Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 241

Which FortiGate feature allows an administrator to save the current configuration so it can be restored later?

  1. Configuration backup
  2. FortiView
  3. Performance SLA
  4. Application Control

Correct Answer: 1

Explanation

Configuration backup allows an administrator to save FortiGate configuration information so it can be restored if the device experiences a failure, configuration mistake, or other operational problem. Backups are also useful before major configuration changes or firmware upgrades. FortiView provides traffic visibility, Performance SLA evaluates network-path quality, and Application Control manages application-based traffic. Maintaining current configuration backups is an important operational practice because it provides a recovery point and can reduce downtime when configuration information needs to be restored.

Question 242

Which FortiGate feature can authenticate administrators or users using a one-time password generated by a token?

  1. LDAP
  2. FortiToken
  3. DHCP
  4. Static route

Correct Answer: 2

Explanation

FortiToken provides token-based authentication using one-time passwords as an additional authentication factor. It can be integrated with FortiGate authentication configurations to strengthen access security beyond a username and password alone. LDAP provides directory-based authentication, DHCP assigns network configuration to clients, and static routes determine packet-forwarding paths. FortiToken is particularly useful when administrators want to implement multi-factor authentication for management or user access. Therefore, FortiToken is the correct feature for token-based one-time-password authentication.

Question 243

Which FortiGate feature can identify users based on logon information received from a supported Windows domain environment?

  1. FSSO
  2. IP pool
  3. Web Filter
  4. Static route

Correct Answer: 1

Explanation

Fortinet Single Sign-On, or FSSO, allows FortiGate to obtain user identity information from supported authentication and directory environments. In a Windows domain environment, FSSO can associate users with their network activity without requiring users to repeatedly enter credentials directly into FortiGate. This identity information can then be used in identity-based firewall policies. IP pools provide NAT addresses, Web Filter controls web access, and static routes control forwarding. Therefore, FSSO is the correct feature for identifying users through supported domain logon information.

Question 244

Which FortiGate feature can automatically provide clients with a default gateway, DNS server, and IP address through DHCP?

  1. Virtual IP
  2. Service group
  3. DHCP server
  4. IPS

Correct Answer: 3

Explanation

The FortiGate DHCP server can automatically provide clients with network configuration information such as an IP address, subnet mask, default gateway, and DNS server addresses. This allows network administrators to centrally manage client addressing without manually configuring every device. A Virtual IP provides destination NAT, a service group combines service objects, and IPS detects network attacks. Therefore, the DHCP server is the correct feature when FortiGate needs to automatically distribute standard network configuration parameters to connected clients.

Question 245

Which FortiGate feature can be used to create a logical network interface associated with a VLAN identifier on a physical interface?

  1. VLAN interface
  2. IP pool
  3. User group
  4. FortiAnalyzer

Correct Answer: 1

Explanation

A VLAN interface is a logical interface associated with a specific VLAN identifier and can be configured with its own IP address and network settings. It allows FortiGate to communicate with devices on tagged VLAN networks through an appropriate physical interface or trunk connection. IP pools are used for NAT addresses, user groups organize authenticated users, and FortiAnalyzer provides centralized logging and analysis. Therefore, VLAN interface is the appropriate configuration when FortiGate needs to participate in a tagged VLAN network.

Question 246

Which FortiGate feature can help identify whether a particular firewall policy is being selected for a connection?

  1. FortiGuard
  2. Policy lookup
  3. DHCP server
  4. FortiToken

Correct Answer: 2

Explanation

Policy lookup helps administrators determine which firewall policy would match specified traffic conditions. It can be useful when troubleshooting policy-order problems or determining why traffic is being handled by an unexpected rule. FortiGuard provides security intelligence, DHCP provides client network configuration, and FortiToken supports token-based authentication. Because FortiGate processes firewall policies according to matching criteria and policy order, policy lookup can help verify which rule is selected for a particular traffic flow. Therefore, Policy lookup is the correct feature.

Question 247

Which FortiGate HA configuration can increase the likelihood that the preferred unit remains the primary unit after recovering from a failure?

  1. Override
  2. Session pickup
  3. Interface zone
  4. DNS Filter

Correct Answer: 1

Explanation

The Override setting can influence HA primary-unit selection after a cluster member recovers. When configured appropriately, it can allow the unit with the preferred HA characteristics, such as higher priority, to resume the primary role after recovery. Session pickup deals with synchronization of supported session information, interface zones group interfaces, and DNS Filter controls DNS requests. HA election depends on several configured factors, but Override is specifically associated with influencing whether a preferred unit can regain the primary role. Therefore, Override is the correct answer.

Question 248

Which FortiGate feature can reduce bandwidth consumption by controlling how much traffic a particular policy or application is allowed to use?

  1. Web Filter
  2. RADIUS
  3. Traffic Shaping
  4. LDAP

Correct Answer: 3

Explanation

Traffic Shaping controls bandwidth usage by limiting or prioritizing traffic according to configured policies and traffic-shaping settings. It can help organizations prevent a particular application or traffic category from consuming excessive network capacity. Web Filter controls website access, RADIUS provides external authentication, and LDAP provides directory-based authentication. Traffic shaping is therefore useful when administrators need to manage bandwidth consumption and maintain predictable network performance. The exact behavior depends on the configured shapers and the policies or traffic to which they are applied.

Question 249

Which FortiGate feature can provide centralized logging and reporting for multiple FortiGate devices?

  1. FortiAnalyzer
  2. FortiToken
  3. FortiView
  4. DHCP server

Correct Answer: 1

Explanation

FortiAnalyzer provides centralized collection, storage, analysis, and reporting of logs from Fortinet devices. In an environment with multiple FortiGate appliances, it allows administrators to investigate traffic and security events from a centralized platform rather than examining each firewall independently. FortiToken is used for token-based authentication, FortiView provides local visibility on FortiGate, and DHCP server functionality provides network configuration to clients. Therefore, FortiAnalyzer is the appropriate solution for centralized FortiGate logging and reporting.

Question 250

Which FortiGate feature can inspect encrypted web traffic by decrypting it and then inspecting the underlying content?

  1. Certificate inspection
  2. Deep inspection
  3. Static routing
  4. DHCP

Correct Answer: 2

Explanation

Deep inspection can decrypt supported SSL/TLS traffic so FortiGate can inspect the underlying content using security profiles such as Antivirus, Web Filter, and Application Control. Because encrypted traffic is decrypted for inspection, administrators must properly configure certificates and client trust to avoid certificate warnings and maintain expected functionality. Certificate inspection examines certificate information without performing the same level of content decryption. Static routing controls packet forwarding, while DHCP provides network configuration. Therefore, Deep inspection is the correct option when encrypted content itself must be inspected.

Question 251

Which FortiGate feature allows administrators to create an exception to a web-filtering decision for a specific website or URL?

  1. Web Filter override
  2. IPsec Phase 2
  3. Traffic Shaping
  4. Interface monitoring

Correct Answer: 1

Explanation

A Web Filter override can provide an exception to normal web-filtering behavior for specified websites or URLs when the configuration supports such an override. This can be useful when a categorized website is blocked but an organization has determined that access should be permitted under defined conditions. IPsec Phase 2 establishes VPN security associations, Traffic Shaping manages bandwidth, and Interface monitoring is associated with HA interface monitoring. Therefore, Web Filter override is the appropriate feature for creating a controlled exception to web-filtering decisions.

Question 252

Which FortiGate command is commonly used to display currently active firewall sessions for troubleshooting?

  1. get system status
  2. diagnose vpn tunnel list
  3. diagnose sys session list
  4. get router info routing-table all

Correct Answer: 3

Explanation

The diagnose sys session list command displays information about active sessions tracked by FortiGate. It can help administrators investigate connection details such as source and destination addresses, ports, interfaces, and session states. This is useful when troubleshooting traffic that appears to be blocked, incorrectly routed, or unexpectedly maintained. get system status provides general system information, diagnose vpn tunnel list displays VPN tunnel information, and the routing-table command displays available routes. Therefore, diagnose sys session list is the appropriate command for examining active sessions.

Question 253

Which FortiGate feature can provide additional security by restricting which IP addresses are allowed to manage the FortiGate using an administrator account?

  1. Trusted hosts
  2. Service group
  3. Application Control
  4. Performance SLA

Correct Answer: 1

Explanation

Trusted hosts restrict management access for an administrator account to specified source IP addresses or networks. This creates an additional access-control layer because even a valid username and password may not be sufficient when the connection originates outside the configured trusted sources. Service groups organize network services, Application Control manages application traffic, and Performance SLA evaluates network-path quality. Trusted hosts are therefore particularly useful for limiting administrative access to known management networks and reducing exposure to unauthorized remote management attempts.

Question 254

Which FortiGate feature can monitor the health of an IPsec VPN tunnel and help identify whether the remote peer is reachable?

  1. Service group
  2. VPN monitoring
  3. Address group
  4. DHCP server

Correct Answer: 2

Explanation

VPN monitoring can be used to observe the operational state and reachability associated with an IPsec VPN connection. Monitoring information can help administrators determine whether a tunnel is established and whether connectivity through the VPN is functioning as expected. Service groups combine service objects, address groups organize IP addresses, and DHCP servers provide network configuration to clients. When troubleshooting VPN connectivity, administrators can also review tunnel status and diagnostic information. Therefore, VPN monitoring is the appropriate feature for observing IPsec tunnel health and peer reachability.

Question 255

Which FortiGate feature can automatically select an SD-WAN member according to rules based on the destination, application, or other traffic characteristics?

  1. SD-WAN rule
  2. Address object
  3. Antivirus
  4. Captive portal

Correct Answer: 1

Explanation

An SD-WAN rule defines how FortiGate selects among available SD-WAN members for matching traffic. Rules can consider factors such as destinations, applications, services, or other supported traffic characteristics and can work together with Performance SLA information. Address objects identify network endpoints, Antivirus inspects supported content for malware, and captive portals provide user authentication through a web interface. Therefore, SD-WAN rule is the correct feature when administrators need to control WAN-path selection according to defined traffic conditions.

Question 256

Which FortiGate component provides security service information such as web-category ratings used by certain security profiles?

  1. FortiView
  2. FortiGuard
  3. FortiAnalyzer
  4. FortiToken

Correct Answer: 2

Explanation

FortiGuard provides security intelligence and subscription services that support several FortiGate security features. One example is web-category information used by Web Filter to classify websites according to available FortiGuard ratings. FortiGuard services can also support other security functions depending on licensing and configuration. FortiView provides visibility, FortiAnalyzer provides centralized logging and analysis, and FortiToken supports authentication. Therefore, FortiGuard is the component associated with external security-service information such as web-category ratings.

Question 257

Which FortiGate feature allows an administrator to define a policy that applies only during specified days and hours?

  1. Service object
  2. Schedule
  3. Address group
  4. IP pool

Correct Answer: 2

Explanation

A Schedule controls the time period during which a firewall policy is active. Administrators can create recurring schedules specifying particular days and time ranges and then assign those schedules to appropriate policies. This allows access to resources or services to be limited according to organizational operating hours. Service objects define protocols and ports, address groups combine address objects, and IP pools provide NAT addresses. Therefore, Schedule is the correct configuration when a firewall policy needs to operate only during specified days and hours.

Question 258

Which FortiGate diagnostic command can help determine why a packet is being accepted or denied by tracing its processing through the firewall?

  1. diagnose debug flow
  2. get system status
  3. diagnose vpn tunnel list
  4. get router info routing-table all

Correct Answer: 1

Explanation

The diagnose debug flow command is a powerful troubleshooting tool for tracing how FortiGate processes packets. It can help reveal routing decisions, policy matching, interface information, and reasons why a packet is accepted or denied. Administrators normally configure appropriate filters before starting the debug process so that the output focuses on the traffic being investigated. get system status provides general device information, diagnose vpn tunnel list displays VPN information, and the routing-table command displays routes. Therefore, diagnose debug flow is the correct diagnostic command.

Question 259

Which FortiGate feature can synchronize supported configuration and operational information between members of an HA cluster?

  1. Web Filter
  2. HA synchronization
  3. DNS Filter
  4. IP pool

Correct Answer: 2

Explanation

HA synchronization allows supported configuration and operational information to be synchronized between FortiGate devices participating in an HA cluster. This helps cluster members maintain consistent configurations and supports reliable failover behavior. The exact information synchronized depends on the HA configuration and FortiOS capabilities. Web Filter controls website access, DNS Filter controls DNS requests, and IP pools provide addresses for NAT. Therefore, HA synchronization is the correct feature for maintaining consistency between members of a FortiGate HA cluster.

Question 260

Which FortiGate feature can use a set of external IP addresses or domains to identify known malicious destinations for security enforcement?

  1. Captive portal
  2. Service group
  3. External threat feed
  4. DHCP server

Correct Answer: 3

Explanation

An external threat feed provides FortiGate with externally maintained indicators such as IP addresses or domains associated with known threats. These feeds can be referenced by supported security configurations to help identify or block traffic associated with potentially malicious destinations. Captive portal provides user authentication, service groups combine service objects, and DHCP servers provide network configuration to clients. External threat feeds can therefore extend FortiGate’s security controls by incorporating threat intelligence maintained outside the firewall. Thus, External threat feed is the correct answer.