5/5 - (2 votes)

NSE4_FGT-7.2 Practice Test Give You First Time Success with 100% Money Back Guarantee!

All Obstacles During NSE4_FGT-7.2 Exam Preparation with NSE4_FGT-7.2 Real Test Questions

NO.42 What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?

 
 
 
 

NO.43 Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

 
 
 
 

NO.44 Refer to the exhibit.

Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)

 
 
 
 

NO.45 Which statement about video filtering on FortiGate is true?

 
 
 
 

NO.46 A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not Which configuration option is the most effective way to support this request?

 
 
 
 

NO.47 Which CLI command will display sessions both from client to the proxy and from the proxy to the servers?

 
 
 
 

NO.48 What are two functions of ZTNA? (Choose two.)

 
 
 
 

NO.49 Why does FortiGate Keep TCP sessions in the session table for several seconds, even after both sides (client and server) have terminated the session?

 
 
 
 

NO.50 Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router.
When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.

Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?

 
 
 
 

NO.51 Examine this FortiGate configuration:

How does the FortiGate handle web proxy traffic coming from the IP address 10.2.1.200 that requires authorization?

 
 
 
 

NO.52 Refer to the exhibit.

The exhibit contains a network diagram, virtual IP, IP pool, and firewall policies configuration.
The WAN (port1) interface has the IP address 10.200. 1. 1/24.
The LAN (port3) interface has the IP address 10 .0.1.254. /24.
The first firewall policy has NAT enabled using IP Pool.
The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0. 1. 10?

 
 
 
 

NO.53 Refer to the exhibits.
Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.


Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)

 
 
 
 

NO.54 Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?

 
 
 
 

NO.55 Examine the exhibit, which contains a virtual IP and firewall policy configuration.


The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port2) interface has the IP address 10.0. 1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0. 1. 10/24?

 
 
 
 

NO.56 Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)

 
 
 
 
 

NO.57 An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?

 
 
 
 

NO.58 Refer to the exhibits.
Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.


Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)

 
 
 
 

NO.59 What are two benefits of flow-based inspection compared to proxy-based inspection? (Choose two.)

 
 
 
 

NO.60 Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)

 
 
 
 

NO.61 Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)

 
 
 
 
 

NO.62 Refer to exhibit.
An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page.

Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?

 
 
 
 

NO.63 FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.
In this scenario, which statement about VLAN IDs is true?

 
 
 
 

NO.64 Refer to the exhibits.
The exhibits show the firewall policies and the objects used in the firewall policies.
The administrator is using the Policy Lookup feature and has entered the search criteria shown in the exhibit.

Which policy will be highlighted, based on the input criteria?

 
 
 
 

Fully Updated Free Actual Fortinet NSE4_FGT-7.2 Exam Questions: https://www.braindumpstudy.com/NSE4_FGT-7.2_braindumps.html

         

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw