FortiGate 7.4 Administrator Sample Questions - Attempt Review2
FortiGate 7.4 Administrator Sample Questions - Attempt Review2
FortiGate 7.4 Administrator Sample Questions - Attempt Review2
Question 1
Incorrect
0 points out of 1
Select one:
When a remote user accesses https://10.200.1.1:443, the FortiGate login page opens.
When a remote user accesses http://10.200.1.1:443, the SSL-VPN login page opens.
When a remote user accesses https://10.200.1.1:443, the SSL-VPN login page opens.
The settings are invalid. The administrator settings and the SSL-VPN settings cannot use the same port.
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 1/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 2
Incorrect
0 points out of 1
Which two settings must you configure when FortiGate is being deployed as a root FortiGate in a Security Fabric topology? (Choose two.)
Question 3
Correct
1 points out of 1
Select one:
DNAT is not supported.
DNAT can automatically apply to multiple firewall policies, based on DNAT rules.
You must configure SNAT for each firewall policy.
SNAT can automatically apply to multiple firewall policies, based on SNAT policies.
Question 4
Correct
1 points out of 1
Which two statements about incoming and outgoing interfaces in firewall policies are true? (Choose two.)
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 2/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 5
Incorrect
0 points out of 1
Which two statements correctly describe the differences between IPsec main mode and IPsec aggressive mode? (Choose two.)
Question 6
Incorrect
0 points out of 1
An administrator needs to create a tunnel mode SSL-VPN to access an internal web server from the internet. The web server is connected to
port1. The internet is connected to port2. Both interfaces belong to the VDOM named Corporation.
What interface must the administrator use as the source for the firewall policy that will allow this traffic?
Select one:
port2
ssl.Corporation
port1
ssl.root
Question 7
Correct
1 points out of 1
Select one:
It is an IPsec extension that forces remote VPN users to authenticate using their credentials (username and password).
It is an IPsec extension that forces remote VPN users to authenticate using their local ID.
It is an IPsec extension that authenticates remote VPN peers using a pre-shared key.
It is an IPsec extension that authenticates remote VPN peers using digital certificates.
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 3/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 8
Partially correct
0 points out of 1
Which three settings and protocols can be used to provide secure and restrictive administrative access to FortiGate? (Choose three.)
Question 9
Correct
1 points out of 1
Which NAT method translates the source IP address in a packet to another IP address?
Select one:
IPPOOL
SNAT
VIP
DNAT
Question 10
Incorrect
0 points out of 1
Which two behaviours result from this full SSL configuration? (Choose two.)
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 4/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 11
Correct
1 points out of 1
Select one:
SSL traffic inspection when protecting multiple clients connecting to multiple servers.
SSL certificate inspection when protecting multiple clients connecting to multiple servers.
SSL certificate inspection when protecting a local SSL server.
SSL traffic inspection when protecting a local SSL server.
Question 12
Correct
1 points out of 1
An administrator needs to inspect all web traffic (including Internet web traffic) coming from users connecting to the SSL-VPN.
How can this be achieved?
Select one:
Configuring web bookmarks
Using web-only mode
Assigning public IP addresses to SSL-VPN users
Disabling split tunneling
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 5/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 13
Correct
1 points out of 1
Question 14
Correct
1 points out of 1
Which two IP pool types are useful for carrier-grade NAT deployments? (Choose two.)
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 6/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 15
Correct
1 points out of 1
FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login
prompt.
What is the most likely reason for this situation?
Select one:
The user is using a guest account profile.
The user was authenticated using passive authentication.
The user is using a super admin account.
No matching user account exists for this user.
Question 16
Correct
1 points out of 1
Which two statements about advanced AD access mode for the FSSO collector agent are true? (Choose two.)
Question 17
Correct
1 points out of 1
Which three methods can you use to deliver the token code to a user who is configured to use two-factor authentication? (Choose three.)
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 7/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 18
Correct
1 points out of 1
Select one:
10.30.20.0/24 [10/0] via 172.20.121.2, port1, [1/0]
Question 19
Incorrect
0 points out of 1
Select one:
It reboots FortiGate.
It synchronizes device priority on all cluster members.
It enables monitored ports.
You must configure override settings manually and separately for each cluster member.
Question 20
Incorrect
0 points out of 1
Which statement best describes the role of a DC agent in an FSSO DC agent mode solution?
Select one:
It captures the login and logoff events and forwards them to the collector agent.
It captures the login events and forwards them to FortiGate.
It captures the user IP address and workstation name and forwards them to FortiGate.
It captures the login events and forwards them to the collector agent.
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 8/9
5/16/24, 11:41 AM FortiGate 7.4 Administrator Sample Questions: Attempt review
Question 21
Correct
1 points out of 1
Select one:
You must configure session-pickup-connectionless enable under configure system ha.
You must configure ha-configuration-sync under configure system ha.
You do not need to configure anything because all TCP sessions are automatically failed over.
You must configure session-pickup-enable under configure system ha.
Question 22
Correct
1 points out of 1
What is the common feature shared between IPv4 and SD-WAN ECMP algorithms?
Select one:
Both control ECMP algorithms.
Both can be enabled at the same time.
Both use the same physical interface load balancing settings.
Both support volume algorithms.
https://training.fortinet.com/mod/quiz/review.php?attempt=19002208&cmid=531498 9/9