[2024年11月07日]FCP_FGT_AD-7.4試験問題集、FCP_FGT_AD-7.4練習テスト問題 [Q14-Q30]

Share

[2024年11月07日]FCP_FGT_AD-7.4試験問題集、FCP_FGT_AD-7.4練習テスト問題

無料で使えるFCP_FGT_AD-7.4学習ガイド試験問題と解答

質問 # 14
Refer to the exhibit.

Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?

  • A. The IPS engine was inspecting high volume of traffic.
  • B. The IPS engine was blocking all traffic.
  • C. The IPS engine was unable to prevent an intrusion attack.
  • D. The IPS engine will continue to run in a normal state.

正解:A

解説:
If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode.
In this mode, the IPS engine is still running, but it is not inspecting traffic.
If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model.
If the CPU use remains high after enabling IPS bypass mode, it usually indicates a problem in the IPS engine, which you must report to Fortinet Support.
If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode. In this mode, the IPS engine is still running, but it is not inspecting traffic. If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model.


質問 # 15
FortiGate is configured as a policy-based next-generation firewall (NGFW) and is applying web filtering and application control directly on the security policy.
Which two other security profiles can you apply to the security policy? (Choose two.)

  • A. Antivirus scanning
  • B. File filter
  • C. DNS filter
  • D. Intrusion prevention

正解:A、D

解説:
Security policy: If the traffic is allowed as per the consolidated policy, FortiGate will then process it based on the security policy to analyze additional criteria, such as URL categories for web filtering and application control. Also, if enabled, the security policy further inspects traffic using security profiles such as IPS and AV.
When FortiGate is configured as a policy-based next-generation firewall (NGFW) and is applying web filtering and application control directly on the security policy, you can also apply Antivirus scanning and Intrusion Prevention security profiles. These additional security profiles enhance the overall security posture of the network.
Extra explanation:
In addition to web filtering and application control, you can apply the following security profiles to the security policy on a FortiGate firewall:
A. Antivirus scanning: This profile scans traffic for viruses, malware, and other malicious content to prevent them from entering the network.
D. Intrusion prevention: This profile protects against network threats by inspecting traffic for known attack patterns and malicious activities, helping to prevent unauthorized access and data breaches. So, the correct answers are A. Antivirus scanning and D. Intrusion prevention


質問 # 16
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile.
Which order must FortiGate use when the web filter profile has features such as safe search enabled?

  • A. Static domain filter, SSL inspection filter, and external connectors filters
  • B. Static URL filter, FortiGuard categoryfilter, and advanced filters
  • C. FortiGuard category filter and ratingfilter
  • D. DNS-based web filter and proxy-based web filter

正解:B


質問 # 17
Which three methods are used by the collector agent for AD polling? (Choose three.)

  • A. NetAPI
  • B. WinSecLog
  • C. FSSO REST API
  • D. WMI
  • E. FortiGate polling

正解:A、C、E


質問 # 18
Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)

  • A. Lowest Quality (SLA) with load balancing
  • B. Best Quality with load balancing
  • C. Lowest Cost (SLA) with load balancing
  • D. Lowest Cost (SLA) without load balancing
  • E. Manual with load balancing

正解:B、C、E

解説:
FortiGate's SD-WAN rule strategies for member selection include the following:
* Manual with load balancing: This strategy allows an administrator to manually configure which SD- WAN member interfaces to use for specific traffic.
* Lowest Cost (SLA) with load balancing: This strategy prioritizes the link with the lowest cost that meets the SLA requirements.
* Best Quality with load balancing: This strategy selects the link with the best performance metrics, such as latency, jitter, or packet loss.
Options D and E are incorrect because "Lowest Quality" is not a valid strategy, and "Lowest Cost without load balancing" contradicts the requirement for load balancing in the strategy name.
References:
* FortiOS 7.4.1 Administration Guide: SD-WAN Rule Strategies


質問 # 19
Refer to the exhibit:

Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)

  • A. There will be eight routes active in the routing table.
  • B. The port3 default route has the highest distance.
  • C. The port3 default route has the lowest metric.
  • D. The port1 and port2 default routes are active in the routing table.

正解:B、D

解説:
*> mean active routes
first square bracked mean administrative distance
second bracket square mean priority (valid only on static routes) metric applies only in multiroutes with same administrative distance.


質問 # 20
Refer to the exhibit, which shows the IPS sensor configuration.

If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will allow attackers matching the Microsoft.Windows.iSCSl.Target.DoS signature.
  • B. The sensor will block all attacks aimed at Windows servers.
  • C. The sensor will reset all connections that match these signatures.
  • D. The sensor will gather a packet log for all matched traffic.

正解:A、D

解説:
The IPS sensor configuration shows that:
* The Microsoft.Windows.iSCSI.Target.DoS signature is set to "Monitor" with packet logging enabled, meaning that while traffic matching this signature will be allowed, it will also be logged for further analysis.
* The generic Windows filter is set to "Block," meaning that all other attacks matching this filter will be blocked. However, the sensor will not reset connections or log packets unless specified.
Therefore, the sensor will allow attackers matching the specific DoS signature while blocking other attacks against Windows.
References:
* FortiOS 7.4.1 Administration Guide: IPS Configuration


質問 # 21
Refer to the exhibit to view the application control profile.



Based on the configuration, what will happen to Apple FaceTime?

  • A. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration.
  • B. Apple FaceTime will be allowed only if the filter in Application and Filter Overrides is set to Learn.
  • C. Apple FaceTime will be allowed, based on the Apple filter configuration.
  • D. Apple FaceTime will be allowed, based on the Categories configuration.

正解:A

解説:
Apple facetime will be blocked according to the "Excessive Bandwidth" filter.
Facetime belongs to VoIP category which is monitored here and therefore should be allowed, however, because of the behavior of the facetime "Excessive-Bandwidth", the custom filter Excessive-Bandwidth will block Facetime and the lookup won't continue to the second filter.
The excessive bandwidth filter contains facetime and is referenced by the application sensor with the action to block. There is no reference to a bandwidth threshold at which point the filter is applied so the number of calls is irrelevant.


質問 # 22
If the Issuer and Subject values are the same in a digital certificate, to which type of entity was the certificate issued?

  • A. A user
  • B. A subordinate CA
  • C. A root CA
  • D. A CRL

正解:C

解説:
If the Issuer and Subject values are the same in a digital certificate, it typically indicates that the certificate is a self-signed certificate.
Therefore, the correct answer is:
B. A root CA (Certificate Authority)
A self-signed certificate is one where the entity that issued the certificate is also the entity identified by the certificate. In the context of a Certificate Authority (CA), this is often referred to as a root CA certificate. Root CA certificates are at the top of the certificate hierarchy and are used to sign other certificates, creating a chain of trust in a Public Key Infrastructure (PKI).


質問 # 23
View the exhibit.

Which two behaviors result from this full (deep) SSL configuration? (Choose two.)

  • A. A temporary trusted FortiGate certificate replaces the server certificate when the server certificate is trusted.
  • B. A temporary untrusted FortiGate certificate replaces the server certificate when the server certificate is untrusted.
  • C. A temporary trusted FortiGate certificate replaces the server certificate, even when the server certificate is untrusted.
  • D. The browser bypasses all certificate warnings and allows the connection.

正解:A、B

解説:
C. A temporary trusted FortiGate certificate replaces the server certificate when the server certificate is trusted.
D. A temporary untrusted FortiGate certificate replaces the server certificate when the server certificate is untrusted.
In a full (deep) SSL configuration, a temporary untrusted FortiGate certificate replaces the server certificate when the server certificate is untrusted, and a temporary trusted FortiGate certificate replaces the server certificate when the server certificate is trusted.
The behavior that results from this full (deep) SSL configuration is that a temporary untrusted FortiGate certificate replaces the server certificate when the server certificate is untrusted. Additionally, a temporary trusted FortiGate certificate replaces the server certificate when the server certificate is trusted.


質問 # 24
Refer to the exhibits.


The exhibits show the firewall policies and the objects used in the firewall policies.
The administrator is using the Policy Lookup feature and has entered the search criteria shown in the exhibit.
Which policy will be highlighted, based on the input criteria?

  • A. Policy with ID 1.
  • B. Policy with ID 4.
  • C. Policy with ID 5.
  • D. Policies with ID 2 and 3.

正解:C

解説:
Policy with ID 5.
It's coming from port 3 - hits Facebook-Web (Application) from the screenshot it show that it allows http and https traffic (80, 443).
There are 3 rules related to port3
and two rules source LOCAL_CLIENT
this would leave us with Rule 1 & 5
Rule one Service is = ULL_UDP
Rule five = Internet Services
Destination port we are looking for is 443 (usually this is TCP)
So it had to be PID5
We are looking for a policy that will allow or deny traffic from the source interface Port3 and source IP address 10.1.1.10 (LOCAL_CLIENT) to facebook.com TCP port 443 (HTTPS). There are only two policies that will match this traffic, policy ID 2 and 5. In FortiGate, firewall policies are evaluated from top to bottom. This means that the first policy that matches the traffic is applied, and subsequent policies are not evaluated. Based on the Policy Lookup criteria, Policy ID 5 will be highlighted.


質問 # 25
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
Which two key configuration changes must the administrator make on FortiGate to meet the requirements?
(Choose two.)

  • A. Configure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
  • B. Enable Dead Peer Detection
  • C. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
  • D. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.

正解:B、C

解説:
To configure redundant IPsec VPN tunnels on FortiGate with failover capability, the following two key configuration changes are required:
* A. Enable Dead Peer Detection (DPD): Dead Peer Detection is crucial for detecting if the remote peer is unreachable. By enabling DPD, FortiGate can quickly detect a dead tunnel, ensuring a faster failover to the secondary tunnel when the primary tunnel goes down.
* C. Configure a lower distance on the static route for the primary tunnel and a higher distance on the static route for the secondary tunnel: The static route with the lower distance (higher priority) will be used when both tunnels are operational. If the primary tunnel fails, the higher distance (lower priority) route for the secondary tunnel will take over, ensuring traffic is routed correctly.
The other options are not suitable:
* B. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels:
This option is not directly related to the requirements of failover between two IPsec VPN tunnels.
* D. Configure a higher distance on the static route for the primary tunnel and a lower distance on the static route for the secondary tunnel: This would prioritize the secondary tunnel over the primary tunnel, which is opposite to the desired configuration.
References
* FortiOS 7.4.1 Administration Guide - Configuring IPsec VPN, page 1320.
* FortiOS 7.4.1 Administration Guide - Redundant VPN Configuration, page 1335.


質問 # 26
An administrator has configured central DNAT and virtual IPs.
Which item can be selected in the firewall policy Destination field?

  • A. The mapped IP address object of the VIP object
  • B. A VIP object
  • C. An IP pool
  • D. A VIP group

正解:A

解説:
- when central NAT is enabled => put the mapped IP address of the VIP object.
- when central NAT is disabled => put the VIP object.
In the context of central DNAT and virtual IPs in FortiGate, the correct option for the firewall policy Destination field is:
D. The mapped IP address object of the VIP object
When configuring central DNAT, you typically select the mapped IP address object associated with the VIP object in the firewall policy Destination field. This mapped IP address represents the internal destination to which traffic will be redirected.
So, the correct choice is D.


質問 # 27
Refer to the exhibit.


The exhibit contains a network diagram, firewall policies, and a firewall address object configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-user2.
Remote-user2 is still able to access Webserver.
Which two changes can the administrator make to deny Webserver access for Remote-User2? (Choose two.)

  • A. Enable match-vip in the Deny policy.
  • B. Set the Destination address as Deny_IP in the Allow-access policy.
  • C. Disable match-vip in the Deny policy.
  • D. Set the Destination address as Web_server in the Deny policy.

正解:A、D

解説:
By default does not match vip in deny policy for destination all. So 2 options we have:
1. Enable match vip in the Deny policy.
2. Add destination as webserver in deny policy. It should set match-vip enable, nor disable it...
Reference: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Firewall-does-not-block-incoming- WAN-to-LAN /ta-p/189641


質問 # 28
Refer to the exhibit.

Why did FortiGate drop the packet?

  • A. The next-hop IP address is unreachable.
  • B. It matched the default implicit firewall policy
  • C. It failed the RPF check.
  • D. 11 matched an explicitly configured firewall policy with the action DENY

正解:B


質問 # 29
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?

  • A. NetAPI polling can increase bandwidth usage in large networks.
  • B. The NetSessionEnum function is used to track user logouts.
  • C. The collector agent must search security event logs.
  • D. The collector agent uses a Windows API to query DCs for user logins.

正解:B

解説:
The NetSessionEnum function is used to track user logouts.
Study Guide - FSSO - FSSO with Windows Active Directory - Collector Agent-Based Polling Mode Options.
Collector agent-based polling mode has three methods (or options) for collecting logon info: NetAPI, WinSecLog and WMI.
NetAPI: Polls temporary sessions created on the DC when a user logs on or logs off and calls the NetSessionEnum function on Windows. It's faster than the WinSec and WMI methods; however, it can miss some logon events if a DC is under heavy system load. This is because sessions can be quickly created and purged form RAM, before the agent has a chance to poll and notify FG.
NetAPI: polls temporary sessions created on the DC when a user logs in or logs out and calls the NetSessionEnum function on Windows. It's faster than the WinSec and WMI methods; however, it can miss some login events if a DC is under heavy system load. This is because sessions can be quickly created and purged from RAM, before the agent has a chance to poll and notify FortiGate.
Incorrect:
A: NetAPI polling can increase bandwidth usage in large networks. (WinSecLog) C: The collector agent must search security event logs. (WinSecLog) D: The collector agent uses a Windows API to query DCs for user logins. (WMI)
- WinSecLog: polis all the security event logs from the DC. It doesn't miss any login events that have been recorded by the DC because events are not normally deleted from the logs. There can be some delay in FortiGate receiving events if the network is large and, therefore, writing to the logs is slow. It also requires that the audit success of specific event IDs is recorded in the Windows security logs. For a full list of supported event IDs, visit the Fortinet Knowledge Base (http://kb.fortinet.com).
- NetAPI: polls temporary sessions created on the DC when a user logs in or logs out and calls the NetSessionEnum function on Windows. It's faster than the WinSec and WMI methods; however, it can miss some login events if a DC is under heavy system load. This is because sessions can be quickly created and purged from RAM, before the agent has a chance to poll and notify FortiGate.


質問 # 30
......

FCP_FGT_AD-7.4試験問題集、FCP_FGT_AD-7.4練習テスト問題:https://www.passtest.jp/Fortinet/FCP_FGT_AD-7.4-shiken.html

検証済みFCP_FGT_AD-7.4問題集PDF資料 [2024年更新]:https://drive.google.com/open?id=1_RedTQGqTTHIHWdJfbxfxDMnjwteD2Tk