Oct-2023 FREE Fortinet NSE4_FGT-7.2 PRACTICE QUESTIONS AND ANSWERS UPDATES
DEMO FREE BEFORE YOU BUY NSE4_FGT-7.2 DUMPS
Fortinet NSE4_FGT-7.2 (Fortinet NSE 4 - FortiOS 7.2) Certification Exam is a valuable certification for IT professionals who are interested in network security. NSE4_FGT-7.2 exam covers a wide range of topics related to network security and requires a deep understanding of Fortinet's FortiOS 7.2 operating system. Fortinet NSE 4 - FortiOS 7.2 certification is recognized by the industry as a valuable credential for network security professionals and is highly regarded by employers.
The Fortinet NSE4_FGT-7.2 exam covers a broad range of topics related to network security, including network security concepts, firewall policies and configurations, VPN configurations, and security fabric components. To pass the exam, candidates must demonstrate a deep understanding of these topics and be able to apply them in real-world scenarios.
NEW QUESTION # 92
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?
- A. Add user accounts to the Ignore User List.
- B. Add the support of NTLM authentication.
- C. Add user accounts to Active Directory (AD).
- D. Add user accounts to the FortiGate group fitter.
Answer: A
NEW QUESTION # 93
Which statements about the firmware upgrade process on an active-active HA cluster are true? (Choose two.)
- A. The firmware image must be manually uploaded to each FortiGate.
- B. Only secondary FortiGate devices are rebooted.
- C. Traffic load balancing is temporally disabled while upgrading the firmware.
- D. Uninterruptable upgrade is enabled by default.
Answer: C,D
NEW QUESTION # 94
On FortiGate, which type of logs record information about traffic directly to and from the FortiGate management IP addresses?
- A. System event logs
- B. Security logs
- C. Forward traffic logs
- D. Local traffic logs
Answer: D
NEW QUESTION # 95
An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
- A. Configure split tunneling in tunnel mode.
- B. Configure host check .
- C. Configure different SSL VPN realms.
- D. Configure Source IP Pools.
Answer: B
NEW QUESTION # 96
Examine the exhibit, which contains a virtual IP and firewall policy configuration.

The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port2) interface has the IP address 10.0. 1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0. 1. 10/24?
- A. Any available IP address in the WAN (port1) subnet 10.200. 1.0/24
66 of 108 - B. 10.200. 1. 1
- C. 10.200. 1. 10
- D. 10.0. 1.254
Answer: C
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Objects/Virtual%20IPs.
NEW QUESTION # 97
Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)
- A. The client FortiGate requires a manually added route to remote subnets.
- B. The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
- C. The client FortiGate uses the SSL VPN tunnel interface type to connect SSL VPN.
- D. The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
Answer: B,C
Explanation:
https://docs.fortinet.com/document/fortigate/7.0.9/administration-guide/508779/fortigate-as-ssl-vpn-client
NEW QUESTION # 98
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
* All traffic must be routed through the primary tunnel when both tunnels are up
* The secondary tunnel must be used only if the primary tunnel goes down
* In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)
- A. Enable Dead Peer Detection.
- B. Configure a high distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
- C. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
- D. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
Answer: A,C
Explanation:
Explanation
Study Guide - IPsec VPN - IPsec configuration - Phase 1 Network.
When Dead Peer Detection (DPD) is enabled, DPD probes are sent to detect a failed tunnel and bring it down before its IPsec SAs expire. This failure detection mechanism is very useful when you have redundant paths to the same destination, and you want to failover to a backup connection when the primary connection fails to keep the connectivity between the sites up.
There are three DPD modes. On demand is the default mode.
Study Guide - IPsec VPN - Redundant VPNs.
Add one phase 1 configuration for each tunnel. DPD should be enabled on both ends.
Add at least one phase 2 definition for each phase 1.
Add one static route for each path. Use distance or priority to select primary routes over backup routes (routes for the primary VPN must have a lower distance or lower priority than the backup). Alternatively, use dynamic routing.
Configure FW policies for each IPsec interface.
NEW QUESTION # 99
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded.
What is the reason for the failed virus detection by FortiGate?
- A. The selected SSL inspection profile has certificate inspection enabled.
- B. The EICAR test file exceeds the protocol options oversize limit.
- C. The browser does not trust the FortiGate self-signed CA certificate.
- D. The website is exempted from SSL inspection.
Answer: C,D
Explanation:
Explanation
https traffic requires SSL decryption. Check the ssh inspection profile
NEW QUESTION # 100
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On Remote-FortiGate, set port2 as Interface.
- B. On HQ-FortiGate, set IKE mode to Main (ID protection).
- C. On both FortiGate devices, set Dead Peer Detection to On Demand.
- D. On HQ-FortiGate, disable Diffie-Helman group 2.
Answer: A,B
NEW QUESTION # 101
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
- A. It limits the scanning of application traffic to the DNS protocol only.
- B. It limits the scanning of application traffic to the browser-based technology category only.
- C. It limits the scanning of application traffic to the application category only.
- D. It limits the scanning of application traffic to use parent signatures only.
Answer: B
Explanation:
FortiGate Security 7.2 Study Guide (p.317): "You can configure the URL Category within the same security policy; however, adding a URL filter causes application control to scan applications in only the browser-based technology category, for example, Facebook Messenger on the Facebook website."
NEW QUESTION # 102
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network and the firewall policy and IP pool configuration on the FortiGate device.
Which two actions does FortiGate take on internet traffic sourced from the subscribers? (Choose two.)
- A. FortiGate allocates 128 port blocks per user.
- B. FortiGate allocates port blocks on a first-come, first-served basis.
- C. FortiGate generates a system event log for every port block allocation made per user.
- D. FortiGate allocates port blocks per user, based on the configured range of internal IP addresses.
Answer: A,D
NEW QUESTION # 103
Refer to the exhibit.
Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
- A. The IPS engine was inspecting high volume of traffic.
- B. The IPS engine was blocking all traffic.
- C. The IPS engine was unable to prevent an intrusion attack .
- D. The IPS engine will continue to run in a normal state.
Answer: A
NEW QUESTION # 104
Refer to the exhibit.
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)
- A. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
- B. FortiGate devices are not in sync because one device is down.
- C. FortiGate SN FGVM010000064692 has the higher HA priority.
- D. FortiGate SN FGVM010000065036 HA uptime has been reset.
Answer: C,D
Explanation:
Explanation
1. Override is disable by default - OK
2. "If the HA uptime of a device is AT LEAST FIVE MINUTES (300 seconds) MORE than the HA Uptime of the other FortiGate devices, it becomes the primary" The question here is : HA Uptime of FGVM01000006492 > 5 minutes? NO - 198 seconds <
300 seconds (5 minutes) Page 314 Infra Study Guide.
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/666653/primary-unit-selection-with-override-disab
NEW QUESTION # 105
By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers.
Which CLI command will cause FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering?
- A. set webfilter-cache disable
- B. set fortiguard-anycast disable
- C. set webfilter-force-off disable
- D. set protocol tcp
Answer: B
Explanation:
y default, "fortiguard-anycast" is enabled, and this setting only works with "set protocol https". To use udp (ie. "set protocol udp"), "fortiguard-anycast" must be disabled.
Reference:
"By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."
NEW QUESTION # 106
Which two types of traffic are managed only by the management VDOM? (Choose two.)
- A. PKI
- B. FortiGuard web filter queries
- C. Traffic shaping
- D. DNS
Answer: B,D
NEW QUESTION # 107
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network and the firewall policy and IP pool configuration on the FortiGate device.
Which two actions does FortiGate take on internet traffic sourced from the subscribers? (Choose two.)
- A. FortiGate allocates 128 port blocks per user.
- B. FortiGate allocates port blocks on a first-come, first-served basis.
- C. FortiGate generates a system event log for every port block allocation made per user.
- D. FortiGate allocates port blocks per user, based on the configured range of internal IP addresses.
Answer: A,D
NEW QUESTION # 108
......
Latest Fortinet NSE4_FGT-7.2 Dumps with Test Engine and PDF: https://torrentpdf.exam4tests.com/NSE4_FGT-7.2-pdf-braindumps.html