Practice Free NSE4_FGT_AD-7.6 Exam Online Questions
A network administrator is reviewing firewall policies in both Interface Pair View and By Sequence View. The policies appear in a different order in each view.
Why is the policy order different in these two views?
- A . By Sequence View groups policies based on rule priority, while Interface Pair View always follows the order of traffic logs.
- B . The firewall dynamically reorders policies in Interface Pair View based on recent traffic patterns, but By Sequence View remains static.
- C . Interface Pair View sorts policies based on matching interfaces, while By Sequence View shows the actual processing order of rules.
- D . Policies in Interface Pair View are prioritized by security levels, while By Sequence View strictly follows the administrator’s manual ordering.
Refer to the exhibits.

The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details.
Based on the configuration, what will happen to Apple FaceTime if there are only a few calls originating or incoming? (Choose one answer)
- A . Apple FaceTime will be allowed, based on the Video/Audio category configuration.
- B . Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration.
- C . Apple FaceTime will be allowed, based on the Apple filter configuration.
- D . Apple FaceTime will be allowed only if the Apple filter in Application and Filter Overrides is set to Allow.
Refer to the exhibit.

As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?
- A . There is a no firewall policy configured with an IPS security profile.
- B . Administrator entered the command diagnose test application ipsmonitor 5.
- C . FortiGate entered into IPS fail open state.
- D . Administrator entered the command diagnose test application ipsmonitor 99.
Refer to the exhibits.



A web filter profile configuration and firewall policy configuration are shown.
You are trying to access www. facebook.com, but you are redirected to a FortiGuard web filtering block page.
Based on the exhibits, what is the possible cause of the issue?
- A . The web rating override configuration is incorrect.
- B . The web filter profile feature set is configured incorrectly.
- C . The firewall policy inspection mode is incorrect.
- D . For www. facebook. com. the URL filter action is incorrect.
Refer to the exhibit

A firewall policy to enable active authentication is shown.
When attempting to access an external website using an active authentication method, the user is not presented with a login prompt.
What is the most likely reason for this situation?
- A . No matching user account exists for this user.
- B . The Remote-users group must be set up correctly in the FSSO configuration.
- C . The Remote-users group is not added to the Destination
- D . The Service DNS is required in the firewall policy.
Refer to the exhibit

A firewall policy to enable active authentication is shown.
When attempting to access an external website using an active authentication method, the user is not presented with a login prompt.
What is the most likely reason for this situation?
- A . No matching user account exists for this user.
- B . The Remote-users group must be set up correctly in the FSSO configuration.
- C . The Remote-users group is not added to the Destination
- D . The Service DNS is required in the firewall policy.
The FortiGate device HQ-NGFW-1 with the IP address 10.0.13.254 sends logs to the FortiAnalyzer device with the IP address 10.0.13.125. The administrator wants to verify that reliable logging is enabled on HQ-NGFW-1.
Which exhibit helps with the verification?
A)

B)

C)

D)

- A . Option A
- B . Option B
- C . Option C
- D . Option D
Refer to the exhibit.

Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)
- A . A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.
- B . A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.
- C . A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.
- D . A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.
Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
- A . On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.
- B . On HQ-NGFW. enable Diffie-Hellman Group 2.
- C . On BR1-FGT. set Seconds to 43200
- D . On HQ-NGFW. set Encryption to AES256.
Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
- A . On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.
- B . On HQ-NGFW. enable Diffie-Hellman Group 2.
- C . On BR1-FGT. set Seconds to 43200
- D . On HQ-NGFW. set Encryption to AES256.
