Fortinet

NSE4_FGT-7.2 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 103-question bank.

Provider
Fortinet
Question bank
103
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE4_FGT-7.2, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

    Choose one answer.

    • It limits the scanning of application traffic to the browser-based technology category only.
    • It limits the scanning of application traffic to the DNS protocol only.
    • It limits the scanning of application traffic to use parent signatures only.
    • It limits the scanning of application traffic to the application category only.
  2. Question 2 · 1

    An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24. Which subnet must the administrator configure for the local quick mode selector for site B?

    Choose one answer.

    • 192.168.2.0/24
    • 192.168.0.0/8
    • 192.168.1.0/24
    • 192.168.3.0/24
  3. Question 3 · 1

    How can you disable RPF checking?

    Choose one answer.

    • Disable fail-detect on the interface level settings.
    • Disable strict-src-check under system settings.
    • Unset fail-alert-interfaces on the interface level settings.
    • Disable src-check on the interface level settings.
  4. Question 4 · 1

    An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What must the administrator do to achieve this objective?

    Choose one answer.

    • The administrator must register the same FortiToken on more than one FortiGate device.
    • The administrator must use the user self-registration server.
    • The administrator must use a FortiAuthenticator device.
    • The administrator must use a third-party RADIUS OTP server.
  5. Question 5 · 1

    Refer to the exhibits. Exhibit A shows a network diagram. Exhibit B shows the central SNAT policy and IP pool configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. A firewall policy is configured to allow all destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching central SNAT policies will be applied. Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • 10.200.1.99
    • 10.200.1.1
    • 10.200.1.49
    • 10.200.1.149
  6. Question 6 · 1

    Refer to the exhibits. The exhibits contain a network interface configuration, firewall policies, and a CLI console configuration. How will the FortiGate device handle user authentication for traffic that arrives on the LAN interface?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • All users will be prompted for authentication; users from the HR group can authenticate successfully with the correct credentials.
    • If there is a fall-through policy in place, users will not be prompted for authentication.
    • All users will be prompted for authentication; users from the sales group can authenticate successfully with the correct credentials.
    • Authentication is enforced only at a policy level; all users will be prompted for authentication.
  7. Question 7 · 1

    Refer to the exhibit. In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output shown in the exhibit. What should the administrator do next, to troubleshoot the problem?

    Choose one answer.

    Question illustration 1
    • Execute a debug flow.
    • Capture the traffic using an external sniffer connected to port1.
    • Execute another sniffer on FortiGate, this time with the filter "host 10.0.1.10".
    • Run a sniffer on the web server.
  8. Question 8 · 1

    Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)

    Choose all answers that apply.

    • The client FortiGate requires a manually added route to remote subnets.
    • The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
    • The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
    • The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
  9. Question 9 · 1

    Which statement correctly describes the use of reliable logging on FortiGate?

    Choose one answer.

    • Reliable logging is enabled by default in all configuration scenarios.
    • Reliable logging is required to encrypt the transmission of logs.
    • Reliable logging can be configured only using the CLI.
    • Reliable logging prevents the loss of logs when the local disk is full.
  10. Question 10 · 1

    Refer to the exhibits. The exhibits contain a network diagram, and virtual IP, IP pool, and firewall policies configuration information. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The first firewall policy has NAT enabled using IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.1.10?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • 10.200.1.1
    • 10.0.1.254
    • 10.200.1.10
    • 10.200.1.100
  11. Question 11 · 1

    Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router. When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output. Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?

    Choose one answer.

    Question illustration 1
    • Configure a loopback interface with address 203.0.113.2/32.
    • In the VIP configuration, enable arp-reply.
    • Enable port forwarding on the server to map the external service port to the internal service port.
    • In the firewall policy configuration, enable match-vip.
  12. Question 12 · 1

    Which two statements are true about the FGCP protocol? (Choose two.)

    Choose all answers that apply.

    • FGCP elects the primary FortiGate device.
    • FGCP is not used when FortiGate is in transparent mode.
    • FGCP runs only over the heartbeat links.
    • FGCP is used to discover FortiGate devices in different HA groups.
  13. Question 13 · 1

    A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover. Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)

    Choose all answers that apply.

    • Configure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
    • Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
    • Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
    • Enable Dead Peer Detection.
  14. Question 14 · 1

    What are two benefits of flow-based inspection compared to proxy-based inspection? (Choose two.)

    Choose all answers that apply.

    • FortiGate uses fewer resources.
    • FortiGate performs a more exhaustive inspection on traffic.
    • FortiGate adds less latency to traffic.
    • FortiGate allocates two sessions per connection.
  15. Question 15 · 1

    Refer to exhibit. An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page. Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?

    Choose one answer.

    Question illustration 1
    • On the FortiGuard Category Based Filter configuration, set Action to Warning for Social Networking.
    • On the Static URL Filter configuration, set Type to Simple.
    • On the Static URL Filter configuration, set Action to Exempt.
    • On the Static URL Filter configuration, set Action to Monitor.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free