ExamGecko
Home / Fortinet / FCP_FGT_AD-7.4 / List of questions
Ask Question

Fortinet FCP_FGT_AD-7.4 Practice Test - Questions Answers, Page 7

List of questions

Question 61

Report Export Collapse

Refer to the exhibit.

Fortinet FCP_FGT_AD-7.4 image Question 61 126280 11122024010310000000

The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router.

When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.

Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?

Become a Premium Member for full access
  Unlock Premium Member

Question 62

Report Export Collapse

An organization requires remote users to send external application data running on their PCs and access FTP resources through an SSUTLS connection.

Which FortiGate configuration can achieve this goal?

Become a Premium Member for full access
  Unlock Premium Member

Question 63

Report Export Collapse

Which three statements explain a flow-based antivirus profile? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 64

Report Export Collapse

Refer to exhibit.

Fortinet FCP_FGT_AD-7.4 image Question 64 126283 11122024010310000000

An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page.

Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?

Become a Premium Member for full access
  Unlock Premium Member

Question 65

Report Export Collapse

There are multiple dial-up IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels.

Which phase 1 setting you can configure to match the user to the tunnel?

Become a Premium Member for full access
  Unlock Premium Member

Question 66

Report Export Collapse

Which three CLI commands, can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 67

Report Export Collapse

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is outbound traffic but no response from the peer.

Which DPD mode on FortiGate meets this requirement?

Become a Premium Member for full access
  Unlock Premium Member

Question 68

Report Export Collapse

Which three statements about SD-WAN zones are true? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 69

Report Export Collapse

An administrator has configured a strict RPF check on FortiGate.

How does strict RPF check work?

Become a Premium Member for full access
  Unlock Premium Member

Question 70

Report Export Collapse

A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.

What is the reason for the certificate warning errors?

Become a Premium Member for full access
  Unlock Premium Member
Total 88 questions
Go to page: of 9
Search

Related questions