Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Fortinet NSE 4 - FortiOS 7.2

Last Update 10 hours ago Total Questions : 170

The Fortinet NSE 4 - FortiOS 7.2 content is now fully updated, with all current exam questions added 10 hours ago. Deciding to include NSE4_FGT-7.2 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our NSE4_FGT-7.2 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these NSE4_FGT-7.2 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Fortinet NSE 4 - FortiOS 7.2 practice test comfortably within the allotted time.

Question # 11

20

Which two statements are true about the RPF check? (Choose two.)

A.

The RPF check is run on the first sent packet of any new session.

B.

The RPF check is run on the first reply packet of any new session.

C.

The RPF check is run on the first sent and reply packet of any new session.

D.

RPF is a mechanism that protects FortiGate and your network from IP spoofing attacks.

Question # 12

You have enabled logging on a FortiGate device for event logs and all security logs, and you have set up logging to use the FortiGate local disk.

What is the default behavior when the local disk is full?

A.

No new log is recorded after the warning is issued when log disk use reaches the threshold of 95%.

B.

No new log is recorded until you manually clear logs from the local disk.

C.

Logs are overwritten and the first warning is issued when log disk use reaches the threshold of 75%.

D.

Logs are overwritten and the only warning is issued when log disk use reaches the threshold of 95%.

Question # 13

Which three statements explain a flow-based antivirus profile? (Choose three.)

A.

Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.

B.

If a virus is detected, the last packet is delivered to the client.

C.

The IPS engine handles the process as a standalone.

D.

FortiGate buffers the whole file but transmits to the client at the same time.

E.

Flow-based inspection optimizes performance compared to proxy-based inspection.

Question # 14

Refer to the FortiGuard connection debug output.

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)

A.

A local FortiManager is one of the servers FortiGate communicates with.

B.

One server was contacted to retrieve the contract information.

C.

There is at least one server that lost packets consecutively.

D.

FortiGate is using default FortiGuard communication settings.

Question # 15

Refer to the exhibits.

Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.

Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)

A.

For non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source.

B.

The traffic sourced from the client and destined to the server is sent to FGT-1.

C.

The cluster can load balance ICMP connections to the secondary.

D.

For load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary.

Question # 16

6

Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)

A.

FortiCache

B.

FortiSIEM

C.

FortiAnalyzer

D.

FortiSandbox

E.

FortiCloud

Question # 17

What are two functions of the ZTNA rule? (Choose two.)

A.

It redirects the client request to the access proxy.

B.

It applies security profiles to protect traffic.

C.

It defines the access proxy.

D.

It enforces access control.

Question # 18

85

Which statement regarding the firewall policy authentication timeout is true?

A.

It is an idle timeout. The FortiGate considers a user to be " idle " if it does not see any packets coming from the user ' s source IP.

B.

It is a hard timeout. The FortiGate removes the temporary policy for a user ' s source IP address after this timer has expired.

C.

It is an idle timeout. The FortiGate considers a user to be " idle " if it does not see any packets coming from the user ' s source MAC.

D.

It is a hard timeout. The FortiGate removes the temporary policy for a user ' s source MAC address after this timer has expired.

Question # 19

Refer to the exhibit.

The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of diagnose sys virtual-wan-link health-check . Which interface will be selected as an outgoing interface?

A.

port2

B.

port4

C.

port3

D.

port1

Question # 20

Which two statements are correct about NGFW Policy-based mode? (Choose two.)

A.

NGFW policy-based mode does not require the use of central source NAT policy

B.

NGFW policy-based mode can only be applied globally and not on individual VDOMs

C.

NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy

D.

NGFW policy-based mode policies support only flow inspection

Go to page: