View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 381
Which FortiGate command displays general system information, including the FortiOS version and serial number?
- get system status
- diagnose sys session list
- get router info routing-table all
- diagnose vpn tunnel list
Correct Answer: 1
Explanation
The get system status command displays important general information about the FortiGate system. Depending on the FortiOS version and device, the output can include the FortiOS firmware version, serial number, system time, hostname, and other system details. This makes the command useful when verifying device information during administration, troubleshooting, or upgrade preparation. The other commands provide information about active sessions, routing entries, or VPN tunnels. Therefore, get system status is the appropriate command for viewing general FortiGate system information.
Question 382
Which FortiGate feature can authenticate users through an external directory using the LDAP protocol?
- RADIUS
- LDAP Server
- FortiToken
- FSSO
Correct Answer: 2
Explanation
An LDAP Server configuration allows FortiGate to communicate with an external LDAP-compatible directory for user authentication. Administrators can configure the server address, authentication settings, and directory information required for FortiGate to validate user credentials. RADIUS uses the RADIUS authentication protocol, FortiToken provides one-time-password authentication, and FSSO provides user identity information through supported single sign-on mechanisms. Therefore, LDAP Server is the correct configuration when FortiGate must authenticate users against an external LDAP directory service.
Question 383
Which FortiGate action prevents traffic when no firewall policy explicitly permits the traffic?
- Accept
- Deny
- Monitor
- Traffic Shape
Correct Answer: 2
Explanation
FortiGate uses an implicit deny behavior when traffic does not match an applicable firewall policy that permits it. This means traffic is denied when no explicit policy allows the connection. Accept allows matching traffic, Monitor records or observes traffic according to the relevant configuration, and Traffic Shape controls bandwidth rather than serving as the general default access action. The implicit deny behavior is an important part of FortiGate’s policy-processing model because administrators normally need to create an appropriate allow policy for legitimate traffic.
Question 384
Which FortiGate feature can map a public IP address and specific external port to an internal server and port?
- IP Pool
- Static Route
- Address Group
- Virtual IP with Port Forwarding
Correct Answer: 4
Explanation
Virtual IP with Port Forwarding allows FortiGate to map an external public IP address and port to a specific internal server address and port. This is commonly used when an internal service must be published externally while controlling which destination port is exposed. An IP Pool is used for source NAT, a Static Route determines packet-forwarding paths, and an Address Group combines address objects. Therefore, Virtual IP with Port Forwarding is the correct configuration for translating a specific external port to an internal service.
Question 385
Which FortiGate feature can apply a different security policy to users belonging to a particular authenticated group?
- Service Group
- User Group
- Address Group
- Interface Zone
Correct Answer: 2
Explanation
A User Group combines authenticated users so they can be referenced together in authentication and identity-based access-control configurations. Administrators can create policies that apply different permissions or security settings according to user identity or group membership. Service Groups combine network services, Address Groups combine network addresses, and Interface Zones combine interfaces. Therefore, User Group is the correct feature when access-control policies need to apply specifically to users belonging to a particular authenticated group.
Question 386
Which FortiGate feature can determine whether an SD-WAN path meets configured latency, jitter, and packet-loss thresholds?
- Static Route
- Address Group
- Service Group
- Performance SLA
Correct Answer: 4
Explanation
Performance SLA monitors the quality of SD-WAN paths using measurements such as latency, jitter, and packet loss. Administrators can configure acceptable thresholds and use the resulting health information in SD-WAN path-selection decisions. A Static Route provides routing information, an Address Group combines address objects, and a Service Group combines service objects. Therefore, Performance SLA is the correct feature for determining whether an SD-WAN member meets configured network-performance requirements and remains suitable for carrying traffic.
Question 387
Which FortiGate interface type can carry traffic for multiple VLANs using VLAN tags over a physical interface?
- VLAN Interface
- Loopback Interface
- Software Switch
- IP Pool
Correct Answer: 1
Explanation
A VLAN Interface provides Layer 3 connectivity for traffic belonging to a specific VLAN and uses VLAN tagging over its associated physical or logical parent interface. Multiple VLAN interfaces can be configured on an appropriate physical interface, allowing FortiGate to route and apply firewall policies to traffic from different VLANs. A Loopback Interface provides a logical endpoint, Software Switch combines interfaces, and IP Pool provides addresses for NAT. Therefore, VLAN Interface is the correct configuration for handling tagged VLAN traffic.
Question 388
Which FortiGate feature can use externally maintained indicators such as malicious IP addresses or domains in security policies?
- Web Filter
- Antivirus
- External Threat Feed
- DHCP Server
Correct Answer: 3
Explanation
An External Threat Feed allows FortiGate to consume externally maintained threat indicators such as malicious IP addresses, domains, or other supported indicators. These indicators can then be referenced by supported security configurations to help identify or block known threats. Web Filter focuses on website access, Antivirus detects malicious files, and DHCP Server provides network configuration to clients. Therefore, External Threat Feed is the appropriate feature when administrators want to incorporate external threat-intelligence data into FortiGate security enforcement.
Question 389
Which FortiGate feature can provide centralized log storage and reporting for multiple FortiGate appliances?
- FortiView
- FortiGuard
- FortiToken
- FortiAnalyzer
Correct Answer: 4
Explanation
FortiAnalyzer provides centralized collection, storage, analysis, and reporting for logs generated by supported Fortinet devices. Multiple FortiGate appliances can send their logs to FortiAnalyzer, allowing administrators to investigate traffic, security events, and operational activity from a central platform. FortiView provides local visibility, FortiGuard supplies security intelligence and related services, and FortiToken provides token-based authentication. Therefore, FortiAnalyzer is the correct solution when centralized log management and reporting are required across multiple FortiGate devices.
Question 390
Which FortiGate diagnostic command displays the current routing table?
- get router info routing-table all
- get system status
- diagnose debug flow
- diagnose sys session list
Correct Answer: 1
Explanation
The get router info routing-table all command displays routing information available on the FortiGate. Administrators can use the output to review connected, static, and dynamically learned routes and investigate how the device determines forwarding paths. get system status displays general system information, diagnose debug flow traces packet processing, and diagnose sys session list displays active sessions. Therefore, get router info routing-table all is the appropriate command for examining the FortiGate routing table during configuration or troubleshooting.
Question 391
Which FortiGate security profile is designed to control applications identified in network traffic?
- Web Filter
- Antivirus
- Application Control
- DNS Filter
Correct Answer: 3
Explanation
Application Control identifies applications within network traffic and allows administrators to configure actions for individual applications or application categories. This provides application-aware control that is more flexible than relying only on IP addresses or port numbers. Web Filter controls website access, Antivirus focuses on malware and malicious files, and DNS Filter controls access through DNS-related filtering. Therefore, Application Control is the correct security profile when administrators need to identify, allow, monitor, or block specific applications or application categories.
Question 392
Which FortiGate setting can define the days and times during which a firewall policy is active?
- Source Address
- Schedule
- Service
- Destination Address
Correct Answer: 2
Explanation
The Schedule setting determines when a firewall policy is active. Administrators can configure recurring schedules for particular days and times and then assign those schedules to firewall policies. This allows organizations to restrict network access according to business hours, maintenance periods, or other operational requirements. Source Address identifies traffic origin, Destination Address identifies the target, and Service identifies protocols and ports. Therefore, Schedule is the correct firewall-policy setting when access must be permitted or denied according to specific time periods.
Question 393
Which FortiGate feature can restrict administrator management access to specified source IP addresses?
- Trusted Hosts
- Service Group
- IP Pool
- Performance SLA
Correct Answer: 1
Explanation
Trusted Hosts allow administrators to specify the IP addresses or networks from which a particular administrator account can access FortiGate management services. This provides an additional security restriction beyond normal authentication because valid credentials cannot normally be used from an unapproved source location. Service Groups combine service objects, IP Pools provide source NAT addresses, and Performance SLA monitors SD-WAN path quality. Therefore, Trusted Hosts is the correct feature for restricting administrator access according to approved source IP addresses.
Question 394
Which FortiGate feature provides automated one-time-password authentication as an additional authentication factor?
- FortiAnalyzer
- FortiGuard
- FortiView
- FortiToken
Correct Answer: 4
Explanation
FortiToken provides one-time-password authentication that can be used as an additional authentication factor. A user can be required to provide a password along with a current token-generated code, strengthening authentication compared with password-only access. FortiAnalyzer provides centralized logging and reporting, FortiGuard supplies security intelligence and subscription services, and FortiView provides visibility into network activity. Therefore, FortiToken is the correct Fortinet component when one-time-password authentication is required as part of a multi-factor authentication configuration.
Question 395
Which FortiGate configuration can combine multiple address objects into one reusable policy object?
- Service Group
- Address Group
- User Group
- Interface Zone
Correct Answer: 2
Explanation
An Address Group combines multiple address objects into a single reusable object. Administrators can then reference the group in firewall policies instead of individually selecting every host or subnet. This simplifies policy administration and makes repeated access-control configurations easier to maintain. Service Groups combine service objects, User Groups combine authenticated users, and Interface Zones group interfaces. Therefore, Address Group is the correct configuration when several network address objects need to be treated together in firewall policies.
Question 396
Which FortiGate feature can inspect encrypted web traffic by decrypting supported SSL/TLS sessions for content inspection?
- Certificate Inspection
- Flow-based Inspection
- Deep Inspection
- Traffic Shaping
Correct Answer: 3
Explanation
Deep Inspection can decrypt supported SSL/TLS sessions so FortiGate can inspect the underlying traffic using applicable security profiles. This provides deeper visibility into encrypted content than certificate inspection, which focuses on certificate information without performing equivalent content decryption. Flow-based inspection describes how traffic is processed, while Traffic Shaping controls bandwidth. Deep Inspection may require appropriate certificate deployment and can have compatibility or privacy considerations. Therefore, Deep Inspection is the correct inspection method when encrypted traffic must be examined at the content level.
Question 397
Which FortiGate feature can automatically select an alternative WAN path when the preferred path fails its configured performance requirements?
- Web Filter
- Service Object
- Address Group
- SD-WAN
Correct Answer: 4
Explanation
SD-WAN can use multiple WAN members and make path-selection decisions according to configured SD-WAN rules and Performance SLA results. If the preferred path becomes unavailable or no longer satisfies required performance conditions, FortiGate can select another eligible member according to the configured policy. Web Filter controls website access, Service Objects define network services, and Address Groups combine network addresses. Therefore, SD-WAN is the appropriate feature for automated WAN path selection and failover based on configured conditions.
Question 398
Which FortiGate feature can allow a firewall policy to apply the same rule to several interfaces grouped together?
- Service Group
- User Group
- Interface Zone
- IP Pool
Correct Answer: 3
Explanation
An Interface Zone groups multiple interfaces so they can be referenced together in appropriate firewall-policy configurations. This can simplify administration when several interfaces require the same access-control treatment. Instead of repeatedly selecting each interface, an administrator can reference the logical zone where supported. Service Groups combine service objects, User Groups organize authenticated users, and IP Pools provide addresses for NAT. Therefore, Interface Zone is the correct feature for grouping interfaces for simplified policy configuration.
Question 399
Which FortiGate feature can provide local graphical information about traffic, applications, users, and security activity?
- FortiView
- FortiAnalyzer
- FortiToken
- FortiGuard
Correct Answer: 1
Explanation
FortiView provides graphical visibility into activity observed by the FortiGate appliance. Depending on the available data and configuration, administrators can use FortiView to examine traffic, applications, users, sources, destinations, and security information. FortiAnalyzer provides centralized logging and analysis across supported devices, FortiToken provides authentication tokens, and FortiGuard provides security intelligence and related services. Therefore, FortiView is the correct feature when administrators need an interactive local view of network and security activity directly from FortiGate.
Question 400
Which FortiGate feature can control traffic destined directly for the FortiGate itself rather than traffic passing through it?
- Local-in Policy
- Firewall Policy
- SD-WAN Rule
- Traffic Shaping
Correct Answer: 1
Explanation
A Local-in Policy controls traffic destined for the FortiGate itself. This differs from regular firewall policies, which primarily control traffic passing through the FortiGate between networks. Local-in policies can be used to restrict access to services exposed by the FortiGate according to configured source, destination, interface, service, and action criteria. SD-WAN Rules control WAN path selection, while Traffic Shaping manages bandwidth. Therefore, Local-in Policy is the correct feature for controlling traffic addressed directly to the FortiGate.