Jan-2023 Free NSE4_FGT-7.2 Test Questions Real Practice Test Questions
NSE4_FGT-7.2 Dumps Updated Jan 30, 2023 WIith 152 Questions
Fortinet NSE4_FGT-7.2 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION 49
Which three statements are true regarding session-based authentication? (Choose three.)
- A. IP sessions from the same source IP address are treated as a single user.
- B. It is not recommended if multiple users are behind the source NAT
- C. HTTP sessions are treated as a single user.
- D. It requires more resources.
- E. It can differentiate among multiple clients behind the same source IP address.
Answer: C,D,E
NEW QUESTION 50
Which feature in the Security Fabric takes one or more actions based on event triggers?
- A. Logical Topology
- B. Security Rating
- C. Fabric Connectors
- D. Automation Stitches
Answer: D
NEW QUESTION 51
An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
- A. Configure Source IP Pools.
- B. Configure different SSL VPN realms.
- C. Configure split tunneling in tunnel mode.
- D. Configure host check .
Answer: D
NEW QUESTION 52
Which two statements are correct about SLA targets? (Choose two.)
- A. SLA targets are used only when referenced by an SD-WAN rule.
- B. SLA targets are optional.
- C. You can configure only two SLA targets per one Performance SLA.
- D. SLA targets are required for SD-WAN rules with a Best Quality strategy.
Answer: A,B
NEW QUESTION 53
Refer to the exhibits.

The exhibits show the SSL and authentication policy (Exhibit A) and the security policy (Exhibit B) for Facebook .
Users are given access to the Facebook web application. They can play video content hosted on Facebook but they are unable to leave reactions on videos or other types of posts.
Which part of the policy configuration must you change to resolve the issue?
- A. Make SSL inspection needs to be a deep content inspection.
- B. Get the additional application signatures are required to add to the security policy.
- C. Force access to Facebook using the HTTP service.
- D. Add Facebook in the URL category in the security policy.
Answer: A
Explanation:
The lock logo behind Facebook_like.Button indicates that SSL Deep Inspection is Required.
NEW QUESTION 54
An administrator is configuring an Ipsec between site A and siteB. The Remotes Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192. 16. 1.0/24 and the remote quick mode selector is 192. 16.2.0/24. How must the administrator configure the local quick mode selector for site B?
- A. 192. 168.3.0/24
- B. 192. 168. 1.0/24
- C. 192. 168.0.0/8
- D. 192. 168.2.0/24
Answer: D
NEW QUESTION 55
An administrator must disable RPF check to investigate an issue.
Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?
- A. Disable the RPF check at the FortiGate interface level for the reply check .
- B. Enable asymmetric routing at the interface level.
- C. Disable the RPF check at the FortiGate interface level for the source check.
- D. Enable asymmetric routing, so the RPF check will be bypassed.
Answer: C
NEW QUESTION 56
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.
What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
- A. Static IP Address
- B. Dynamic DNS
- C. Pre-shared Key
- D. Dialup User
Answer: D
Explanation:
Dialup user is used when the remote peer's IP address is unknown. The remote peer whose IP address is unknown acts as the dialup clien and this is often the case for branch offices and mobile VPN clients that use dynamic IP address and no dynamic DNS
NEW QUESTION 57
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?
- A. The public key of the web server certificate must be installed on the browser.
- B. The web-server certificate must be installed on the browser.
- C. The CA certificate that signed the web-server certificate must be installed on the browser.
- D. The private key of the CA certificate that signed the browser certificate must be installed on the browser.
Answer: C
NEW QUESTION 58
Refer to the exhibit.
An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic.
Why is FortiGate not sending probes to 4.2.2.2 and 4.2.2.1 servers? (Choose two.)
- A. Administrator didn't configure a gateway for the SD-WAN members, or configured gateway is not valid.
- B. The Detection Mode setting is not set to Passive.
- C. The configured participants are not SD-WAN members.
- D. The Enable probe packets setting is not enabled.
Answer: A,D
NEW QUESTION 59
Refer to the exhibits.

The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?
- A. Change the idle-timeout.
- B. Change the Server IP address.
- C. Change the SSL VPN portal to the tunnel.
- D. Change the SSL VPN port on the client.
Answer: D
NEW QUESTION 60
Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)
- A. The primary device in the cluster is always assigned IP address 169.254.0.1.
- B. Heartbeat interfaces have virtual IP addresses that are manually assigned.
- C. A change in the virtual IP address happens when a FortiGate device joins or leaves the cluster.
- D. Virtual IP addresses are used to distinguish between cluster members.
Answer: A,C
NEW QUESTION 61
When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
- A. Log ID
- B. Universally Unique Identifier
- C. Policy ID
- D. Sequence ID
Answer: B
NEW QUESTION 62
Refer to the exhibit.
Which contains a session diagnostic output. Which statement is true about the session diagnostic output?
- A. The session is in FIN_ACK state.
- B. The session is in SYN_SENT state.
- C. The session is in FTN_WAIT state.
- D. The session is in ESTABLISHED state.
Answer: B
Explanation:
Indicates TCP (proto=6) session in SYN_SENT state (proto=state=2) https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
NEW QUESTION 63
Which of the following statements is true regarding SSL VPN settings for an SSL VPN portal?
- A. By default, split tunneling is enabled.
- B. By default, the admin GUI and SSL VPN portal use the same HTTPS port.
- C. By default, FortiGate uses WINS servers to resolve names.
- D. By default, the SSL VPN portal requires the installation of a client's certificate.
Answer: B
NEW QUESTION 64
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
- A. The operation mode is transparent.
- B. The interface is a member of a virtual wire pair.
- C. The interface is a member of a zone.
- D. Captive portal is enabled in the interface.
- E. The interface has been configured for one-arm sniffer.
Answer: A,B,E
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm
NEW QUESTION 65
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. Application control
- B. Web application firewall
- C. DNS filter
- D. Antivirus in flow-based inspection
- E. Web filter in flow-based inspection
Answer: A,D,E
Explanation:
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/739623/dns-filter-handled-by-ips-engine-in-flow-mode
NEW QUESTION 66
Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).

Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?
- A. The intrusion prevention security profile needs to be enabled when using flow-based inspection mode.
- B. The flow-based inspection is used, which resets the last packet to the user.
- C. The firewall policy performs the full content inspection on the file.
- D. The volume of traffic being inspected is too high for this model of FortiGate.
Answer: B
Explanation:
* "ONLY" If the virus is detected at the "START" of the connection, the IPS engine sends the block replacement message immediately
* When a virus is detected on a TCP session (FIRST TIME), but where "SOME PACKETS" have been already forwarded to the receiver, FortiGate "resets the connection" and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a "SECOND ATTEMPT" to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
In flow mode, the FortiGate drops the last packet killing the file. But because of that the block replacement message cannot be displayed. If the file is attempted to download again the block message will be shown.
NEW QUESTION 67
In an explicit proxy setup, where is the authentication method and database configured?
- A. Authentication scheme
- B. Firewall Policy
- C. Proxy Policy
- D. Authentication Rule
Answer: A
NEW QUESTION 68
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?
- A. On Remote-FortiGate, set Seconds to 43200.
- B. On HQ-FortiGate, enable Auto-negotiate.
- C. On HQ-FortiGate, set Encryption to AES256.
- D. On HQ-FortiGate, enable Diffie-Hellman Group 2.
Answer: C
Explanation:
Reference:
:
Encryption and authentication algorithm needs to match in order for IPSEC be successfully established.
NEW QUESTION 69
......
View All NSE4_FGT-7.2 Actual Free Exam Questions Updated: https://www.itpassleader.com/Fortinet/NSE4_FGT-7.2-dumps-pass-exam.html
Pass Authentic Fortinet NSE4_FGT-7.2 with Free Practice Tests and Exam Dumps: https://drive.google.com/open?id=1zSOTbeW8vvRPurftwrbyzQyvesN-OHoP