Fortinet NSE4_FGT-7.0 Exam Practice Questions (P. 3)
- Full Access (106 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
An administrator has configured outgoing interface any in a firewall policy.
Which statement is true about the policy list view?
Which statement is true about the policy list view?
- AInterface Pair view will be disabled.Most Voted
- BSearch option will be disabled.
- CPolicy lookup will be disabled.
- DBy Sequence view will be disabled.
Correct Answer:
A
A
send
light_mode
delete
Question #12
Refer to the exhibit.

Given the interfaces shown in the exhibit, which two statements are true? (Choose two.)

Given the interfaces shown in the exhibit, which two statements are true? (Choose two.)
- ATraffic between port2 and port2-vlan1 is allowed by default.
- Bport1-vlan10 and port2-vlan10 are part of the same broadcast domain.
- Cport1-vlan1 and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.Most Voted
- Dport1 is a native VLAN.Most Voted
Correct Answer:
CD
CD
send
light_mode
delete
Question #13
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
✑ All traffic must be routed through the primary tunnel when both tunnels are up
✑ The secondary tunnel must be used only if the primary tunnel goes down
In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover

Which two key configuration changes are needed in FortiGate to meet the design requirements? (Choose two.)
✑ All traffic must be routed through the primary tunnel when both tunnels are up
✑ The secondary tunnel must be used only if the primary tunnel goes down
In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover

Which two key configuration changes are needed in FortiGate to meet the design requirements? (Choose two.)
- AConfigure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
- BEnable Dead Peer Detection.Most Voted
- CEnable Auto-negotiate and Auto Keep Alive on the phase 2 configuration of both tunnels.
- DConfigure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.Most Voted
Correct Answer:
BD
BD
send
light_mode
delete
Question #14
Refer to the exhibit.

The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
The override setting is enable for the FortiGate with SN FGVM010000064692.
Which two statements are true? (Choose two.)

The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
The override setting is enable for the FortiGate with SN FGVM010000064692.
Which two statements are true? (Choose two.)
- AFortiGate SN FGVM010000065036 HA uptime has been reset.Most Voted
- BFortiGate devices are not in sync because one device is down.
- CFortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
- DFortiGate SN FGVM010000064692 has the higher HA priority.Most Voted
Correct Answer:
AC
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/666653/primary-unit-selection-with-override-disabled-default
AC
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/666653/primary-unit-selection-with-override-disabled-default
send
light_mode
delete
Question #15
Refer to the exhibits.
Exhibit A shows system performance output.

Exhibit B shows s FortiGate configured with the default configuration of high memory usage thresholds.

Based on the system performance output, which two statements are correct? (Choose two.)
Exhibit A shows system performance output.

Exhibit B shows s FortiGate configured with the default configuration of high memory usage thresholds.

Based on the system performance output, which two statements are correct? (Choose two.)
- AFortiGate will start sending all files to FortiSandbox for inspection.
- BFortiGate has entered conserve mode.Most Voted
- CAdministrators cannot change the configuration.Most Voted
- DAdministrators can access FortiGate only through the console port.
Correct Answer:
BC
Reference:
https://www.skillfulist.com/fortigate/fortigate-conserve-mode-how-to-stop-it-and-what-it-means/
BC
Reference:
https://www.skillfulist.com/fortigate/fortigate-conserve-mode-how-to-stop-it-and-what-it-means/
send
light_mode
delete
All Pages