{"id":14888,"date":"2026-09-17T07:38:49","date_gmt":"2026-09-17T07:38:49","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14888"},"modified":"2026-09-17T07:38:49","modified_gmt":"2026-09-17T07:38:49","slug":"fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Fortinet NSE4_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-ad-7-6-exam-dumps\"><b>Fortinet NSE4_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which FortiGate feature can identify unusually high CPU usage caused by an IPS sensor or security inspection process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System diagnostics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">System diagnostics can help administrators investigate resource usage and identify conditions such as unusually high CPU utilization. When security inspection features such as IPS contribute to increased processing demand, administrators can review system resources and diagnostic information to determine the source of the load. Web Filter controls website access, Address Groups combine address objects, and Service Objects define network services. Therefore, System diagnostics is the appropriate starting point for investigating high CPU usage and determining whether a security process may be contributing to the problem.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which FortiGate component provides security intelligence and subscription-based services such as antivirus and web-rating updates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGuard provides security intelligence and subscription-based services that support several FortiGate security functions. These services can include antivirus updates, web-rating information, application-related intelligence, and other threat intelligence depending on the licensed services. FortiAnalyzer provides centralized log management, FortiView provides local visibility into network activity, and FortiToken supports token-based authentication. Therefore, FortiGuard is the correct component when FortiGate needs current security intelligence and related service updates.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Which FortiGate setting can prevent a management service from being reachable through an interface when that service is disabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative Access controls which management services are enabled on a FortiGate interface. If a protocol such as HTTPS or SSH is not enabled for administrative access on that interface, the corresponding management service is not normally available through it. Performance SLA evaluates WAN-link performance, Service Groups combine service objects, and IP Pools provide addresses for source NAT. Therefore, Administrative Access is the correct setting when an administrator needs to prevent a specific management service from being reachable through an interface.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which FortiGate feature can combine physical interfaces into a single logical interface for simplified policy configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN Interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Loopback Interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software Switch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Software Switch combines multiple physical or logical interfaces into a single logical interface. This can simplify network configuration by allowing the grouped interfaces to be treated as one interface for appropriate networking and firewall-policy purposes. A VLAN Interface provides Layer 3 connectivity for a VLAN, a Loopback Interface provides a logical endpoint, and an IP Pool supplies addresses for NAT. Therefore, Software Switch is the correct feature when multiple interfaces need to be combined into a logical interface.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which FortiGate feature can save the current configuration so it can be restored later if required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration Backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration Backup allows administrators to save FortiGate configuration information for later recovery or restoration. Maintaining current backups is important before major changes such as firmware upgrades, policy modifications, or other system maintenance. Performance SLA monitors network-path quality, Application Control identifies applications, and Web Filter manages website access. A backup provides a recovery point if a configuration change causes unexpected behavior or if the device needs to be restored. Therefore, Configuration Backup is the appropriate feature for preserving the current FortiGate configuration.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which FortiGate feature can allow administrators to restore a previously saved configuration file?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration Restore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration Restore allows administrators to load a previously saved FortiGate configuration and return the device to an earlier configuration state. This can be useful after an unsuccessful configuration change, during recovery procedures, or when moving a known configuration to an appropriate device or environment. FortiView provides operational visibility, Traffic Shaping manages bandwidth, and Application Control identifies applications. Before restoring a configuration, administrators should verify that the file is appropriate for the device and FortiOS environment. Therefore, Configuration Restore is the correct feature.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which FortiGate component can provide centralized event and traffic-log analysis from several FortiGate devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is designed to receive and centrally analyze logs from supported Fortinet devices. It can store traffic, event, and security information and provide reporting and investigation capabilities across multiple FortiGate appliances. FortiToken provides authentication tokens, FortiView provides local visibility on a FortiGate, and FortiGuard provides security intelligence and subscription services. Centralized logging is particularly useful when administrators need to investigate activity across several devices from one location. Therefore, FortiAnalyzer is the correct component for centralized log analysis.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which FortiGate feature can reduce the risk of unauthorized administrative access by restricting an administrator account to known source networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted Hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted Hosts restrict an administrator account so that management access is accepted only from specified source IP addresses or networks. This provides an additional control beyond username and password authentication and can significantly reduce exposure to unauthorized management attempts from unapproved locations. Service Groups combine network services, DNS Filter controls domain-based access, and Traffic Shaping manages bandwidth. Therefore, Trusted Hosts is the appropriate feature when administrator accounts need to be limited to known management networks.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which FortiGate feature can determine whether traffic should use one SD-WAN member instead of another based on configured conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN Rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN Rule determines how FortiGate selects among available SD-WAN members for matching traffic. Rules can use criteria such as source, destination, application, service, and link-quality information to influence path selection. Performance SLA measures path health, but the SD-WAN rule uses those conditions when deciding how traffic should be handled. Static Routes provide routing entries, while Address Groups combine address objects. Therefore, SD-WAN Rule is the correct feature for controlling which SD-WAN member should be selected for matching traffic.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which FortiGate routing feature can provide a backup path when the preferred static route becomes unavailable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routes with different priorities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static routes with different priorities can provide route redundancy. When multiple routes exist for the same destination, the route with the preferred routing attributes can be selected while another route remains available as a backup. If the preferred route becomes unavailable, FortiGate can use the alternate route when the routing conditions allow it. Web Filter, Service Object, and Application Control are unrelated to route selection. Therefore, configuring static routes with different priorities is an appropriate method for creating a primary and backup routing path.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which FortiGate security profile can identify applications even when multiple applications use commonly shared network ports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control uses application signatures and inspection techniques to identify applications within network traffic rather than relying only on destination port numbers. This is useful because multiple applications can use common ports such as TCP 80 or TCP 443. Static Routes determine packet-forwarding paths, DHCP Server assigns network configuration, and IP Pools provide addresses for NAT. Therefore, Application Control is the appropriate security profile when administrators need application-level identification and control beyond simple port-based filtering.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which FortiGate feature can detect and block network attacks using configured intrusion-prevention signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPS uses intrusion-prevention signatures and inspection mechanisms to identify known malicious patterns and network attacks. An IPS profile can be applied to firewall policies and configured with appropriate actions, such as blocking or monitoring matching traffic. Web Filter controls website access, DNS Filter manages domain-based access, and Traffic Shaping manages bandwidth. Therefore, IPS is the correct FortiGate security feature when the objective is to detect and prevent network attacks using intrusion-prevention signatures.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which FortiGate feature can provide domain-based filtering by evaluating DNS requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Filter controls access based on domain names by evaluating DNS-related requests and applying configured filtering actions. It can be used to block or allow domains according to categories, reputation, or administrator-defined settings supported by the FortiGate configuration. Web Filter operates primarily on web traffic and URL filtering, Antivirus focuses on malicious content, and IP Pool provides addresses for NAT. Therefore, DNS Filter is the appropriate security profile when administrators need to control access at the domain-resolution level.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which FortiGate feature can authenticate users against a directory service using the LDAP protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LDAP Server configuration allows FortiGate to communicate with an external LDAP directory for user authentication and related directory operations. Administrators can configure the server address, connection parameters, and appropriate directory settings so FortiGate can validate user credentials against the organization&#8217;s directory service. Performance SLA measures SD-WAN path quality, Virtual IP provides destination NAT, and Traffic Shaping manages bandwidth. Therefore, LDAP Server is the correct configuration when user authentication needs to be performed through an LDAP-compatible directory.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which FortiGate feature can provide two-factor authentication by requiring a password and a one-time token?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGuard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiToken provides one-time-password authentication that can be used as an additional factor alongside a password. This creates a multi-factor authentication process in which possession of the token is required in addition to knowledge of the password. FortiAnalyzer is used for centralized logging, FortiGuard provides security intelligence and services, and FortiView provides network visibility. Therefore, FortiToken is the correct Fortinet component when administrators need to implement token-based two-factor authentication.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which FortiGate feature can control traffic sent to services running directly on the FortiGate itself?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-in Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN Rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Local-in Policy controls traffic destined for the FortiGate itself rather than traffic passing through the appliance between other networks. It can be used to restrict access to services and management functions exposed by FortiGate according to configured source, destination, interface, service, and action criteria. Firewall policies generally control transit traffic, SD-WAN rules influence WAN path selection, and Service Groups combine service objects. Therefore, Local-in Policy is the appropriate feature for controlling traffic addressed directly to FortiGate.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which FortiGate feature can provide visibility into the current state of IPsec VPN tunnels for troubleshooting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPN Monitoring provides information about configured VPN connections and can help administrators determine whether IPsec tunnels are operational. When a tunnel is not established or traffic is not passing as expected, VPN monitoring information can be useful as part of the troubleshooting process. FortiView provides broader activity visibility, Web Filter controls website access, and DHCP Server provides client network configuration. Therefore, VPN Monitoring is the appropriate feature for checking the operational state of IPsec VPN tunnels.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which FortiGate feature can capture packets passing through an interface for detailed network troubleshooting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet Capture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Packet Capture allows administrators to capture network packets for detailed troubleshooting and analysis. Captured traffic can help identify whether packets are arriving at the expected interface, determine whether responses are being generated, and investigate protocol-level connectivity problems. FortiToken provides authentication tokens, Address Groups combine network objects, and Schedule controls when firewall policies are active. Packet captures should normally be filtered appropriately so that the resulting information remains focused on the traffic under investigation. Therefore, Packet Capture is the correct troubleshooting feature.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a reusable collection of authenticated users for use in access-control policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface Zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A User Group combines configured or externally authenticated users so they can be referenced together in authentication and identity-based access-control configurations. This simplifies administration when several users require the same access permissions. Address Groups combine network address objects, Service Groups combine service objects, and Interface Zones group interfaces. User Groups are therefore appropriate when firewall or authentication policies need to apply the same treatment to multiple users without configuring each identity separately.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which FortiGate feature can use a DNS name rather than a fixed IP address when defining a destination address object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FQDN Address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An FQDN Address object uses a fully qualified domain name as the address definition. FortiGate can resolve the configured domain name and use the resulting address information in supported firewall-policy decisions. This can be useful for destinations whose IP addresses may change while their DNS name remains consistent. IP Pools provide source NAT addresses, Service Objects define protocols and ports, and Static Routes determine forwarding paths. Therefore, FQDN Address is the correct feature when a destination needs to be represented by a DNS name rather than a fixed IP address.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which FortiGate feature can identify unusually high CPU usage caused by an IPS sensor or security inspection process? System diagnostics Web Filter Address Group Service Object Correct Answer: 1 Explanation System diagnostics can help administrators investigate resource usage and identify conditions such [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14888"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14888"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14888\/revisions"}],"predecessor-version":[{"id":14894,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14888\/revisions\/14894"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}