NSE4_FGT-7.2 Sample Practice Exam Questions 2023 Updated Verified
Exam Study Guide Free Practice Test LAST UPDATED NSE4_FGT-7.2
Fortinet NSE4_FGT-7.2 exam is designed for IT professionals who want to prove their knowledge and skills in deploying and managing Fortinet security solutions. Fortinet NSE 4 - FortiOS 7.2 certification exam is intended for network and security professionals who are responsible for configuring and monitoring Fortinet security devices and implementing security policies. The Fortinet NSE4_FGT-7.2 exam is a comprehensive test that covers different topics related to Fortinet security products and services.
Achieving the Fortinet NSE4_FGT-7.2 certification demonstrates that an IT professional has a deep understanding of Fortinet security solutions and can effectively manage and troubleshoot them. Fortinet NSE 4 - FortiOS 7.2 certification enhances the credibility and marketability of IT professionals, making them stand out in the competitive job market. IT professionals with this certification can expect to earn higher salaries and have more career growth opportunities.
NEW QUESTION # 86
Which three methods are used by the collector agent for AD polling? (Choose three.)
- A. Novell API
- B. WMI
- C. WinSecLog
- D. NetAPI
- E. FortiGate polling
Answer: B,C,D
NEW QUESTION # 87
Which three statements are true regarding session-based authentication? (Choose three.)
- A. It is not recommended if multiple users are behind the source NAT
- B. HTTP sessions are treated as a single user.
- C. It requires more resources.
- D. IP sessions from the same source IP address are treated as a single user.
- E. It can differentiate among multiple clients behind the same source IP address.
Answer: B,C,E
NEW QUESTION # 88
Refer to the exhibit.
Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
- A. CLI diagnostics commands permission
- B. Read/Write permission for Log & Report
- C. Custom permission for Network
- D. Read/Write permission for Firewall
Answer: A
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD50220
NEW QUESTION # 89
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?
- A. Static domain filter, SSL inspection filter, and external connectors filters
- B. DNS-based web filter and proxy-based web filter
- C. FortiGuard category filter and rating filter
- D. Static URL filter, FortiGuard category filter, and advanced filters
Answer: D
NEW QUESTION # 90
Examine the exhibit, which contains a virtual IP and firewall policy configuration.

The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port2) interface has the IP address 10.0. 1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0. 1. 10/24?
- A. Any available IP address in the WAN (port1) subnet 10.200. 1.0/24
66 of 108 - B. 10.200. 1. 1
- C. 10.200. 1. 10
- D. 10.0. 1.254
Answer: C
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Objects/Virtual%20IPs.
NEW QUESTION # 91
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings.
What is true about the DNS connection to a FortiGuard server?
- A. It uses UDP 53.
- B. It uses DNS over HTTPS.
- C. It uses DNS overTLS.
- D. It uses UDP 8888.
Answer: A
NEW QUESTION # 92
Which statement regarding the firewall policy authentication timeout is true?
- A. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets coming from the user's source IP.
- B. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets coming from the user's source MAC.
- C. It is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address after this timer has expired.
- D. It is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address after this timer has expired.
Answer: A
NEW QUESTION # 93
If the Services field is configured in a Virtual IP (VIP), which statement is true when central NAT is used?
- A. The Services field removes the requirement to create multiple VIPs for different services.
- B. The Services field prevents SNAT and DNAT from being combined in the same policy.
- C. The Services field prevents multiple sources of traffic from using multiple services to connect to a single computer.
- D. The Services field is used when you need to bundle several VIPs into VIP groups.
Answer: A
NEW QUESTION # 94
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
- A. It limits the scanning of application traffic to the application category only.
- B. It limits the scanning of application traffic to the DNS protocol only.
- C. It limits the scanning of application traffic to the browser-based technology category only.
- D. It limits the scanning of application traffic to use parent signatures only.
Answer: C
Explanation:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-mode
NEW QUESTION # 95
FortiGate is configured as a policy-based next-generation firewall (NGFW) and is applying web filtering and application control directly on the security policy. Which two other security profiles can you apply to the security policy? (Choose two.)
- A. Intrusion prevention
- B. DNS filter
- C. File filter
- D. Antivirus scanning
Answer: A,D
NEW QUESTION # 96
Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).

Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?
- A. The volume of traffic being inspected is too high for this model of FortiGate.
- B. The firewall policy performs the full content inspection on the file.
- C. The intrusion prevention security profile needs to be enabled when using flow-based inspection mode.
- D. The flow-based inspection is used, which resets the last packet to the user.
Answer: D
Explanation:
* "ONLY" If the virus is detected at the "START" of the connection, the IPS engine sends the block replacement message immediately
* When a virus is detected on a TCP session (FIRST TIME), but where "SOME PACKETS" have been already forwarded to the receiver, FortiGate "resets the connection" and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a "SECOND ATTEMPT" to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
In flow mode, the FortiGate drops the last packet killing the file. But because of that the block replacement message cannot be displayed. If the file is attempted to download again the block message will be shown.
NEW QUESTION # 97
Refer to the exhibit.
Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
- A. The IPS engine will continue to run in a normal state.
- B. The IPS engine was unable to prevent an intrusion attack .
- C. The IPS engine was inspecting high volume of traffic.
- D. The IPS engine was blocking all traffic.
Answer: C
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/232929/troubleshooting-high-cpu-usage
NEW QUESTION # 98
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
* All traffic must be routed through the primary tunnel when both tunnels are up
* The secondary tunnel must be used only if the primary tunnel goes down
* In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)
- A. Enable Dead Peer Detection.
- B. Configure a high distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
- C. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
- D. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
Answer: A,D
Explanation:
Study Guide - IPsec VPN - IPsec configuration - Phase 1 Network.
When Dead Peer Detection (DPD) is enabled, DPD probes are sent to detect a failed tunnel and bring it down before its IPsec SAs expire. This failure detection mechanism is very useful when you have redundant paths to the same destination, and you want to failover to a backup connection when the primary connection fails to keep the connectivity between the sites up.
There are three DPD modes. On demand is the default mode.
Study Guide - IPsec VPN - Redundant VPNs.
Add one phase 1 configuration for each tunnel. DPD should be enabled on both ends.
Add at least one phase 2 definition for each phase 1.
Add one static route for each path. Use distance or priority to select primary routes over backup routes (routes for the primary VPN must have a lower distance or lower priority than the backup). Alternatively, use dynamic routing.
Configure FW policies for each IPsec interface.
NEW QUESTION # 99
An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel.
Which DPD mode on FortiGate will meet the above requirement?
- A. Disabled
- B. Enabled
- C. On Demand
- D. On Idle
Answer: D
NEW QUESTION # 100
Which two inspection modes can you use to configure a firewall policy on a profile-based next-generation firewall (NGFW)? (Choose two.)
- A. Proxy-based inspection
- B. Certificate inspection
- C. Full Content inspection
- D. Flow-based inspection
Answer: A,D
NEW QUESTION # 101
If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy?
- A. IP address
- B. Once Internet Service is selected, no other object can be added
- C. FQDN address
- D. User or User Group
Answer: B
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.2.5/cookbook/179236/using-internet-service-in-policy
NEW QUESTION # 102
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router.
When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.
Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?
- A. Enable port forwarding on the server to map the external service port to the internal service port.
- B. In the VIP configuration, enable arp-reply.
- C. Configure a loopback interface with address 203.0.113.2/32.
- D. In the firewall policy configuration, enable match-vip.
Answer: D
NEW QUESTION # 103
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
- A. The operation mode is transparent.
- B. The interface is a member of a virtual wire pair.
- C. Captive portal is enabled in the interface.
- D. The interface has been configured for one-arm sniffer.
- E. The interface is a member of a zone.
Answer: A,B,D
Explanation:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm
NEW QUESTION # 104
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On HQ-FortiGate, set IKE mode to Main (ID protection).
- B. On both FortiGate devices, set Dead Peer Detection to On Demand.
- C. On Remote-FortiGate, set port2 as Interface.
- D. On HQ-FortiGate, disable Diffie-Helman group 2.
Answer: A,C
NEW QUESTION # 105
......
Fortinet NSE4_FGT-7.2 (Fortinet NSE 4 - FortiOS 7.2) Certification Exam is an essential certification for IT professionals who specialize in network security. NSE4_FGT-7.2 exam tests the candidate's knowledge and skills in deploying, configuring, and managing security solutions using Fortinet FortiOS 7.2, making them a valuable asset to any organization. Fortinet NSE 4 - FortiOS 7.2 certification is recognized globally and is highly respected in the IT industry, making it an excellent choice for professionals who want to enhance their career prospects.
The New NSE4_FGT-7.2 2023 Updated Verified Study Guides & Best Courses: https://www.test4cram.com/NSE4_FGT-7.2_real-exam-dumps.html
Authentic NSE4_FGT-7.2 Exam Dumps PDF - 2023 Updated: https://drive.google.com/open?id=1qnJw_1mybic8o_a1SpXC1GvrhP1KC33Z