Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection? (Choose two.)
A. The CA extension must be set to TRUE
B. The keyUsage extension must be set to keyCertSign
C. The Authority Key Identifier must be of type SSL
D. The issuer must be a public CA
正解:A,B
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2.
The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver.
Which two configuration changes can the administrator make to the policy to deny Webserver access for Remote-User2? (Choose two.)
A. Disable match-vip in the Deny policy.
B. Enable match-vip in the Deny policy.
C. Set the Destination address as Deny_IP in the Allow_access policy.
D. Set the Destination address as Webserver in the Deny policy.
正解:B,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
What are two features of collector agent advanced mode? (Choose two.)
A. Advanced mode supports nested or inherited groups.
B. Advanced mode uses the Windows convention -NetBios: Domain\Username.
C. In advanced mode, security profiles can be applied only to user groups, not individual users.
D. In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
正解:A,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Refer to the exhibits.

The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy. and the sniffer CLI output on the FortiGate device.
The WAN (port1) interface has the IP address 10.200.1.1 /24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The webserver host (10. 0.1. 10) must use its VIP external IP address as the source NAT (SNAT) when It pings remote server (10.200.3.1).
Which two statements are valid to achieve this goal? (Choose two.)
A. Disable port forwarding on the VIP object.
B. Disable NAT on the lnternet_Access firewall policy.
C. Create a new firewall policy before lnternet_Access for the webserver and apply the IP pool.
D. Enable NAT on the Allow_access firewall policy.
正解:A,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Refer to the exhibit.

Why did FortiGate drop the packet?
A. The next-hop IP address is unreachable.
B. It matched the default implicit firewall policy
C. It failed the RPF check.
D. 11 matched an explicitly configured firewall policy with the action DENY
正解:B
質問 6:
Refer to the exhibit.

In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output shown in the exhibit.
What should the administrator do next, to troubleshoot the problem?
A. Execute a debug flow.
B. Run a sniffer on the web server.
C. Execute another sniffer on FortiGate, this time with the filter "hose 10.o.1.10".
D. Capture the traffic using an external sniffer connected to part1.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)
A. The client FortiGate requires a manually added route to remote subnets.
B. The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
C. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
D. The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
正解:C,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
FortiGuard categories can be overridden and defined in different categories. To create a web rating override for the example.com home page the override must be configured using a specific syntax.
Which two syntaxes are correct to configure a web rating override for the home page? (Choose two.)
A. www.example.com:443
B. www.example.com/index.hrml
C. example.com
D. www.example.com
正解:C,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 9:
A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad.
Which IPsec Wizard template must the administrator apply?
A. Dial up User
B. iHub-and-Spoke
C. Site to Site
D. Remote Access
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
Okada -
Fortinet FCP_FGT_AD-7.4試験参考書がなければ、FCP_FGT_AD-7.4試験に合格できません。とてもいい資料です。