Fortinet NSE 4 - FortiOS 7.2 - NSE4_FGT-7.2 Exam Practice Test

Question 1
Refer to the exhibit.

Which contains a session list output. Based on the information shown in the exhibit, which statement is true?

Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 2
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)

Correct Answer: C,D,E
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 3
Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).


Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 4
On FortiGate, which type of logs record information about traffic directly to and from the FortiGate management IP addresses?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 5
Refer to the exhibits.


Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default configuration of high memory usage thresholds. Based on the system performance output, which two statements are correct? (Choose two.)

Correct Answer: B,D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 6
Refer to the exhibits.


An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?

Correct Answer: C
Question 7
Examine the exhibit, which contains a virtual IP and firewall policy configuration.


The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port2) interface has the IP address 10.0. 1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0. 1. 10/24?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 8
What are two scanning techniques supported by FortiGate? (Choose two.)

Correct Answer: A,C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 9
An administrator has configured the following settings:

What are the two results of this configuration? (Choose two.)

Correct Answer: A,B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 10
Which certificate value can FortiGate use to determine the relationship between the issuer and the certificate?

Correct Answer: B
Question 11
What is a reason for triggering IPS fail open?

Correct Answer: A