection decisions. Address groups organize IP addresses, local-in policies control traffic destined for the FortiGate itself, and Antivirus inspects supported content for malicious files. Therefore, Performance SLA is the correct feature for determining whether an SD-WAN member satisfies configured connectivity requirements.
Question 212
Which FortiGate policy type is specifically designed to control traffic destined for the FortiGate itself rather than traffic passing through it?
- Firewall policy
- Local-in policy
- SD-WAN rule
- Authentication rule
Correct Answer: 2
Explanation
A local-in policy controls traffic that is destined for the FortiGate itself, such as management or other traffic addressed to one of the FortiGate’s own interfaces. This differs from regular firewall policies, which primarily control traffic passing through the FortiGate between networks. Local-in policies can provide additional control over access to services running on the FortiGate. SD-WAN rules influence path selection, while authentication rules support user authentication processes. Therefore, Local-in policy is the appropriate policy type for controlling traffic destined for the FortiGate itself.
Question 213
Which FortiGate feature can identify and control applications even when application traffic does not use a single fixed destination port?
- Application Control
- DHCP server
- Static route
- IP pool
Correct Answer: 1
Explanation
Application Control identifies applications using FortiGate’s application signatures and inspection capabilities rather than relying solely on a fixed destination port. This allows administrators to apply policies to specific applications or application categories and is useful when applications use dynamic ports or multiple communication methods. DHCP provides IP configuration, static routes determine forwarding paths, and IP pools provide addresses for NAT. Application Control can therefore provide application-aware enforcement beyond traditional port-based filtering. Hence, Application Control is the correct feature for this requirement.
Question 214
Which FortiGate diagnostic tool is most useful for examining how a packet is processed through firewall policies and routing decisions?
- FortiView
- Packet capture
- Web Filter
- FortiGuard
Correct Answer: 2
Explanation
Packet capture is a valuable diagnostic tool for examining network traffic entering and leaving FortiGate. It can help administrators determine whether packets are arriving on the expected interface, whether responses are returning, and whether traffic is being transmitted as expected. When combined with other diagnostic commands, packet capture can help isolate routing, policy, or connectivity problems. FortiView provides graphical visibility, Web Filter controls website access, and FortiGuard provides security services. Therefore, Packet capture is the appropriate diagnostic tool for examining actual packets during troubleshooting.
Question 215
Which FortiGate feature allows an administrator to create a customized TCP or UDP service definition using specific port numbers?
- Service object
- Address group
- User group
- Virtual IP
Correct Answer: 1
Explanation
A service object defines network services according to protocols and port numbers. Administrators can create custom service objects when a required application or service is not represented by an existing predefined service. These objects can then be referenced in firewall policies. Address groups contain IP address objects, user groups organize authenticated identities, and Virtual IP configurations perform destination NAT. Creating a custom service object is therefore the appropriate approach when a firewall policy needs to permit or control traffic using specific TCP or UDP port numbers.
Question 216
Which FortiGate feature can quarantine or take a configured action when Antivirus detects malicious content?
- Static route
- SD-WAN rule
- Antivirus profile
- Address object
Correct Answer: 3
Explanation
An Antivirus profile defines how FortiGate handles files or content identified as malicious or suspicious by its antivirus inspection. Depending on the configured options and supported protocols, FortiGate can take actions such as blocking, monitoring, or applying other available handling mechanisms. Static routes determine packet forwarding, SD-WAN rules influence WAN path selection, and address objects identify hosts or networks. Antivirus profiles are applied through appropriate firewall policies so that matching traffic receives the configured malware inspection and response. Therefore, Antivirus profile is the correct answer.
Question 217
Which FortiGate HA setting can influence which cluster member is preferred to become the primary unit when configured conditions are satisfied?
- Session pickup
- Override
- Interface zone
- Traffic shaping
Correct Answer: 2
Explanation
The Override setting in FortiGate HA can influence primary-unit selection according to the configured HA election behavior. When enabled, the device with the higher configured priority can regain the primary role after recovering, subject to the cluster’s HA configuration and conditions. Session pickup concerns synchronization of supported session information, while interface zones group interfaces and traffic shaping controls bandwidth. HA election behavior depends on several factors, including device priority and monitored interfaces. Therefore, Override is the appropriate setting for influencing primary-unit preference in this context.
Question 218
Which FortiGate feature can provide centralized storage and analysis of logs when a FortiGate is registered to an external logging appliance?
- FortiView
- FortiAnalyzer
- FortiToken
- Web Filter
Correct Answer: 2
Explanation
FortiAnalyzer provides centralized log collection, storage, analysis, and reporting for Fortinet devices. A FortiGate can be configured to send relevant logs to FortiAnalyzer, allowing administrators to investigate traffic and security events from a centralized location. This is especially useful in environments with multiple FortiGate devices because administrators can analyze information without relying entirely on local device storage. FortiView provides local visibility, FortiToken supports authentication, and Web Filter controls web access. Therefore, FortiAnalyzer is the correct solution for centralized FortiGate log management.
Question 219
Which FortiGate routing feature can use multiple available routes to provide redundancy or distribute traffic according to configured routing behavior?
- Static route
- Route redundancy and load balancing
- Web Filter
- Captive portal
Correct Answer: 2
Explanation
FortiGate supports routing configurations that can use multiple routes for redundancy and, where supported by the routing design, load-balancing behavior. Multiple available paths can help maintain connectivity when one route becomes unavailable and can provide more efficient use of network links. A static route represents a specific manually configured path, while Web Filter and captive portal are unrelated to route selection. Route redundancy and load balancing therefore provide the functionality needed when an administrator wants FortiGate to use multiple routing paths for availability or traffic distribution.
Question 220
Which FortiGate feature can require a second authentication factor in addition to a user’s password?
- Multi-factor authentication
- Address group
- Service group
- Static route
Correct Answer: 1
Explanation
Multi-factor authentication requires users to provide an additional authentication factor beyond their primary password. FortiGate can integrate supported authentication mechanisms, including FortiToken-based authentication, to provide stronger account protection. This reduces reliance on a password alone and can help protect administrative or user access if a password is compromised. Address groups organize network addresses, service groups combine service definitions, and static routes control packet forwarding. Therefore, Multi-factor authentication is the correct feature when an additional authentication factor is required.