Fortinet FCP_FGT_AD-7.4 Practice Test - Questions Answers, Page 6
List of questions
Question 51

Refer to the exhibit showing a debug flow output.
What two conclusions can you make from the debug flow output? (Choose two.)
The debug flow is for ICMP traffic.
A firewall policy allowed the connection.
A new traffic session was created.
The default route is required to receive a reply.
A - The debug flow is for ICMP traffic.
B . A firewall policy allowed the connection.
C . A new traffic session was created.
D . The default route is required to receive a reply.
The debug flow is for ICMP traffic.
The output shows 'proto=1,' which indicates that the protocol is ICMP (Internet Control Message Protocol).
A new traffic session was created.
The message 'allocate a new session-00003dd5' confirms that a new session was created for this traffic.
Question 52

Which two statements are correct when FortiGate enters conserve mode? (Choose two.)
Question 53

Refer to the exhibit.
The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name.
FortiGate allows the traffic according to policy ID 1. This is the policy that allows SD-WAN traffic.
Despite these settings the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows.
What can be the reason?
Question 54

FortiGuard categories can be overridden and defined in different categories. To create a web rating override for the example.com home page the override must be configured using a specific syntax.
Which two syntaxes are correct to configure a web rating override for the home page? (Choose two.)
Question 55

An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
Question 56

Which two statements explain antivirus scanning modes? (Choose two.)
Question 57

Refer to the exhibits, which show the firewall policy and the security profile for Facebook.
Users are given access to the Facebook web application. They can play video content hosted on Facebook but they are unable to leave reactions on videos or other types of posts.
Which part of the configuration must you change to resolve the issue?
Question 58

Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
Question 59

A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal.
Which SSL timer can you use to mitigate a denial of service (DoS) attack?
Question 60

A FortiGate firewall policy is configured with active authentication however, the user cannot authenticate when accessing a website.
Which protocol must FortiGate allow even though the user cannot authenticate?
Question