Practice Free NSE4_FGT_AD-7.6 Exam Online Questions
Refer to the exhibit.
![]()
What can you conclude from the log shown in the exhibit?
- A . The IPS socket buffer is full and IPS engine needs more memory to create new sessions.
- B . The IPS socket buffer is full and IPS engine cannot decode a packet.
- C . The IPS scan is paused by the IPS diagnostic command with bypass mode option 5.
- D . The IPS session scan is paused and reevaluating the packet because of a dirty flag.
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode.
Which step is not part of the expected process?
- A . The DC agent sends login event data directly to FortiGate.
- B . FortiGate determines user identity based on the IP address in the FSSO list.
- C . The collector agent forwards login event data to FortiGate.
- D . The user logs into the windows domain.
Refer to the exhibits.

An administrator wants to add HQ-ISFW-2 in the Security Fabric. HQ-ISFW-2 is in the same subnet as HQ-ISFW. After configuring the Security Fabric settings on HQ-ISFW-2, the status stays Pending.
What can be the two possible reasons? (Choose two answers)
- A . Upstream FortiGate IP must be set to 10.0.11.254.
- B . SAML Single Sign-On must be set to Manual.
- C . HQ-ISFW-2 must be authorized on HQ-ISFW.
- D . Management IP must be set to 10.0.13.254.
Refer to the exhibits.

The system performance output and default configuration of high memory usage thresholds on a FortiGate device are shown.
Based on the system performance output, what are the two possible outcomes? (Choose two.)
- A . Administrators can access FortiGate only through the console port.
- B . FortiGate has entered conserve mode.
- C . FortiGate drops new sessions.
- D . Most Voted Administrators cannot change the configuration
An administrator manages a FortiGate model that supports NTurbo How does NTurbo acceleration enhance antivirus performance?
- A . For flow-based inspection. NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces.
- B . For flow-based inspection. NTurbo creates two inspection sessions on the FortiGate device.
- C . For proxy-based inspection. NTurbo offloads traffic to the content processor.
- D . For proxy-based inspection. NTurbo buffers the whole file and then sends it to the antivirus engine.
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?
- A . On Demand
- B . Enabled
- C . On Idle
- D . Usabled
Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.)
- A . FortiSASE Firewall-as-a-Service (FWaaS)
- B . The proxy auto-configuration (PAC) file
- C . VPN policies
- D . FortiExtender
An administrator wants to address shadow IT visibility challenges and prevent users from sending sensitive files outside the organization without proper approval.
Which FortiSASE method should the administrator implement to achieve these goals? (Choose one answer)
- A . Secure SD-WAN access (SSD-WAN)
- B . Secure private access (SPA)
- C . Secure SaaS access (SSA)
- D . Secure internet access (SIA)
How does FortiExtender connect to FortiSASE in a site-based, remote internet access method?
- A . FortiExtender uses a Virtual Extensible LAN (VXLAN)-over-IPsec connection.
- B . FortiExtender establishes a secure SSL connection using FortiClient.
- C . FortiExtender first connects to a FortiGate LAN extension through a secure web gateway (SWG).
- D . FortiExtender uses the proxy auto-configuration <PAC) file and an explicit web proxy to connect.
Exhibits:

You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS.
While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS.
What could be the cause?
- A . The feature set in the antivirus profile is not set to Flow-based.
- B . Web filter is not enabled on the firewall policy to complement the antivirus profile.
- C . The action on the firewall policy is not set to deny.
- D . The SSL inspection mode in the firewall policy is not deep content inspection.
