[2023年更新]NSE4_FGT-7.2はFortinet NSE 4リアルな無料試験練習テスト [Q86-Q104]

Share

[2023年更新]NSE4_FGT-7.2はFortinet NSE 4リアルな無料試験練習テスト

無料Fortinet NSE 4 NSE4_FGT-7.2試験問題を提供します


Fortinet NSE4_FGT-7.2認定試験は、Fortinet FortiOS 7.2のさまざまな領域における知識とスキルをテストするために設計された多肢選択問題から構成されています。試験は、ネットワークセキュリティ、ファイアウォール構成、脅威防止などのトピックをカバーしています。試験に合格するには、試験で少なくとも70%のスコアを取得する必要があります。

 

質問 # 86
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?

  • A. Add user accounts to the FortiGate group fitter.
  • B. Add the support of NTLM authentication.
  • C. Add user accounts to the Ignore User List.
  • D. Add user accounts to Active Directory (AD).

正解:C


質問 # 87
Which three CLI commands can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)

  • A. execute traceroute
  • B. execute ping
  • C. get system arp
  • D. diagnose sniffer packet any
  • E. diagnose sys top

正解:A、B、D


質問 # 88
An administrator is running the following sniffer command:
Which three pieces of Information will be Included in me sniffer output? {Choose three.)

  • A. Ethernet header
  • B. Application header
  • C. IP header
  • D. Interface name
  • E. Packet payload

正解:C、D、E


質問 # 89
Refer to the exhibits.
Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.


If the host 10.200.3.1 sends a TCP SYN packet on port 10443 to 10.200.1.10, what will the source address, destination address, and destination port of the packet be, after FortiGate forwards the packet to the destination?

  • A. 10.200.3.1, 10.0.1.10, and 443, respectively
  • B. 10.0.1.254, 10.0.1.10, and 10443, respectively
  • C. 10.0.1.254, 10.0.1.10, and 443, respectively

正解:A


質問 # 90
How does FortiGate act when using SSL VPN in web mode?

  • A. FortiGate acts as an FDS server.
  • B. FortiGate acts as DNS server.
  • C. FortiGate acts as router.
  • D. FortiGate acts as an HTTP reverse proxy.

正解:D

解説:
Reference:
https://pub.kb.fortinet.com/ksmcontent/Fortinet-Public/current/Fortigate_v4.0MR3/fortigate-sslvpn-40-mr3.pdf


質問 # 91
Why does FortiGate keep TCP sessions in the session table for some seconds even after both sides (client and server) have terminated the session?

  • A. To remove the NAT operation.
  • B. To generate logs
  • C. To finish any inspection operations.
  • D. To allow for out-of-order packets that could arrive after the FIN/ACK packets.

正解:D


質問 # 92
What are two benefits of flow-based inspection compared to proxy-based inspection? (Choose two.)

  • A. FortiGate uses fewer resources.
  • B. FortiGate adds less latency to traffic.
  • C. FortiGate allocates two sessions per connection.
  • D. FortiGate performs a more exhaustive inspection on traffic.

正解:A、B


質問 # 93
Refer to the exhibit.




The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200. 1. 1/24.
The LAN (port3) interface has the IP address 10.0. 1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0. 1. 10) pings the IP address of Remote-FortiGate (10.200.3. 1)?

  • A. 10.200. 1.99
  • B. 10.200. 1. 1
  • C. 10.200. 1.49
  • D. 10.200. 1. 149

正解:A


質問 # 94
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded.
What is the reason for the failed virus detection by FortiGate?

  • A. The selected SSL inspection profile has certificate inspection enabled.
  • B. The EICAR test file exceeds the protocol options oversize limit.
  • C. The website is exempted from SSL inspection.
  • D. The browser does not trust the FortiGate self-signed CA certificate.

正解:C、D

解説:
https traffic requires SSL decryption. Check the ssh inspection profile


質問 # 95
Refer to the exhibit.

The exhibit shows the IPS sensor configuration.
If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will reset all connections that match these signatures.
  • B. The sensor will gather a packet log for all matched traffic.
  • C. The sensor will block all attacks aimed at Windows servers.
  • D. The sensor will allow attackers matching the Microsoft Windows.iSCSI.Target.DoS signature.

正解:C、D


質問 # 96
Which scanning technique on FortiGate can be enabled only on the CLI?

  • A. Heuristics scan
  • B. Trojan scan
  • C. Ransomware scan
  • D. Antivirus scan

正解:A


質問 # 97
An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What must an administrator do to achieve this objective?

  • A. The administrator must use a FortiAuthenticator device
  • B. The administrator can use a third-party radius OTP server.
  • C. The administrator must use the user self-registration server.
  • D. The administrator can register the same FortiToken on more than one FortiGate.

正解:A


質問 # 98
FortiGate is configured as a policy-based next-generation firewall (NGFW) and is applying web filtering and application control directly on the security policy. Which two other security profiles can you apply to the security policy? (Choose two.)

  • A. File filter
  • B. Antivirus scanning
  • C. Intrusion prevention
  • D. DNS filter

正解:B、C


質問 # 99
Which statement is correct regarding the use of application control for inspecting web applications?

  • A. Application control does not require SSL inspection to identity web applications.
  • B. Application control signatures are organized in a nonhierarchical structure.
  • C. Application control does not display a replacement message for a blocked web application.
  • D. Application control can identity child and parent applications, and perform different actions on them.

正解:D


質問 # 100
Which feature in the Security Fabric takes one or more actions based on event triggers?

  • A. Fabric Connectors
  • B. Security Rating
  • C. Automation Stitches
  • D. Logical Topology

正解:C


質問 # 101
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.

Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)

  • A. On Remote-FortiGate, set port2 as Interface.
  • B. On both FortiGate devices, set Dead Peer Detection to On Demand.
  • C. On HQ-FortiGate, disable Diffie-Helman group 2.
  • D. On HQ-FortiGate, set IKE mode to Main (ID protection).

正解:A、D


質問 # 102
Which two types of traffic are managed only by the management VDOM? (Choose two.)

  • A. PKI
  • B. Traffic shaping
  • C. FortiGuard web filter queries
  • D. DNS

正解:C、D


質問 # 103
Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. Traffic matching the signature will be allowed and logged.
  • B. Traffic matching the signature will be silently dropped and logged.
  • C. The signature setting includes a group of other signatures.
  • D. The signature setting uses a custom rating threshold.

正解:B

解説:
Action is drop, signature default action is listed only in the signature, it would only match if action was set to default.


質問 # 104
......


Fortinet NSE4_FGT-7.2 認定試験は、ネットワークセキュリティの概念、ファイアウォールポリシー、VPN、ユーザー認証、Fortinetセキュリティソリューションなど、幅広いトピックをカバーしています。この試験は、一般的なネットワークセキュリティの脅威を特定し、セキュリティポリシーと手順を実装し、Fortinetセキュリティソリューションを構成するための知識とスキルを候補者が持っているかどうかをテストするために設計されています。この認定試験は、ネットワークセキュリティの専門家、システム管理者、サイバーセキュリティの分野でキャリアを発展させたいITプロフェッショナルに適しています。

 

Fortinet NSE4_FGT-7.2リアルな問題と知能問題集:https://jp.fast2test.com/NSE4_FGT-7.2-premium-file.html

NSE4_FGT-7.2問題集でFortinet NSE 4高確率練習問題集:https://drive.google.com/open?id=1sykZ8Vr6kayOctfL0PRhVs75KcZIh1ZZ


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어