Fortinet NSE4_FGT_AD-7.6 - Fortinet NSE 4 - FortiOS 7.6 Administrator Exam

Question #11 (Topic: Exam A)
Refer to the exhibit.

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit.
For which two reasons are these web categories exempted? (Choose two.)
A. The FortiGate temporary certificate denies the browser’s access to websites that use HTTP Strict Transport Security. B. The resources utilization is optimized because these websites are in the trusted domain list on FortiGate. C. These websites are in an allowlist of reputable domain names maintained by FortiGuard. D. The legal regulation aims to prioritize user privacy and protect sensitive information for these websites.
Answer: AD
Question #12 (Topic: Exam A)
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
A. FortiGate does not support workstation check. B. FortiGate directs the collector agent to use a remote LDAP server. C. FortiGate uses the AD server as the collector agent. D. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
Answer: AD
Question #13 (Topic: Exam A)
Refer to the exhibit.

Which two ways can you view the log messages shown in the exhibit? (Choose two.)
A. By right clicking the implicit deny policy B. By filtering the policy universally unique identifier (UUID) and application name in the log entry C. Using the FortiGate CLI command diagnose log test D. In the Forward Traffic section
Answer: BD
Question #14 (Topic: Exam A)
Refer to the exhibit.
A partial cloud topology is shown.

You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS.
During the deployment, which components must be FortiGate CNF create to handle traffic from the EC2 instance?
A. The GWLB, GWLBe, and the internet gateway (IGW) in the customer VPC B. The CNF VPC, customer VPC, and GWLB C. The customer VPC and GWLBe D. The gateway load balancer endpoint (GWLBe) in the customer virtual private cloud (VPC)
Answer: D
Question #15 (Topic: Exam A)
You have configured the below commands on a FortiGate.

What would be the impact of this configuration on FortiGate?
A. FortiGate will enable strict RPF on all its interfaces and port1 will be enable for asymmetric routing. B. Port1 will be enabled with flexible RPF, and all other interfaces will be enabled for strict RPF. C. FortiGate will enable strict RPF on all its interfaces and port1 will be exempted from RPF checks. D. The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces.
Answer: C
Download Exam
Page: 3 / 17
Total 84 questions