Fortinet NSE4_FGT-7.2日本語日常練習試験は2024年最新のに更新された175問あります
有効問題を試そう!NSE4_FGT-7.2日本語試験で実際の試験問題と解答
質問 # 71
展示を参照してください。
展示は、診断コマンドの出力を示しています。
出力は、ポリシー ルートについて何を明らかにしますか?
- A. ポリシー ルート内の ISDB ルートです。
- B. ポリシー ルートの SDWAN ルールです。
- C. SDWAN ルールを持つ ISDB ポリシー ルートです。
- D. 通常のポリシー ルートです。
正解:C
質問 # 72
インターネット サービスがファイアウォール ポリシーのソースとして既に選択されている場合、ファイアウォール ポリシーのソース フィールドに追加できる他の構成オブジェクトはどれですか?
- A. ユーザーまたはユーザー グループ
- B. FQDN アドレス
- C. Internet Service を選択すると、他のオブジェクトを追加できなくなります
- D. IPアドレス
正解:C
解説:
Reference:
https://docs.fortinet.com/document/fortigate/6.2.5/cookbook/179236/using-internet-service-in-policy
質問 # 73
SSL インスペクションで CA 証明書として使用できるように、証明書に必要な 2 つの属性はどれですか? (2つ選んでください。)
- A. 件名フィールドの共通名には、ワイルドカード名を使用する必要があります。
- B. keyUsage 拡張を keyCertSign に設定する必要があります。
- C. CA 拡張を TRUE に設定する必要があります。
- D. 発行者はパブリック CA である必要があります。
正解:B、C
解説:
"In order for FortiGate to act in these roles, its CA certificate must have the basic constraints extension set to cA=True and the value of the keyUsage extension set to keyCertSign."
質問 # 74
FGCP プロトコルについて正しい記述はどれですか? (2つ選んでください。)
- A. FGCP はハートビート リンク上でのみ実行されます。
- B. FGCP は、異なる HA グループ内の FortiGate デバイスを検出するために使用されます。
- C. FortiGate がトランスペアレント モードの場合、FGCP は使用されません。
- D. FGCP がプライマリ FortiGate デバイスを選択します。
正解:A、D
解説:
Reference:
https://docs.fortinet.com/document/fortigate/6.4.0/ports-and-protocols/564712/fgcp-fortigate-clustering-protocol
質問 # 75
展示を参照してください。
IPSセンサーの構成を展示。
トラフィックがこの IPS センサーと一致する場合、センサーが実行すると予想されるアクションはどれですか? (2つ選んでください。)
- A. センサーは、これらの署名に一致するすべての接続をリセットします。
- B. センサーは、Microsoft Windows.iSCSI.Target.DoS 署名に一致する攻撃者を許可します。
- C. センサーは、一致したすべてのトラフィックのパケット ログを収集します。
- D. センサーは、Windows サーバーを対象としたすべての攻撃をブロックします。
正解:B、D
質問 # 76
展示を参照してください。



展示物には、ネットワーク ダイアグラム、中央の SNAT ポリシー、および IP プールの構成が含まれています。
WAN (ポート 1) インターフェイスの IP アドレスは 10.200. 1. 1/24。
LAN (ポート 3) インターフェースの IP アドレスは 10.0.0.0 です。1.254/24。
ファイアウォール ポリシーは、LAN (ポート 3) から WAN (ポート 1) への宛先を許可するように構成されています。
セントラル NAT が有効になっているため、一致するセントラル SNAT ポリシーからの NAT 設定が適用されます。
Local-Client (10.0.1.10) のユーザーが Remote-FortiGate (10.200.3.1) の IP アドレスに ping を実行する場合、トラフィックのソース NAT に使用される IP アドレスはどれですか?
- A. 10.200。1.49
- B. 10.200. 1.149
- C. 10.200。1.99
- D. 10.200. 1.1
正解:C
質問 # 77
Web フィルターの生ログを参照してください。
展示物に示されている未加工のログに基づいて、正しい記述はどれですか?
- A. ファイアウォール ポリシー ID 1 のアクションは警告に設定されています。
- B. ソーシャル ネットワーキング Web フィルター カテゴリは、認証するように設定されたアクションで構成されます。
- C. ソーシャル ネットワーキング Web フィルター カテゴリへのアクセスは、すべてのユーザーに対して明示的にブロックされました。
- D. ファイアウォール ポリシーの名前は all_users_web です。
正解:B
質問 # 78
出品物を参照してください。
管理者は、展示物に示されている Web フィルタリング プロファイルを、Twitter を除くすべてのソーシャル ネットワーキング サイトへのアクセスをブロックするように設定しました。ただし、ユーザーが twitter.com にアクセスしようとすると、FortiGuard Web フィルタリング ブロック ページにリダイレクトされます。
展示に基づいて、管理者は他のすべてのソーシャル ネットワーキング サイトをブロックしながら Twitter を許可するにはどのような設定変更を行うことができますか?
- A. 静的 URL フィルター設定で、タイプを [シンプル] に設定します。
- B. ソーシャル ネットワーキングの警告に対する FortiGuard カテゴリ ベースのフィルター アクションについて
- C. 静的 URL フィルター設定で、アクションを除外に設定します。
- D. 静的 URL フィルター構成で、アクションをモニターに設定します。
正解:C
質問 # 79
展示品を参照してください。
図 A は、トラフィックに対してプロキシベースの検査を実行する FortiGate HA クラスタのトポロジを示しています。図 B は、HA 構成と get system ha status コマンドの出力の一部を示しています。

資料に基づいて、クラスターを通過するトラフィックに関する 2 つの記述のうち、正しいものはどれですか? (2つ選んでください。)
- A. クラスターは、セカンダリへの ICMP 接続の負荷を分散できます。
- B. 負荷分散接続の場合、プライマリは TCP SYN パケットをカプセル化してからセカンダリに転送します。
- C. 負荷分散されていない接続の場合、クラスターによってサーバーに転送されるパケットには、ソースとしてポート 2 の仮想 MAC アドレスが含まれます。
- D. クライアントから送信され、サーバーに送信されるトラフィックは、FGT-1 に送信されます。
正解:B、C
解説:
FortiGate Infrastructure 7.2 Study Guide (p.317 & p.320): "To forward traffic correctly, a FortiGate HA solution uses virtual MAC addresses." "The primary forwards the SYN packet to the selected secondary. (...) This is also known as MAC address rewrite. In addition, the primary encapsulates the packet in an Ethernet frame type 0x8891. The encapsulation is done only for the first packet of a load balanced session. The encapsulated packet includes the original packet plus session information that the secondary requires to process the traffic."
質問 # 80
管理者が次の設定を構成しました。
この構成の 2 つの結果は何ですか? (2つ選んでください。)
- A. 拒否されたトラフィックのセッションが作成されます。
- B. 拒否されたトラフィックによって生成されるログの数が減少します。
- C. すべてのインターフェースでのデバイス検出が 30 分間強制されます。
- D. 拒否されたユーザーは 30 分間ブロックされます。
正解:A、B
解説:
Explanation
ses-denied-traffic
Enable/disable including denied session in the session table.
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/20620/config-system-settings block-session-timer Duration in seconds for blocked sessions .
integer
Minimum value: 1 Maximum value: 300
30
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/1620/config-system-global
質問 # 81
展示品を参照してください。

展示物は、Facebook の SSL と認証ポリシー (展示物 A) とセキュリティ ポリシー (展示物 B) を示しています。
ユーザーには、Facebook Web アプリケーションへのアクセス権が付与されます。Facebook でホストされている動画コンテンツを再生することはできますが、動画やその他の種類の投稿に反応を残すことはできません。
問題を解決するには、ポリシー構成のどの部分を変更する必要がありますか?
- A. セキュリティ ポリシーに追加するために必要な追加のアプリケーション シグネチャを取得します。
- B. セキュリティ ポリシーの URL カテゴリに Facebook を追加します。
- C. HTTP サービスを使用して Facebook へのアクセスを強制します。
- D. SSL インスペクションを詳細なコンテンツ インスペクションにする必要があります。
正解:D
解説:
They can play video (tick) content hosted on Facebook, but they are unable to leave reactions on videos or other types of posts. This indicate that the rule are partially working as they can watch video but cant react, i.e. liking the content. So must be an issue with the SSL inspection rather then adding an app rule.
質問 # 82
従業員は、遅延の長いインターネット接続を介してオフィスに接続する必要があります。
SSL VPN ネゴシエーションの失敗を防ぐために、管理者はどの SSL VPN 設定を調整する必要がありますか?
- A. ログインタイムアウト
- B. アイドルタイムアウト
- C. セッション-ttl
- D. udp-アイドルタイマー
正解:A
解説:
FortiGate Infrastructure 7.2 Study Guide (p.222):
"When connected to SSL VPN over high latency connections, FortiGate can time out the client before the client can finish the negotiation process, such as DNS lookup and time to enter a token. Two new CLI commands under config vpn ssl settings have been added to address this. The first command allows you to set up the login timeout, replacing the previous hard timeout value. The second command allows you to set up the maximum DTLS hello timeout for SSL VPN connections."
質問 # 83
管理者は、ユーザーのタイムアウトを構成したいと考えています。userTM の動作に関係なく、タイマーはユーザーが認証されるとすぐに開始し、構成された値の後に期限切れになる必要があります。
FortiGate で構成する必要があるタイムアウト オプションはどれですか?
- A. 新しいセッション
- B. アイドルタイムアウト
- C. オンデマンド認証
- D. ハードタイムアウト
- E. ソフトタイムアウト
正解:D
解説:
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221#:~:text=Hard%20timeout%3A%20User%20
質問 # 84
FortiGate が一致するファイアウォール ポリシーを検索してトラフィックを処理するために使用できる 3 つの基準はどれですか? (3つ選んでください。)
- A. ファイアウォール ポリシーでインターネット サービスとして定義されている送信先。
- B. ファイアウォール ポリシーで定義されている優先度の高い順。
- C. ファイアウォール ポリシーで定義されたサービス。
- D. 最小から最大のポリシー ID 番号。
- E. ファイアウォール ポリシーで Internet Services として定義されているソース。
正解:A、C、E
解説:
Explanation
When a packet arrives, how does FortiGate find a matching policy? Each policy has match criteria, which you can define using the following objects:
* Incoming Interface
* Outgoing Interface
* Source: IP address, user, internet services
* Destination: IP address or internet services
* Service: IP protocol and port number
* Schedule: Applies during configured times
質問 # 85
FortiGate のビデオ フィルタリングに関する次の記述はどれが真実ですか?
- A. 完全な SSL 検査は必要ありません。
- B. プロキシベースのファイアウォール ポリシーでのみ使用できます。
- C. 個別の FortiGuard ライセンスは必要ありません。
- D. ビデオ フィルタリング FortiGuard カテゴリは、Web フィルタ FortiGuard カテゴリに基づいています。
正解:B
解説:
FortiGate Security 7.2 Study Guide (p.279): "To apply the video filter profile, proxy-based firewall polices currently allow you to enable the video filter profile. You must enable full SSL inspection on the firewall policy."
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/860867/filtering-based-on-fortiguard-categories
質問 # 86
展示品を参照してください。

ユーザーが接続を試みると、SSL VPN 接続は失敗します。SSL VPN に正常に接続するには、ユーザーは何をする必要がありますか?
- A. サーバーの IP アドレスを変更します。
- B. SSL VPN ポータルをトンネルに変更します。
- C. クライアントの SSL VPN ポートを変更します。
- D. アイドルタイムアウトを変更します。
正解:C
質問 # 87
展示を参照してください。
この展示は、ネットワークに接続された FortiGate デバイスの図と、FortiGate デバイス上のファイアウォール ポリシーと IP プール構成を示しています。
加入者から発信されたインターネット トラフィックに対して FortiGate が実行する 2 つのアクションはどれですか? (2つ選んでください。)
- A. FortiGate は、ユーザーごとにポート ブロックが割り当てられるたびにシステム イベント ログを生成します。
- B. FortiGate はポート ブロックを先着順で割り当てます。
- C. FortiGate は、ユーザーごとに 128 個のポート ブロックを割り当てます。
- D. FortiGate は、構成された内部 IP アドレスの範囲に基づいて、ユーザーごとにポート ブロックを割り当てます。
正解:C、D
質問 # 88
FortiGate で構成できるリモート ログ ストレージ オプションを 3 つ選んでください。(3つ選んでください。)
- A. FortiSandbox
- B. FortiCache
- C. FortiSIEM
- D. フォーティクラウド
- E. FortiAnalyzer
正解:C、D、E
解説:
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/265052/logging-and-reporting-overview
質問 # 89
RPF チェックの使用方法を説明している 2 つのステートメントはどれですか? (2つお選びください。)
- A. RPF チェックは、新しいセッションの最初に送信されたパケットに対して実行されます。
- B. RPF チェックは、新しいセッションの最初の応答パケットに対して実行されます。
- C. RPF チェックは、FortiGate とネットワークを IP スプーフィング攻撃から保護するメカニズムです。
- D. RPF チェックは、新しいセッションの最初に送信されたパケットと応答パケットに対して実行されます。
正解:A、C
解説:
FortiGate Infrastructure 7.2 Study Guide (p.41): "The RPF check is a mechanism that protects FortiGate and your network from IP spoofing attacks by checking for a return path to the source in the routing table." "FortiGate performs an RPF check only on the first packet of a new session. That is, after the first packet passes the RPF check and FortiGate accepts the session, FortiGate doesn't perform any additional RPF checks on that session." A) The RPF check is a mechanism that protects FortiGate and the network from IP spoofing attacks.
This is true because the RPF check verifies that the source IP address of an incoming packet matches the reverse route for that address, meaning that the packet came from a legitimate source and not from an attacker who is trying to impersonate another host. This prevents IP spoofing attacks, where an attacker sends packets with a forged source IP address to bypass security policies or launch denial-of-service attacks1 C) The RPF check is run on the first sent packet of any new session.
This is true because the RPF check is performed only once per session, on the first packet sent by either the client or the server, depending on the direction of the session initiation. This reduces the processing overhead and improves performance2
質問 # 90
セッション診断出力を含む展示を参照してください。
セッション診断出力について正しい文はどれですか?
- A. セッションは双方向 UDP 接続です。
- B. セッションは双方向の TCP 接続です。
- C. セッションは TCP ESTABLISHED 状態です。
- D. セッションは UDP 単方向状態です。
正解:A
解説:
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
質問 # 91
プロキシベースの検査と比較したフローベースの検査の利点を 2 つ挙げてください。(2つ選んでください。)
- A. FortiGate により、トラフィックの遅延が減少します。
- B. FortiGate は、トラフィックに対してより徹底的な検査を実行します。
- C. FortiGate は、接続ごとに 2 つのセッションを割り当てます。
- D. FortiGate はより少ないリソースを使用します。
正解:A、D
質問 # 92
SSL VPN Web モードについて正しい説明はどれですか?
- A. クライアントに仮想 IP アドレスを割り当てます。
- B. クライアントが接続されている間、トンネルはアップしています。
- C. 限られた数のプロトコルをサポートしています。
- D. 外部ネットワーク アプリケーションは、VPN 経由でデータを送信します。
正解:C
解説:
Explanation
FortiGate_Security_6.4 page 575 - Web mode requires only a web browser, but supports a limited number of protocols.
質問 # 93
FortiGate HA クラスターの仮想 IP アドレスの 2 つの特徴は何ですか? (2つお選びください。)
- A. FortiGate デバイスがクラスターに参加またはクラスターから離脱すると、仮想 IP アドレスが変更されます。
- B. ハートビート インターフェイスには、手動で割り当てられた仮想 IP アドレスがあります。
- C. 仮想 IP アドレスは、クラスタ メンバーを区別するために使用されます。
- D. クラスター内のプライマリ デバイスには常に IP アドレス 169.254.0.1 が割り当てられます。
正解:A、C
解説:
Fortigate Infrastructure 7.2 Study Guide page 301
FortiGate Infrastructure 7.2 Study Guide (p.301):
"FGCP automatically assigns the heartbeat IP addresses based on the serial number of each device. The IP address 169.254.0.1 is assigned to the device with the highest serial number."
"A change in the heartbeat IP addresses may happen when a FortiGate device joins or leaves the cluster."
"The HA cluster uses the heartbeat IP addresses to distinguish the cluster members and synchronize data."
https://networkinterview.com/fortigate-ha-high-availability/
質問 # 94
展示を参照してください。
展示に示されているように、管理者は sniffer コマンドを実行しています。
sniffer の出力に含まれる 3 つの情報はどれですか? (3つ選んでください。)
- A. Packet payload
- B. Application header
- C. Ethernet header
- D. IP header
- E. Interface name
正解:A、D、E
質問 # 95
展示を参照してください。
展示品に示されているインターフェースを考えると。どの2つのステートメントが正しいですか? (2つ選んでください。)
- A. port1-vlan10 と port2-vlan10 は同じブロードキャスト ドメインの一部です。
- B. port1-vlan と port2-vlan1 は、同じ VDOM または異なる VDOM に割り当てることができます。
- C. port1 はネイティブ VLAN です。
- D. port2 と port2-vlan1 の間のトラフィックはデフォルトで許可されます。
正解:B、C
解説:
Explanation
https://community.fortinet.com/t5/FortiGate/Technical-Tip-rules-about-VLAN-configuration-and-VDOM-interf
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30883
質問 # 96
......
テストエンジンに練習NSE4_FGT-7.2日本語テスト問題:https://www.passtest.jp/Fortinet/NSE4_FGT-7.2-JPN-shiken.html