Summer Sale - Special Limited Time 55% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 44314956B5

Good News !!! NSE4_FGT-7.2 Fortinet NSE 4 - FortiOS 7.2 is now Stable and With Pass Result

NSE4_FGT-7.2 Practice Exam Questions and Answers

Fortinet NSE 4 - FortiOS 7.2

Last Update 5 days ago
Total Questions : 170

NSE4_FGT-7.2 is stable now with all latest exam questions are added 5 days ago. Just download our Full package and start your journey with Fortinet NSE 4 - FortiOS 7.2 certification. All these Fortinet NSE4_FGT-7.2 practice exam questions are real and verified by our Experts in the related industry fields.

NSE4_FGT-7.2 PDF

NSE4_FGT-7.2 PDF (Printable)
$54
$119.99

NSE4_FGT-7.2 Testing Engine

NSE4_FGT-7.2 PDF (Printable)
$63
$139.99

NSE4_FGT-7.2 PDF + Testing Engine

NSE4_FGT-7.2 PDF (Printable)
$79.65
$176.99
Question # 1

Refer to the exhibit.

Question # 1

Question # 1

The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of diagnose sys virtual-wan-link health-check . Which interface will be selected as an outgoing interface?

Options:

A.  

port2

B.  

port4

C.  

port3

D.  

port1

Discussion 0
Question # 2

Refer to the exhibit.

The exhibit shows the output of a diagnose command.

Question # 2

What does the output reveal about the policy route?

Options:

A.  

It is an ISDB route in policy route.

B.  

It is a regular policy route.

C.  

It is an ISDB policy route with an SDWAN rule.

D.  

It is an SDWAN rule in policy route.

Discussion 0
Question # 3

Options:

Discussion 0
Question # 4

Which two types of traffic are managed only by the management VDOM? (Choose two.)

Options:

A.  

FortiGuard web filter queries

B.  

PKI

C.  

Traffic shaping

D.  

DNS

Discussion 0
Question # 5

62

Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)

C.  

Security policy

D.  

SSL inspection and authentication policy

Options:

Discussion 0
Question # 6

Refer to the exhibit.

Question # 6

The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.

Which two statements are true? (Choose two.)

Options:

A.  

FortiGate SN FGVM010000065036 HA uptime has been reset.

B.  

FortiGate devices are not in sync because one device is down.

C.  

FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.

D.  

FortiGate SN FGVM010000064692 has the higher HA priority.

Discussion 0
Question # 7

17

In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)

Options:

A.  

The IP version of the sources and destinations in a firewall policy must be different.

B.  

The Incoming Interface. Outgoing Interface. Schedule, and Service fields can be shared with both IPv4 and IPv6.

C.  

The policy table in the GUI can be filtered to display policies with IPv4, IPv6 or IPv4 and IPv6 sources and destinations.

D.  

The IP version of the sources and destinations in a policy must match.

E.  

The policy table in the GUI will be consolidated to display policies with IPv4 and IPv6 sources and destinations.

Discussion 0
Question # 8

Refer to the exhibit to view the application control profile.

Question # 8

Based on the configuration, what will happen to Apple FaceTime?

Options:

A.  

Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration

B.  

Apple FaceTime will be allowed, based on the Apple filter configuration.

C.  

Apple FaceTime will be allowed only if the filter in Application and Filter Overrides is set to Learn

D.  

Apple FaceTime will be allowed, based on the Categories configuration.

Discussion 0
Question # 9

17

Refer to the exhibit.

Question # 9

An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic.

Why is FortiGate not sending probes to 4.2.2.2 and 4.2.2.1 servers? (Choose two.)

Options:

A.  

The Detection Mode setting is not set to Passive.

B.  

Administrator didn't configure a gateway for the SD-WAN members, or configured gateway is not valid.

C.  

The configured participants are not SD-WAN members.

D.  

The Enable probe packets setting is not enabled.

Discussion 0
Question # 10

Refer to the exhibit.

Question # 10

Which contains a session diagnostic output. Which statement is true about the session diagnostic output?

Options:

A.  

The session is in SYN_SENT state.

B.  

The session is in FIN_ACK state.

C.  

The session is in FTN_WAIT state.

D.  

The session is in ESTABLISHED state.

Discussion 0
Question # 11

An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings.

What is true about the DNS connection to a FortiGuard server?

Options:

A.  

It uses UDP 8888.

B.  

It uses UDP 53.

C.  

It uses DNS over HTTPS.

D.  

It uses DNS overTLS.

Discussion 0
Question # 12

Refer to the exhibit.

Question # 12

Which contains a network diagram and routing table output.

The Student is unable to access Webserver.

What is the cause of the problem and what is the solution for the problem?

Options:

A.  

The first packet sent from Student failed the RPF check.

This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.

B.  

The first reply packet for Student failed the RPF check.

This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.

C.  

The first reply packet for Student failed the RPF check .

This issue can be resolved by adding a static route to 203.0. 114.24/32 through port3.

D.  

The first packet sent from Student failed the RPF check.

This issue can be resolved by adding a static route to 203.0. 114.24/32 through port3.

Discussion 0
Question # 13

13

Which two inspection modes can you use to configure a firewall policy on a profile-based next-generation firewall (NGFW)? (Choose two.)

Options:

A.  

Proxy-based inspection

B.  

Certificate inspection

C.  

Flow-based inspection

D.  

Full Content inspection

Discussion 0
Question # 14

On FortiGate, which type of logs record information about traffic directly to and from the FortiGate management IP addresses?

Options:

A.  

System event logs

B.  

Forward traffic logs

C.  

Local traffic logs

D.  

Security logs

Discussion 0
Question # 15

An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?

Options:

A.  

Policy lookup will be disabled.

B.  

By Sequence view will be disabled.

C.  

Search option will be disabled

D.  

Interface Pair view will be disabled.

Discussion 0
Question # 16

53

Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?

Options:

A.  

The public key of the web server certificate must be installed on the browser.

B.  

The web-server certificate must be installed on the browser.

C.  

The CA certificate that signed the web-server certificate must be installed on the browser.

D.  

The private key of the CA certificate that signed the browser certificate must be installed on the browser.

Discussion 0
Question # 17

Refer to the exhibit.

Question # 17

Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)

Options:

A.  

The port3 default route has the highest distance.

B.  

The port3 default route has the lowest metric.

C.  

There will be eight routes active in the routing table.

D.  

The port1 and port2 default routes are active in the routing table.

Discussion 0
Question # 18

Examine this PAC file configuration.

Which of the following statements are true? (Choose two.)

Options:

A.  

Browsers can be configured to retrieve this PAC file from the FortiGate.

B.  

Any web request to the 172.25. 120.0/24 subnet is allowed to bypass the proxy.

C.  

All requests not made to Fortinet.com or the 172.25. 120.0/24 subnet, have to go through altproxy.corp.com: 8060.

D.  

Any web request fortinet.com is allowed to bypass the proxy.

Discussion 0
Question # 19

Which two protocols are used to enable administrator access of a FortiGate device? (Choose two.)

Options:

A.  

SSH

B.  

HTTPS

C.  

FTM

D.  

FortiTelemetry

Discussion 0
Question # 20

Which statement correctly describes the use of reliable logging on FortiGate?

Options:

A.  

Reliable logging is enabled by default in all configuration scenarios.

B.  

Reliable logging is required to encrypt the transmission of logs.

C.  

Reliable logging can be configured only using the CLI.

D.  

Reliable logging prevents the loss of logs when the local disk is full.

Discussion 0
Question # 21

30

A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not Which configuration option is the most effective way to support this request?

Options:

A.  

Implement a web filter category override for the specified website

B.  

Implement a DNS filter for the specified website.

C.  

Implement web filter quotas for the specified website

D.  

Implement web filter authentication for the specified website.

Discussion 0
Question # 22

Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

Options:

A.  

FortiGate points the collector agent to use a remote LDAP server.

B.  

FortiGate uses the AD server as the collector agent.

C.  

FortiGate uses the SMB protocol to read the event viewer logs from the DCs.

D.  

FortiGate queries AD by using the LDAP to retrieve user group information.

Discussion 0
Question # 23

45

Which three CLI commands can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)

Options:

A.  

diagnose sys top

B.  

execute ping

C.  

execute traceroute

D.  

diagnose sniffer packet any

E.  

get system arp

Discussion 0
Get NSE4_FGT-7.2 dumps and pass your exam in 24 hours!

Free Exams Sample Questions