Fortinet FCP_FGT_AD-7.4 Exam Notes
13 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Refer to the exhibit. Which route will be selected when trying to reach 10.20.30.254?

  • 0.0.0.0/0 [10/0] via 172.20.121.2, port1, [1/0]
  • 10.30.20.0/24 [10/0] via 172.20.121.2, port1, [1/0]
  • 10.20.30.0/24 [10/0] via 172.20.167.254, port3, [1/0] (correct)
  • 10.20.30.0/26 [10/0] via 172.20.168.254, port2, [1/0]
  • Which two IP pool types are useful for carrier-grade NAT deployments? (Choose two.)

  • Fixed port range (correct)
  • Overload
  • Port block allocation (correct)
  • One-to-one
  • What is eXtended Authentication (XAuth)?

  • It is an IPsec extension that authenticates remote VPN peers using a pre-shared key.
  • It is an IPsec extension that forces remote VPN users to authenticate using their credentials (username and password). (correct)
  • It is an IPsec extension that forces remote VPN users to authenticate using their local ID.
  • It is an IPsec extension that authenticates remote VPN peers using digital certificates.
  • What must you configure to enable proxy-based TCP session failover?

    <p>You must configure session-pickup-enable under configure system ha.</p> Signup and view all the answers

    An administrator needs to inspect all web traffic (including Internet web traffic) coming from users connecting to the SSL-VPN. How can this be achieved?

    <p>Disabling split tunneling</p> Signup and view all the answers

    Which NAT method translates the source IP address in a packet to another IP address?

    <p>SNAT</p> Signup and view all the answers

    What is the common feature shared between IPv4 and SD-WAN ECMP algorithms?

    <p>Both control ECMP algorithms.</p> Signup and view all the answers

    Refer to the exhibit. Which statement about the configuration settings is true?

    <p>When a remote user accesses <a href="https://10.200.1.1:443">https://10.200.1.1:443</a>, the SSL-VPN login page opens.</p> Signup and view all the answers

    What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

    <p>It limits the scanning of application traffic to the browser-based technology category only.</p> Signup and view all the answers

    Refer to the exhibits. Which policy will be highlighted, based on the input criteria?

    <p>Policy with ID 5.</p> Signup and view all the answers

    FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface. In this scenario, what are two requirements for the VLAN ID? (Choose two.)

    <p>The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.</p> Signup and view all the answers

    An administrator has configured a strict RPF check on FortiGate. How does strict RPF check work?

    <p>Strict RPF checks the best route back to the source using the incoming interface.</p> Signup and view all the answers

    An administrator has configured the following settings: config system settings set ses-denied-traffic enable end config system global set block-session-timer 30 end What are the two results of this configuration? (Choose two.)

    <p>A session for denied traffic is created.</p> Signup and view all the answers

    Study Notes

    Fortinet FCP_FGT_AD-7.4 Exam Notes

    • Exam is about Fortinet Network Security Expert
    • Exam contains 232 questions
    • Exam covers topics like routing tables, IP pool types, NAT methods, authentication, and firewall policies for carrier-grade NAT deployments.

    Studying That Suits You

    Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

    Quiz Team

    Related Documents

    Description

    Prepare for the Fortinet Network Security Expert exam with these comprehensive notes. Covering essential topics such as routing tables, NAT methods, and firewall policies, this resource will help you tackle the 232 questions effectively. Ideal for anyone looking to excel in network security expertise.

    More Like This

    Fortinet NSE7_OTS-7.2 Exam Preparation
    5 questions
    Fortinet NSE6_FWB-6.4 Exam Preparation
    8 questions
    Use Quizgecko on...
    Browser
    Browser