{"id":14875,"date":"2026-09-17T07:41:33","date_gmt":"2026-09-17T07:41:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14875"},"modified":"2026-09-17T07:41:33","modified_gmt":"2026-09-17T07:41:33","slug":"fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-ad-7-6-exam-dumps\"><b>Fortinet NSE4_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which FortiGate feature can identify and control applications by using application signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies network applications using application signatures and related detection mechanisms. Administrators can create an Application Control profile and apply actions to selected applications or categories through firewall policies. This allows FortiGate to control applications even when they do not consistently use a single network port. DNS Filter focuses on DNS requests, IPS detects network attacks, and DHCP provides IP configuration. Therefore, Application Control is the appropriate FortiGate feature when an administrator needs to identify and control network applications based on their signatures.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>Which FortiGate feature allows administrators to save a copy of the current configuration for later restoration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration backup allows administrators to save the FortiGate configuration so it can be restored later if necessary. Backups are particularly useful before firmware upgrades, major configuration changes, or troubleshooting activities because they provide a recovery point. FortiView displays traffic and security information, Traffic Shaping manages bandwidth, and Web Filter controls web access. A properly maintained configuration backup can help reduce recovery time after an unexpected configuration problem. Therefore, Configuration backup is the correct feature for preserving the current FortiGate configuration.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>Which FortiGate routing value is used to determine the preference of routes learned from different routing sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative distance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session TTL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority queue<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative distance is used to determine the preference of routes learned from different routing sources. When multiple routes to the same destination are available through different routing mechanisms, FortiGate uses routing attributes including administrative distance as part of the route-selection process. A route with a more preferred administrative distance can be selected over another route to the same destination, subject to the routing process. Session TTL controls session lifetime, priority queues relate to traffic handling, and firewall action controls policy decisions. Therefore, Administrative distance is the correct answer.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>Which FortiGate object is used to represent a collection of IP addresses that can be referenced in a firewall policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An address group combines multiple address objects into one logical object that can be referenced by firewall policies and other supported configurations. This makes policy management easier because administrators can manage several related networks or hosts through one reusable object. Service groups contain service definitions, user groups organize authenticated users, and interface zones group interfaces. For example, several internal server addresses can be combined into an address group and used as the destination in a policy. Therefore, Address group is the correct answer.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>Which FortiGate security feature can use FortiGuard services to classify websites according to content categories?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can use FortiGuard web-rating services to classify websites into categories and apply configured actions to web requests. Administrators can allow, block, monitor, or otherwise handle websites based on their assigned categories and filtering configuration. Application Control focuses on applications, IPS detects network attacks, and Antivirus scans supported traffic for malicious content. FortiGuard categorization can help organizations enforce acceptable-use policies and reduce exposure to unwanted or harmful websites. Therefore, Web Filter is the appropriate feature for category-based website classification and control.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which FortiGate authentication method can verify users against an external RADIUS server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FSSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS allows FortiGate to authenticate users against an external RADIUS server. This can centralize authentication and allow FortiGate to use an existing authentication infrastructure rather than maintaining all user credentials locally. The RADIUS server receives authentication requests and returns the appropriate response based on its configuration. Local authentication uses accounts stored directly on FortiGate, FSSO provides user identity information through supported single sign-on mechanisms, and certificate inspection handles certificate-related traffic inspection. Therefore, RADIUS is the correct authentication method for an external RADIUS server.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>Which FortiGate troubleshooting tool provides detailed information about how packets are processed by firewall policies and routing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Debug flow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System dashboard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Debug flow provides detailed information about packet processing inside FortiGate. It can help administrators determine how traffic is routed, which firewall policy is matched, and why a packet may be accepted or denied. This makes it especially useful when normal logs do not provide enough detail to diagnose a connectivity problem. FortiView provides visual traffic information, traffic logs record session information, and the system dashboard displays general device status. Therefore, Debug flow is the appropriate troubleshooting tool for examining detailed packet-processing decisions.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which FortiGate feature allows administrators to define a destination NAT mapping from a public IP address to an internal server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Virtual IP, commonly called a VIP, defines a destination NAT mapping that can translate an external address to an internal address. VIPs are frequently used when internal servers must be reachable through selected public IP addresses or ports. They can also be configured for port forwarding when only specific services should be exposed. IP pools are primarily associated with source NAT, service groups combine service objects, and loopback interfaces provide logical interfaces. Therefore, Virtual IP is the correct FortiGate feature for destination NAT to an internal server.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>Which FortiGate feature can provide centralized log storage, analysis, and reporting for multiple Fortinet devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized log collection, analysis, reporting, and related management capabilities for Fortinet devices. Organizations can use it to consolidate logs from multiple FortiGate devices and analyze security or traffic events from a central location. FortiView provides visibility directly on FortiGate, FortiToken supports multi-factor authentication, and FortiGuard provides various security and intelligence services. Centralized log management can make investigations and reporting more efficient when many devices are deployed. Therefore, FortiAnalyzer is the correct solution for centralized Fortinet log storage and analysis.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which FortiGate HA mode uses one primary unit to actively process traffic while another unit is available to take over after a failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-active<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load-balanced mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-passive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standalone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In an active-passive HA configuration, one FortiGate unit operates as the primary device and processes network traffic, while another unit remains available to take over when the primary unit fails. This provides redundancy and helps maintain network availability during hardware or system problems. Active-active HA can involve multiple units processing traffic depending on the configuration and platform capabilities. Load-balanced mode is not the standard FortiGate HA mode name, while standalone means the device is not operating as part of an HA cluster. Therefore, Active-passive is correct.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which FortiGate feature allows administrators to define a recurring time period during which a firewall policy is active?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy schedule determines when the policy is active. Administrators can configure schedules such as always-active or recurring time periods and then assign them to firewall policies. This allows organizations to restrict certain types of access to particular hours, days, or operational periods. Service groups combine protocol and port definitions, address groups combine address objects, and IP pools provide addresses for source NAT. Therefore, Schedule is the correct feature when a firewall policy needs to operate only during specified recurring periods.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>Which FortiGate feature can enforce bandwidth limits on selected traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Shaping controls the amount of bandwidth available to selected traffic. Administrators can use traffic-shaping policies or profiles to manage bandwidth consumption and help ensure that important applications or users receive appropriate network resources. This can be useful when high-bandwidth applications might otherwise consume excessive capacity. Web Filter controls web access, Antivirus scans for malicious content, and DNS Filter controls DNS requests. Therefore, Traffic Shaping is the appropriate FortiGate feature for controlling or limiting bandwidth consumption for selected traffic.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which FortiGate VPN component establishes the security associations used to protect actual user data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IKE negotiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec Phase 2 establishes the security associations used to protect the actual data traffic passing through the VPN tunnel. During Phase 2 negotiation, the peers agree on parameters such as encryption, authentication, and traffic selectors for the IPsec security association. Phase 1 establishes the initial secure IKE relationship between the peers. Firewall policies determine whether traffic is permitted through FortiGate, while IKE negotiation encompasses the broader key-management process. Therefore, Phase 2 is the correct component for establishing the security associations that protect user data.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which FortiGate setting can determine the preference between multiple routes that have the same destination and routing protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session timeout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route priority is used as part of FortiGate&#8217;s route-selection process when comparing routes that meet the relevant destination criteria. Administrators can configure route attributes so that one available path is preferred over another when multiple routes exist. Session timeout controls the duration of sessions, web categories are used by web filtering, and security action determines how inspected traffic is handled. Understanding route preference is important when troubleshooting situations where FortiGate appears to select a path different from the one expected. Therefore, Route priority is the correct answer.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>Which FortiGate feature can authenticate administrators or users using a digital certificate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate-based authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate-based authentication uses digital certificates to verify the identity of a user or system. Certificates can provide a stronger authentication mechanism by relying on cryptographic credentials rather than only passwords. The certificate must be issued and trusted according to the configured certificate infrastructure and authentication requirements. Traffic Shaping controls bandwidth, DNS Filtering controls DNS requests, and static routing determines network paths. Therefore, Certificate-based authentication is the appropriate choice when digital certificates are used as the authentication mechanism.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>Which FortiGate feature can detect malicious or suspicious network traffic using intrusion prevention signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System, or IPS, uses signatures and other detection mechanisms to identify known network attacks and suspicious traffic patterns. An IPS profile can be applied through a firewall policy so that matching traffic is inspected and handled according to configured actions. Web Filter controls website access, Antivirus focuses on malicious files and supported content, and DHCP assigns network configuration. IPS is therefore the appropriate FortiGate security feature when the goal is to detect network-based attacks using intrusion prevention signatures and related inspection mechanisms.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which FortiGate command is commonly used to display the routing table and help verify the routes currently known to the device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get router info routing-table all<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose vpn tunnel list<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose debug flow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">get router info routing-table all<\/span><span style=\"font-weight: 400;\"> command displays the FortiGate routing table and provides information about routes known to the device. It is useful for troubleshooting connectivity problems and verifying whether a destination has an appropriate route. Administrators can use the output to inspect route sources, destination networks, gateways, interfaces, and related routing information. <\/span><span style=\"font-weight: 400;\">get system status<\/span><span style=\"font-weight: 400;\"> displays general system information, <\/span><span style=\"font-weight: 400;\">diagnose vpn tunnel list<\/span><span style=\"font-weight: 400;\"> focuses on VPN tunnels, and debug flow examines packet processing. Therefore, the routing-table command is correct.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>Which FortiGate feature can provide multi-factor authentication by requiring an additional authentication factor beyond a password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiToken can be used as an additional authentication factor in supported FortiGate authentication configurations. Multi-factor authentication improves account security by requiring users to provide another verification factor in addition to their primary credentials. This can help reduce the impact of compromised passwords. Web Filter controls web access, FortiView provides visibility into traffic and security activity, and Traffic Shaping manages bandwidth. Therefore, FortiToken is the appropriate choice when an administrator needs an additional authentication factor for supported FortiGate access.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which FortiGate inspection method can decrypt and inspect HTTPS traffic by using a FortiGate-generated certificate for the destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flow-based inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deep inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Deep inspection can decrypt supported HTTPS traffic so FortiGate can inspect the underlying content using security profiles. During this process, FortiGate can generate certificates for inspected destinations, and client devices must trust the appropriate certificate authority to avoid certificate warnings. Certificate inspection examines certificate information without fully decrypting the protected content, while flow-based inspection refers to a broader inspection approach and DNS inspection focuses on DNS traffic. Therefore, Deep inspection is the appropriate method when encrypted HTTPS content must be decrypted and inspected.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>Which FortiGate feature provides a graphical view of traffic activity, top applications, users, destinations, and security information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CLI console<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides graphical visibility into traffic and security activity on FortiGate. Depending on the available views and configuration, administrators can examine information such as top applications, users, destinations, sources, bandwidth usage, and security events. This makes FortiView useful for quickly identifying traffic patterns and investigating unusual activity through an interactive interface. DHCP monitoring focuses on address assignments, the CLI console provides command-line access, and static routes control packet forwarding. Therefore, FortiView is the correct feature for graphical traffic and security visibility.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 101 Which FortiGate feature can identify and control applications by using application signatures? Application Control DNS Filter IPS DHCP Correct Answer: 1 Explanation Application Control identifies network applications using application signatures and related detection mechanisms. Administrators can create an Application Control profile and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14875"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14875"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14875\/revisions"}],"predecessor-version":[{"id":14910,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14875\/revisions\/14910"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}