Fortinet FCP_FGT_AD-7.4 Practice Test - Questions Answers, Page 3
List of questions
Question 21

Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)
FortiGate's SD-WAN rule strategies for member selection include the following:Manual with load balancing: This strategy allows an administrator to manually configure whichSD-WAN member interfaces to use for specific traffic.Lowest Cost (SLA) with load balancing: This strategy prioritizes the link with the lowest cost thatmeets the SLA requirements.Best Quality with load balancing: This strategy selects the link with the best performancemetrics, such as latency, jitter, or packet loss.Options D and E are incorrect because 'Lowest Quality' is not a valid strategy, and 'Lowest Costwithout load balancing' contradicts the requirement for load balancing in the strategy name.FortiOS 7.4.1 Administration Guide: SD-WAN Rule Strategies
Question 22

Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)
Question 23

Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.)
Question 24

What are two features of the NGFW profile-based mode? (Choose two.)
Question 25

Refer to the exhibit to view the firewall policy.
Why would the firewall policy not block a well-known virus, for example eicar?
The firewall policy shown in the exhibit is configured in flow-based inspection mode. In flow-based inspection, certain security features, such as deep content inspection, might not be aseffective as in proxy-based mode. Proxy-based inspection is necessary for thorough contentinspection, which includes identifying and blocking well-known viruses like EICAR.FortiOS 7.4.1 Administration Guide: Inspection Modes
Question 26

Which inspection mode does FortiGate use for application profiles if it is configured as a profile-based next-generation firewall (NGFW)?
Question 27

Refer to the exhibit showing a FortiGuard connection debug output.
Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
Question 28

Refer to the exhibit.
Why did FortiGate drop the packet?
Question 29

An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable the service on the interface.
In this scenario, what prevents the administrator from enabling DHCP service?
Question 30

Refer to the exhibit.
Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit.
What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?
The exhibit shows that the 'FTP.Login.Failed' IPS signature is set with the action 'Pass' andpacket logging enabled. This means that any traffic matching this signature will be allowedthrough the FortiGate, and the traffic details will be logged for monitoring and analysispurposes.FortiOS 7.4.1 Administration Guide: IPS Signature Actions
Question