Fortinet

NSE4_FGT-7.0 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 101-question bank.

Provider
Fortinet
Question bank
101
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE4_FGT-7.0, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which two statements about FortiGate FSSO agentless polling mode are true? (Choose two.)

    Choose all answers that apply.

    • FortiGate uses the AD server as the collector agent.
    • FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
    • FortiGate does not support workstation check.
    • FortiGate directs the collector agent to use a remote LDAP server.
  2. Question 2 · 1

    Which two statements are true about the Security Fabric rating? (Choose two.)

    Choose all answers that apply.

    • The Security Fabric rating is a free service that comes bundled with all FortiGate devices.
    • Many of the security issues can be fixed immediately by clicking Apply where available.
    • The Security Fabric rating must be run on the root FortiGate device in the Security Fabric.
    • It provides executive summaries of the four largest areas of security focus.
  3. Question 3 · 1

    A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not. Which two configuration changes are the most effective way to support this requirement? (Choose two.)

    Choose all answers that apply.

    • Implement web filter quotas for the specified website.
    • Implement a firewall policy with authentication for the specified users.
    • Implement a DNS filter for the specified website.
    • Implement web category authentication for the specified website using a web filter profile.
  4. Question 4 · 1

    Refer to the exhibit to view the firewall policy. Which statement is correct if well-known viruses are not being blocked?

    Choose one answer.

    Question illustration 1
    • The firewall policy must be configured in proxy-based inspection mode.
    • The firewall policy does not apply deep content inspection.
    • The action on the firewall policy must be set to deny.
    • Web filter should be enabled on the firewall policy to complement the antivirus profile.
  5. Question 5 · 1

    You have enabled logging on your FortiGate device for Event logs and all Security logs, and you have set up logging to use the FortiGate local disk. What is the default behavior when the local disk is full?

    Choose one answer.

    • No new log is recorded after the warning is issued when log disk usage reaches the threshold of 95%.
    • Logs are overwritten and the only warning is issued when log disk usage reaches the threshold of 95%.
    • No new log is recorded until you manually clear logs from the local disk.
    • Logs are overwritten and the first warning is issued when log disk usage reaches the threshold of 75%.
  6. Question 6 · 1

    An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)

    Choose all answers that apply.

    • Set the TTL value to never under config system-ttl.
    • Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
    • Create a new service object for HTTP service and set the session TTL to never.
    • Set the session TTL on the HTTP policy to maximum.
  7. Question 7 · 1

    Which security feature does FortiGate provide to protect servers located in the internal networks from attacks such as SQL injections?

    Choose one answer.

    • Denial of Service
    • Web application firewall
    • Antivirus
    • Application control
  8. Question 8 · 1

    What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?

    Choose one answer.

    • Certificate inspection
    • Flow-based inspection
    • Proxy-based inspection
    • Full Content inspection
  9. Question 9 · 1

    Refer to the exhibit. Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?

    Choose one answer.

    Question illustration 1
    • Read/Write permission for Firewall
    • CLI diagnostics commands permission
    • Custom permission for Network
    • Read/Write permission for Log & Report
  10. Question 10 · 1

    An administrator has configured outgoing interface any in a firewall policy. Which statement is true about the policy list view?

    Choose one answer.

    • Interface Pair view will be disabled.
    • Search option will be disabled.
    • Policy lookup will be disabled.
    • By Sequence view will be disabled.
  11. Question 11 · 1

    Refer to the exhibit. Given the interfaces shown in the exhibit, which two statements are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Traffic between port2 and port2-vlan1 is allowed by default.
    • port1-vlan10 and port2-vlan10 are part of the same broadcast domain.
    • port1-vlan1 and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.
    • port1 is a native VLAN.
  12. Question 12 · 1

    Refer to the exhibit. The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster. The override setting is enable for the FortiGate with SN FGVM010000064692. Which two statements are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • FortiGate SN FGVM010000065036 HA uptime has been reset.
    • FortiGate devices are not in sync because one device is down.
    • FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
    • FortiGate SN FGVM010000064692 has the higher HA priority.
  13. Question 13 · 1

    Refer to the exhibits. Exhibit A shows system performance output. Exhibit B shows s FortiGate configured with the default configuration of high memory usage thresholds. Based on the system performance output, which two statements are correct? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • FortiGate will start sending all files to FortiSandbox for inspection.
    • FortiGate has entered conserve mode.
    • Administrators cannot change the configuration.
    • Administrators can access FortiGate only through the console port.
  14. Question 14 · 1

    An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24. Which subnet must the administrator configure for the local quick mode selector for site B?

    Choose one answer.

    • 192.168.3.0/24
    • 192.168.1.0/24
    • 192.168.0.0/8
    • 192.168.2.0/24
  15. Question 15 · 1

    Refer to the exhibits. Exhibit A. Exhibit B. The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Change the SSL VPN port on the client.
    • Change the Server IP address.
    • Change the idle-timeout.
    • Change the SSL VPN portal to the tunnel.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free