Try NSE4_FGT-7.2 Free Now! Real Exam Question Answers Updated [Dec 23, 2023]
Get Ready to Pass the NSE4_FGT-7.2 exam with Fortinet Latest Practice Exam
Fortinet NSE4_FGT-7.2 certification exam is designed to test the knowledge and skills of network security professionals in configuring and managing Fortinet security solutions using FortiOS 7.2. Fortinet NSE 4 - FortiOS 7.2 certification is intended for individuals who are responsible for managing and maintaining network security solutions in enterprise environments. NSE4_FGT-7.2 exam covers topics such as network security concepts, firewall policies, VPN configurations, authentication mechanisms, and more. Passing the NSE4_FGT-7.2 exam validates that the candidate has a comprehensive understanding of Fortinet security products and can effectively use them to secure enterprise networks.
NEW QUESTION # 23
Which two statements are true about the FGCP protocol? (Choose two.)
- A. FGCP runs only over the heartbeat links.
- B. FGCP elects the primary FortiGate device.
- C. FGCP is not used when FortiGate is in transparent mode.
- D. FGCP is used to discover FortiGate devices in different HA groups.
Answer: A,B
Explanation:
Explanation
The FGCP (FortiGate Clustering Protocol) is a protocol that is used to manage high availability (HA) clusters of FortiGate devices. It performs several functions, including the following:
FGCP elects the primary FortiGate device: In an HA cluster, FGCP is used to determine which FortiGate device will be the primary device, responsible for handling traffic and making decisions about what to allow or block. FGCP uses a variety of factors, such as the device's priority, to determine which device should be the primary.
FGCP runs only over the heartbeat links: FGCP communicates between FortiGate devices in the HA cluster using the heartbeat links. These are dedicated links that are used to exchange status and control information between the devices. FGCP does not run over other types of links, such as data links.
NEW QUESTION # 24
Refer to the exhibit.
The exhibit shows the output of a diagnose command.
What does the output reveal about the policy route?
- A. It is an ISDB policy route with an SDWAN rule.
- B. It is an ISDB route in policy route.
- C. It is an SDWAN rule in policy route.
- D. It is a regular policy route.
Answer: C
Explanation:
FortiGate Infrastructure 7.2 Study Guide (p.59): "ISDB routes and SD-WAN rules are assigned an ID higher than 65535. However, SD-WAN rule entries include the vwl_service field, and ISDB route entries don't."
NEW QUESTION # 25
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. get system performance status
- B. diagnose sys top
- C. get system status
- D. get system arp
Answer: D
Explanation:
Explanation
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."
NEW QUESTION # 26
Refer to the exhibit.
The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?
- A. Change password
- B. Change Administrator profile
- C. Enable restrict access to trusted hosts
- D. Enable two-factor authentication
Answer: B
NEW QUESTION # 27
An administrator wants to configure timeouts for users. Regardless of the userTMs behavior, the timer should start as soon as the user authenticates and expire after the configured value.
Which timeout option should be configured on FortiGate?
- A. idle-timeout
- B. auth-on-demand
- C. hard-timeout
- D. new-session
- E. soft-timeout
Answer: C
Explanation:
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221#:~:text=Hard%20timeout%3A%20User%20
NEW QUESTION # 28
FortiGuard categories can be overridden and defined in different categories. To create a web rating override for example.com home page, the override must be configured using a specific syntax.
Which two syntaxes are correct to configure web rating for the home page? (Choose two.)
- A. www.example.com/index.html
- B. example.com
- C. www.example.com
- D. www.example.com:443
Answer: B,C
Explanation:
Explanation
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names - no URLs or wildcard characters are allowed.
OK: google.com or www.google.com
NO OK: www.google.com/index.html or google.*
FortiGate_Security_6.4 page 384
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names-- "no URLs or wildcard characters are allowed".
NEW QUESTION # 29
Why does FortiGate keep TCP sessions in the session table for some seconds even after both sides (client and server) have terminated the session?
- A. To remove the NAT operation.
- B. To allow for out-of-order packets that could arrive after the FIN/ACK packets.
- C. To finish any inspection operations.
- D. To generate logs
Answer: B
NEW QUESTION # 30
Refer to the exhibit.
Which contains a session list output. Based on the information shown in the exhibit, which statement is true?
- A. One-to-one NAT IP pool is used in the firewall policy.
- B. Overload NAT IP pool is used in the firewall policy.
- C. Destination NAT is disabled in the firewall policy.
- D. Port block allocation IP pool is used in the firewall policy.
Answer: A
Explanation:
FortiGate_Security_6.4 page 155 . In one-to-one, PAT is not required.
NEW QUESTION # 31
On FortiGate, which type of logs record information about traffic directly to and from the FortiGate management IP addresses?
- A. System event logs
- B. Security logs
- C. Local traffic logs
- D. Forward traffic logs
Answer: C
NEW QUESTION # 32
Refer to the exhibit.
Given the security fabric topology shown in the exhibit, which two statements are true? (Choose two.)
- A. Device detection is disabled on all FortiGate devices.
- B. There are five devices that are part of the security fabric.
- C. This security fabric topology is a logical topology view.
- D. There are 19 security recommendations for the security fabric.
Answer: C,D
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/761085/results
https://docs.fortinet.com/document/fortimanager/6.2.0/new-features/736125/security-fabric-topology
NEW QUESTION # 33
Refer to the exhibit.
Which contains a session diagnostic output. Which statement is true about the session diagnostic output?
- A. The session is in FTN_WAIT state.
- B. The session is in ESTABLISHED state.
- C. The session is in SYN_SENT state.
- D. The session is in FIN_ACK state.
Answer: C
Explanation:
Explanation
Indicates TCP (proto=6) session in SYN_SENT state (proto=state=2)
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
NEW QUESTION # 34
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
- A. It limits the scanning of application traffic to the browser-based technology category only.
- B. It limits the scanning of application traffic to use parent signatures only.
- C. It limits the scanning of application traffic to the application category only.
- D. It limits the scanning of application traffic to the DNS protocol only.
Answer: A
Explanation:
FortiGate Security 7.2 Study Guide (p.317): "You can configure the URL Category within the same security policy; however, adding a URL filter causes application control to scan applications in only the browser-based technology category, for example, Facebook Messenger on the Facebook website."
NEW QUESTION # 35
Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)
- A. FortiGate uses the AD server as the collector agent.
- B. FortiGate points the collector agent to use a remote LDAP server.
- C. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
- D. FortiGate queries AD by using the LDAP to retrieve user group information.
Answer: C,D
Explanation:
Fortigate Infrastructure 7.0 Study Guide P.272-273
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732
NEW QUESTION # 36
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?
- A. The web-server certificate must be installed on the browser.
- B. The CA certificate that signed the web-server certificate must be installed on the browser.
- C. The public key of the web server certificate must be installed on the browser.
- D. The private key of the CA certificate that signed the browser certificate must be installed on the browser.
Answer: B
NEW QUESTION # 37
Refer to the exhibit.
Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
- A. The IPS engine was inspecting high volume of traffic.
- B. The IPS engine will continue to run in a normal state.
- C. The IPS engine was unable to prevent an intrusion attack .
- D. The IPS engine was blocking all traffic.
Answer: A
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/232929/troubleshooting-high-cpu-usage
NEW QUESTION # 38
Which statement is correct regarding the inspection of some of the services available by web applications embedded in third-party websites?
- A. FortiGuard maintains only one signature of each web application that is unique.
- B. FortiGate can inspect sub-application traffic regardless where it was originated.
- C. The security actions applied on the web applications will also be explicitly applied on the third-party websites.
- D. The application signature database inspects traffic only from the original web application server.
Answer: B
Explanation:
Reference:
https://help.fortinet.com/fortiproxy/11/Content/Admin%20Guides/FPX-AdminGuide/300_System/303d_FortiG
NEW QUESTION # 39
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?
- A. Policy lookup will be disabled.
- B. Search option will be disabled
- C. By Sequence view will be disabled.
- D. Interface Pair view will be disabled.
Answer: D
Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47821
NEW QUESTION # 40
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
- A. The collector agent must search security event logs.
- B. NetAPI polling can increase bandwidth usage in large networks.
- C. The NetSession Enum function is used to track user logouts.
- D. The collector agent uses a Windows API to query DCs for user logins.
Answer: C
Explanation:
FortiGate_Infrastructure_7.0 page 270: "NetAPI: polls temporary sessions created on the DC when a user logs in or logs out and calls the NetSessionEnum function in Windows." Reference:
https://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD34906&sliceId=1
NEW QUESTION # 41
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
- A. The operation mode is transparent.
- B. Captive portal is enabled in the interface.
- C. The interface has been configured for one-arm sniffer.
- D. The interface is a member of a zone.
- E. The interface is a member of a virtual wire pair.
Answer: A,C,E
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm
NEW QUESTION # 42
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
- A. Denied users are blocked for 30 minutes.
- B. The number of logs generated by denied traffic is reduced.
- C. A session for denied traffic is created.
- D. Device detection on all interfaces is enforced for 30 minutes.
Answer: B,C
Explanation:
ses-denied-traffic
Enable/disable including denied session in the session table.
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/20620/config-system-settings block-session-timer Duration in seconds for blocked sessions .
integer
Minimum value: 1 Maximum value: 300
30
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/1620/config-system-global
NEW QUESTION # 43
Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)
- A. FortiGate hostname
- B. NTP
- C. DNS
- D. FortiGuard web filter cache
Answer: B,C
Explanation:
In the 7.2 Infrastructure Guide (page 306) the list of configuration settings that are NOT synchronized includes both 'FortiGate host name' and 'Cache'
NEW QUESTION # 44
Examine this FortiGate configuration:
How does the FortiGate handle web proxy traffic coming from the IP address 10.2.1.200 that requires authorization?
- A. It drops the traffic.
- B. It always authorizes the traffic without requiring authentication.
- C. It authenticates the traffic using the authentication scheme SCHEME1.
- D. It authenticates the traffic using the authentication scheme SCHEME2.
Answer: C
Explanation:
Explanation
"What happens to traffic that requires authorization, but does not match any authentication rule? The active and passive SSO schemes to use for those cases is defined under config authentication setting"
NEW QUESTION # 45
......
Pass Your Next NSE4_FGT-7.2 Certification Exam Easily & Hassle Free: https://www.dumpsmaterials.com/NSE4_FGT-7.2-real-torrent.html
Get Prepared for Your NSE4_FGT-7.2 Exam With Actual Fortinet Study Guide!: https://drive.google.com/open?id=1Pr-JHwpxFi7pNfa-i_e4j778bpuI_Ju2
