Fortinet NSE4_FGT-7.2 Exam Practice Questions (P. 5)
- Full Access (104 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
Which three criteria can FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)
- AServices defined in the firewall policyMost Voted
- BHighest to lowest priority defined in the firewall policy
- CDestination defined as Internet Services in the firewall policyMost Voted
- DLowest to highest policy ID number
- ESource defined as Internet Services in the firewall policyMost Voted
Correct Answer:
ABE
ABE

The FortiGate firewall identifies a matching policy based on specific criteria including the services defined, as well as the source and destination specified as Internet Services in the policy. Each policy is structured to specify what qualifies as matching traffic, emphasizing the importance of configuring these aspects accurately to ensure proper traffic filtering and security measures. Policies are processed in the order they appear, without preference to policy ID, highlighting the need for strategic policy organization. Misconfiguration can lead to unintended traffic flow or security breaches.
send
light_mode
delete
Question #22
What are two functions of ZTNA? (Choose two.)
- AZTNA manages access through the client only.
- BZTNA manages access for remote users only.
- CZTNA provides a security posture check.Most Voted
- DZTNA provides role-based access.Most Voted
Correct Answer:
CD
CD

ZTNA, or Zero Trust Network Access, crucially includes functions like security posture checks and role-based access provisions. Specifically, security posture checks ensure a stringent verification process for devices and users by evaluating their security settings, configurations, and potential threats like malware. Meanwhile, role-based access facilitates secure environment management by allowing user access strictly according to their operational roles, thus effectively minimizing unauthorized access and potential security breaches by adhering to the principle of "never trust, always verify." These elements form the core mechanisms by which ZTNA maintains network integrity and security.
send
light_mode
delete
Question #23
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.
Which type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
Which type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
- APre-shared key
- BDialup userMost Voted
- CDynamic DNS
- DStatic IP address
Correct Answer:
D
D

In the context of IPsec VPN setups on FortiGate when dealing with a remote peer with a dynamic IP address and no support for dynamic DNS, the correct configuration to opt for is typically a "Dialup User." This setup is designed to handle dynamic IPs effectively by allowing the VPN to initiate only when traffic from the remote peer is detected, thus accommodating the changing IP address. Make sure the FortiGate VPN settings are adjusted to recognize and authenticate the dial-up connections appropriately.
send
light_mode
delete
Question #24
Which timeout setting can be responsible for deleting SSL VPN associated sessions?
- ASSL VPN idle-timeoutMost Voted
- BSSL VPN http-request-body-timeout
- CSSL VPN login-timeout
- DSSL VPN dtls-hello-timeout
Correct Answer:
A
A
send
light_mode
delete
Question #25
Which statement is correct regarding the use of application control for inspecting web applications?
- AApplication control can identify child and parent applications, and perform different actions on them.Most Voted
- BApplication control signatures are organized in a nonhierarchical structure.
- CApplication control does not require SSL inspection to identify web applications.
- DApplication control does not display a replacement message for a blocked web application.
Correct Answer:
A
A
send
light_mode
delete
All Pages