Fortinet - Celebrate 2025 with Discount Offer - Ends In 1d 00h 00m 00s Coupon code: Y2530OFF
  1. Home
  2. Fortinet
  3. NSE4_FGT-7.2 Dumps
  4. Free NSE4_FGT-7.2 Questions

Free Practice Questions for Fortinet NSE4_FGT-7.2 Exam

Pass4Future also provide interactive practice exam software for preparing Fortinet NSE 4 - FortiOS 7.2 (NSE4_FGT-7.2) Exam effectively. You are welcome to explore sample free Fortinet NSE4_FGT-7.2 Exam questions below and also try Fortinet NSE4_FGT-7.2 Exam practice test software.

Page:    1 / 14   
Total 183 questions

Question 1

What are two scanning techniques supported by FortiGate? (Choose two.)



Answer : A, B

FortiGate Security 7.2 Study Guide (p.341):

'Like viruses, which use many methods to avoid detection, FortiGate uses many techniques to detect viruses. These detection techniques include:

* Antivirus scan

* Grayware scan

* Machine learning (AI) scan

If all antivirus features are enabled, FortiGate applies the following scanning order: antivirus scan, followed by grayware scan, followed by AI scan.'


Question 2

Refer to the exhibit.

In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit.

What should the administrator do next to troubleshoot the problem?



Question 3

Refer to the exhibit to view the firewall policy

Why would the firewall policy not block a well-known virus, for

example eicar?



Answer : B


Question 4

Refer to the exhibits.

Exhibit A

Exhibit B

The exhibit contains a network interface configuration, firewall policies, and a CLI console configuration.

How will FortiGate handle user authentication for traffic that arrives on the LAN interface?



Answer : D


Question 5

Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)



Answer : A, B, E

A) The server name indication (SNI) extension in the client hello message. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The SNI extension is a feature of the TLS protocol that allows a client to indicate the hostname of the server it wants to connect to during the TLS handshake.This helps the server to present the appropriate certificate for the requested hostname, especially when the server hosts multiple domains on the same IP address1.FortiGate can use the SNI extension in the client hello message to identify the hostname of the SSL server and verify it against the server certificate2.

B) The subject alternative name (SAN) field in the server certificate. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The SAN field is an extension of the X.509 certificate standard that allows a certificate to specify multiple hostnames or IP addresses that are valid for the certificate.This helps the certificate to support multiple domains or subdomains on the same server, or multiple servers with different IP addresses3.FortiGate can use the SAN field in the server certificate to identify the hostname of the SSL server and verify it against the client request2.

E) The subject field in the server certificate. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The subject field is a part of the X.509 certificate standard that contains information about the identity of the entity that owns the certificate, such as common name, organization, country, and so on.The common name usually specifies the hostname or domain name of the server that owns the certificate4.FortiGate can use the subject field in the server certificate to identify the hostname of the SSL server and verify it against the client request2.


Page:    1 / 14   
Total 183 questions