Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 321

Which FortiGate feature can identify the network path selected for a destination by examining the routing table?

  1. Routing table
  2. Web Filter
  3. Application Control
  4. FortiAnalyzer

Correct Answer: 1

Explanation

The routing table contains the routes FortiGate uses when determining how traffic should be forwarded toward a destination. Administrators can examine routing-table entries to identify connected, static, and dynamically learned routes and determine which path is available for a particular destination. Web Filter controls website access, Application Control manages application-based traffic, and FortiAnalyzer provides centralized logging and analysis. Therefore, the Routing table is the appropriate FortiGate component for examining available paths and understanding how destination traffic is routed through the device.

Question 322

Which FortiGate feature can authenticate users through an external server using the RADIUS protocol?

  1. LDAP Server
  2. RADIUS Server
  3. FSSO
  4. FortiToken

Correct Answer: 2

Explanation

A RADIUS Server configuration allows FortiGate to communicate with an external RADIUS server for centralized user authentication. FortiGate sends authentication requests to the configured RADIUS server, which validates the credentials and returns the authentication result. LDAP Server uses the LDAP protocol, FSSO provides user identity information through supported single sign-on mechanisms, and FortiToken provides token-based authentication. RADIUS is widely used when organizations already have centralized authentication infrastructure. Therefore, RADIUS Server is the correct configuration for this requirement.

Question 323

Which FortiGate feature can control access to websites based on URL categories and configured filtering actions?

  1. Antivirus
  2. Web Filter
  3. IPS
  4. Traffic Shaping

Correct Answer: 2

Explanation

Web Filter controls website access according to URL categories, ratings, and configured filtering actions. FortiGate can use available web-rating information to classify websites and then apply actions such as allow, block, monitor, or warning. Antivirus focuses on malicious content, IPS detects network attacks, and Traffic Shaping controls bandwidth usage. Web Filter is therefore the appropriate security profile when administrators need to enforce browsing restrictions based on website categories or other supported URL classification information.

Question 324

Which FortiGate feature can distribute network traffic across multiple WAN connections according to configured SD-WAN rules?

  1. Static Route
  2. Traffic Shaping
  3. Performance SLA
  4. SD-WAN

Correct Answer: 4

Explanation

SD-WAN allows FortiGate to manage multiple WAN connections and select forwarding paths according to configured SD-WAN rules and link-performance conditions. Administrators can define members, Performance SLAs, and traffic-selection rules to determine how different types of traffic use available WAN links. Static routes provide individual routing entries, Traffic Shaping controls bandwidth, and Performance SLA measures link quality. Therefore, SD-WAN is the correct feature when traffic needs to be distributed or directed across multiple WAN connections according to configured policies.

Question 325

Which FortiGate feature can combine multiple network address objects into a single reusable object?

  1. Address Group
  2. Service Group
  3. User Group
  4. Interface Zone

Correct Answer: 1

Explanation

An Address Group combines multiple individual address objects into a single reusable object. This makes firewall-policy configuration easier when several hosts, subnets, or other address definitions require identical treatment. Instead of selecting each address separately, an administrator can reference the group as a source or destination. Service Groups combine service objects, User Groups organize authenticated users, and Interface Zones group interfaces. Therefore, Address Group is the correct feature when multiple network address objects need to be referenced together in firewall policies.

Question 326

Which FortiGate feature can inspect encrypted traffic by decrypting supported SSL/TLS sessions before applying security inspection?

  1. Certificate Inspection
  2. Deep Inspection
  3. Flow-based Inspection
  4. Static Routing

Correct Answer: 2

Explanation

Deep Inspection can decrypt supported SSL/TLS sessions so FortiGate can inspect the underlying content with security profiles such as Antivirus, Web Filter, and Application Control. This provides deeper visibility into encrypted traffic than certificate inspection, which evaluates certificate information without performing the same level of content decryption. Flow-based inspection analyzes traffic as it passes through the device, while static routing determines forwarding paths. Therefore, Deep Inspection is the appropriate inspection mode when encrypted traffic needs to be decrypted for content-level security inspection.

Question 327

Which FortiGate feature can provide a web-based authentication page before a user is granted network access?

  1. Captive Portal
  2. Static Route
  3. Service Object
  4. IP Pool

Correct Answer: 1

Explanation

A captive portal presents users with a web-based authentication page before normal network access is granted. It is commonly used in guest networks, public access environments, and networks where administrators require users to authenticate before accessing external resources. A static route controls packet forwarding, a service object defines protocols and ports, and an IP pool provides addresses for NAT operations. Therefore, Captive Portal is the correct feature when users must complete a web-based authentication process before receiving network access.

Question 328

Which FortiGate feature can provide a stable logical IP endpoint for routing or management purposes?

  1. VLAN Interface
  2. Service Group
  3. Loopback Interface
  4. IP Pool

Correct Answer: 3

Explanation

A Loopback Interface is a logical interface that can provide a stable IP endpoint independently of the operational status of a particular physical interface. It can be useful for routing, management, and other network functions requiring a consistent logical address. A VLAN Interface is associated with a VLAN identifier, a Service Group combines service objects, and an IP Pool provides addresses for NAT. Therefore, Loopback Interface is the appropriate feature when a stable logical endpoint is needed for routing or management purposes.

Question 329

Which FortiGate feature can restrict administrator access to specified source IP addresses?

  1. Administrative Access
  2. Trusted Hosts
  3. Service Group
  4. Performance SLA

Correct Answer: 2

Explanation

Trusted Hosts allow administrators to restrict a specific administrator account to management connections originating from approved IP addresses or networks. This adds another layer of protection because valid credentials cannot be used from unauthorized source locations. Administrative Access controls which management protocols are enabled on an interface, Service Groups combine network services, and Performance SLA evaluates SD-WAN path quality. Therefore, Trusted Hosts is the correct feature when management access needs to be limited according to specific source IP addresses.

Question 330

Which FortiGate feature can identify known malicious network traffic by using intrusion-prevention signatures?

  1. Web Filter
  2. Application Control
  3. IPS
  4. DHCP Server

Correct Answer: 3

Explanation

The Intrusion Prevention System, or IPS, uses signatures and related inspection mechanisms to identify known attacks and suspicious network activity. Administrators can configure IPS profiles with appropriate actions and apply them through firewall policies. Web Filter controls website access, Application Control identifies applications, and DHCP Server provides network configuration to clients. IPS is therefore the FortiGate security profile specifically designed for detecting and responding to network-based attacks. It is commonly used as part of a layered security configuration to protect internal and external network traffic.

Question 331

Which FortiGate feature can determine whether an SD-WAN member satisfies configured packet-loss and latency thresholds?

  1. Performance SLA
  2. Static Route
  3. Address Group
  4. FortiAnalyzer

Correct Answer: 1

Explanation

Performance SLA measures SD-WAN path quality using values such as latency, jitter, and packet loss. Administrators can configure thresholds that determine whether a WAN member meets the required service level. The resulting health status can then be used by SD-WAN rules when selecting a path for traffic. Static routes provide forwarding information, Address Groups combine network objects, and FortiAnalyzer provides centralized log analysis. Therefore, Performance SLA is the correct feature for determining whether an SD-WAN member satisfies configured performance thresholds.

Question 332

Which FortiGate feature can provide centralized collection and analysis of logs from FortiGate devices?

  1. FortiView
  2. FortiGuard
  3. FortiAnalyzer
  4. FortiToken

Correct Answer: 3

Explanation

FortiAnalyzer provides centralized log collection, storage, analysis, and reporting for supported Fortinet devices. FortiGate devices can send traffic, event, and security logs to FortiAnalyzer, allowing administrators to investigate information from a centralized platform. FortiView provides graphical visibility on an individual FortiGate, FortiGuard supplies security intelligence and related services, and FortiToken provides token-based authentication. Therefore, FortiAnalyzer is the correct solution when administrators need centralized logging and analysis across FortiGate devices.

Question 333

Which FortiGate feature allows an administrator to define a reusable collection of TCP and UDP services?

  1. Address Object
  2. Service Group
  3. User Group
  4. Interface Zone

Correct Answer: 2

Explanation

A Service Group combines multiple service objects into one reusable object. Individual service objects define protocols and ports, and a service group allows administrators to reference several of them together in firewall policies. Address Objects identify hosts or networks, User Groups organize authenticated users, and Interface Zones group interfaces. Service Groups can simplify policy configuration when the same set of services must be permitted or controlled across multiple rules. Therefore, Service Group is the correct feature for combining multiple TCP and UDP services.

Question 334

Which FortiGate setting controls which management protocols are enabled on a network interface?

  1. Trusted Hosts
  2. Schedule
  3. Administrative Access
  4. Address Group

Correct Answer: 3

Explanation

Administrative Access settings determine which management protocols are permitted through a FortiGate interface. Administrators can enable appropriate protocols such as HTTPS and SSH and disable unnecessary management services to reduce exposure. Trusted Hosts restrict the source locations for an administrator account, Schedule determines when a firewall policy operates, and Address Groups combine address objects. Therefore, Administrative Access is the correct setting when the objective is to control which management protocols can be used through a specific interface.

Question 335

Which FortiGate feature can use a public IP address to publish an internal server to external users?

  1. Virtual IP
  2. IP Pool
  3. Address Group
  4. Service Group

Correct Answer: 1

Explanation

A Virtual IP, or VIP, performs destination NAT by mapping a public IP address to an internal private server address. It is commonly used when services such as web, mail, or other applications need to be accessible from external networks. The corresponding firewall policy determines whether the inbound traffic is allowed. An IP Pool is primarily used for source NAT, an Address Group combines address objects, and a Service Group combines service objects. Therefore, Virtual IP is the appropriate feature for publishing an internal server through a public IP address.

Question 336

Which FortiGate diagnostic command can trace packet processing to help determine why traffic is accepted or denied?

  1. get system status
  2. diagnose debug flow
  3. diagnose vpn tunnel list
  4. get router info routing-table all

Correct Answer: 2

Explanation

The diagnose debug flow command can trace packet processing through FortiGate and help administrators identify routing decisions, policy matching, and reasons for traffic being accepted or denied. It is especially useful when normal logs do not provide enough detail to explain a connectivity problem. Administrators typically apply suitable filters before starting the debug process to limit the output to the traffic under investigation. The other commands provide system, VPN, or routing information. Therefore, diagnose debug flow is the correct troubleshooting command for tracing packet processing.

Question 337

Which FortiGate feature can control how much bandwidth is available to selected traffic?

  1. Traffic Shaping
  2. Web Filter
  3. RADIUS
  4. LDAP

Correct Answer: 1

Explanation

Traffic Shaping controls bandwidth allocation for selected network traffic. Administrators can use traffic-shaping settings to limit bandwidth consumption or prioritize important traffic so that critical applications receive appropriate network resources. Web Filter controls website access, RADIUS provides external authentication, and LDAP provides directory-based authentication. Traffic Shaping is therefore the appropriate FortiGate feature when bandwidth needs to be limited, prioritized, or managed for particular traffic classes. Its configuration can be associated with relevant firewall policies and traffic-shaping profiles.

Question 338

Which FortiGate feature can identify users through directory logon information and use that identity in firewall policies?

  1. FSSO
  2. DHCP Server
  3. IP Pool
  4. Static Route

Correct Answer: 1

Explanation

FSSO, or Fortinet Single Sign-On, provides FortiGate with user identity information obtained from supported authentication and directory environments. FortiGate can use this identity information in identity-based firewall policies, allowing access controls to be based on users or groups rather than only IP addresses. DHCP Server provides network configuration, IP Pool provides addresses for NAT, and Static Route determines packet-forwarding paths. Therefore, FSSO is the correct feature when administrators need to associate network activity with authenticated directory users.

Question 339

Which FortiGate feature can store logs directly on the device when local storage is available?

  1. FortiAnalyzer
  2. Local Disk
  3. FortiGuard
  4. FortiToken

Correct Answer: 2

Explanation

Local Disk allows supported FortiGate models to store logs directly on the appliance. This can provide administrators with locally available traffic, event, and security information for troubleshooting and review. The exact logging capabilities depend on the FortiGate model, storage availability, and configured log settings. FortiAnalyzer provides centralized log storage and analysis, FortiGuard supplies security intelligence, and FortiToken supports authentication. Therefore, Local Disk is the correct option when logs need to be stored directly on the FortiGate device.

Question 340

Which FortiGate feature can use an external threat-intelligence list containing malicious IP addresses or domains?

  1. Web Filter
  2. External Threat Feed
  3. Service Group
  4. DHCP Server

Correct Answer: 2

Explanation

An External Threat Feed allows FortiGate to use externally maintained threat indicators, such as malicious IP addresses or domains, in supported security configurations. These indicators can help administrators identify or block traffic associated with known threats and supplement other FortiGate security controls. Web Filter manages website access, Service Groups combine service objects, and DHCP Server provides network configuration to clients. Therefore, External Threat Feed is the appropriate feature when administrators want to incorporate external threat-intelligence indicators into FortiGate security enforcement.