FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. Fortinet Certification
  3. FCP_FGT_AD-7.4 Exam
  4. Fortinet.FCP_FGT_AD-7.4.v2024-12-12.q52 Dumps
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • …
  • »
  • »»
Download Now

Question 11

Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2.
The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver.
Which two configuration changes can the administrator make to the policy to deny Webserver access for Remote-User2? (Choose two.)

Correct Answer: A,B
To deny access to the web server for Remote-User2 while allowing Remote-User1 to access the same web server, two configuration changes can be made:
* Enable match-vip in the Deny policy:By enabling the match-vip option in the Deny policy, the FortiGate will check for virtual IP (VIP) objects during policy matching. This setting allows the firewall policy to correctly identify and block traffic directed to a specific mapped IP address, such as the web server, when using a VIP configuration.
* Set the Destination address as Webserver in the Deny policy:Setting the Destination address to
"Webserver" in the Deny policy ensures that the policy specifically targets traffic attempting to reach the web server. This configuration helps to precisely control which traffic should be blocked, focusing the Deny policy on the intended destination.
References:
* FortiOS 7.4.1 Administration Guide: Deny matching with a policy with a virtual IP applied
* FortiOS 7.4.1 Administration Guide: Configuring Policies with VIPs
insert code

Question 12

Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)

Correct Answer: C,D
C: NTP
D: DNS
Not all the configuration settings are synchronized.
There are a few that are not, such as:
* System interface settings of the HA reserved management interface and the HA default route for the reserved management interface
* In-band HA management interface
* HA override
* HA device priority
* Virtual cluster priority
* FortiGate hostname
* HA priority setting for a ping server (or dead gateway detection) configuration
* All licenses except FortiToken licenses (serial numbers)
* Cache
Fortigate Hostname is not synchronized between cluster member.
insert code

Question 13

Refer to the exhibit.

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

Correct Answer: C
insert code

Question 14

An administrator configured a FortiGate to act as a collector for agentless polling mode.
What must the administrator add to the FortiGate device to retrieve AD user group information?

Correct Answer: A
To retrieve AD user group information in agentless polling mode, the administrator must add an LDAP server to the FortiGate device.
insert code

Question 15

Refer to the exhibit to view the application control profile.

Users who use Apple FaceTime video conferences are unable to set up meetings.
In this scenario, which statement is true?

Correct Answer: C
Apple FaceTime belongs to the custom blocked filter.
FaceTime categorized (filtered) under "Excessive-Bandwidth" and custom filter override set to block this.
Also we know that users can't use FaceTime.
Apple FaceTime falls under (VoIP Catagory), (Excessive-Bandwidth Behavior) and (Vendor as Apple).
A. Correct, but that comes 2nd.
B. Correct, but that comes 2nd, as custom Filter Overrides the precedence of Category.
C. Correct, and that comes 1st.
D. Wrong, VoIP Category is monitored
So correct answer is (C).
insert code
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download Fortinet.FCP_FGT_AD-7.4.v2024-12-12.q52 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2025 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.