NSE4_FGT_AD-7.6 Sample Questions

NSE4_FGT_AD-7.6 Sample Questions & Answers

Inspecting encrypted traffic with certificates and configuring web filtering and application control carries the most weight, alongside initial FortiOS setup and FGCP clustering, firewall policies using SNAT and DNAT, routing with SD-WAN, and SSL and IPsec VPNs.

Launch the full NSE4_FGT_AD-7.6 simulator →

Showing 6 of 12 free samples.

  1. Question 1IntermediateSelect 2

    Deployment and System Configuration · Diagnose resource and connectivity problems

    Which TWO of the following statements correctly describe the behavior of the FortiGate diagnose sys session list command? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    diagnose sys session list displays the sessions in the kernel session table (addresses, ports, protocol, state, policy ID, NPU offload state, and so on). You can narrow the output by first setting criteria with diagnose sys session filter , such as src, dst, dport or policy. The list and clear commands then act only on matching sessions. The list itself removes nothing; diagnose sys session clear does. Sessions are not kept across reboots.

    diagnose sys session list displays the sessions in the kernel session table (addresses, ports, protocol, state, policy ID, NPU offload state, and so on). You can narrow the output by first setting criteria with diagnose sys session filter , such as src, dst, dport or policy. The list and clear commands then act only on matching sessions. The list itself removes nothing; diagnose sys session clear does. Sessions are not kept across reboots.

  2. Question 2Intermediate

    Firewall Policies and Authentication · Configure SNAT and DNAT options in firewall policies

    A FortiGate administrator needs to configure a Virtual IP (VIP) to forward traffic from the WAN interface (IP 203.0.113.10) on port 8443 to an internal web server (192.168.1.50) on port 443. Which configuration correctly achieves this Port Forwarding requirement?

    Show answer & explanation

    Correct answer: C

    This is the correct method for Port Forwarding. The VIP object defines the translation. The External Service Port (8443) is the listening port on the WAN, and 'Map to Port' (443) is the target port on the internal server. This object must then be used as the Destination in a firewall policy.

  3. Question 3Intermediate

    Firewall Policies and Authentication · Explain how to deploy and configure FSSO

    In a Fortinet Single Sign-On (FSSO) deployment using the Collector Agent mode, how does the FortiGate receive user logon information?

    Show answer & explanation

    Correct answer: A

    With a Collector Agent (CA), logon events are gathered either from DC agents installed on the domain controllers (DC-agent mode, DC agents send to the CA on UDP 8002) or by the CA polling the DCs. The CA then sends the user IP-to-group logon information to the FortiGate over TCP 8000. The FortiGate does not poll the DCs itself in this mode, and RADIUS/multicast are not used.

  4. Question 4Advanced

    Firewall Policies and Authentication · Configure firewall policies

    Case Study: A FortiGate running FortiOS 7.6 has two VDOMs: Root and CustomerA. The administrator switches the CustomerA VDOM (flow-based inspection) to NGFW Mode 'Policy-based' so that applications and URL categories can be used directly in security policies.

    Where must the administrator now select the SSL/SSH inspection profile that is used for the CustomerA traffic?

    Show answer & explanation

    Correct answer: A

    In policy-based NGFW mode (available only when the VDOM inspection mode is flow-based), SSL inspection - formerly configured in the VDOM settings - is configured in SSL Inspection & Authentication policies. These policies pre-match traffic (they have no schedule or action) and redirect it to the IPS engine, where security policies match applications, URL categories, users and groups and apply UTM inspection. Central NAT is always enabled in this mode, but the Central SNAT table only defines source NAT, not SSL inspection.

  5. Question 5Beginner

    Deployment and System Configuration · Perform initial configuration

    Which command is used to restart the FortiGate system without erasing the current configuration?

    Show answer & explanation

    Correct answer: C

    The execute reboot command restarts the FortiGate appliance. It prompts for confirmation before proceeding. This does not alter the saved configuration.

  6. Question 6Beginner

    Content Inspection · Explain and inspect encrypted traffic using certificates

    True or False: In FortiOS 7.6, enabling 'Deep Inspection' in an SSL/TLS profile requires the FortiGate's CA certificate to be installed as a Trusted Root CA on all client endpoints to prevent browser certificate warnings.

    Show answer & explanation

    Correct answer: A

    True. Deep Inspection involves the FortiGate acting as a Man-in-the-Middle (MITM), decrypting traffic, scanning it, and re-encrypting it. To do this, it signs the re-encrypted traffic with its own CA certificate. If clients do not trust this CA certificate, browsers will display security warnings.

Ready for the real thing?

The full NSE4_FGT_AD-7.6 simulator has every exam-style question, timed mode, and instant scoring.