{"id":14886,"date":"2026-09-17T07:39:15","date_gmt":"2026-09-17T07:39:15","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14886"},"modified":"2026-09-17T07:39:15","modified_gmt":"2026-09-17T07:39:15","slug":"fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-ad-7-6-exam-dumps\"><b>Fortinet NSE4_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>Which FortiGate feature can identify the network path selected for a destination by examining the routing table?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The routing table contains the routes FortiGate uses when determining how traffic should be forwarded toward a destination. Administrators can examine routing-table entries to identify connected, static, and dynamically learned routes and determine which path is available for a particular destination. Web Filter controls website access, Application Control manages application-based traffic, and FortiAnalyzer provides centralized logging and analysis. Therefore, the Routing table is the appropriate FortiGate component for examining available paths and understanding how destination traffic is routed through the device.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>Which FortiGate feature can authenticate users through an external server using the RADIUS protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FSSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A RADIUS Server configuration allows FortiGate to communicate with an external RADIUS server for centralized user authentication. FortiGate sends authentication requests to the configured RADIUS server, which validates the credentials and returns the authentication result. LDAP Server uses the LDAP protocol, FSSO provides user identity information through supported single sign-on mechanisms, and FortiToken provides token-based authentication. RADIUS is widely used when organizations already have centralized authentication infrastructure. Therefore, RADIUS Server is the correct configuration for this requirement.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>Which FortiGate feature can control access to websites based on URL categories and configured filtering actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter controls website access according to URL categories, ratings, and configured filtering actions. FortiGate can use available web-rating information to classify websites and then apply actions such as allow, block, monitor, or warning. Antivirus focuses on malicious content, IPS detects network attacks, and Traffic Shaping controls bandwidth usage. Web Filter is therefore the appropriate security profile when administrators need to enforce browsing restrictions based on website categories or other supported URL classification information.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>Which FortiGate feature can distribute network traffic across multiple WAN connections according to configured SD-WAN rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SD-WAN allows FortiGate to manage multiple WAN connections and select forwarding paths according to configured SD-WAN rules and link-performance conditions. Administrators can define members, Performance SLAs, and traffic-selection rules to determine how different types of traffic use available WAN links. Static routes provide individual routing entries, Traffic Shaping controls bandwidth, and Performance SLA measures link quality. Therefore, SD-WAN is the correct feature when traffic needs to be distributed or directed across multiple WAN connections according to configured policies.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>Which FortiGate feature can combine multiple network address objects into a single reusable object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface Zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Address Group combines multiple individual address objects into a single reusable object. This makes firewall-policy configuration easier when several hosts, subnets, or other address definitions require identical treatment. Instead of selecting each address separately, an administrator can reference the group as a source or destination. Service Groups combine service objects, User Groups organize authenticated users, and Interface Zones group interfaces. Therefore, Address Group is the correct feature when multiple network address objects need to be referenced together in firewall policies.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>Which FortiGate feature can inspect encrypted traffic by decrypting supported SSL\/TLS sessions before applying security inspection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deep Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flow-based Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Deep Inspection can decrypt supported SSL\/TLS sessions so FortiGate can inspect the underlying content with security profiles such as Antivirus, Web Filter, and Application Control. This provides deeper visibility into encrypted traffic than certificate inspection, which evaluates certificate information without performing the same level of content decryption. Flow-based inspection analyzes traffic as it passes through the device, while static routing determines forwarding paths. Therefore, Deep Inspection is the appropriate inspection mode when encrypted traffic needs to be decrypted for content-level security inspection.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a web-based authentication page before a user is granted network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Captive Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A captive portal presents users with a web-based authentication page before normal network access is granted. It is commonly used in guest networks, public access environments, and networks where administrators require users to authenticate before accessing external resources. A static route controls packet forwarding, a service object defines protocols and ports, and an IP pool provides addresses for NAT operations. Therefore, Captive Portal is the correct feature when users must complete a web-based authentication process before receiving network access.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a stable logical IP endpoint for routing or management purposes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN Interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback Interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Loopback Interface is a logical interface that can provide a stable IP endpoint independently of the operational status of a particular physical interface. It can be useful for routing, management, and other network functions requiring a consistent logical address. A VLAN Interface is associated with a VLAN identifier, a Service Group combines service objects, and an IP Pool provides addresses for NAT. Therefore, Loopback Interface is the appropriate feature when a stable logical endpoint is needed for routing or management purposes.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>Which FortiGate feature can restrict administrator access to specified source IP addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted Hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted Hosts allow administrators to restrict a specific administrator account to management connections originating from approved IP addresses or networks. This adds another layer of protection because valid credentials cannot be used from unauthorized source locations. Administrative Access controls which management protocols are enabled on an interface, Service Groups combine network services, and Performance SLA evaluates SD-WAN path quality. Therefore, Trusted Hosts is the correct feature when management access needs to be limited according to specific source IP addresses.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>Which FortiGate feature can identify known malicious network traffic by using intrusion-prevention signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System, or IPS, uses signatures and related inspection mechanisms to identify known attacks and suspicious network activity. Administrators can configure IPS profiles with appropriate actions and apply them through firewall policies. Web Filter controls website access, Application Control identifies applications, and DHCP Server provides network configuration to clients. IPS is therefore the FortiGate security profile specifically designed for detecting and responding to network-based attacks. It is commonly used as part of a layered security configuration to protect internal and external network traffic.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which FortiGate feature can determine whether an SD-WAN member satisfies configured packet-loss and latency thresholds?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Performance SLA measures SD-WAN path quality using values such as latency, jitter, and packet loss. Administrators can configure thresholds that determine whether a WAN member meets the required service level. The resulting health status can then be used by SD-WAN rules when selecting a path for traffic. Static routes provide forwarding information, Address Groups combine network objects, and FortiAnalyzer provides centralized log analysis. Therefore, Performance SLA is the correct feature for determining whether an SD-WAN member satisfies configured performance thresholds.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>Which FortiGate feature can provide centralized collection and analysis of logs from FortiGate devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized log collection, storage, analysis, and reporting for supported Fortinet devices. FortiGate devices can send traffic, event, and security logs to FortiAnalyzer, allowing administrators to investigate information from a centralized platform. FortiView provides graphical visibility on an individual FortiGate, FortiGuard supplies security intelligence and related services, and FortiToken provides token-based authentication. Therefore, FortiAnalyzer is the correct solution when administrators need centralized logging and analysis across FortiGate devices.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>Which FortiGate feature allows an administrator to define a reusable collection of TCP and UDP services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface Zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Service Group combines multiple service objects into one reusable object. Individual service objects define protocols and ports, and a service group allows administrators to reference several of them together in firewall policies. Address Objects identify hosts or networks, User Groups organize authenticated users, and Interface Zones group interfaces. Service Groups can simplify policy configuration when the same set of services must be permitted or controlled across multiple rules. Therefore, Service Group is the correct feature for combining multiple TCP and UDP services.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>Which FortiGate setting controls which management protocols are enabled on a network interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted Hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative Access settings determine which management protocols are permitted through a FortiGate interface. Administrators can enable appropriate protocols such as HTTPS and SSH and disable unnecessary management services to reduce exposure. Trusted Hosts restrict the source locations for an administrator account, Schedule determines when a firewall policy operates, and Address Groups combine address objects. Therefore, Administrative Access is the correct setting when the objective is to control which management protocols can be used through a specific interface.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>Which FortiGate feature can use a public IP address to publish an internal server to external users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Virtual IP, or VIP, performs destination NAT by mapping a public IP address to an internal private server address. It is commonly used when services such as web, mail, or other applications need to be accessible from external networks. The corresponding firewall policy determines whether the inbound traffic is allowed. An IP Pool is primarily used for source NAT, an Address Group combines address objects, and a Service Group combines service objects. Therefore, Virtual IP is the appropriate feature for publishing an internal server through a public IP address.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which FortiGate diagnostic command can trace packet processing to help determine why traffic is accepted or denied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose debug flow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose vpn tunnel list<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get router info routing-table all<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">diagnose debug flow<\/span><span style=\"font-weight: 400;\"> command can trace packet processing through FortiGate and help administrators identify routing decisions, policy matching, and reasons for traffic being accepted or denied. It is especially useful when normal logs do not provide enough detail to explain a connectivity problem. Administrators typically apply suitable filters before starting the debug process to limit the output to the traffic under investigation. The other commands provide system, VPN, or routing information. Therefore, <\/span><span style=\"font-weight: 400;\">diagnose debug flow<\/span><span style=\"font-weight: 400;\"> is the correct troubleshooting command for tracing packet processing.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>Which FortiGate feature can control how much bandwidth is available to selected traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Shaping controls bandwidth allocation for selected network traffic. Administrators can use traffic-shaping settings to limit bandwidth consumption or prioritize important traffic so that critical applications receive appropriate network resources. Web Filter controls website access, RADIUS provides external authentication, and LDAP provides directory-based authentication. Traffic Shaping is therefore the appropriate FortiGate feature when bandwidth needs to be limited, prioritized, or managed for particular traffic classes. Its configuration can be associated with relevant firewall policies and traffic-shaping profiles.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>Which FortiGate feature can identify users through directory logon information and use that identity in firewall policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FSSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FSSO, or Fortinet Single Sign-On, provides FortiGate with user identity information obtained from supported authentication and directory environments. FortiGate can use this identity information in identity-based firewall policies, allowing access controls to be based on users or groups rather than only IP addresses. DHCP Server provides network configuration, IP Pool provides addresses for NAT, and Static Route determines packet-forwarding paths. Therefore, FSSO is the correct feature when administrators need to associate network activity with authenticated directory users.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>Which FortiGate feature can store logs directly on the device when local storage is available?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local Disk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local Disk allows supported FortiGate models to store logs directly on the appliance. This can provide administrators with locally available traffic, event, and security information for troubleshooting and review. The exact logging capabilities depend on the FortiGate model, storage availability, and configured log settings. FortiAnalyzer provides centralized log storage and analysis, FortiGuard supplies security intelligence, and FortiToken supports authentication. Therefore, Local Disk is the correct option when logs need to be stored directly on the FortiGate device.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>Which FortiGate feature can use an external threat-intelligence list containing malicious IP addresses or domains?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External Threat Feed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An External Threat Feed allows FortiGate to use externally maintained threat indicators, such as malicious IP addresses or domains, in supported security configurations. These indicators can help administrators identify or block traffic associated with known threats and supplement other FortiGate security controls. Web Filter manages website access, Service Groups combine service objects, and DHCP Server provides network configuration to clients. Therefore, External Threat Feed is the appropriate feature when administrators want to incorporate external threat-intelligence indicators into FortiGate security enforcement.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 321 Which FortiGate feature can identify the network path selected for a destination by examining the routing table? Routing table Web Filter Application Control FortiAnalyzer Correct Answer: 1 Explanation The routing table contains the routes FortiGate uses when determining how traffic should be [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14886"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14886"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14886\/revisions"}],"predecessor-version":[{"id":14896,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14886\/revisions\/14896"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}