{"id":21446,"date":"2026-09-25T05:16:27","date_gmt":"2026-09-25T05:16:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21446"},"modified":"2026-09-25T05:16:27","modified_gmt":"2026-09-25T05:16:27","slug":"fortinet-nse4_fgt-7-0-practice-test-questions-and-exam-dumps-part-14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse4_fgt-7-0-practice-test-questions-and-exam-dumps-part-14-q261-280\/","title":{"rendered":"Fortinet NSE4_FGT-7.0 Practice Test Questions and Exam Dumps Part 14 Q261-280"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse4-fgt-7-0-exam-dumps\"><b>Fortinet NSE4_FGT-7.0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 261. Which FortiGate feature allows an administrator to create a logical collection of interfaces and reference them collectively in firewall policies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface zone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Interface zone<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface zone allows multiple FortiGate interfaces to be grouped into a logical object that can be referenced by firewall policies. This can simplify policy configuration when several interfaces should have similar security treatment. An IP pool provides addresses for source NAT, a virtual IP performs destination NAT, and a service group combines service objects. Interface zones are therefore useful for reducing repetitive policy configuration while maintaining consistent access control across several interfaces.<\/span><\/p>\n<p><b>Question 262. A FortiGate administrator needs to verify whether a firewall policy is actually receiving traffic. Which information can be reviewed directly in the policy configuration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache entries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy hit count<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP lease duration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec encryption algorithm<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Policy hit count<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy hit information can help administrators determine whether traffic has matched a particular firewall policy. When troubleshooting policy behavior, reviewing hit counts and associated logging can provide evidence that a rule is being used. DNS cache entries, DHCP lease duration, and IPsec encryption algorithms address different functions and do not directly indicate whether a firewall policy is receiving traffic. Policy hit information is therefore useful for validating policy usage and identifying rules that may not be matching expected traffic.<\/span><\/p>\n<p><b>Question 263. Which FortiGate feature can use a predefined set of security profiles together so they can be applied consistently to multiple firewall policies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security profile group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Address group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Security profile group<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security profile group combines selected security profiles into a reusable collection. This can simplify policy administration by allowing administrators to apply a consistent set of protections to multiple firewall policies. Address groups combine network addresses, user groups combine authenticated users, and IP pools provide addresses for source NAT. Security profile groups are therefore useful when several policies should use a standardized combination of protections such as Antivirus, IPS, Web Filter, and Application Control.<\/span><\/p>\n<p><b>Question 264. Which FortiGate feature can authenticate administrators or users using a centralized directory based on LDAP?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> LDAP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaping<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. LDAP<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LDAP integration allows FortiGate to communicate with an external directory service for authentication and identity-related access control. This is useful when an organization maintains centralized user accounts and wants FortiGate to use those identities instead of maintaining every account locally. ECMP manages multiple equal-cost routes, traffic shaping controls bandwidth, and virtual IPs perform destination NAT. LDAP is therefore the appropriate authentication mechanism when credentials and group information are maintained in an external directory service.<\/span><\/p>\n<p><b>Question 265. Which FortiGate feature is used to define a manually configured route to a destination network?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Captive portal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Static route<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A static route is a manually configured route that specifies how FortiGate should reach a particular destination network. It can define a destination prefix, gateway or next hop, and outgoing interface as appropriate. Application Control identifies applications, Web Filter controls web access, and captive portal provides authentication through a web interface. Static routes are therefore appropriate when an administrator needs to explicitly define a forwarding path rather than relying on a dynamically learned route.<\/span><\/p>\n<p><b>Question 266. Which FortiGate feature can determine whether traffic belongs to a known application and then apply a configured action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HA heartbeat<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Application Control<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control uses FortiGate application signatures and traffic characteristics to identify applications. Administrators can then configure actions for recognized applications, such as allowing, monitoring, or blocking them. DHCP relay forwards DHCP requests, static routes control forwarding paths, and HA heartbeat communication supports cluster operation. Application Control is therefore the appropriate feature when the security decision needs to be based on application identity rather than simply on IP addresses or service ports.<\/span><\/p>\n<p><b>Question 267. Which FortiGate feature can provide a backup path when the primary route becomes unavailable, assuming an appropriate route with a different administrative distance is configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Floating static route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Floating static route<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A floating static route can be configured with a higher administrative distance than a preferred route. Under normal conditions, the preferred route is selected, while the floating static route can become active when the preferred route is no longer available. Web Filter and Antivirus are security profiles, while a service group combines service objects. A floating static route is therefore useful for providing a manually configured backup forwarding path when redundancy is required and dynamic routing is not being used for that purpose.<\/span><\/p>\n<p><b>Question 268. Which FortiGate command can display the configured firewall policies from the CLI?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">show firewall policy<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">execute ping<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">get system performance status<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">diagnose sniffer packet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. <\/b><b>show firewall policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">show firewall policy<\/span><span style=\"font-weight: 400;\"> command displays firewall policy configuration from the FortiGate CLI. Administrators can use it to inspect policy IDs, source and destination objects, services, schedules, actions, NAT settings, and associated security profiles. <\/span><span style=\"font-weight: 400;\">execute ping<\/span><span style=\"font-weight: 400;\"> is used for connectivity testing, <\/span><span style=\"font-weight: 400;\">get system performance status<\/span><span style=\"font-weight: 400;\"> provides resource information, and <\/span><span style=\"font-weight: 400;\">diagnose sniffer packet<\/span><span style=\"font-weight: 400;\"> captures traffic. The firewall policy command is therefore appropriate when an administrator needs to review the configured policy definitions directly from the CLI.<\/span><\/p>\n<p><b>Question 269. Which FortiGate feature can allow an administrator to see applications, users, destinations, and traffic patterns through a graphical monitoring interface?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiView<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Link aggregation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. FortiView<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides graphical and detailed visibility into traffic and security activity on FortiGate. Depending on the selected view and available logging information, administrators can investigate applications, users, destinations, sources, sessions, and security events. DHCP Server provides client addressing, IP pools support source NAT, and link aggregation combines physical interfaces. FortiView is therefore the appropriate monitoring feature when administrators need an operational overview of network activity and want to drill into traffic information through the FortiGate interface.<\/span><\/p>\n<p><b>Question 270. Which FortiGate feature is used to define the protocol and destination port that a firewall policy should match?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Schedule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Address object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Service<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service object defines the protocol and port or port range that FortiGate should match when evaluating traffic against a firewall policy. Standard services such as HTTP, HTTPS, SSH, and DNS can be used, and administrators can create custom services for non-standard requirements. Schedules define when policies are active, address objects identify network endpoints, and user groups identify authenticated users. The Service field is therefore the policy component that controls which network protocols and ports are matched.<\/span><\/p>\n<p><b>Question 271. Which FortiGate feature can use FortiGuard intelligence to categorize websites and determine whether access should be permitted?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec Monitor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Web Filter<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can use FortiGuard web categorization and reputation information to classify websites and apply configured access actions. Administrators can configure categories according to organizational requirements, including blocking or monitoring selected categories. ECMP provides multiple equal-cost routing paths, IPsec Monitor displays VPN information, and DHCP relay forwards DHCP requests. Web Filter is therefore the appropriate FortiGate security feature when website access needs to be controlled using category or reputation information.<\/span><\/p>\n<p><b>Question 272. Which FortiGate feature allows a device to forward DHCP requests to a DHCP server located on another network?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP reservation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. DHCP relay<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP relay forwards DHCP client requests between a local client network and a DHCP server located on another network. This is useful when a centralized DHCP server serves multiple network segments and FortiGate is responsible for forwarding the requests. DHCP reservation assigns a predictable address to a particular client, DNS Filter controls DNS-based access, and virtual IP provides destination NAT. DHCP relay is therefore the correct feature when FortiGate needs to connect clients with a remote DHCP server.<\/span><\/p>\n<p><b>Question 273. Which FortiGate feature can provide encrypted connectivity between two private networks across the public Internet?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec VPN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaping<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Address group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. IPsec VPN<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPsec VPN can establish an encrypted tunnel between two private networks across an untrusted network such as the Internet. FortiGate uses IPsec negotiation and security parameters to establish and protect the tunnel according to the configured VPN design. Web Filter controls website access, Traffic Shaping manages bandwidth, and Address Groups organize network addresses. IPsec VPN is therefore the appropriate technology for securely connecting geographically separated private networks over a public network.<\/span><\/p>\n<p><b>Question 274. Which FortiGate feature can inspect traffic for malicious network activity by comparing it against intrusion signatures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Loopback interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. IPS<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System examines traffic for known attack patterns and signatures. When an IPS profile is applied to a firewall policy, FortiGate can detect, log, and potentially block traffic associated with recognized threats according to the configured action. DHCP Server provides client addressing, IP pools provide NAT addresses, and loopback interfaces provide logical endpoints. IPS is therefore the security feature intended to identify and protect against network attacks using intrusion detection and prevention techniques.<\/span><\/p>\n<p><b>Question 275. Which FortiGate feature can restrict an administrator account so that management access is accepted only from specified trusted IP addresses?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trusted hosts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security profile group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Trusted hosts<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted hosts restrict where an administrator account can be used to access FortiGate management services. Administrators can specify trusted source IP addresses or networks, reducing the exposure of management access to unauthorized locations. Application Control identifies applications, security profile groups combine security profiles, and ECMP manages equal-cost routes. Trusted hosts are therefore particularly useful as an additional administrative security control when management access should be limited to designated networks or workstation addresses.<\/span><\/p>\n<p><b>Question 276. Which FortiGate feature allows an administrator to inspect the current active connection entries maintained by the firewall?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">diagnose sys session list<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">execute ping<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">show firewall address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. <\/b><b>diagnose sys session list<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">diagnose sys session list<\/span><span style=\"font-weight: 400;\"> command displays active sessions currently maintained in the FortiGate session table. Session information can help administrators troubleshoot connectivity, identify whether traffic has established a session, and investigate source and destination information or policy references. <\/span><span style=\"font-weight: 400;\">get system status<\/span><span style=\"font-weight: 400;\"> provides general system details, <\/span><span style=\"font-weight: 400;\">execute ping<\/span><span style=\"font-weight: 400;\"> tests connectivity, and <\/span><span style=\"font-weight: 400;\">show firewall address<\/span><span style=\"font-weight: 400;\"> displays address configuration. The session-list command is therefore the appropriate diagnostic tool when investigating active connections through the firewall.<\/span><\/p>\n<p><b>Question 277. Which FortiGate feature can provide centralized storage and analysis of logs generated by one or more FortiGate devices?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FortiAnalyzer<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is designed to collect, store, analyze, and report on logs from Fortinet security devices. FortiGate can forward supported traffic, security, and event logs to FortiAnalyzer, allowing administrators to perform centralized investigations and generate reports. DHCP relay forwards DHCP requests, virtual IPs perform destination NAT, and VLAN interfaces provide connectivity to tagged networks. FortiAnalyzer is therefore the appropriate centralized logging platform when organizations need broader historical analysis than local FortiGate logs alone can provide.<\/span><\/p>\n<p><b>Question 278. Which FortiGate feature can combine several related TCP or UDP ports into a single reusable service definition?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Address group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Custom service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Loopback interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Custom service<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A custom service can define protocols and port ranges that are not represented by an existing predefined service. Administrators can then use the custom service in firewall policies to control applications or network services using specific ports. Address groups combine network addresses, user groups combine authenticated identities, and loopback interfaces provide logical endpoints. Custom services are therefore useful when a firewall policy needs to match a non-standard or specifically defined TCP or UDP port range.<\/span><\/p>\n<p><b>Question 279. Which FortiGate routing principle selects the most specific route when multiple routes match a destination IP address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Highest interface number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Longest prefix match<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Oldest route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Largest gateway address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Longest prefix match<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The longest prefix match principle means FortiGate prefers the route with the most specific destination prefix when multiple routes match the same destination address. For example, a route for a \/24 network is more specific than a route for the encompassing \/16 network and will be selected for destinations within that \/24 when both are available. This principle is fundamental to routing decisions and helps ensure that more specific network paths override broader destination routes when appropriate.<\/span><\/p>\n<p><b>Question 280. A FortiGate administrator wants to reduce the available bandwidth consumed by a particular class of traffic without blocking it. Which feature should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual IP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic Shaping<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> LDAP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec Phase 1<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Traffic Shaping<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Shaping allows FortiGate administrators to control how much bandwidth selected traffic can consume without necessarily blocking that traffic. Shaping can be applied to appropriate firewall policies or traffic classes to manage network capacity and prevent a particular type of traffic from consuming excessive resources. Virtual IP provides destination NAT, LDAP supports external authentication, and IPsec Phase 1 establishes VPN negotiation parameters. Traffic Shaping is therefore the appropriate feature when traffic should remain permitted but its bandwidth usage needs to be controlled.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE4_FGT-7.0 Exam Dumps and Practice Test Dumps &nbsp; Question 261. Which FortiGate feature allows an administrator to create a logical collection of interfaces and reference them collectively in firewall policies? Interface zone IP pool Virtual IP Service group Correct Answer: 1. Interface zone Explanation :- An interface zone allows multiple FortiGate interfaces [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21446"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21446"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21446\/revisions"}],"predecessor-version":[{"id":21447,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21446\/revisions\/21447"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}