NSE4_FGT_AD-7.6練習テスト問題解答には更新された100問があります [Q33-Q54]

Share

NSE4_FGT_AD-7.6練習テスト問題解答には更新された100問があります

NSE4_FGT_AD-7.6問題集はFortinet NSE 4合格確定させる練習で100問があります

質問 # 33
Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.)

  • A. Checksums of devices will be different from each other because some configuration items are not synced to other HA members.
  • B. Incremental configuration synchronization can occur only from changes made on the primary FortiGate device.
  • C. Incremental configuration synchronization can occur from changes made on any FortiGate device within the HA cluster.
  • D. Checksums of devices are compared against each other to ensure configurations are the same.

正解:C、D

解説:
After the initial synchronization is complete, whenever a change is made to the configuration of an HA cluster device (primary or secondary), incremental synchronization sends the same configuration change to all other cluster devices over the HA heartbeat link.


質問 # 34
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.
What is the reason for the certificate warning errors?

  • A. The matching firewall policy is set to proxy inspection mode.
  • B. The browser does not trust the certificate used by FortiGate for SSL inspection.
  • C. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
  • D. The option invalid SSL certificates is set to allow on the SSL/SSH inspection profile

正解:B

解説:
When full SSL inspection is enabled, FortiGate decrypts and re-signs HTTPS traffic using its own SSL inspection certificate. If the FortiGate CA certificate is not imported and trusted by the client's browser or OS, the browser sees it as untrusted and displays certificate warning errors. HTTP traffic is unaffected since it does not use certificates.


質問 # 35
Refer to the exhibit. Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)

  • A. A packet with the source IP address 10.100.110.10arriving on port3 is allowed if strict RPF is disabled.
  • B. A packet with the source IP address 10.0.13.10arriving on port2 is allowed if strict RPF is disabled.
  • C. A packet with the source IP address 10.10.10.10arriving on port2 is allowed if strict RPF is enabled.
  • D. A packet with the source IP address 10.100.110.10arriving on port2 is allowed if strict RPF is enabled.

正解:A、B

解説:
With strict RPF disabled, asymmetric routing is allowed. So, a packet sourced from
10.100.110.10 (not present in the routing table) and arriving on port3 will be accepted as long as a return route exists (default route via port2).
With strict RPF disabled, a packet from 10.0.13.10 arriving on port2 is also allowed, even though the routing table expects it to come via port6, since the system does not enforce the interface check without strict RPF.


質問 # 36
You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic.
In which two ways can you effectively resolve the problem? (Choose two.)

  • A. You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 or 4500).
  • B. You can turn on fragmentation to fix large certificate negotiation problems.
  • C. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP ports.
  • D. You should use the protocol IKEv2.

正解:A、D

解説:
Using SSL VPN tunnel mode avoids issues with blocked ESP (IP protocol 50) and UDP ports (500/4500), since SSL VPN uses HTTPS (TCP 443), which is usually allowed.
Switching to IKEv2 helps with NAT traversal and firewall compatibility because it supports UDP encapsulation on port 4500 and is more robust than IKEv1.


質問 # 37
An administrator suspects that the Collector Agent is not forwarding login events to FortiGate.
What is the most effective troubleshooting step?

  • A. Check if TCP port 8000 is open between the collector agent and FortiGate.
  • B. Verify if DC agent is enabled on the FortiGate.
  • C. Restart the domain controller to refresh authentication services.
  • D. Verify if FortiGate is set to use LDAP authentication instead of FSSO.

正解:A

解説:
The Collector Agent communicates with FortiGate over TCP port 8000. Ensuring this port is open and reachable is essential for forwarding login events.


質問 # 38
Refer to the exhibit. As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?

  • A. Administrator entered the command diagnose test application ipsmonitor 99.
  • B. FortiGate entered into IPS fail open state.
  • C. Administrator entered the command diagnose test application ipsmonitor 5.
  • D. There is a no firewall policy configured with an IPS security profile.

正解:D

解説:
The output shows the IPS engine count as 0, indicating no active IPS engines are running. This typically means no firewall policy is referencing the IPS security profile, so the IPS profile is not being applied or triggered.


質問 # 39
Refer to the exhibit, which shows a partial configuration from the remote authentication server.

Why does the FortiGate administrator need this configuration?

  • A. To authenticate only the Training user group.
  • B. To set up a RADIUS server Secret.
  • C. To authenticate Any FortiGate user groups.
  • D. To authenticate and match the Training OU on the RADIUS server.

正解:A

解説:
The Fortinet-Group-Name attribute is used to restrict authentication to users who belong specifically to the "Training" user group on the RADIUS server.


質問 # 40
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?

  • A. Enabled
  • B. Disabled
  • C. On Idle
  • D. On Demand

正解:D

解説:
Disable: Disable Dead Peer Detection.
On-idle: Trigger Dead Peer Detection when no IPsec traffic is received.
On-demand: Trigger Dead Peer Detection when no IPsec traffic is received AND FortiGate has been sending IPsec traffic. On-demand is the default setting.


質問 # 41
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)

  • A. FortiGate uses the AD server as the collector agent.
  • B. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
  • C. FortiGate directs the collector agent to use a remote LDAP server.
  • D. FortiGate does not support workstation check.

正解:A、B

解説:
FortiGate uses the SMB protocol to read the event viewer logs from the DCs → In agentless polling mode, FortiGate connects directly to the AD domain controllers using SMB to collect logon events.
FortiGate uses the AD server as the collector agent → There is no external FSSO collector; instead, the FortiGate itself polls the AD servers, effectively treating them as the source of logon information.


質問 # 42
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects.

The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)

  • A. 100.65.0.99
  • B. 100.65.0.101
  • C. 100.65.0.149
  • D. 100.65.0.49

正解:A

解説:
The ping traffic policy uses the IP pool named SNAT-Remote1, which has the external IP range
100.65.0.99. Therefore, traffic matching this policy (ping from HQ-PC-1 to BR1-FGT) will use
100.65.0.99 for source NAT.


質問 # 43
You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?

  • A. Network Protocol Enforcement
  • B. Replacement Messages for UDP-based Applications
  • C. Application and Filter Overrides
  • D. FortiGuard category ratings

正解:A

解説:
Network Protocol Enforcement settings control how FortiGate inspects and enforces protocols on traffic, including peer-to-peer applications on known ports. If not properly enabled, peer-to-peer traffic may bypass blocking despite the application control profile.


質問 # 44
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate device.
The WAN (port2) interface has the IP address 100.65.0.101/24.
The LAN (port4) interface has the IP address 10.0.11.254/24.
The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.11.50?



  • A. 10.0.11.254
  • B. 100.65.0.102
  • C. 100.65.0.101
  • D. 100.65.0.200

正解:B

解説:
Traffic from the workstation 10.0.11.50 going to the internet matches the Internet(1) policy (LAN
→ WAN) which has NAT enabled and is configured to use the IP Pool. The IP pool specifies the external address 100.65.0.102.
FortiGate will perform source NAT (SNAT) on the outbound traffic, translating the source IP of the workstation to 100.65.0.102.


質問 # 45
You have created a web filter profile named restrict_media-profile with a daily category usage quota. When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.
What could be the reason?

  • A. The firewall policy is in no-inspection mode instead of deep-inspection.
  • B. The web filter profile is already referenced in another firewall policy.
  • C. The naming convention used in the web filter profile is restricting it in the firewall policy.
  • D. The inspection mode in the firewall policy is not matching with web filter profile feature set.

正解:D

解説:
Web filter profiles with category usage quotas require the firewall policy to be in proxy-based (deep) inspection mode; if the inspection mode does not match this requirement, the profile will not appear in the drop-down list.


質問 # 46
Refer to the exhibit. The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD- WAN Rule Name.
FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows.
What could be the reason?

  • A. SD-WAN rule names do not appear immediately. The administrator must refresh the page.
  • B. There is no application control profile applied to the firewall policy.
  • C. Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled.
  • D. FortiGate load balanced the traffic according to the implicit SD-WAN rule.

正解:D

解説:
The SD-WAN traffic log does not display an SD-WAN rule name because the traffic is being forwarded by the implicit SD-WAN rule. If no explicit SD-WAN rule matches the traffic, FortiGate falls back to the default implicit rule, which balances traffic based on the configured strategy (such as volume or sessions). Since no explicit rule applied, the rule name field remains blank in the logs.


質問 # 47
Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)

  • A. Manual with load balancing
  • B. Lowest Cost (SLA) without load balancing
  • C. Best Quality with load balancing
  • D. Lowest Quality (SLA) with load balancing
  • E. Lowest Cost (SLA) with load balancing

正解:B、C、E

解説:
Lowest Cost (SLA) without load balancing → This is a valid strategy, selecting the path with the lowest cost that meets SLA requirements.
Lowest Cost (SLA) with load balancing → Also valid; it distributes sessions across the lowest-cost links that satisfy the SLA.
Best Quality with load balancing → Valid; it chooses the best-performing link based on SLA metrics such as latency, jitter, and packet loss, while also distributing sessions.


質問 # 48
What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device?
(Choose two.)

  • A. The heartbeat interface of the primary device in the cluster is always assigned IP address
    169.254.0.1.
  • B. A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster.
  • C. Heartbeat interfaces have virtual IP addresses that are manually assigned.
  • D. Heartbeat IP addresses are used to distinguish between cluster members.

正解:B、D

解説:
Heartbeat IP addresses are used to distinguish between cluster members → Each FortiGate in the HA cluster uses unique heartbeat IPs so members can identify one another.
A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster → Heartbeat IPs are dynamically reassigned when the cluster membership changes to maintain proper communication.


質問 # 49
An administrator configured a FortiGate device to act as a collector for agentless polling mode.
What must the administrator add to the FortiGate device to retrieve AD user group information?

  • A. Keycloak server
  • B. LDAP server
  • C. TACACS server
  • D. RADIUS server

正解:B

解説:
In agentless polling mode, FortiGate directly queries Active Directory to obtain user and group information. To do this, the administrator must configure an LDAP server on the FortiGate, which allows it to retrieve user group membership details from AD.


質問 # 50
Refer to the exhibit showing a debug flow output.

Which two conclusions can you make from the debug flow output? (Choose two.)

  • A. The default gateway is configured on port2.
  • B. The RPF check fails.
  • C. The matching firewall policy denies the traffic.
  • D. The debug flow is for UDP traffic.

正解:A、C

解説:
The default gateway is configured on port2 → The debug output shows find a route:
flag=00000000 gw-0.0.0.0 via port2, which indicates that the default route (0.0.0.0/0) points out port2.
The matching firewall policy denies the traffic → The log line Denied by forward policy check (policy 2) confirms that policy 2 matched and explicitly dropped the traffic.


質問 # 51
Refer to the exhibit. What can you conclude from the log shown in the exhibit?

  • A. The IPS scan is paused by the IPS diagnostic command with bypass mode option 5.
  • B. The IPS socket buffer is full and IPS engine cannot decode a packet.
  • C. The IPS session scan is paused and reevaluating the packet because of a dirty flag.
  • D. The IPS socket buffer is full and IPS engine needs more memory to create new sessions.

正解:D

解説:
The log message IPS session scan paused, enter fail open mode indicates that the IPS socket buffer is full, meaning the IPS engine does not have enough memory to process new sessions.
As a result, FortiGate switches to fail-open mode, allowing traffic to pass (or temporarily dropping it) without full IPS scanning.


質問 # 52
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)

  • A. Both interfaces must have IP addresses assigned.
  • B. Both interfaces must have directly connected routes on the routing table.
  • C. Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.
  • D. Both interfaces must have the interface role assigned.

正解:A、B

解説:
Interfaces must have directly connected routes in the routing table to forward traffic correctly.
Interfaces must have IP addresses assigned to communicate within their respective networks.


質問 # 53
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?

  • A. NetAPI polling can increase bandwidth usage in large networks.
  • B. The NetSessionEnum function is used to track user logouts.
  • C. The collector agent uses a Windows API to query DCs for user logins.
  • D. The collector agent must search Windows application event logs.

正解:A

解説:
NetAPI polling mode involves frequent queries to domain controllers, which can cause increased bandwidth usage, especially in large networks with many login events.


質問 # 54
......

最新NSE4_FGT_AD-7.6試験問題にはリアルなNSE4_FGT_AD-7.6問題集があります:https://www.jpntest.com/shiken/NSE4_FGT_AD-7.6-mondaishu

最新NSE4_FGT_AD-7.6認証有効な試験問題集解答を試そう!:https://drive.google.com/open?id=1YgMXMC0FS4t8oyASBayXTzQXPCSW5mNZ

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡