Actual NSE4_FGT-7.2 Exam Recently Updated Questions with Free Demo
Free Fortinet NSE4_FGT-7.2 Exam Questions Self-Assess Preparation
NEW QUESTION # 78
An administrator is configuring an IPsec VPN between site A and site B.
The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192. 168. 1.0/24 and the remote quick mode selector is 192. 168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
- A. 192. 168.0.0/24
- B. 192. 168.3.0/24
- C. 192. 168.2.0/24
- D. 192. 168. 1.0/24
Answer: C
NEW QUESTION # 79
An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel.
Which DPD mode on FortiGate will meet the above requirement?
- A. Disabled
- B. On Demand
- C. Enabled
- D. On Idle
Answer: D
NEW QUESTION # 80
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.
What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
- A. Static IP Address
- B. Pre-shared Key
- C. Dynamic DNS
- D. Dialup User
Answer: D
Explanation:
Explanation
Dialup user is used when the remote peer's IP address is unknown. The remote peer whose IP address is unknown acts as the dialup clien and this is often the case for branch offices and mobile VPN clients that use dynamic IP address and no dynamic DNS
NEW QUESTION # 81
Refer to the exhibit.
Refer to the FortiGuard connection debug output.
Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
- A. FortiGate is using default FortiGuard communication settings.
- B. A local FortiManager is one of the servers FortiGate communicates with.
- C. One server was contacted to retrieve the contract information.
- D. There is at least one server that lost packets consecutively.
Answer: A,C
Explanation:
FortiGate Security 7.2 Study Guide (p.287-288): "Flags: D (IP returned from DNS), I (Contract server contacted), T (being timed), F (failed)" "By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."
NEW QUESTION # 82
Which statement about video filtering on FortiGate is true?
- A. It does not require a separate FortiGuard license.
- B. Full SSL inspection is not required.
- C. Otis available only on a proxy-based firewall policy.
- D. Video filtering FortiGuard categories are based on web filter FortiGuard categories.
Answer: A
NEW QUESTION # 83
Examine this output from a debug flow:
Why did the FortiGate drop the packet?
- A. It matched the default implicit firewall policy.
- B. It matched an explicitly configured firewall policy with the action DENY.
- C. It failed the RPF check .
- D. The next-hop IP address is unreachable.
Answer: A
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=13900
https://www.fortinetguru.com/2016/03/what-is-policy-id-0-and-why-lot-of-denied-traffic-on-this-policy/
NEW QUESTION # 84
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. get system arp
- B. get system status
- C. diagnose sys top
- D. get system performance status
Answer: A
Explanation:
Explanation
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."
NEW QUESTION # 85
Refer to the exhibit to view the application control profile.
Based on the configuration, what will happen to Apple FaceTime?
- A. Apple FaceTime will be allowed only if the filter in Application and Filter Overrides is set to Learn
- B. Apple FaceTime will be allowed, based on the Categories configuration.
- C. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration
- D. Apple FaceTime will be allowed, based on the Apple filter configuration.
Answer: C
NEW QUESTION # 86
Refer to the exhibit.
The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?
- A. Enable restrict access to trusted hosts
- B. Change password
- C. Enable two-factor authentication
- D. Change Administrator profile
Answer: D
NEW QUESTION # 87
FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.
In this scenario, which statement about VLAN IDs is true?
- A. The two VLAN subinterfaces can have the same VLAN ID only if they have IP addresses in different subnets.
- B. The two VLAN subinterfaces must have different VLAN IDs.
- C. The two VLAN subinterfaces can have the same VLAN ID only if they belong to different VDOMs.
- D. The two VLAN subinterfaces can have the same VLAN ID only if they have IP addresses in the same subnet.
Answer: A,D
NEW QUESTION # 88
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.
What is the reason for the certificate warning errors?
- A. FortiGate does not support full SSL inspection when web filtering is enabled.
- B. There are network connectivity issues.
- C. The browser requires a software update.
- D. The CA certificate set on the SSL/SSH inspection profile has not been imported into the browser.
Answer: D
NEW QUESTION # 89
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded.
What is the reason for the failed virus detection by FortiGate?
- A. The website is exempted from SSL inspection.
- B. The EICAR test file exceeds the protocol options oversize limit.
- C. The selected SSL inspection profile has certificate inspection enabled.
- D. The browser does not trust the FortiGate self-signed CA certificate.
Answer: A,D
Explanation:
Explanation
https traffic requires SSL decryption. Check the ssh inspection profile
NEW QUESTION # 90
Which two statements are correct about a software switch on FortiGate? (Choose two.)
- A. All interfaces in the software switch share the same IP address
- B. It can group only physical interfaces
- C. It can be configured only when FortiGate is operating in NAT mode
- D. Can act as a Layer 2 switch as well as a Layer 3 router
Answer: A,C
NEW QUESTION # 91
Which statement about the IP authentication header (AH) used by IPsec is true?
- A. AH does not provide any data integrity or encryption.
- B. AH does not support perfect forward secrecy.
- C. AH provides strong data integrity but weak encryption.
- D. AH provides data integrity bur no encryption.
Answer: D
NEW QUESTION # 92
View the exhibit.
Which of the following statements are correct? (Choose two.)
- A. Dead peer detection must be disabled to support this type of IPsec setup.
- B. This is a redundant IPsec setup.
- C. This setup requires at least two firewall policies with the action set to IPsec.
- D. The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
Answer: B,D
Explanation:
https://docs.fortinet.com/document/fortigate/6.2.4/cookbook/632796/ospf-with-ipsec-vpn-for-network-redundancy
NEW QUESTION # 93
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. DNS filter
- B. Application control
- C. Web application firewall
- D. Antivirus in flow-based inspection
- E. Web filter in flow-based inspection
Answer: B,D,E
Explanation:
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/739623/dns-filter-handled-by-ips-engine-in-flow-mode
NEW QUESTION # 94
Refer to the exhibit.
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)
- A. FortiGate devices are not in sync because one device is down.
- B. FortiGate SN FGVM010000064692 has the higher HA priority.
- C. FortiGate SN FGVM010000065036 HA uptime has been reset.
- D. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
Answer: B,C
Explanation:
1. Override is disable by default - OK
2. "If the HA uptime of a device is AT LEAST FIVE MINUTES (300 seconds) MORE than the HA Uptime of the other FortiGate devices, it becomes the primary" The
198 seconds < 300 seconds (5 minutes) Page 314 Infra Study Guide. https://docs.fortinet.com/document/fortigate/6.0.0/handbook/666653/primary-unit-selection-with-override-disab
NEW QUESTION # 95
Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)
- A. Operating mode
- B. System time
- C. FortiGuaid update servers
- D. NGFW mode
Answer: A,D
Explanation:
Explanation
C: "Operating mode is per-VDOM setting. You can combine transparent mode VDOM's with NAT mode VDOMs on the same physical Fortigate.
D: "Inspection-mode selection has moved from VDOM to firewall policy, and the default inspection-mode is flow, so NGFW Mode can be changed from Profile-base (Default) to Policy-base directly in System > Settings from the VDOM" Page 125 of
NEW QUESTION # 96
What are two features of collector agent advanced mode? (Choose two.)
- A. In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
- B. Advanced mode supports nested or inherited groups.
- C. In advanced mode, security profiles can be applied only to user groups, not individual users.
- D. Advanced mode uses the Windows convention-NetBios: Domain\Username.
Answer: A,B
Explanation:
A) In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
This is true because advanced mode allows FortiGate to query the LDAP server directly for user information and group membership, without relying on the collector agent. This enables FortiGate to apply security policies based on LDAP group filters, which can be configured on FortiGate1 D) Advanced mode supports nested or inherited groups.
This is true because advanced mode can handle complex group structures, such as nested groups or inherited groups, where a user belongs to a group that is a member of another group. This allows FortiGate to apply security policies based on the effective group membership of a user, not just the direct group membership1 FortiGate Infrastructure 7.2 Study Guide (p.146): "Also, advanced mode supports nested or inherited groups; that is, users can be members of subgroups that belong to monitored parent groups." "In advanced mode, you can configure FortiGate as an LDAP client and configure the group filters on FortiGate. You can also configure group filters on the collector agent."
NEW QUESTION # 97
Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster?
(Choose two.)
- A. DNS
- B. FortiGuard web filter cache
- C. NTP
- D. FortiGate hostname
Answer: A,C
NEW QUESTION # 98
Refer to the exhibit.
Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)
- A. There will be eight routes active in the routing table.
- B. The port1 and port2 default routes are active in the routing table.
- C. The port3 default route has the highest distance.
- D. The port3 default route has the lowest metric.
Answer: B,C
NEW QUESTION # 99
Refer to the exhibit.
Based on the raw log, which two statements are correct? (Choose two.)
- A. This is a security log.
- B. Traffic is blocked because Action is set to DENY in the firewall policy.
- C. Log severity is set to error on FortiGate.
- D. Traffic belongs to the root VDOM.
Answer: A,B
NEW QUESTION # 100
To complete the final step of a Security Fabric configuration, an administrator must authorize all the devices on which device?
- A. FortiManager
- B. FortiAnalyzer
- C. Root FortiGate
- D. Downstream FortiGate
Answer: C
NEW QUESTION # 101
......
NSE4_FGT-7.2 Free Sample Questions to Practice One Year Update: https://www.vceprep.com/NSE4_FGT-7.2-latest-vce-prep.html
Download NSE4_FGT-7.2 exam with Fortinet NSE4_FGT-7.2 Real Exam Questions: https://drive.google.com/open?id=1dO72lOlbtOJOK-IUVDs9I055oZgffu2M