NSE4_FGT-7.2 Dumps

NSE4_FGT-7.2 Free Practice Test

Fortinet NSE4_FGT-7.2: Fortinet NSE 4 - FortiOS 7.2

QUESTION 21

Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

Correct Answer: CD
Fortigate Infrastructure 7.0 Study Guide P.272-273 https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732

QUESTION 22

An administrator configures outgoing interface any in a firewall policy. What is the result of the policy list view?

Correct Answer: D
"If you use multiple source or destination interfaces, or the any interface in a firewall policy, you cannot separate policies into sections by interface pairs—some would be triplets or more. So instead, policies are then always displayed in a single list (By Sequence)."

QUESTION 23

Refer to the exhibit.
NSE4_FGT-7.2 dumps exhibit
Based on the ZTNA tag, the security posture of the remote endpoint has changed. What will happen to endpoint active ZTNA sessions?

Correct Answer: C
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/580880/posture-check-verification-for-active-zt FortiGate Infrastructure 7.2 Study Guide (p.182): "Endpoint posture changes trigger active ZTNA proxy
sessions to be re-verified and terminated if the endpoint is no longer compliant with the ZTNA policy."

QUESTION 24

Which two statements are correct about SLA targets? (Choose two.)

Correct Answer: BD

QUESTION 25

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
NSE4_FGT-7.2 dumps exhibit
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)

Correct Answer: AD
"In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: main, and aggressive mode. Settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel."