Refer to the exhibit.

Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
A. Read/Write permission for Firewall
B. Read/Write permission for Log & Report
C. CLI diagnostics commands permission
D. Custom permission for Network
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)
A. Create a new service object for HTTP service and set the session TTL to never
B. Set the session TTL on the HTTP policy to maximum
C. Set the TTL value to never under config system-ttl
D. Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
正解:A,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
A. get system performance status
B. get system arp
C. get system status
D. diagnose sys top
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which three CLI commands can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)
A. get system arp
B. execute traceroute
C. diagnose sys top
D. diagnose sniffer packet any
E. execute ping
正解:B,D,E
質問 5:
Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
A. The signature setting uses a custom rating threshold.
B. Traffic matching the signature will be allowed and logged.
C. The signature setting includes a group of other signatures.
D. Traffic matching the signature will be silently dropped and logged.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Which two inspection modes can you use to configure a firewall policy on a profile-based next-generation firewall (NGFW)? (Choose two.)
A. Certificate inspection
B. Flow-based inspection
C. Full Content inspection
D. Proxy-based inspection
正解:B,D
質問 7:
Which statements are true regarding firewall policy NAT using the outgoing interface IP address with fixed port disabled? (Choose two.)
A. This is known as many-to-one NAT.
B. Source IP is translated to the outgoing interface IP.
C. Port address translation is not used.
D. Connections are tracked using source port and source MAC address.
正解:B,C
質問 8:
What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?
A. Certificate inspection
B. Flow-based inspection
C. Full Content inspection
D. Proxy-based inspection
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
柴田** -
NSE4_FGT-7.0問題集を使って簡単に試験に受かることができました。ありがとねPass4Testさん