Real NSE4_FGT-7.2 Exam PDF Test Engine Practice Test Questions
Fortinet NSE4_FGT-7.2 Real 2023 Braindumps Mock Exam Dumps
NEW QUESTION 67
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
- A. Antivirus engine
- B. Detection engine
- C. Flow engine
- D. Intrusion prevention system engine
Answer: D
Explanation:
http://docs.fortinet.com/document/fortigate/6.0.0/handbook/240599/application-control
NEW QUESTION 68
Which two statements explain antivirus scanning modes? (Choose two.)
- A. In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.
- B. In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.
- C. In flow-based inspection mode, files bigger than the buffer size are scanned.
- D. In proxy-based inspection mode, files bigger than the buffer size are scanned.
Answer: A,B
Explanation:
An antivirus profile in full scan mode buffers up to your specified file size limit. The default is 10 MB. That is large enough for most files, except video files. If your FortiGate model has more RAM, you may be able to increase this threshold. Without a limit, very large files could exhaust the scan memory. So, this threshold balances risk and performance. Is this tradeoff unique to FortiGate, or to a specific model? No. Regardless of vendor or model, you must make a choice. This is because of the difference between scans in theory, that have no limits, and scans on real-world devices, that have finite RAM. In order to detect 100% of malware regardless of file size, a firewall would need infinitely large RAM--something that no device has in the real world. Most viruses are very small. This table shows a typical tradeoff. You can see that with the default 10 MB threshold, only 0.01% of viruses pass through.
NEW QUESTION 69
Which two actions can you perform only from the root FortiGate in a Security Fabric? (Choose two.)
- A. Ban or unban compromised hosts.
- B. Shut down/reboot a downstream FortiGate device.
- C. Disable FortiAnalyzer logging for a downstream FortiGate device.
- D. Log in to a downstream FortiSwitch device.
Answer: B,C
NEW QUESTION 70
Refer to the exhibits.
Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.

If the host 10.200.3.1 sends a TCP SYN packet on port 10443 to 10.200.1.10, what will the source address, destination address, and destination port of the packet be, after FortiGate forwards the packet to the destination?
- A. 10.200.3.1, 10.0.1.10, and 443, respectively
- B. 10.0.1.254, 10.0.1.10, and 443, respectively
- C. 10.0.1.254, 10.0.1.10, and 10443, respectively
Answer: A
NEW QUESTION 71
Refer to the exhibit.

The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of diagnose sys virtual-wan-link health-check . Which interface will be selected as an outgoing interface?
- A. port4
- B. port3
- C. port2
- D. port1
Answer: D
Explanation:
Port 1 shows the lowest latency.
NEW QUESTION 72
Examine this output from a debug flow:
Why did the FortiGate drop the packet?
- A. It failed the RPF check .
- B. It matched the default implicit firewall policy.
- C. It matched an explicitly configured firewall policy with the action DENY.
- D. The next-hop IP address is unreachable.
Answer: B
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=13900
NEW QUESTION 73
Which statement is correct regarding the inspection of some of the services available by web applications embedded in third-party websites?
- A. FortiGate can inspect sub-application traffic regardless where it was originated.
- B. FortiGuard maintains only one signature of each web application that is unique.
- C. The application signature database inspects traffic only from the original web application server.
- D. The security actions applied on the web applications will also be explicitly applied on the third-party websites.
Answer: A
Explanation:
Reference:
https://help.fortinet.com/fortiproxy/11/Content/Admin%20Guides/FPX-AdminGuide/300_System/303d_FortiG
NEW QUESTION 74
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
- A. To dynamically change phase 1 negotiation mode aggressive mode.
- B. To force a new DH exchange with each phase 2 rekey.
- C. To encapsulation ESP packets in UDP packets using port 4500.
- D. To detect intermediary NAT devices in the tunnel path.
Answer: C,D
NEW QUESTION 75
Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)
- A. FortiGate queries AD by using the LDAP to retrieve user group information.
- B. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
- C. FortiGate points the collector agent to use a remote LDAP server.
- D. FortiGate uses the AD server as the collector agent.
Answer: A,B
Explanation:
Fortigate Infrastructure 7.0 Study Guide P.272-273
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732
NEW QUESTION 76
When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
- A. Policy ID
- B. Universally Unique Identifier
- C. Log ID
- D. Sequence ID
Answer: B
NEW QUESTION 77
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. get system status
- B. get system arp
- C. get system performance status
- D. diagnose sys top
Answer: B
Explanation:
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."
NEW QUESTION 78
You have enabled logging on your FortiGate device for Event logs and all Security logs, and you have set up logging to use the FortiGate local disk . What is the default behavior when the local disk is full?
- A. No new log is recorded until you manually clear logs from the local disk .
- B. Logs are overwritten and the first warning is issued when log disk usage reaches the threshold of 75%.
- C. Logs are overwritten and the only warning is issued when log disk usage reaches the threshold of 95%.
- D. No new log is recorded after the warning is issued when log disk usage reaches the threshold of 95%.
Answer: B
NEW QUESTION 79
Which scanning technique on FortiGate can be enabled only on the CLI?
- A. Antivirus scan
- B. Heuristics scan
- C. Trojan scan
- D. Ransomware scan
Answer: B
NEW QUESTION 80
Refer to the FortiGuard connection debug output.
Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
- A. A local FortiManager is one of the servers FortiGate communicates with.
- B. One server was contacted to retrieve the contract information.
- C. There is at least one server that lost packets consecutively.
- D. FortiGate is using default FortiGuard communication settings.
Answer: B,D
NEW QUESTION 81
Refer to the exhibits.
The exhibits show a network diagram and firewall configurations.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. Remote-User1 must be able to access the Webserver. Remote-User2 must not be able to access the Webserver.

In this scenario, which two changes can the administrator make to deny Webserver access for Remote-User2? (Choose two.)
- A. Enable match vip in the Deny policy.
- B. Disable match-vip in the Deny policy.
- C. Set the Destination address as Deny_IP in the Allow-access policy.
- D. Set the Destination address as Web_server in the Deny policy.
Answer: A,D
Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Firewall-does-not-block-incoming-WAN-to-LAN/ta-p/189641
NEW QUESTION 82
Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).

Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?
- A. The volume of traffic being inspected is too high for this model of FortiGate.
- B. The firewall policy performs the full content inspection on the file.
- C. The flow-based inspection is used, which resets the last packet to the user.
- D. The intrusion prevention security profile needs to be enabled when using flow-based inspection mode.
Answer: C
Explanation:
* "ONLY" If the virus is detected at the "START" of the connection, the IPS engine sends the block replacement message immediately
* When a virus is detected on a TCP session (FIRST TIME), but where "SOME PACKETS" have been already forwarded to the receiver, FortiGate "resets the connection" and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a "SECOND ATTEMPT" to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
In flow mode, the FortiGate drops the last packet killing the file. But because of that the block replacement message cannot be displayed. If the file is attempted to download again the block message will be shown.
NEW QUESTION 83
Which two protocols are used to enable administrator access of a FortiGate device? (Choose two.)
- A. FortiTelemetry
- B. HTTPS
- C. SSH
- D. FTM
Answer: B,C
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/995103/buildingsecurity-into-fortios
NEW QUESTION 84
Which feature in the Security Fabric takes one or more actions based on event triggers?
- A. Automation Stitches
- B. Logical Topology
- C. Fabric Connectors
- D. Security Rating
Answer: A
NEW QUESTION 85
Which two statements about FortiGate FSSO agentless polling mode are true? (Choose two.)
- A. FortiGate does not support workstation check .
- B. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
- C. FortiGate directs the collector agent to use a remote LDAP server.
- D. FortiGate uses the AD server as the collector agent.
Answer: A,B
Explanation:
You can deploy FSSO w/o installing an agent. FG polls the DCs directly, instead of receiving logon info indirectly from a collector agent.
Because FG collects all of the data itself, agentless polling mode requires greater system resources, and it doesn't scale as easily.
Agentless polling mode operates in a similar way to WinSecLog, but with only two event IDs: 4768 and 4769. Because there's no collector agent, FG uses the SMB protocol to read the event viewer logs from the DCs.
FG acts as a collector. It 's responsible for polling on top of its normal FSSO tasks but does not have all the extra features, such as workstation checks, that are available with the external collector agent.
Reference:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-FSSO-agentless-polling/ta-p/214349
NEW QUESTION 86
Refer to the exhibits.

The exhibits show the SSL and authentication policy (Exhibit A) and the security policy (Exhibit B) for Facebook .
Users are given access to the Facebook web application. They can play video content hosted on Facebook but they are unable to leave reactions on videos or other types of posts.
Which part of the policy configuration must you change to resolve the issue?
- A. Add Facebook in the URL category in the security policy.
- B. Make SSL inspection needs to be a deep content inspection.
- C. Force access to Facebook using the HTTP service.
- D. Get the additional application signatures are required to add to the security policy.
Answer: B
Explanation:
The lock logo behind Facebook_like.Button indicates that SSL Deep Inspection is Required.
NEW QUESTION 87
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?
- A. A root CA
- B. A subordinate CA
- C. A person
- D. A CRL
Answer: A
NEW QUESTION 88
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
- A. The interface is a member of a virtual wire pair.
- B. The interface has been configured for one-arm sniffer.
- C. The interface is a member of a zone.
- D. Captive portal is enabled in the interface.
- E. The operation mode is transparent.
Answer: A,B,E
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm
NEW QUESTION 89
View the exhibit.
Which of the following statements are correct? (Choose two.)
- A. This setup requires at least two firewall policies with the action set to IPsec.
- B. This is a redundant IPsec setup.
- C. The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
- D. Dead peer detection must be disabled to support this type of IPsec setup.
Answer: B,C
Explanation:
https://docs.fortinet.com/document/fortigate/6.2.4/cookbook/632796/ospf-with-ipsec-vpn-for-network-redundancy
NEW QUESTION 90
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On both FortiGate devices, set Dead Peer Detection to On Demand.
- B. On HQ-FortiGate, disable Diffie-Helman group 2.
- C. On Remote-FortiGate, set port2 as Interface.
- D. On HQ-FortiGate, set IKE mode to Main (ID protection).
Answer: C,D
NEW QUESTION 91
Refer to the exhibit showing a debug flow output.
Which two statements about the debug flow output are correct? (Choose two.)
- A. A firewall policy allowed the connection.
- B. The default route is required to receive a reply.
- C. A new traffic session is created.
- D. The debug flow is of ICMP traffic.
Answer: C,D
NEW QUESTION 92
......
Prepare For The NSE4_FGT-7.2 Question Papers In Advance: https://www.freepdfdump.top/NSE4_FGT-7.2-valid-torrent.html
Released Fortinet NSE4_FGT-7.2 Updated Questions PDF: https://drive.google.com/open?id=1jePeXqG1R-7x7_Ew5mCvLNiLtRZBKS5D

