Fortinet NSE4_FGT-7.0 Exam Practice Questions (P. 4)
- Full Access (106 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address.
For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
- A192.168.3.0/24
- B192.168.1.0/24
- C192.168.0.0/8
- D192.168.2.0/24Most Voted
Correct Answer:
D
D
send
light_mode
delete
Question #17
Refer to the exhibits.
Exhibit A.

Exhibit B.

The SSL VPN connection fails when a user attempts to connect to it.
What should the user do to successfully connect to SSL VPN?
Exhibit A.

Exhibit B.

The SSL VPN connection fails when a user attempts to connect to it.
What should the user do to successfully connect to SSL VPN?
- AChange the SSL VPN port on the client.Most Voted
- BChange the Server IP address.
- CChange the idle-timeout.
- DChange the SSL VPN portal to the tunnel.
Correct Answer:
A
Reference:
https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/150494
A
Reference:
https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/150494
send
light_mode
delete
Question #18
Which two statements about SSL VPN between two FortiGate devices are true? (Choose two.)
- AThe client FortiGate requires a client certificate signed by the CA on the server FortiGate.
- BThe client FortiGate requires a manually added route to remote subnets.
- CThe client FortiGate uses the SSL VPN tunnel interface type to connect SSL VPN.Most Voted
- DServer FortiGate requires a CA certificate to verify the client FortiGate certificate.Most Voted
Correct Answer:
CD
Reference:
https://docs.fortinet.com/document/fortigate/6.2.9/cookbook/266506/ssl-vpn-with-certificate-authentication
CD
Reference:
https://docs.fortinet.com/document/fortigate/6.2.9/cookbook/266506/ssl-vpn-with-certificate-authentication
send
light_mode
delete
Question #19
Refer to the exhibit.

The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem.
With this configuration, which statement is true?

The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem.
With this configuration, which statement is true?
- AInter-VDOM links are required to allow traffic between the Local and Root VDOMs.Most Voted
- BA default static route is not required on the To_Internet VDOM to allow LAN users to access the internet.
- CInter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
- DInter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.
Correct Answer:
AB
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46542
AB
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46542
send
light_mode
delete
Question #20
Refer to the exhibits.
Exhibit A.

Exhibit B.

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?
Exhibit A.

Exhibit B.

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?
- AChange the csf setting on Local-FortiGate (root) to set configuration-sync local.
- BChange the csf setting on ISFW (downstream) to set configuration-sync local.
- CChange the csf setting on Local-FortiGate (root) to set fabric-object-unification default.Most Voted
- DChange the csf setting on ISFW (downstream) to set fabric-object-unification default.
Correct Answer:
C
C
send
light_mode
delete
All Pages