View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 81
Which FortiGate feature is used to define a group of interfaces that can be referenced together by SD-WAN rules?
- Interface zone
- Address group
- Service group
- IP pool
Correct Answer: 1
Explanation
An interface zone can group multiple interfaces so they can be referenced together in configurations that support interface zones. In SD-WAN deployments, logical grouping can simplify policy and traffic-management configurations by allowing administrators to work with related interfaces as a group instead of repeatedly selecting individual members. Address groups organize IP addresses, service groups organize services and ports, and IP pools provide addresses for source NAT. Therefore, an interface zone is the appropriate choice when related interfaces need to be represented as a logical group.
Question 82
Which SD-WAN component determines how FortiGate selects an SD-WAN member for matching traffic?
- Health check
- SD-WAN rule
- Static route
- Firewall address
Correct Answer: 2
Explanation
An SD-WAN rule defines how FortiGate handles traffic that matches specific criteria and determines which SD-WAN member or path should be selected. Rules can use destinations, services, applications, source information, or performance-related criteria depending on the configuration. Health checks monitor path quality, but they do not by themselves define the complete traffic-selection policy. Static routes provide routing information, while firewall addresses identify network objects. Therefore, the SD-WAN rule is the component responsible for directing matching traffic toward an appropriate SD-WAN member.
Question 83
Which metric can an SD-WAN performance SLA use to evaluate the quality of a network path?
- MAC address
- VLAN ID
- Packet loss
- Administrator profile
Correct Answer: 3
Explanation
Packet loss is one of the performance measurements that can be used by an SD-WAN performance SLA to evaluate the quality of a network path. FortiGate can monitor service-level conditions and use measurements such as latency, jitter, and packet loss to determine whether a path meets configured requirements. A MAC address identifies a network interface, a VLAN ID identifies VLAN membership, and an administrator profile controls management permissions. Therefore, packet loss is a valid performance metric for evaluating an SD-WAN path.
Question 84
Which setting determines the amount of time FortiGate keeps an administrator’s inactive GUI session before logging the administrator out?
- Authentication server
- Session timeout
- Firewall schedule
- Route priority
Correct Answer: 2
Explanation
The administrator session timeout controls how long an inactive management session can remain open before FortiGate automatically logs the administrator out. This security setting helps reduce the risk of an unattended management session being misused by another person. The authentication server provides identity verification, a firewall schedule controls when policies operate, and route priority influences route selection. Administrators can configure an appropriate timeout based on their security requirements. Therefore, Session timeout is the setting that controls the duration of an inactive administrator session.
Question 85
Which FortiGate object represents a combination of multiple service definitions such as HTTP and HTTPS?
- Service group
- Address group
- User group
- Interface zone
Correct Answer: 1
Explanation
A service group allows multiple service objects to be combined into a single logical object. For example, HTTP and HTTPS service definitions can be placed in one service group and then referenced in a firewall policy. This simplifies policy configuration because administrators do not need to repeatedly select each individual service. Address groups contain network address objects, user groups contain authenticated users, and interface zones organize interfaces. Therefore, Service group is the correct object for combining multiple services into one reusable configuration object.
Question 86
Which firewall policy setting determines whether matching traffic is accepted or denied?
- Source
- Destination
- Action
- Service
Correct Answer: 3
Explanation
The Action setting determines what FortiGate does when traffic matches the conditions of a firewall policy. Common actions include Accept and Deny, depending on the policy configuration and FortiOS capabilities. Source identifies where the traffic originates, Destination identifies the target address, and Service identifies protocols or ports. FortiGate evaluates the policy criteria and then applies the configured action when a match occurs. Therefore, Action is the setting that determines whether matching traffic is permitted or blocked by the firewall policy.
Question 87
Which FortiGate feature can identify applications such as social media, messaging, or file-sharing applications regardless of their standard TCP or UDP port?
- Application Control
- DHCP server
- Static route
- IP pool
Correct Answer: 1
Explanation
Application Control identifies network applications and can apply controls based on application signatures rather than relying solely on port numbers. This is useful because modern applications may use multiple ports, dynamic ports, or common protocols to communicate. Administrators can configure application-control profiles to allow, monitor, or block selected application categories or signatures. DHCP assigns network configuration, static routes control packet forwarding, and IP pools provide source addresses for NAT. Therefore, Application Control is the appropriate FortiGate feature for application-based traffic identification and control.
Question 88
Which FortiGate inspection profile is specifically designed to detect and block malicious files such as viruses and trojans?
- Web Filter
- Antivirus
- Traffic Shaping
- DNS Filter
Correct Answer: 2
Explanation
The Antivirus security profile is designed to inspect traffic for malicious content such as viruses, trojans, worms, and other supported malware types. When attached to an appropriate firewall policy, the profile can scan traffic according to its configured inspection mode and actions. Web Filter controls access to websites and categories, Traffic Shaping manages bandwidth, and DNS Filter controls DNS requests. Antivirus inspection is therefore the security function specifically intended to detect malicious files and malware within supported traffic flows.
Question 89
Which FortiGate feature can block access to websites based on categories such as social networking, gambling, or malicious websites?
- Application Control
- Web Filter
- IPS
- Antivirus
Correct Answer: 2
Explanation
Web Filter can control access to websites according to URL categories and other configured filtering criteria. FortiGate can use FortiGuard web-rating information to classify websites and allow, block, warn, or otherwise handle requests according to the configured profile. Application Control identifies applications, IPS detects network attacks, and Antivirus focuses on malicious content. Therefore, Web Filter is the appropriate security profile when an administrator needs to restrict access based on website categories such as gambling, social networking, or malicious content.
Question 90
Which FortiGate security profile is primarily responsible for detecting network attacks by comparing traffic against known attack signatures?
- IPS
- Web Filter
- DNS Filter
- Traffic Shaping
Correct Answer: 1
Explanation
The Intrusion Prevention System, or IPS, examines network traffic and compares activity against known attack signatures and configured detection rules. It can detect and take action against various network-based threats, depending on the enabled signatures and policy configuration. Web Filter controls web access, DNS Filter evaluates DNS requests, and Traffic Shaping controls bandwidth usage. IPS is therefore the security profile specifically designed to detect network attacks based on traffic patterns and known signatures. Proper IPS configuration can help protect services and users from network-based threats.
Question 91
Which IPsec VPN component negotiates the initial secure communication parameters between two VPN peers?
- Phase 1
- Phase 2
- Firewall policy
- Static route
Correct Answer: 1
Explanation
IPsec Phase 1 establishes the initial secure communication relationship between two VPN peers. During this stage, the peers negotiate parameters such as authentication, encryption, and key-exchange settings to establish a secure IKE session. Phase 2 is used to negotiate the IPsec security associations that protect actual data traffic. Firewall policies control whether traffic is allowed, while static routes determine how traffic reaches destinations. Therefore, Phase 1 is responsible for establishing the initial secure relationship between the VPN peers.
Question 92
Which IPsec VPN setting defines the networks or IP ranges that can be carried through a Phase 2 tunnel?
- Encryption algorithm
- Phase 2 selectors
- Authentication method
- IKE version
Correct Answer: 2
Explanation
Phase 2 selectors define the source and destination IP ranges that are protected by an IPsec Phase 2 security association. The selectors must correspond appropriately between the VPN peers so that the intended traffic can be negotiated and encrypted through the tunnel. Encryption algorithms determine how data is protected, authentication methods verify peer identity, and IKE version determines the negotiation framework. Therefore, Phase 2 selectors are the configuration elements that specify which networks or IP ranges should be carried through the IPsec tunnel.
Question 93
Which FortiGate command can be used to display information about IPsec VPN tunnels and their status?
- diagnose vpn tunnel list
- get system status
- diagnose sys session list
- get router info routing-table all
Correct Answer: 1
Explanation
The diagnose vpn tunnel list command provides information about IPsec VPN tunnels and can help administrators examine tunnel status and related details. It is useful during VPN troubleshooting when an administrator needs to determine whether a configured tunnel is established and inspect information associated with the tunnel. get system status provides general system information, diagnose sys session list displays sessions, and get router info routing-table all displays routing information. Therefore, diagnose vpn tunnel list is the appropriate command for examining IPsec tunnel information.
Question 94
Which FortiGate log category is most useful for investigating whether a firewall policy allowed or denied a specific connection?
- Event logs
- Traffic logs
- System logs
- VPN logs
Correct Answer: 2
Explanation
Traffic logs provide detailed information about network sessions processed by FortiGate firewall policies. Depending on the logging configuration, they can show source and destination information, interfaces, services, actions, policy identifiers, and other session details. This makes traffic logs particularly useful when determining whether a connection was accepted or denied and which firewall policy processed it. Event logs focus on system and security events, system logs contain device-related information, and VPN logs focus on VPN activity. Therefore, Traffic logs are the most relevant category for investigating firewall-policy decisions.
Question 95
Which FortiGate feature can forward logs to a remote logging server using the standard syslog mechanism?
- FortiAnalyzer
- Syslog
- FortiView
- Local disk
Correct Answer: 2
Explanation
Syslog allows FortiGate to forward supported log messages to a remote syslog server for centralized collection and analysis. This can be useful when an organization already operates a centralized logging platform or security monitoring infrastructure that accepts syslog messages. FortiAnalyzer is a Fortinet platform designed for centralized log management and analysis, FortiView provides local visibility into traffic and security information, and local disk stores logs on the FortiGate when configured. Therefore, Syslog is the appropriate mechanism for sending logs to a remote syslog server.
Question 96
Which HA setting can help ensure that an administrator-configured primary FortiGate remains the primary unit when conditions allow?
- Override
- Session TTL
- Firewall schedule
- Administrative distance
Correct Answer: 1
Explanation
The HA override setting can influence primary-unit selection by allowing a configured device with higher priority to become or remain the primary unit when the relevant HA conditions are met. This can be useful when administrators want predictable primary-unit selection within an HA cluster. Session TTL controls session lifetime, firewall schedules determine when policies operate, and administrative distance influences routing decisions. Therefore, Override is the HA setting associated with influencing primary-unit selection based on configured HA priorities and conditions.
Question 97
Which FortiGate HA mechanism is used to monitor the availability of interfaces and can trigger an HA response when a monitored interface fails?
- Interface monitoring
- Web filtering
- Application control
- Traffic shaping
Correct Answer: 1
Explanation
HA interface monitoring allows FortiGate to monitor selected interfaces for availability and detect failures that may affect connectivity. If a monitored interface fails, the HA cluster can use the configured monitoring behavior as part of its decision-making process and may trigger a failover depending on the overall HA configuration. Web Filtering, Application Control, and Traffic Shaping are security or traffic-management features unrelated to HA interface health monitoring. Therefore, Interface monitoring is the correct feature for monitoring critical interfaces in an HA cluster.
Question 98
Which FortiGate configuration is commonly used to restrict management access to HTTPS, SSH, or other administrative services on an interface?
- Firewall address
- Administrative access
- Security profile
- Service group
Correct Answer: 2
Explanation
Administrative access settings determine which management services are available through a FortiGate interface. Depending on the configuration, administrators can enable services such as HTTPS, SSH, PING, or other supported management options. Restricting unnecessary management services helps reduce the device’s management exposure. Firewall addresses define network objects, security profiles inspect traffic, and service groups combine service definitions for policy use. Therefore, Administrative access is the correct configuration for controlling which management services can be reached through a FortiGate interface.
Question 99
Which FortiGate feature can automatically obtain an IP address and related network settings from an upstream DHCP server on an interface?
- DHCP server
- DHCP client
- DNS Filter
- Static route
Correct Answer: 2
Explanation
A DHCP client allows a FortiGate interface to obtain an IP address and other network parameters from an upstream DHCP server. This is commonly used when the connected network dynamically assigns addressing information rather than requiring a manually configured static address. A DHCP server performs the opposite role by assigning addresses to downstream clients. DNS Filter controls DNS requests, while static routes define forwarding paths. Therefore, DHCP client is the correct configuration when FortiGate needs to receive its interface addressing information dynamically from another DHCP server.
Question 100
Which FortiGate feature can create a secure tunnel between two networks across an untrusted public network?
- SSL certificate
- IPsec VPN
- Service group
- Web Filter
Correct Answer: 2
Explanation
An IPsec VPN creates an encrypted tunnel between network endpoints across an untrusted network such as the public internet. FortiGate uses IPsec negotiation and security associations to authenticate peers and protect traffic with configured cryptographic parameters. This allows private networks to communicate securely without requiring a dedicated private connection between locations. SSL certificates can support authentication and inspection functions, service groups organize services, and Web Filter controls web access. Therefore, IPsec VPN is the appropriate FortiGate feature for securely connecting networks across a public or untrusted network.