NSE4_FGT-7.2 Dumps

NSE4_FGT-7.2 Free Practice Test

Fortinet NSE4_FGT-7.2: Fortinet NSE 4 - FortiOS 7.2

QUESTION 1

Which statements best describe auto discovery VPN (ADVPN). (Choose two.)

Correct Answer: AC

QUESTION 2

Examine this PAC file configuration.
Which of the following statements are true? (Choose two.)

Correct Answer: AD

QUESTION 3

Which two statements are true when FortiGate is in transparent mode? (Choose two.)

Correct Answer: AD

QUESTION 4

The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?

Correct Answer: B
FortiGate Security 7.2 Study Guide (p.285): "Remember that the web filtering profile has several features. So, if you have enabled many of them, the inspection order flows as follows: 1. The local static URL filter 2. FortiGuard category filtering (to determine a rating) 3. Advanced filters (such as safe search or removing Active X components)"

QUESTION 5

Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).
NSE4_FGT-7.2 dumps exhibit
NSE4_FGT-7.2 dumps exhibit
Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?

Correct Answer: B
· "ONLY" If the virus is detected at the "START" of the connection, the IPS engine sends the block replacement message immediately
· When a virus is detected on a TCP session (FIRST TIME), but where "SOME PACKETS" have been already forwarded to the receiver, FortiGate "resets the connection" and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a "SECOND ATTEMPT" to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
In flow mode, the FortiGate drops the last packet killing the file. But because of that the block replacement message cannot be displayed. If the file is attempted to download again the block message will be shown.