Fortinet FCP_FGT_AD-7.4 Practice Test - Questions Answers, Page 7
List of questions
Related questions
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router.
When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.
Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?
Configure a loopback interface with address 203.0.113.2/32.
In the VIP configuration, enable arp-reply.
In the firewall policy configuration, enable match-vip.
Enable port forwarding on the server to map the external service port to the internal service port.
An organization requires remote users to send external application data running on their PCs and access FTP resources through an SSUTLS connection.
Which FortiGate configuration can achieve this goal?
SSL VPN quick connection
SSL VPN tunnel
SSL VPN bookmark
Zero trust network access
Which three statements explain a flow-based antivirus profile? (Choose three.)
Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection
Flow-based inspection optimizes performance compared to proxy-based inspection
FortiGate buffers the whole file but transmits to the client at the same time.
If a virus is detected, the last packet is delivered to the client.
The IPS engine handles the process as a standalone.
Refer to exhibit.
An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page.
Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?
On the Static URL Filter configuration set Type to Simple
On the FortiGuard Category Based Filter configuration set Action to Warning for Social Networking
On the Static URL Filter configuration set Action to Monitor
On the Static URL Filter configuration set Action to Exempt
There are multiple dial-up IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels.
Which phase 1 setting you can configure to match the user to the tunnel?
Peer ID
Local Gateway
Dead Peer Detection
IKE Mode Config
Which three CLI commands, can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)
execute ping
execute traceroute
diagnose sys top
get system arp
diagnose sniffer packet any
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is outbound traffic but no response from the peer.
Which DPD mode on FortiGate meets this requirement?
On Demand
On Idle
Disabled
Enabled
Which three statements about SD-WAN zones are true? (Choose three.)
An SD-WAN zone can contain physical and logical interfaces
You can use an SD-WAN zone in static route definitions
You can define up to three SD-WAN zones per FortiGate device
An SD-WAN zone must contains at least two members
An SD-WAN zone is a logical grouping of members
An administrator has configured a strict RPF check on FortiGate.
How does strict RPF check work?
Strict RPF checks the best route back to the source using the incoming interface.
Strict RPF allows packets back to sources with all active routes.
Strict RPF checks only for the existence of at least one active route back to the source using the incoming interface.
Strict RPF check is run on the first sent and reply packet of any new session.
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.
What is the reason for the certificate warning errors?
The option invalid SSL certificates is set to allow on the SSL/SSH inspection profile
The browser does not trust the certificate used by FortiGate for SSL inspection
The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
The matching firewall policy is set to proxy inspection mode
Question