Win IT Exam with Last Dumps 2025


Fortinet NSE4_FGT-7.2 Exam

Page 3/7
Viewing Questions 21 30 out of 65 Questions
42.86%

Question 21
Which three criteria can FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)




Question 22
What are two functions of ZTNA? (Choose two.)




Question 23
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.
Which type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?




Question 24
Which timeout setting can be responsible for deleting SSL VPN associated sessions?




Question 25
Which statement is correct regarding the use of application control for inspecting web applications?





Question 26
A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded.
The administrator confirms that the traffic matches the configured firewall policy.
What are two reasons for the failed virus detection by FortiGate? (Choose two.)




Question 27
Refer to the exhibits.
Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.
Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)
Image NSE4_FGT-7.2_27Q.png related to the Fortinet NSE4_FGT-7.2 Exam




Question 28
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection? (Choose two.)




Question 29
Refer to the exhibit.
An administrator is running a sniffer command as shown in the exhibit.
Which three pieces of information are included in the sniffer output? (Choose three.)
Image NSE4_FGT-7.2_29Q.png related to the Fortinet NSE4_FGT-7.2 Exam




Question 30
By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers.
Which CLI command causes FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering?