Free NSE4_FGT-7.2 Sample Questions — Fortinet NSE 4 - FortiOS 7.2

Free NSE4_FGT-7.2 sample questions for the Fortinet NSE 4 - FortiOS 7.2 exam. No account required: study at your own pace.

Want an interactive quiz? Take the full NSE4_FGT-7.2 practice test

Looking for more? Click here to get the full PDF with 65+ practice questions for $10 for offline study and deeper preparation.

Question 1

What is a reason for triggering IPS fail open?

  • A. The IPS socket buffer is full and the IPS engine cannot process additional packets
  • B. The IPS engine cannot decode a packet
  • C. The IPS engine is upgraded
  • D. The administrator enabled NTurbo acceleration
Show Answer
Correct Answer:
A. The IPS socket buffer is full and the IPS engine cannot process additional packets
Question 2

Which two statements are true about the FGCP protocol? (Choose two.)

  • A. FGCP elects the primary FortiGate device
  • B. FGCP is not used when FortiGate is in transparent mode
  • C. FGCP runs only over the heartbeat links
  • D. FGCP is used to discover FortiGate devices in different HA groups
Show Answer
Correct Answer:
  • A. FGCP elects the primary FortiGate device
  • C. FGCP runs only over the heartbeat links
Question 3

An administrator needs to increase network bandwidth and provide redundancy. Which interface type must the administrator select to bind multiple FortiGate interfaces?

  • A. Redundant interface
  • B. Software switch interface
  • C. VLAN interface
  • D. Aggregate interface
Show Answer
Correct Answer:
D. Aggregate interface
Question 4

FortiGate is integrated with FortiAnalyzer and FortiManager. When a firewall policy is created, which attribute is added to the policy to improve functionality and to support recording logs to FortiAnalyzer or FortiManager?

  • A. Policy ID
  • B. Log ID
  • C. Sequence ID
  • D. Universally Unique Identifier
Show Answer
Correct Answer:
D. Universally Unique Identifier
Question 5

The IPS engine is used by which three security features? (Choose three.)

  • A. Antivirus in flow-based inspection
  • B. Web filter in flow-based inspection
  • C. Application control
  • D. DNS filter
  • E. Web application firewall
Show Answer
Correct Answer:
  • A. Antivirus in flow-based inspection
  • B. Web filter in flow-based inspection
  • C. Application control
Question 6

Which inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?

  • A. Flow-based inspection
  • B. Full content inspection
  • C. Certificate inspection
  • D. Proxy-based inspection
Show Answer
Correct Answer:
A. Flow-based inspection
Question 7

Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

  • A. The host field in the HTTP header
  • B. The subject alternative name (SAN) field in the server certificate
  • C. The subject field in the server certificate
  • D. The server name indication (SNI) extension in the client hello message
  • E. The serial number in the server certificate
Show Answer
Correct Answer:
  • B. The subject alternative name (SAN) field in the server certificate
  • C. The subject field in the server certificate
  • D. The server name indication (SNI) extension in the client hello message
Question 8

Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)

  • A. FortiGuard web filter cache
  • B. FortiGate hostname
  • C. DNS
  • D. NTP
Show Answer
Correct Answer:
  • C. DNS
  • D. NTP
Question 9

What are two features of the NGFW policy-based mode? (Choose two.)

  • A. NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy
  • B. NGFW policy-based mode does not require the use of central source NAT policy
  • C. NGFW policy-based mode policies support only flow inspection
  • D. NGFW policy-based mode can only be applied globally and not on individual VDOMs
Show Answer
Correct Answer:
  • A. NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy
  • C. NGFW policy-based mode policies support only flow inspection
Question 10

On FortiGate, which type of logs record information about traffic directly to and from the FortiGate management IP addresses?

  • A. Forward traffic logs
  • B. Local traffic logs
  • C. Security logs
  • D. System event logs
Show Answer
Correct Answer:
B. Local traffic logs
Question 11

FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface. In this scenario, what are two requirements for the VLAN ID? (Choose two.)

  • A. The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in the same subnet
  • B. The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs
  • C. The two VLAN subinterfaces must have different VLAN IDs
  • D. The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets
Show Answer
Correct Answer:
  • B. The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs
  • C. The two VLAN subinterfaces must have different VLAN IDs
Question 12

What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

  • A. It limits the scanning of application traffic to the browser-based technology category only
  • B. It limits the scanning of application traffic to the DNS protocol only
  • C. It limits the scanning of application traffic to use parent signatures only
  • D. It limits the scanning of application traffic to the application category only
Show Answer
Correct Answer:
A. It limits the scanning of application traffic to the browser-based technology category only
Question 13

An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?

  • A. It uses UDP 8888
  • B. It uses UDP 53
  • C. It uses DNS over HTTPS
  • D. It uses DNS over TLS
Show Answer
Correct Answer:
D. It uses DNS over TLS
Question 14

Which two types of traffic are managed only by the management VDOM? (Choose two.)

  • A. DNS
  • B. FortiGuard web filter queries
  • C. PKi
  • D. Traffic shaping
Show Answer
Correct Answer:
  • A. DNS
  • B. FortiGuard web filter queries
Question 15

Which statement about video filtering on FortiGate is true?

  • A. Video filtering FortiGuard categories are based on web filter FortiGuard categories
  • B. It does not require a separate FortiGuard license
  • C. Full SSL inspection is not required
  • D. Otis available only on a proxy-based firewall policy
Show Answer
Correct Answer:
D. Otis available only on a proxy-based firewall policy
Question 16

What are two characteristics of FortiGate HA cluster virtual IP addresses? (Choose two.)

  • A. Virtual IP addresses are used to distinguish between cluster members
  • B. Heartbeat interfaces have virtual IP addresses that are manually assigned
  • C. The primary device in the cluster is always assigned IP address 169.254.0.1.
  • D. change in the virtual IP address happens when a FortiGate device joins or leaves the cluster
Show Answer
Correct Answer:
  • A. Virtual IP addresses are used to distinguish between cluster members
  • D. change in the virtual IP address happens when a FortiGate device joins or leaves the cluster
Question 17

An administrator wants to simplify remote access without asking users to provide user credentials. Which access control method provides this solution?

  • A. ZTNA IP/MAC filtering mode
  • B. ZTNA access proxy
  • C. SSL VPN
  • D. L2TP
Show Answer
Correct Answer:
B. ZTNA access proxy
Question 18

Which statement describes a characteristic of automation stitches?

  • A. They can have one or more triggers
  • B. They can be run only on devices in the Security Fabric
  • C. They can run multiple actions simultaneously
  • D. They can be created on any device in the fabric
Show Answer
Correct Answer:
C. They can run multiple actions simultaneously
Question 19

Which statement is correct regarding the security fabric?

  • A. FortiManager is one of the required member devices
  • B. FortiGate devices must be operating in NAT mode
  • C. minimum of two Fortinet devices is required
  • D. FortiGate Cloud cannot be used for logging purposes
Show Answer
Correct Answer:
B. FortiGate devices must be operating in NAT mode
Question 20

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two.)

  • A. The website is exempted from SSL inspection
  • B. The EICAR test file exceeds the protocol options oversize limit
  • C. The selected SSL inspection profile has certificate inspection enabled
  • D. The browser does not trust the FortiGate self-signed CA certificate
Show Answer
Correct Answer:
  • A. The website is exempted from SSL inspection
  • C. The selected SSL inspection profile has certificate inspection enabled

Aced these? Get the Full Exam

Download the complete NSE4_FGT-7.2 study bundle with 65+ questions in a single printable PDF.