Free 2023 Fortinet NSE 4 NSE4_FGT-7.2 dumps are available by Actual4dump [Q67-Q82]

Share

Free 2023 Fortinet NSE 4 NSE4_FGT-7.2 dumps are available on Google Drive shared by Actual4dump

Welcome to download the newest Actual4dump NSE4_FGT-7.2 PDF dumps: https://www.actual4dump.com/Fortinet/NSE4_FGT-7.2-actualtests-dumps.html ( 152 Q&As)

NEW QUESTION # 67
Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

  • A. FortiGate queries AD by using the LDAP to retrieve user group information.
  • B. FortiGate points the collector agent to use a remote LDAP server.
  • C. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
  • D. FortiGate uses the AD server as the collector agent.

Answer: A,C

Explanation:
Fortigate Infrastructure 7.0 Study Guide P.272-273
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732


NEW QUESTION # 68
Which statement correctly describes the use of reliable logging on FortiGate?

  • A. Reliable logging is enabled by default in all configuration scenarios.
  • B. Reliable logging prevents the loss of logs when the local disk is full.
  • C. Reliable logging is required to encrypt the transmission of logs.
  • D. Reliable logging can be configured only using the CLI.

Answer: B


NEW QUESTION # 69
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?

  • A. A subordinate CA
  • B. A person
  • C. A CRL
  • D. A root CA

Answer: D


NEW QUESTION # 70
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?

  • A. Flow engine
  • B. Antivirus engine
  • C. Intrusion prevention system engine
  • D. Detection engine

Answer: C

Explanation:
http://docs.fortinet.com/document/fortigate/6.0.0/handbook/240599/application-control


NEW QUESTION # 71
Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).


Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?

  • A. The flow-based inspection is used, which resets the last packet to the user.
  • B. The intrusion prevention security profile needs to be enabled when using flow-based inspection mode.
  • C. The volume of traffic being inspected is too high for this model of FortiGate.
  • D. The firewall policy performs the full content inspection on the file.

Answer: A

Explanation:
* "ONLY" If the virus is detected at the "START" of the connection, the IPS engine sends the block replacement message immediately
* When a virus is detected on a TCP session (FIRST TIME), but where "SOME PACKETS" have been already forwarded to the receiver, FortiGate "resets the connection" and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a "SECOND ATTEMPT" to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
In flow mode, the FortiGate drops the last packet killing the file. But because of that the block replacement message cannot be displayed. If the file is attempted to download again the block message will be shown.


NEW QUESTION # 72
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

  • A. It limits the scope of application control to scan application traffic based on application category only.
  • B. It limits the scope of application control to the browser-based technology category only.
  • C. It limits the scope of application control to scan application traffic on DNS protocol only.
  • D. It limits the scope of application control to scan application traffic using parent signatures only

Answer: A


NEW QUESTION # 73
Refer to the exhibit, which contains a session diagnostic output.

Which statement is true about the session diagnostic output?

  • A. The session is in TCP ESTABLISHED state.
  • B. The session is a bidirectional UDP connection.
  • C. The session is a UDP unidirectional state.
  • D. The session is a bidirectional TCP connection.

Answer: B

Explanation:
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042


NEW QUESTION # 74
Which statement describes a characteristic of automation stitches?

  • A. They can run multiple actions simultaneously.
  • B. They can have one or more triggers.
  • C. They can be run only on devices in the Security Fabric.
  • D. They can be created on any device in the fabric.

Answer: A


NEW QUESTION # 75
Refer to the FortiGuard connection debug output.

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)

  • A. FortiGate is using default FortiGuard communication settings.
  • B. One server was contacted to retrieve the contract information.
  • C. There is at least one server that lost packets consecutively.
  • D. A local FortiManager is one of the servers FortiGate communicates with.

Answer: A,B


NEW QUESTION # 76
By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers.
Which CLI command will cause FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering?

  • A. set protocol tcp
  • B. set webfilter-force-off disable
  • C. set fortiguard-anycast disable
  • D. set webfilter-cache disable

Answer: C

Explanation:
y default, "fortiguard-anycast" is enabled, and this setting only works with "set protocol https". To use udp (ie. "set protocol udp"), "fortiguard-anycast" must be disabled.
Reference:
"By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."


NEW QUESTION # 77
Which two statements are true about the FGCP protocol? (Choose two.)

  • A. FGCP runs only over the heartbeat links.
  • B. FGCP is used to discover FortiGate devices in different HA groups.
  • C. FGCP is not used when FortiGate is in transparent mode.
  • D. FGCP elects the primary FortiGate device.

Answer: A,D

Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.4.0/ports-and-protocols/564712/fgcp-fortigate-clustering-protocol


NEW QUESTION # 78
Refer to the exhibits.
The exhibits show the firewall policies and the objects used in the firewall policies.
The administrator is using the Policy Lookup feature and has entered the search criteria shown in the exhibit.

Which policy will be highlighted, based on the input criteria?

  • A. Policy with ID 4.
  • B. Policies with ID 2 and 3.
  • C. Policy with ID 5.
  • D. Policy with ID 4.

Answer: C


NEW QUESTION # 79
Refer to the exhibits.
Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.


Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)

  • A. For load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary.
  • B. The traffic sourced from the client and destined to the server is sent to FGT-1.
  • C. For non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source.
  • D. The cluster can load balance ICMP connections to the secondary.

Answer: B,C


NEW QUESTION # 80
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.

Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)

  • A. On HQ-FortiGate, set IKE mode to Main (ID protection).
  • B. On Remote-FortiGate, set port2 as Interface.
  • C. On both FortiGate devices, set Dead Peer Detection to On Demand.
  • D. On HQ-FortiGate, disable Diffie-Helman group 2.

Answer: A,B


NEW QUESTION # 81
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

  • A. The interface has been configured for one-arm sniffer.
  • B. The interface is a member of a zone.
  • C. The operation mode is transparent.
  • D. The interface is a member of a virtual wire pair.
  • E. Captive portal is enabled in the interface.

Answer: A,C,D

Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm


NEW QUESTION # 82
......

Tested Material Used To NSE4_FGT-7.2: https://www.actual4dump.com/Fortinet/NSE4_FGT-7.2-actualtests-dumps.html

Following are some new NSE4_FGT-7.2 Real Exam Questions!: https://drive.google.com/open?id=1YWgugkw_Tyto2lV6dudm_yIrZlQ4AXBx