{"id":21442,"date":"2026-09-25T05:15:59","date_gmt":"2026-09-25T05:15:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21442"},"modified":"2026-09-25T05:15:59","modified_gmt":"2026-09-25T05:15:59","slug":"fortinet-nse4_fgt-7-0-practice-test-questions-and-exam-dumps-part-12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt-7-0-practice-test-questions-and-exam-dumps-part-12-q221-240\/","title":{"rendered":"Fortinet NSE4_FGT-7.0 Practice Test Questions and Exam Dumps Part 12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-7-0-exam-dumps\"><b>Fortinet NSE4_FGT-7.0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 221. A FortiGate administrator needs to ensure that a specific internal subnet uses ISP2 instead of the default route through ISP1. Which feature should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy-based routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP reservation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Policy-based routing<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy-based routing allows FortiGate to make forwarding decisions based on criteria such as source address, destination address, incoming interface, or other configured conditions. It is useful when selected traffic must use a particular gateway or interface instead of the normal routing-table decision. Web Filter and Antivirus are security inspection features, while DHCP reservation controls client address assignment. Policy-based routing is therefore appropriate when traffic from a specific subnet needs to be directed through ISP2 while other traffic continues using the normal routing path.<\/span><\/p>\n<p><b>Question 222. Which FortiGate feature allows a single physical interface to carry traffic for multiple VLANs using 802.1Q tagging?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Loopback interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. VLAN interface<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VLAN interface allows FortiGate to communicate with a specific VLAN carried over a physical interface using VLAN tagging. Multiple VLAN interfaces can be configured over the same physical interface when the connected switch uses an appropriate trunk configuration. An IP pool is used for source NAT, a loopback interface is a logical endpoint independent of a physical port, and a virtual IP provides destination NAT. A VLAN interface is therefore the appropriate configuration for routing and securing tagged VLAN traffic through FortiGate.<\/span><\/p>\n<p><b>Question 223. Which FortiGate feature can prevent users from accessing websites classified by FortiGuard as malicious or inappropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HA heartbeat<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Web Filter<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can use FortiGuard web categorization to identify websites and apply configured actions based on their categories or reputation. Administrators can configure categories to be blocked, monitored, or allowed according to organizational requirements. ECMP handles multiple equal-cost routes, static routes define forwarding paths, and HA heartbeat communication supports cluster operation. Web Filter is therefore the appropriate FortiGate security feature when administrators need to restrict access to malicious, inappropriate, or otherwise unwanted websites.<\/span><\/p>\n<p><b>Question 224. A FortiGate policy contains several address objects representing different internal networks. The administrator wants to reference them collectively in one policy. What should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Address group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Address group<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An address group combines multiple address objects into a single logical object that can be referenced by firewall policies. This simplifies policy configuration when several networks should receive the same treatment. A service group combines service objects, an IP pool provides source NAT addresses, and a security profile provides traffic inspection or protection functions. An address group is therefore the appropriate choice when multiple internal networks need to be referenced collectively as a source or destination in a firewall policy.<\/span><\/p>\n<p><b>Question 225. Which FortiGate feature provides a logical interface that can remain available even if the physical interface used for another network connection changes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Loopback interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Loopback interface<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A loopback interface is a logical interface that is not directly tied to the operational state of a particular physical interface. Because of this, its address can provide a stable endpoint for management, routing protocols, monitoring, or other services. A service group organizes service objects, DHCP relay forwards DHCP requests, and a virtual IP performs destination NAT. A loopback interface is therefore useful when FortiGate requires a consistent logical address that remains independent of individual physical link states.<\/span><\/p>\n<p><b>Question 226. Which FortiGate feature can inspect network traffic for known attack signatures and take configured protective action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic Shaping<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. IPS<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System uses signatures and detection mechanisms to identify known exploits, attacks, and suspicious traffic patterns. An IPS profile can be applied to firewall policies so FortiGate can log or block detected threats according to the configured action. DNS Filter focuses on DNS requests, Traffic Shaping manages bandwidth, and DHCP Server provides network configuration to clients. IPS is therefore the appropriate security feature when the objective is to detect and prevent recognized network-based attacks.<\/span><\/p>\n<p><b>Question 227. An administrator wants to verify whether a particular IP address appears in the active FortiGate session table. Which command is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">execute ping<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">diagnose sys session list<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">show system interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. <\/b><b>diagnose sys session list<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">diagnose sys session list<\/span><span style=\"font-weight: 400;\"> command displays active sessions tracked by the FortiGate session table. Administrators can inspect session information and use filtering or related diagnostic techniques to investigate whether traffic from or to a particular address has an active session. <\/span><span style=\"font-weight: 400;\">get system status<\/span><span style=\"font-weight: 400;\"> provides general device information, <\/span><span style=\"font-weight: 400;\">execute ping<\/span><span style=\"font-weight: 400;\"> tests reachability, and <\/span><span style=\"font-weight: 400;\">show system interface<\/span><span style=\"font-weight: 400;\"> displays interface configuration. The session-list command is therefore the appropriate diagnostic starting point when investigating active connections involving a specific IP address.<\/span><\/p>\n<p><b>Question 228. Which FortiGate setting controls the days and times during which a firewall policy is active?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Address object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Schedule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec monitor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Schedule<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy schedule defines when that policy is active. FortiGate can use recurring schedules to permit or deny traffic during specified days and times. Address objects identify network endpoints, service groups combine service definitions, and IPsec Monitor provides information about VPN status. A schedule is therefore the appropriate configuration when an organization needs time-based access control, such as allowing a particular service only during business hours or restricting access outside a defined operating period.<\/span><\/p>\n<p><b>Question 229. Which FortiGate feature can translate an external destination IP address and port to an internal server address and port?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaper<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RADIUS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Virtual IP<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual IP, or VIP, can perform destination NAT by translating traffic sent to an external address and, when configured, a specific external port toward an internal server address and port. This is commonly used when publishing internal services such as HTTPS, SSH, or other applications to external clients. Traffic shapers manage bandwidth, RADIUS supports authentication, and ECMP manages equal-cost routes. A virtual IP is therefore the appropriate FortiGate object for mapping an external destination to an internal server.<\/span><\/p>\n<p><b>Question 230. Which FortiGate feature can provide centralized authentication by communicating with an external directory service based on LDAP?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> LDAP server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. LDAP server<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An LDAP server configuration allows FortiGate to communicate with an external directory for user authentication and related identity-based access control. This is useful when an organization maintains centralized user accounts and wants FortiGate authentication to use those existing directory identities. IP pools support source NAT, static routes determine forwarding, and traffic shaping manages bandwidth. LDAP integration is therefore the appropriate feature when FortiGate needs to authenticate users through an external directory rather than relying exclusively on local accounts.<\/span><\/p>\n<p><b>Question 231. Which FortiGate feature can distribute incoming connections between several backend servers hosting the same application?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server Load Balance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Server Load Balance<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Server Load Balance allows FortiGate to distribute incoming client connections across multiple backend servers. The FortiGate virtual server can provide a single externally accessible service while forwarding connections to members of the configured server pool according to the selected load-balancing method. DNS Filter controls domain access, DHCP relay forwards DHCP requests, and policy routes influence forwarding decisions. Server Load Balance is therefore appropriate when multiple backend servers should share incoming application traffic for availability or capacity purposes.<\/span><\/p>\n<p><b>Question 232. Which FortiGate command is most useful for checking whether a destination network is present in the routing table?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">diagnose debug flow<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">get router info routing-table all<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">diagnose sys session list<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">execute ping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. <\/b><b>get router info routing-table all<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">get router info routing-table all<\/span><span style=\"font-weight: 400;\"> command displays the routes known and installed by the FortiGate. It can be used to verify whether a destination network exists in the routing table and to identify the associated next hop and outgoing interface. Debug flow provides deeper packet-processing information, session-list displays active sessions, and ping tests connectivity. When the specific question is whether FortiGate has a route for a destination network, inspecting the routing table is the most direct approach.<\/span><\/p>\n<p><b>Question 233. Which FortiGate feature can apply different permissions to administrators based on their assigned management role?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrator profile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Administrator profile<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrator profiles define the permissions and access levels available to FortiGate administrators. Different administrators can receive different roles so that some may have read-only access while others can modify specific configuration areas. IP pools support address translation, Web Filter controls web traffic, and VLAN interfaces provide logical connectivity to tagged networks. Administrator profiles are therefore the appropriate feature for implementing role-based administrative privileges and limiting users to the management capabilities required for their responsibilities.<\/span><\/p>\n<p><b>Question 234. Which FortiGate mechanism prevents traffic from being allowed when it does not match any explicit firewall policy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Implicit deny<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Implicit deny<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate applies an implicit deny to traffic that does not match an explicit firewall policy allowing it. This default behavior ensures that traffic is not automatically permitted simply because a route exists. Administrators must create an appropriate policy with matching interfaces, addresses, services, schedules, and required security settings when traffic needs to be allowed. ECMP handles routing, DHCP relay forwards DHCP requests, and source NAT translates source addresses. The implicit deny is therefore a fundamental part of FortiGate&#8217;s default firewall behavior.<\/span><\/p>\n<p><b>Question 235. Which FortiGate feature can use an external RADIUS server to authenticate users?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RADIUS server configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Loopback interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. RADIUS server configuration<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate can be configured as a RADIUS client and communicate with an external RADIUS server for authentication. This allows user credentials and authentication decisions to be handled through centralized RADIUS infrastructure. A loopback interface provides a logical network endpoint, a virtual IP performs destination NAT, and a service group combines service objects. RADIUS server configuration is therefore the appropriate choice when FortiGate needs to authenticate users through an external RADIUS-based authentication system.<\/span><\/p>\n<p><b>Question 236. Which FortiGate security profile can identify and control traffic generated by specific applications even when applications use non-standard ports?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP reservation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HA heartbeat<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Application Control<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control uses application signatures and traffic characteristics to identify applications rather than depending exclusively on TCP or UDP port numbers. This allows administrators to control recognized applications even when they use non-standard ports or dynamically selected communication methods. Static routes determine forwarding paths, DHCP reservations assign predictable client addresses, and HA heartbeat interfaces support cluster communication. Application Control is therefore appropriate when application identity must be used as a security-control criterion independent of the application&#8217;s expected port.<\/span><\/p>\n<p><b>Question 237. Which FortiGate feature can provide a centralized platform for collecting, analyzing, and reporting logs from FortiGate devices?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaper<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FortiAnalyzer<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized log collection, analysis, reporting, and historical visibility for Fortinet security devices. FortiGate devices can forward supported logs to FortiAnalyzer so administrators can investigate security events and traffic activity from a centralized platform. IP pools provide NAT addresses, VLAN interfaces provide logical VLAN connectivity, and traffic shapers manage bandwidth. FortiAnalyzer is therefore the appropriate platform when an organization needs centralized logging and reporting rather than relying only on local FortiGate log storage.<\/span><\/p>\n<p><b>Question 238. Which FortiGate feature can restrict administrative access to a specific source network for an individual administrator account?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trusted hosts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Trusted hosts<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted hosts allow an administrator account to specify which source IP addresses or networks are permitted to access the FortiGate management interface. This provides an additional restriction beyond username and password authentication and can significantly narrow the locations from which administrative access is accepted. Application Control manages application traffic, ECMP manages equal-cost routes, and DHCP server functionality provides client addressing. Trusted hosts are therefore the appropriate feature for restricting management access to designated administrative networks.<\/span><\/p>\n<p><b>Question 239. Which FortiGate command can provide a detailed view of how a packet is processed through routing and firewall policy evaluation?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">execute ping<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">diagnose debug flow<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">show system dns<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. <\/b><b>diagnose debug flow<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">diagnose debug flow<\/span><span style=\"font-weight: 400;\"> provides detailed information about packet processing within FortiGate. It can help administrators trace routing decisions, policy matching, session handling, and other processing stages. This makes it especially useful when traffic appears to be routed incorrectly or unexpectedly accepted or denied. <\/span><span style=\"font-weight: 400;\">execute ping<\/span><span style=\"font-weight: 400;\"> tests reachability, <\/span><span style=\"font-weight: 400;\">get system status<\/span><span style=\"font-weight: 400;\"> displays general system information, and <\/span><span style=\"font-weight: 400;\">show system dns<\/span><span style=\"font-weight: 400;\"> displays DNS configuration. Debug flow is therefore the most appropriate diagnostic tool for tracing the internal processing of a specific packet flow.<\/span><\/p>\n<p><b>Question 240. Which FortiGate feature can provide encrypted connectivity between two geographically separated networks over an untrusted network such as the Internet?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec VPN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. IPsec VPN<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPsec VPN can establish an encrypted tunnel between FortiGate devices or between FortiGate and another compatible VPN endpoint. This allows traffic between geographically separated networks to traverse an untrusted network such as the Internet while receiving confidentiality and integrity protection according to the configured IPsec parameters. Web Filter controls web access, service groups organize service objects, and DHCP relay forwards DHCP requests. IPsec VPN is therefore the appropriate technology for secure site-to-site connectivity across an untrusted network.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps &nbsp; Question 221. A FortiGate administrator needs to ensure that a specific internal subnet uses ISP2 instead of the default route through ISP1. Which feature should be configured? Web Filter Policy-based routing Antivirus DHCP reservation Correct Answer: 2. Policy-based routing Explanation :- Policy-based routing allows [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21442"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21442"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21442\/revisions"}],"predecessor-version":[{"id":21443,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21442\/revisions\/21443"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}