{"id":14879,"date":"2026-09-17T07:40:51","date_gmt":"2026-09-17T07:40:51","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14879"},"modified":"2026-09-17T07:40:51","modified_gmt":"2026-09-17T07:40:51","slug":"fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-ad-7-6-exam-dumps\"><b>Fortinet NSE4_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which FortiGate feature can be used to define a logical interface that remains available independently of a physical interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tag<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A loopback interface is a logical interface that does not depend directly on a physical interface being operational. It can have its own IP address and can be used for routing, management, or other network functions that benefit from a stable logical endpoint. An IP pool provides addresses for NAT, a service group combines service objects, and a VLAN tag identifies traffic belonging to a VLAN. Because a loopback interface remains logically available regardless of a particular physical port&#8217;s status, it is the appropriate choice for this requirement.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>Which FortiGate feature allows administrators to define different actions for traffic depending on the application that generated it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control allows FortiGate to identify applications and apply configured actions based on their detected application signatures. Administrators can create profiles that allow, monitor, or block selected applications or application categories and then apply those profiles through firewall policies. This provides application-aware control even when applications use different ports or protocols. DNS Filter focuses on DNS requests, DHCP assigns network settings, and static routes control packet forwarding. Therefore, Application Control is the appropriate feature when traffic treatment must depend on the application generating the traffic.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>Which FortiGate component is responsible for storing information about destinations and next hops used during packet forwarding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The routing table contains the routes FortiGate uses to determine how packets should be forwarded toward their destinations. Entries can come from connected networks, static routes, or dynamic routing protocols, depending on the configuration. FortiGate evaluates available routes and selects the appropriate path according to its routing process. Firewall policies determine whether traffic is allowed, security profiles inspect permitted traffic, and user groups organize authenticated identities. Therefore, the Routing table is the correct component for storing and evaluating destination and next-hop routing information.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>Which FortiGate feature can provide additional protection by requiring users to complete an authentication step before accessing a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Captive portal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A captive portal can require users to authenticate before they are granted access through a configured network interface or policy. It is commonly used for guest networks, wireless access, and environments where administrators want users to complete a web-based authentication process before receiving network access. Static routing controls forwarding paths, traffic shaping manages bandwidth, and address groups organize network address objects. A captive portal adds an identity-based access step before normal network access is provided. Therefore, Captive portal is the correct FortiGate feature for this requirement.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>Which FortiGate setting identifies the network from which traffic originates in a firewall policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Destination<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Source field in a FortiGate firewall policy identifies the source interface and source addresses or address groups from which traffic originates. FortiGate evaluates this information together with destination, service, schedule, and other policy criteria when determining whether traffic matches the policy. Destination identifies where traffic is going, Service identifies supported protocols or ports, and Schedule determines when the policy is active. Therefore, Source is the correct firewall-policy field for identifying the network or address from which traffic originates.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>Which FortiGate feature can distribute outbound traffic across a pool of public IP addresses for source NAT?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IP pool provides one or more public IP addresses that FortiGate can use when performing source NAT for outbound connections. Instead of translating all internal clients to only the outgoing interface address, FortiGate can use addresses from the configured pool according to the NAT configuration. A Virtual IP is generally used for destination NAT, DNS Filter controls DNS requests, and a loopback interface is a logical interface. Therefore, IP pool is the appropriate feature when multiple public addresses are required for source NAT.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which FortiGate feature allows an administrator to monitor system resources such as CPU and memory usage from the graphical interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System dashboard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec Phase 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The system dashboard provides an overview of FortiGate health and resource utilization through the graphical interface. Depending on the configured dashboard widgets and FortiOS version, administrators can view CPU usage, memory utilization, sessions, interface activity, and other system information. Service groups organize services, IPsec Phase 2 establishes security associations for VPN data traffic, and address groups combine address objects. Therefore, the System dashboard is the appropriate feature for monitoring general CPU, memory, and device-resource information through the GUI.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>Which FortiGate feature is used to create an encrypted IPsec tunnel after the initial peer relationship has been established?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec Phase 2 establishes the security associations used to protect actual data traffic after the initial IKE relationship has been established during Phase 1. Phase 2 negotiates parameters such as encryption, authentication, and traffic selectors for the protected networks. A firewall policy determines whether traffic is permitted through FortiGate, while a static route determines the forwarding path. Phase 1 establishes the initial secure peer relationship, whereas Phase 2 creates the IPsec security associations used for data protection. Therefore, Phase 2 is the correct answer.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>Which FortiGate feature can identify network attacks by matching traffic against configured intrusion-prevention signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System, or IPS, uses signatures and related detection mechanisms to identify known network attacks and suspicious traffic patterns. An IPS profile can be applied through a firewall policy so FortiGate can inspect matching traffic and take the configured action. Web Filter controls website access, DNS Filter controls DNS requests, and Antivirus focuses on malware and malicious content. IPS is specifically designed for detecting network-based attacks through intrusion-prevention signatures. Therefore, IPS is the correct security profile for this requirement.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>Which FortiGate feature can store multiple IP address objects under one name for easier firewall-policy configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An address group allows administrators to combine multiple IP address objects into one reusable object. This is useful when several hosts or networks need identical firewall-policy treatment. Instead of selecting every address separately in each policy, an administrator can reference the address group as a single source or destination object. Service groups contain service definitions, user groups organize authenticated users, and interface zones group interfaces. Therefore, Address group is the appropriate feature for storing multiple IP address objects under one reusable name.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which FortiGate authentication method can use an external server to verify a user&#8217;s credentials through a centralized authentication protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FSSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS provides a centralized authentication mechanism in which FortiGate sends authentication requests to an external RADIUS server. The external server validates the user&#8217;s credentials and returns the authentication result. This allows organizations to integrate FortiGate with existing authentication infrastructure and avoid maintaining every user credential locally. Local authentication uses accounts stored on FortiGate, FSSO provides identity information through supported single sign-on mechanisms, and certificate inspection evaluates certificate information. Therefore, RADIUS is the appropriate authentication method for centralized external credential verification.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>Which FortiGate feature can identify users based on authentication information collected from a supported directory environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FSSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaper<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet Single Sign-On, or FSSO, provides FortiGate with user identity information obtained through supported directory and authentication environments. This information can then be used in identity-based firewall policies to apply access controls according to authenticated users or groups. Static routes control packet forwarding, IP pools provide addresses for source NAT, and traffic shapers manage bandwidth. FSSO is particularly useful when organizations want user-aware policy enforcement without requiring repeated direct authentication to FortiGate. Therefore, FSSO is the correct feature for this scenario.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>Which FortiGate feature allows administrators to configure a recurring period during which a firewall policy is permitted to operate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Schedule determines when a firewall policy is active. Administrators can configure recurring schedules for specific days and times and then assign them to firewall policies. This allows access to services or destinations to be limited to defined operational periods. Address objects identify networks or hosts, service groups combine protocol and port definitions, and user groups organize authenticated identities. For example, an organization can configure a policy to permit a particular service only during business hours. Therefore, Schedule is the correct configuration for controlling when a policy operates.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>Which FortiGate feature can collect logs from multiple FortiGate devices and provide centralized analysis and reporting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is designed to collect and analyze logs from Fortinet devices and provide centralized reporting and investigation capabilities. In environments containing multiple FortiGate devices, it can provide a consolidated view of traffic, security events, and other logged information. FortiView provides local graphical visibility on FortiGate, FortiGuard provides security intelligence and related services, and FortiToken supports authentication. Centralized log management is useful for monitoring and investigating activity across multiple devices. Therefore, FortiAnalyzer is the correct solution for centralized FortiGate log analysis.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which FortiGate feature can inspect a web connection&#8217;s certificate information without performing full content decryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deep inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate inspection examines information contained in SSL\/TLS certificates without fully decrypting and inspecting the underlying encrypted content. It can allow FortiGate to evaluate certificate-related information and make supported security decisions while avoiding the full proxying and certificate-generation process associated with deep inspection. Deep inspection decrypts supported encrypted traffic for content inspection, Application Control identifies applications, and Traffic Shaping controls bandwidth. Therefore, Certificate inspection is the correct method when certificate information needs to be examined without decrypting the complete session.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>Which FortiGate feature can control access to websites according to URL categories and configured filtering actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter controls access to websites according to configured URL categories, ratings, and other supported filtering criteria. FortiGate can use FortiGuard web-rating information to classify websites and then apply actions such as allow, block, monitor, or warning. Antivirus focuses on malicious content, IPS detects network attacks, and DHCP provides IP configuration to clients. Web filtering can therefore help organizations enforce acceptable-use policies and reduce access to unwanted or potentially harmful websites. Therefore, Web Filter is the correct security profile for category-based website control.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which FortiGate feature can evaluate latency, jitter, and packet loss to determine whether an SD-WAN path meets configured requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Performance SLA measures the quality of SD-WAN paths using criteria such as latency, jitter, and packet loss. Administrators can configure thresholds that define acceptable path performance, and FortiGate can use the resulting status when applying SD-WAN rules. This allows traffic to be directed toward paths that satisfy the configured service requirements. Static routes provide forwarding information, firewall policies control access, and service groups organize network services. Therefore, Performance SLA is the correct feature for evaluating SD-WAN path performance against defined criteria.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>Which FortiGate HA feature can synchronize supported session information so that traffic can continue more smoothly after a failover?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Override<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session pickup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device priority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session pickup allows supported session information to be synchronized between HA cluster members so that sessions can continue more smoothly after a failover. Without appropriate session synchronization, existing connections may be interrupted when the primary unit changes. The exact behavior depends on the configured HA options and the types of sessions being synchronized. Override and device priority influence primary-unit selection, while interface monitoring observes selected interfaces for failures. Therefore, Session pickup is the appropriate HA feature for preserving supported session state during failover.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which FortiGate feature can restrict management access to an administrator account based on specific source IP addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted hosts can restrict an administrator account so that management access is accepted only from specified source IP addresses or networks. This provides an additional security layer beyond username and password authentication and can reduce exposure to unauthorized management attempts from untrusted locations. Administrative access controls which management protocols are enabled on an interface, address groups organize IP address objects, and service objects define network services. Therefore, Trusted hosts is the correct feature for restricting an administrator account according to source IP addresses.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>Which FortiGate feature can automatically select an appropriate WAN path according to configured traffic rules and link-performance conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP client<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SD-WAN allows FortiGate to manage multiple WAN paths and select traffic paths according to configured SD-WAN rules and performance conditions. Administrators can define SD-WAN members, performance SLAs, and rules that determine how specific traffic should use available connections. This enables FortiGate to respond to path-quality changes and apply different forwarding decisions for different types of traffic. DHCP clients obtain network configuration, Web Filter controls website access, and Antivirus scans supported content. Therefore, SD-WAN is the correct feature for dynamic WAN-path selection.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 181 Which FortiGate feature can be used to define a logical interface that remains available independently of a physical interface? Loopback interface IP pool Service group VLAN tag Correct Answer: 1 Explanation A loopback interface is a logical interface that does not depend [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14879"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14879"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14879\/revisions"}],"predecessor-version":[{"id":14905,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14879\/revisions\/14905"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}