Free FCP-FGT-AD-7-4 Fortinet FCP-FGT-AD-7-4 Practice Test Question

Loading demo links...

Showing 7–9 of 9 questions

Question 7 (Topic 1)

An administrator has configured the following settings: What are the two results of this configuration? (Choose two.)

Select an option, then click Submit answer.

  • Denied users are blocked for 30 minutes.
  • A session for denied traffic is created.
  • The number of logs generated by denied traffic is reduced.
  • Device detection on all interfaces is enforced for 30 minutes.
Question 8 (Topic 1)

Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router. When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output. Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?

Select an option, then click Submit answer.

  • Configure a loopback interface with address 203.0.113.2/32.
  • In the VIP configuration, enable arp-reply.
  • In the firewall policy configuration, enable match-vip.
  • Enable port forwarding on the server to map the external service port to the internal service port.
Question 9 (Topic 1)

Refer to the exhibits. An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW). What must the administrator do to synchronize the address object?

Select an option, then click Submit answer.

  • Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
  • Change the csf setting on both devices to set downstream-access enable.
  • Change the csf setting on ISFW (downstream) to set authorization-request-type certificate.
  • Change the csf setting on ISFW (downstream) to set configuration-sync local.