Fortinet NSE4_FGT-7.2 Practice Test - Questions Answers
List of questions
Question 1

Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)
Question 2

The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?
FortiGate Security 7.2 Study Guide (p.285): 'Remember that the web filtering profile has several features. So, if you have enabled many of them, the inspection order flows as follows: 1. The local static URL filter 2. FortiGuard category filtering (to determine a rating) 3. Advanced filters (such as safe search or removing Active X components)'
Question 3

If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy?
https://docs.fortinet.com/document/fortigate/6.2.5/cookbook/179236/using-internet-service-in-policy
Question 4

Which statement about the IP authentication header (AH) used by IPsec is true?
Question 5

When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
FortiGate Security 7.2 Study Guide (p.67): 'When creating firewall objects or policies, a universally unique identifier (UUID) attribute is added so that logs can record these UUIDs and improve functionality when integrating with FortiManager or FortiAnalyzer.'
Question 6

Which statements about the firmware upgrade process on an active-active HA cluster are true? (Choose two.)
Question 7

Which two statements ate true about the Security Fabric rating? (Choose two.)
Question 8

An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
Question 9

Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?
Question 10

Which two statements are correct about NGFW Policy-based mode? (Choose two.)
Question