{"id":14881,"date":"2026-09-17T07:40:25","date_gmt":"2026-09-17T07:40:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14881"},"modified":"2026-09-17T07:40:25","modified_gmt":"2026-09-17T07:40:25","slug":"fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-ad-7-6-exam-dumps\"><b>Fortinet NSE4_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which FortiGate feature is used to define a collection of interfaces that can be referenced together in firewall policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface zone allows multiple FortiGate interfaces to be grouped logically and referenced together in firewall policies. This can simplify policy configuration when several interfaces require the same security treatment. Instead of creating separate policies for every individual interface, an administrator can use the zone as a policy interface. Address groups combine address objects, service groups combine network services, and user groups organize authenticated users. Therefore, Interface zone is the appropriate feature when multiple interfaces need to be managed together for policy purposes.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>Which FortiGate feature allows administrators to assign IP addresses automatically to devices connecting to a network interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The DHCP server feature allows FortiGate to automatically assign IP addresses and related network parameters to DHCP clients. A DHCP configuration can provide information such as the IP address, subnet mask, default gateway, and DNS server settings. This reduces the need to configure every client manually. A static route controls packet forwarding, an IP pool provides addresses for NAT operations, and a Virtual IP is generally used for destination NAT. Therefore, DHCP server is the correct feature when FortiGate needs to automatically provide network configuration to connected clients.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which FortiGate inspection profile is designed to detect malicious files and malware in supported traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Antivirus security profile is designed to inspect supported traffic for malicious files, malware, and other threats identified by FortiGate&#8217;s antivirus engine and related security intelligence. It can be applied to firewall policies so that matching traffic receives malware inspection according to the configured profile. Web Filter controls website access, Application Control identifies and controls applications, and Traffic Shaping manages bandwidth usage. Antivirus inspection is therefore the appropriate security feature when the primary objective is detecting and handling malicious content transmitted through supported network protocols.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>Which FortiGate routing protocol is commonly used to exchange route information between neighboring autonomous systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP, or Border Gateway Protocol, is designed to exchange routing information between autonomous systems and is widely used for inter-domain routing. It allows routers to exchange network reachability information and apply routing policies to control path selection. OSPF is primarily an interior gateway protocol used within an autonomous system, while DHCP provides network configuration and DNS resolves names to addresses. Therefore, BGP is the correct routing protocol when route information needs to be exchanged between autonomous systems.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>Which FortiGate configuration is used to specify the encryption and authentication parameters for the initial IKE negotiation of an IPsec VPN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 1<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec Phase 1 establishes the initial secure relationship between VPN peers using IKE. It defines important parameters such as authentication method, encryption algorithms, hashing, Diffie-Hellman groups, and negotiation settings. Phase 2 defines the security associations used to protect the actual data traffic and includes traffic selectors and additional IPsec parameters. A firewall policy controls permitted traffic, while an IP pool provides addresses for NAT. Therefore, Phase 1 is the correct configuration for the initial IKE negotiation parameters.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which FortiGate setting determines how long an established session can remain active before timing out when no relevant traffic is received?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session TTL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard license<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session TTL, or Time To Live, determines how long a session can remain in the FortiGate session table before it expires according to the applicable timeout behavior. Proper session timeout values help manage firewall resources and ensure stale connections are eventually removed. Administrative access controls management protocols, FortiGuard provides security services and intelligence, and DNS Filter controls DNS-related access. Session TTL is therefore the setting associated with controlling the lifetime of established sessions and is useful when troubleshooting connections that expire unexpectedly.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a graphical view of traffic, applications, users, and security activity on the device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides graphical visibility into activity occurring on the FortiGate device. Depending on the available data and configuration, administrators can use FortiView to examine traffic, applications, users, destinations, sources, and security-related information. It can be particularly useful for quickly identifying traffic patterns or investigating unusual activity. FortiAnalyzer provides centralized logging and analysis, FortiToken supports authentication, and FortiGuard provides security intelligence and services. Therefore, FortiView is the appropriate feature for graphical, real-time-oriented visibility into FortiGate activity.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which FortiGate configuration can translate a public destination port to a different private destination port on an internal server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP with port forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaper<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Virtual IP with port forwarding can perform destination NAT while translating a public destination port to a different private port on an internal server. This is useful when an external service must be published through a specific public port while the internal application listens on another port. Static routes determine forwarding paths, address groups organize IP objects, and traffic shapers control bandwidth. A VIP with port forwarding therefore provides the appropriate mechanism for mapping a public address and port to a private server address and port.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>Which FortiGate authentication method uses a centralized server that commonly provides authentication, authorization, and accounting services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS is a centralized authentication protocol that can provide authentication, authorization, and accounting capabilities through an external server. FortiGate can communicate with a RADIUS server to validate user credentials and receive the authentication result. LDAP is commonly used for directory-based authentication, local authentication uses accounts configured on FortiGate, and certificate inspection examines SSL\/TLS certificate information. RADIUS is particularly useful when an organization already maintains centralized authentication infrastructure. Therefore, RADIUS is the correct choice for this scenario.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>Which FortiGate feature can block or allow websites based on their categorized reputation or content classification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can control website access using URL categories, ratings, and configured filtering actions. FortiGate can use available FortiGuard web-rating information to classify websites and apply actions such as allow, block, monitor, or warning according to the configured policy. Antivirus is designed primarily for malware detection, IPS focuses on network attack signatures, and DHCP provides IP configuration to clients. Therefore, Web Filter is the correct security feature when website access needs to be controlled according to reputation or content categories.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which FortiGate feature can identify traffic according to predefined application signatures and allow administrators to block selected applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications using FortiGate application signatures and related inspection mechanisms. Administrators can create Application Control profiles that monitor, allow, or block selected applications or application categories and then apply those profiles to firewall policies. Static routes determine how packets are forwarded, DHCP provides client configuration, and IP pools supply addresses for NAT operations. Application Control is therefore the appropriate feature when administrators need application-aware traffic management rather than relying only on IP addresses or port numbers.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>Which FortiGate security profile is specifically designed to detect suspicious network activity associated with known attack signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System, or IPS, examines traffic for patterns associated with known attacks and suspicious network behavior. FortiGate uses IPS signatures and configured actions to detect and respond to matching traffic. Depending on the profile configuration, an administrator can choose appropriate actions for detected threats. Web Filter focuses on website access, DNS Filter controls DNS requests, and Traffic Shaping manages bandwidth. Therefore, IPS is the security profile specifically intended for detecting network attacks through intrusion-prevention signatures.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which FortiGate command displays all active routes in the routing table?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose debug flow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get router info routing-table all<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose sys session list<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">get router info routing-table all<\/span><span style=\"font-weight: 400;\"> command displays the routes currently available in the FortiGate routing table. It can help administrators identify connected, static, and dynamically learned routes and determine which paths are available for packet forwarding. <\/span><span style=\"font-weight: 400;\">get system status<\/span><span style=\"font-weight: 400;\"> provides general device information, <\/span><span style=\"font-weight: 400;\">diagnose debug flow<\/span><span style=\"font-weight: 400;\"> is used to trace packet processing, and <\/span><span style=\"font-weight: 400;\">diagnose sys session list<\/span><span style=\"font-weight: 400;\"> displays active sessions. Therefore, <\/span><span style=\"font-weight: 400;\">get router info routing-table all<\/span><span style=\"font-weight: 400;\"> is the appropriate command when an administrator needs to inspect the complete routing table.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which FortiGate feature can restrict administrative access to selected source networks for an individual administrator account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted hosts allow administrators to specify the source IP addresses or networks from which a particular administrator account can access FortiGate management services. This provides an additional restriction beyond normal authentication and can reduce exposure to unauthorized management attempts. Service groups combine service objects, Performance SLA measures network-path performance, and Virtual IP configurations provide destination NAT functionality. Therefore, Trusted hosts is the appropriate feature when management access needs to be limited to selected source networks for a specific administrator account.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>Which FortiGate feature allows a network administrator to define a preferred forwarding path and an alternative path for redundancy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routes with different priorities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User groups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate can use static routes with different administrative distances or priorities to provide primary and backup routing paths. The preferred route can be selected while an alternative route remains available if the primary path becomes unavailable or otherwise fails the relevant routing conditions. Web Filter and Application Control are security features, while user groups organize authenticated identities. Proper route configuration is important for maintaining connectivity during path failures. Therefore, Static routes with different priorities are appropriate for implementing basic routing redundancy.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>Which FortiGate feature can provide users with a web-based authentication page before allowing network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Captive portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A captive portal presents users with a web-based authentication process before they receive normal network access through the configured interface or policy. It is commonly used for guest networks, public access environments, and networks where users must authenticate before browsing. Static routes control packet forwarding, service objects define protocols and ports, and IP pools provide addresses for NAT. A captive portal therefore provides the required interactive authentication step before access is granted to the protected network.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which FortiGate feature can group several physical or logical interfaces so they can be referenced as a single interface in policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface zone provides a logical grouping of multiple interfaces so that they can be referenced together in firewall policies. This can simplify configurations where several interfaces require the same policy treatment. Administrators can create the zone and then use it as an interface reference instead of repeatedly configuring individual interfaces. An IP pool is used for NAT addresses, an address object represents a network or host, and FortiGuard provides security services. Therefore, Interface zone is the correct feature for logically grouping interfaces for policy use.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>Which FortiGate feature can use DNS-based filtering to block domains associated with unwanted or malicious content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Filter controls DNS requests and can use configured filtering categories and available security intelligence to allow or block domain resolution. This provides a way to prevent users from reaching certain domains before a connection to the destination is established. Antivirus focuses on malicious files and content, IPS detects network attacks, and Application Control identifies applications. DNS filtering can therefore be useful for blocking domains associated with malicious, inappropriate, or otherwise restricted content. Hence, DNS Filter is the correct feature for this requirement.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which FortiGate configuration is used to define a group of authenticated users that can be referenced in an identity-based firewall policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A user group combines authenticated users or directory groups so that they can be referenced together in FortiGate authentication and identity-based firewall policies. This allows administrators to apply common access rules to a group rather than configuring each user individually. Service groups combine network services, address groups combine IP address objects, and interface zones group interfaces. User groups are therefore the appropriate configuration when firewall access needs to be based on the identity of multiple users or directory groups.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>Which FortiGate security profile can identify and control DNS requests according to configured categories and filtering policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Filter examines DNS requests and applies configured filtering rules to domain queries. It can use categories and available security intelligence to determine whether a requested domain should be allowed, blocked, or handled according to another configured action. Web Filter operates primarily on web access and URL categories, Antivirus detects malicious files and content, and IPS detects network attacks. DNS Filter is therefore the correct security profile when administrators need to control domain resolution according to DNS-based filtering policies.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 221 Which FortiGate feature is used to define a collection of interfaces that can be referenced together in firewall policies? Address group Service group Interface zone User group Correct Answer: 3 Explanation An interface zone allows multiple FortiGate interfaces to be grouped logically [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14881"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14881"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14881\/revisions"}],"predecessor-version":[{"id":14902,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14881\/revisions\/14902"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14881"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14881"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}