Fortinet FCP_FGT_AD-7.4 Practice Test - Questions Answers, Page 8
List of questions
Related questions
Refer to the exhibit.
The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.
What must the administrator configure to answer this specific request from the NOC team?
Enable the parameter Never Timeout in the admin profiles
Increase the admintimeout value under config system accprofile super_admin.
Increase the admintimeout value under config system global
Increase the offline value of the Override idle Timeout parameter in the NOC_Access admin profile
A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy.
When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the and does not block the file allowing it to be downloaded.
The administrator confirms that the traffic matches the configured firewall policy.
What are two reasons for the failed virus detection by FortiGate? (Choose two.)
The selected SSL inspection profile has certificate inspection enabled
The browser does not trust the FortiGate self-siqned CA certificate
The EICAR test file exceeds the protocol options oversize limit
The website is exempted from SSL inspection
Refer to the exhibit.
Examine the intrusion prevention system (IPS) diagnostic command shown in the exhibit.
If option 5 is used with the IPS diagnostic command and the outcome is a decrease in the CPU usage, what is the correct conclusion?
The IPS engine is blocking all traffic.
The IPS engine is inspecting a high volume of traffic.
The IPS engine is unable to prevent an intrusion attack.
The IPS engine will continue to run in a normal state.
How can you disable RPF checking?
Disable src-check on the interface level settings
Unset fail-alert-interfaces on the interface level settings.
Disable fail-detect on the interface level settings.
Disable strict-src-check under system settings.
An administrator is configuring an IPsec VPN between site A and site . The Remote Gateway setting in both sites has been configured as Static IP Address.
For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
192.168.3.0/24
192.168.0.0/8
192.168.2.0/24
192.168.1.0/24
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements are true about the requirements of connected physical interfaces on FortiGate? (Choose two.)
Both interfaces must have the interface role assigned
Both interfaces must have directly connected routes on the routing table
Both interfaces must have DHCP enabled
Both interfaces must have IP addresses assigned
Which two pieces of information are synchronized between FortiGate HA members? (Choose two.)
OSPF adjacencies
IPsec security associations
BGP peerings
DHCP leases
Refer to the exhibit.
Based on the routing database shown in the exhibit which two conclusions can you make about the routes? (Choose two.)
There will be eight routes active in the routing table
The port1 and port2 default routes are active in the routing table
The port3 default route has the highest distance
The port3 default route has the lowest metric
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
FortiGate directs the collector agent to use a remote LDAP server.
FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
FortiGate does not support workstation check.
FortiGate uses the AD server as the collector agent.
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
The NetSessionEnum function is used to track user logouts.
NetAPI polling can increase bandwidth usage in large networks.
The collector agent must search Windows application event logs.
The collector agent uses a Windows API to query DCs for user logins.
Question