Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 221

Which FortiGate feature is used to define a collection of interfaces that can be referenced together in firewall policies?

  1. Address group
  2. Service group
  3. Interface zone
  4. User group

Correct Answer: 3

Explanation

An interface zone allows multiple FortiGate interfaces to be grouped logically and referenced together in firewall policies. This can simplify policy configuration when several interfaces require the same security treatment. Instead of creating separate policies for every individual interface, an administrator can use the zone as a policy interface. Address groups combine address objects, service groups combine network services, and user groups organize authenticated users. Therefore, Interface zone is the appropriate feature when multiple interfaces need to be managed together for policy purposes.

Question 222

Which FortiGate feature allows administrators to assign IP addresses automatically to devices connecting to a network interface?

  1. DHCP server
  2. Static route
  3. IP pool
  4. Virtual IP

Correct Answer: 1

Explanation

The DHCP server feature allows FortiGate to automatically assign IP addresses and related network parameters to DHCP clients. A DHCP configuration can provide information such as the IP address, subnet mask, default gateway, and DNS server settings. This reduces the need to configure every client manually. A static route controls packet forwarding, an IP pool provides addresses for NAT operations, and a Virtual IP is generally used for destination NAT. Therefore, DHCP server is the correct feature when FortiGate needs to automatically provide network configuration to connected clients.

Question 223

Which FortiGate inspection profile is designed to detect malicious files and malware in supported traffic?

  1. Web Filter
  2. Application Control
  3. Antivirus
  4. Traffic Shaping

Correct Answer: 3

Explanation

The Antivirus security profile is designed to inspect supported traffic for malicious files, malware, and other threats identified by FortiGate’s antivirus engine and related security intelligence. It can be applied to firewall policies so that matching traffic receives malware inspection according to the configured profile. Web Filter controls website access, Application Control identifies and controls applications, and Traffic Shaping manages bandwidth usage. Antivirus inspection is therefore the appropriate security feature when the primary objective is detecting and handling malicious content transmitted through supported network protocols.

Question 224

Which FortiGate routing protocol is commonly used to exchange route information between neighboring autonomous systems?

  1. OSPF
  2. BGP
  3. DHCP
  4. DNS

Correct Answer: 2

Explanation

BGP, or Border Gateway Protocol, is designed to exchange routing information between autonomous systems and is widely used for inter-domain routing. It allows routers to exchange network reachability information and apply routing policies to control path selection. OSPF is primarily an interior gateway protocol used within an autonomous system, while DHCP provides network configuration and DNS resolves names to addresses. Therefore, BGP is the correct routing protocol when route information needs to be exchanged between autonomous systems.

Question 225

Which FortiGate configuration is used to specify the encryption and authentication parameters for the initial IKE negotiation of an IPsec VPN?

  1. Phase 2
  2. Firewall policy
  3. IP pool
  4. Phase 1

Correct Answer: 4

Explanation

IPsec Phase 1 establishes the initial secure relationship between VPN peers using IKE. It defines important parameters such as authentication method, encryption algorithms, hashing, Diffie-Hellman groups, and negotiation settings. Phase 2 defines the security associations used to protect the actual data traffic and includes traffic selectors and additional IPsec parameters. A firewall policy controls permitted traffic, while an IP pool provides addresses for NAT. Therefore, Phase 1 is the correct configuration for the initial IKE negotiation parameters.

Question 226

Which FortiGate setting determines how long an established session can remain active before timing out when no relevant traffic is received?

  1. Administrative access
  2. Session TTL
  3. FortiGuard license
  4. DNS Filter

Correct Answer: 2

Explanation

Session TTL, or Time To Live, determines how long a session can remain in the FortiGate session table before it expires according to the applicable timeout behavior. Proper session timeout values help manage firewall resources and ensure stale connections are eventually removed. Administrative access controls management protocols, FortiGuard provides security services and intelligence, and DNS Filter controls DNS-related access. Session TTL is therefore the setting associated with controlling the lifetime of established sessions and is useful when troubleshooting connections that expire unexpectedly.

Question 227

Which FortiGate feature can provide a graphical view of traffic, applications, users, and security activity on the device?

  1. FortiView
  2. FortiAnalyzer
  3. FortiToken
  4. FortiGuard

Correct Answer: 1

Explanation

FortiView provides graphical visibility into activity occurring on the FortiGate device. Depending on the available data and configuration, administrators can use FortiView to examine traffic, applications, users, destinations, sources, and security-related information. It can be particularly useful for quickly identifying traffic patterns or investigating unusual activity. FortiAnalyzer provides centralized logging and analysis, FortiToken supports authentication, and FortiGuard provides security intelligence and services. Therefore, FortiView is the appropriate feature for graphical, real-time-oriented visibility into FortiGate activity.

Question 228

Which FortiGate configuration can translate a public destination port to a different private destination port on an internal server?

  1. Static route
  2. Address group
  3. Virtual IP with port forwarding
  4. Traffic shaper

Correct Answer: 3

Explanation

A Virtual IP with port forwarding can perform destination NAT while translating a public destination port to a different private port on an internal server. This is useful when an external service must be published through a specific public port while the internal application listens on another port. Static routes determine forwarding paths, address groups organize IP objects, and traffic shapers control bandwidth. A VIP with port forwarding therefore provides the appropriate mechanism for mapping a public address and port to a private server address and port.

Question 229

Which FortiGate authentication method uses a centralized server that commonly provides authentication, authorization, and accounting services?

  1. LDAP
  2. RADIUS
  3. Local authentication
  4. Certificate inspection

Correct Answer: 2

Explanation

RADIUS is a centralized authentication protocol that can provide authentication, authorization, and accounting capabilities through an external server. FortiGate can communicate with a RADIUS server to validate user credentials and receive the authentication result. LDAP is commonly used for directory-based authentication, local authentication uses accounts configured on FortiGate, and certificate inspection examines SSL/TLS certificate information. RADIUS is particularly useful when an organization already maintains centralized authentication infrastructure. Therefore, RADIUS is the correct choice for this scenario.

Question 230

Which FortiGate feature can block or allow websites based on their categorized reputation or content classification?

  1. Antivirus
  2. IPS
  3. Web Filter
  4. DHCP server

Correct Answer: 3

Explanation

Web Filter can control website access using URL categories, ratings, and configured filtering actions. FortiGate can use available FortiGuard web-rating information to classify websites and apply actions such as allow, block, monitor, or warning according to the configured policy. Antivirus is designed primarily for malware detection, IPS focuses on network attack signatures, and DHCP provides IP configuration to clients. Therefore, Web Filter is the correct security feature when website access needs to be controlled according to reputation or content categories.

Question 231

Which FortiGate feature can identify traffic according to predefined application signatures and allow administrators to block selected applications?

  1. Static route
  2. DHCP server
  3. Application Control
  4. IP pool

Correct Answer: 3

Explanation

Application Control identifies applications using FortiGate application signatures and related inspection mechanisms. Administrators can create Application Control profiles that monitor, allow, or block selected applications or application categories and then apply those profiles to firewall policies. Static routes determine how packets are forwarded, DHCP provides client configuration, and IP pools supply addresses for NAT operations. Application Control is therefore the appropriate feature when administrators need application-aware traffic management rather than relying only on IP addresses or port numbers.

Question 232

Which FortiGate security profile is specifically designed to detect suspicious network activity associated with known attack signatures?

  1. Web Filter
  2. IPS
  3. DNS Filter
  4. Traffic Shaping

Correct Answer: 2

Explanation

The Intrusion Prevention System, or IPS, examines traffic for patterns associated with known attacks and suspicious network behavior. FortiGate uses IPS signatures and configured actions to detect and respond to matching traffic. Depending on the profile configuration, an administrator can choose appropriate actions for detected threats. Web Filter focuses on website access, DNS Filter controls DNS requests, and Traffic Shaping manages bandwidth. Therefore, IPS is the security profile specifically intended for detecting network attacks through intrusion-prevention signatures.

Question 233

Which FortiGate command displays all active routes in the routing table?

  1. get system status
  2. diagnose debug flow
  3. get router info routing-table all
  4. diagnose sys session list

Correct Answer: 3

Explanation

The get router info routing-table all command displays the routes currently available in the FortiGate routing table. It can help administrators identify connected, static, and dynamically learned routes and determine which paths are available for packet forwarding. get system status provides general device information, diagnose debug flow is used to trace packet processing, and diagnose sys session list displays active sessions. Therefore, get router info routing-table all is the appropriate command when an administrator needs to inspect the complete routing table.

Question 234

Which FortiGate feature can restrict administrative access to selected source networks for an individual administrator account?

  1. Trusted hosts
  2. Service group
  3. Performance SLA
  4. Virtual IP

Correct Answer: 1

Explanation

Trusted hosts allow administrators to specify the source IP addresses or networks from which a particular administrator account can access FortiGate management services. This provides an additional restriction beyond normal authentication and can reduce exposure to unauthorized management attempts. Service groups combine service objects, Performance SLA measures network-path performance, and Virtual IP configurations provide destination NAT functionality. Therefore, Trusted hosts is the appropriate feature when management access needs to be limited to selected source networks for a specific administrator account.

Question 235

Which FortiGate feature allows a network administrator to define a preferred forwarding path and an alternative path for redundancy?

  1. Web Filter
  2. Static routes with different priorities
  3. Application Control
  4. User groups

Correct Answer: 2

Explanation

FortiGate can use static routes with different administrative distances or priorities to provide primary and backup routing paths. The preferred route can be selected while an alternative route remains available if the primary path becomes unavailable or otherwise fails the relevant routing conditions. Web Filter and Application Control are security features, while user groups organize authenticated identities. Proper route configuration is important for maintaining connectivity during path failures. Therefore, Static routes with different priorities are appropriate for implementing basic routing redundancy.

Question 236

Which FortiGate feature can provide users with a web-based authentication page before allowing network access?

  1. Static route
  2. Captive portal
  3. Service object
  4. IP pool

Correct Answer: 2

Explanation

A captive portal presents users with a web-based authentication process before they receive normal network access through the configured interface or policy. It is commonly used for guest networks, public access environments, and networks where users must authenticate before browsing. Static routes control packet forwarding, service objects define protocols and ports, and IP pools provide addresses for NAT. A captive portal therefore provides the required interactive authentication step before access is granted to the protected network.

Question 237

Which FortiGate feature can group several physical or logical interfaces so they can be referenced as a single interface in policies?

  1. Interface zone
  2. IP pool
  3. Address object
  4. FortiGuard

Correct Answer: 1

Explanation

An interface zone provides a logical grouping of multiple interfaces so that they can be referenced together in firewall policies. This can simplify configurations where several interfaces require the same policy treatment. Administrators can create the zone and then use it as an interface reference instead of repeatedly configuring individual interfaces. An IP pool is used for NAT addresses, an address object represents a network or host, and FortiGuard provides security services. Therefore, Interface zone is the correct feature for logically grouping interfaces for policy use.

Question 238

Which FortiGate feature can use DNS-based filtering to block domains associated with unwanted or malicious content?

  1. Antivirus
  2. IPS
  3. Application Control
  4. DNS Filter

Correct Answer: 4

Explanation

DNS Filter controls DNS requests and can use configured filtering categories and available security intelligence to allow or block domain resolution. This provides a way to prevent users from reaching certain domains before a connection to the destination is established. Antivirus focuses on malicious files and content, IPS detects network attacks, and Application Control identifies applications. DNS filtering can therefore be useful for blocking domains associated with malicious, inappropriate, or otherwise restricted content. Hence, DNS Filter is the correct feature for this requirement.

Question 239

Which FortiGate configuration is used to define a group of authenticated users that can be referenced in an identity-based firewall policy?

  1. Service group
  2. User group
  3. Address group
  4. Interface zone

Correct Answer: 2

Explanation

A user group combines authenticated users or directory groups so that they can be referenced together in FortiGate authentication and identity-based firewall policies. This allows administrators to apply common access rules to a group rather than configuring each user individually. Service groups combine network services, address groups combine IP address objects, and interface zones group interfaces. User groups are therefore the appropriate configuration when firewall access needs to be based on the identity of multiple users or directory groups.

Question 240

Which FortiGate security profile can identify and control DNS requests according to configured categories and filtering policies?

  1. DNS Filter
  2. Web Filter
  3. Antivirus
  4. IPS

Correct Answer: 1

Explanation

DNS Filter examines DNS requests and applies configured filtering rules to domain queries. It can use categories and available security intelligence to determine whether a requested domain should be allowed, blocked, or handled according to another configured action. Web Filter operates primarily on web access and URL categories, Antivirus detects malicious files and content, and IPS detects network attacks. DNS Filter is therefore the correct security profile when administrators need to control domain resolution according to DNS-based filtering policies.