NSE4_FGT_AD-7.6: Fortinet NSE 4 - FortiOS 7.6 Administrator Fortigate Practice Questions
The free NSE4_FGT_AD-7.6: Fortinet NSE 4 - FortiOS 7.6 Administrator questions that deal with fortigate, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #2
There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels. Which phase 1 setting you can configure to match the user to the tunnel?
Correct answer: C
Explanation
Aggressive mode sends the identifier in the first exchange, so FortiGate can use the peer ID to match each dialup user to the correct department tunnel.
Question #3
Refer to the exhibit. The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team? (Choose one answer)

Correct answer: D
Explanation
The idle timeout can be overridden per administrative profile with admintimeout under config system accprofile, so raising that value for NOC_Access keeps their GUI sessions alive longer.
Question #4
You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab. and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?
Correct answer: B
Explanation
Network protocol enforcement controls which protocols are allowed on known ports, so its configuration determines whether peer-to-peer sessions on those ports are inspected and blocked by the application control category action.
Question #6
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)

Select 2 answers.
Correct answer: A, D
Question #7
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is not part of the expected process?
Correct answer: A
Explanation
In DC agent mode the agent installed on each domain controller sends logon events to the collector agent, which then forwards them to FortiGate; the DC agent never talks to FortiGate directly.
Question #10
Which two statements are correct when FortiGate enters conserve mode? (Choose two answers)
Select 2 answers.
Correct answer: B, D
Explanation
In conserve mode FortiGate stops accepting configuration changes to protect memory, and if the IPS fail-open setting is enabled it keeps forwarding packets without IPS inspection instead of dropping them.
Continue with NSE4_FGT_AD-7.6: Fortinet NSE 4 - FortiOS 7.6 Administrator
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in NSE4_FGT_AD-7.6: Fortinet NSE 4 - FortiOS 7.6 Administrator, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All NSE4_FGT_AD-7.6: Fortinet NSE 4 - FortiOS 7.6 Administrator practice questions →
