Sign In
Home/Fortinet/NSE4_FGT-7.0/Free questions

NSE4_FGT-7.0 — Free Practice Questions

10 free sample questions from a bank of 105, with the correct answers and explanations. No signup required — start practising right now.

1Which two statements about FortiGate FSSO agentless polling mode are true? (Choose two.)
  • FortiGate uses the AD server as the collector agent.
  • FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
  • FortiGate does not support workstation check.
  • FortiGate directs the collector agent to use a remote LDAP server.
Answer: B, C
2Which two statements are true about the Security Fabric rating? (Choose two.)
  • The Security Fabric rating is a free service that comes bundled with all FortiGate devices.
  • Many of the security issues can be fixed immediately by clicking Apply where available.
  • The Security Fabric rating must be run on the root FortiGate device in the Security Fabric.
  • It provides executive summaries of the four largest areas of security focus.
Answer: B, C
3A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not. Which two configuration changes are the most effective way to support this requirement? (Choose two.)
  • Implement web filter quotas for the specified website.
  • Implement a firewall policy with authentication for the specified users.
  • Implement a DNS filter for the specified website.
  • Implement web category authentication for the specified website using a web filter profile.
Answer: B, D
4Refer to the exhibit to view the firewall policy. Which statement is correct if well-known viruses are not being blocked?
NSE4_FGT-7.0 question 4
  • The firewall policy must be configured in proxy-based inspection mode.
  • The firewall policy does not apply deep content inspection.
  • The action on the firewall policy must be set to deny.
  • Web filter should be enabled on the firewall policy to complement the antivirus profile.
Answer: B
5You have enabled logging on your FortiGate device for Event logs and all Security logs, and you have set up logging to use the FortiGate local disk. What is the default behavior when the local disk is full?
  • No new log is recorded after the warning is issued when log disk usage reaches the threshold of 95%.
  • Logs are overwritten and the only warning is issued when log disk usage reaches the threshold of 95%.
  • No new log is recorded until you manually clear logs from the local disk.
  • Logs are overwritten and the first warning is issued when log disk usage reaches the threshold of 75%.
Answer: D
6An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)
  • Set the TTL value to never under config system-ttl.
  • Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
  • Create a new service object for HTTP service and set the session TTL to never.
  • Set the session TTL on the HTTP policy to maximum.
Answer: B, C
7Which security feature does FortiGate provide to protect servers located in the internal networks from attacks such as SQL injections?
  • Denial of Service
  • Web application firewall
  • Antivirus
  • Application control
Answer: B
8What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?
  • Certificate inspection
  • Flow-based inspection
  • Proxy-based inspection
  • Full Content inspection
Answer: B
9Refer to the exhibit. Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
NSE4_FGT-7.0 question 9
  • Read/Write permission for Firewall
  • CLI diagnostics commands permission
  • Custom permission for Network
  • Read/Write permission for Log & Report
Answer: B
10An administrator has configured outgoing interface any in a firewall policy. Which statement is true about the policy list view?
  • Interface Pair view will be disabled.
  • Search option will be disabled.
  • Policy lookup will be disabled.
  • By Sequence view will be disabled.
Answer: A

Want the full bank of 105 questions for NSE4_FGT-7.0? See all practice exams.