Which of the following statements is true regarding a FortiGate configured as an explicit web proxy?
A. FortiGate limits the number of workstations that authenticate using the same web proxy user credentials. This limit CANNOT be modified by the administrator.
B. FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT be modified by the administrator.
C. FortiGate limits the number of simultaneous sessions per explicit web proxy user The limit CAN be modified by the administrator
D. FortiGate limits the total number of simultaneous explicit web proxy users.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
View the exhibit, which contains the output of a real-time debug, Which statement about this output is true?

Which of the following statements is true regarding this output?
A. The requested URL belongs to category ID 255.
B. FortiGate found the requested URL in its local cache.
C. The server hostname Is training, fortinet.com.
D. This web request was inspected using the ftgd-allow web filler profile.
正解:B
質問 3:
View the global IPS configuration, and then answer the question below.

Which of the following statements is true regarding this configuration?
A. IPS will scan every byte in every session.
B. New packets will be passed through without inspection if the IPS socket buffer runs out of memory.
C. IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.
D. FortiGate will spawn IPS engine instances based on the system load.
正解:A
質問 4:
Refer to the exhibits.

Which contain the partial configurations of two VPNs on FortiGate.
An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovered that FortiGate is not matching the user-2 VPN for members of the Users-2 group.
Which two changes must administrator make to fix the issue? (Choose two.)
A. Change to aggressive mode on both VPNs.
B. Enable Mode Config on both VPNs.
C. Set up specific peer IDs on both VPNs.
D. Use different pre-shared keys on both VPNs
正解:A,C
質問 5:
Refer to the exhibit, which shows a partial routing table.

Assuming all the appropriate firewall policies are configured, which two pings will FortiGate route? (Choose two.)
A. Source IPaddress: 10.73.9.10, Destination IPaddress: 10.72.3.15
B. Source IPaddress: 10.10.4.24, Destination IPaddress: 10.72.3.20
C. Source IPaddress: 10.72.3.52. Destination IP address: 10.1.0.254
D. Source IP address: 10.1.0.10. Destination IP address: 10.64.1.52
正解:C,D
質問 6:
Which statement about NGFW policy-based application filtering is true?
A. The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT.
B. After IPS identifies the application, it adds an entry to a dynamic ISDB table.
C. After the application has been identified, the kernel uses only the Layer 4 header to match the traffic.
D. FortiGate will drop all packets until the application can be identified.
正解:D
質問 7:
Refer to the exhibit, which contains partial output from an IKE real-time debug.

Which two statements about this debug output are correct? (Choose two.)
A. The initiator provided remote as its IPsec peer ID.
B. The negotiation is using AES128 encryption with CBC hash.
C. The remote gateway IP address is 10.0.0.1.
D. It shows a phase 1 negotiation.
正解:A,D
藤原** -
最高です!一回試験に受けて合格になりました。Pass4TestのNSE7_EFW-6.4問題集を強くお勧めたいです。