Fortinet NSE4_FGT-7.2日本語認定ガイドPDFは100%カバー率でリアル試験問題
合格させるNSE4_FGT-7.2日本語試験にはリアル問題解答
質問 # 75
FortiGate のビデオ フィルタリングに関する次の記述はどれが真実ですか?
- A. ビデオ フィルタリング FortiGuard カテゴリは、Web フィルタ FortiGuard カテゴリに基づいています。
- B. プロキシベースのファイアウォール ポリシーでのみ使用できます。
- C. 完全な SSL 検査は必要ありません。
- D. 個別の FortiGuard ライセンスは必要ありません。
正解:B
解説:
FortiGate Security 7.2 Study Guide (p.279): "To apply the video filter profile, proxy-based firewall polices currently allow you to enable the video filter profile. You must enable full SSL inspection on the firewall policy."
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/860867/filtering-based-on-fortiguard-categories
質問 # 76
IPS エンジンは、どの 3 つのセキュリティ機能で使用されていますか? (3つお選びください。)
- A. アプリケーション制御
- B. フローベース検査のWebフィルタ
- C. フローベースの検査におけるウイルス対策
- D. Web アプリケーション ファイアウォール
- E. DNSフィルター
正解:A、B、C
解説:
FortiGate Security 7.2 Study Guide (p.385): "The IPS engine is responsible for most of the features shown in this lesson: IPS and protocol decoders. It's also responsible for application control, flow-based antivirus protection, web filtering, and email filtering."
質問 # 77
展示を参照してください。
ネットワーク管理者は、2 つの FortiGate デバイス間の IPsec トンネルのトラブルシューティングを行っています。管理者は、フェーズ 1 のステータスがアップしていると判断しましたが、フェーズ 2 はアップしません。
資料に示されているフェーズ 2 構成に基づいて、どの構成変更によってフェーズ 2 が起動しますか?
- A. HQ-FortiGate で、オートネゴシエーションを有効にします。
- B. Remote-FortiGate では、Seconds を 43200 に設定します。
- C. HQ-FortiGate で、Diffie-Hellman グループ 2 を有効にします。
- D. HQ-FortiGate で、暗号化を AES256 に設定します。
正解:D
質問 # 78
CLI でのみ有効にできる FortiGate のスキャン技術はどれですか?
- A. トロイの木馬スキャン
- B. ヒューリスティックスキャン
- C. ウイルス対策スキャン
- D. ランサムウェア スキャン
正解:B
質問 # 79
管理 VDOM によってのみ管理される 2 種類のトラフィックはどれですか? (2つ選んでください。)
- A. トラフィック シェーピング
- B. PKI
- C. DNS
- D. FortiGuard Web フィルタ クエリ
正解:C、D
質問 # 80
NGFW ポリシーベース モードで、同じファイアウォール ポリシーで URL リストとアプリケーション制御を使用する際の制限は何ですか?
- A. アプリケーション トラフィックのスキャンを DNS プロトコルのみに制限します。
- B. アプリケーション トラフィックのスキャンを、親署名のみを使用するように制限します。
- C. アプリケーション トラフィックのスキャンをアプリケーション カテゴリのみに制限します。
- D. アプリケーション トラフィックのスキャンをブラウザベースのテクノロジ カテゴリのみに制限します。
正解:C
解説:
Explanation
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-mode In policy-based mode on a next-generation firewall (NGFW), you can use a URL list and application control in the same firewall policy to control traffic to and from specific websites or applications. However, there is a limitation to consider when using these features together:
It limits the scanning of application traffic to the application category only: The URL list and application control both rely on the firewall to inspect traffic and make decisions about what to allow or block. However, the URL list is limited to inspecting traffic at the URL level, while the application control can inspect traffic at a deeper level, such as at the application layer. This means that the application control is more comprehensive and can provide more granular control over specific applications, while the URL list is limited to controlling traffic at the URL level.
質問 # 81
SSL VPN ポータルの SSL VPN 設定に関する次の記述のうち、正しいものはどれですか?
- A. デフォルトでは、FortiGate は WINS サーバーを使用して名前を解決します。
- B. デフォルトでは、SSL VPN ポータルにはクライアントの証明書のインストールが必要です。
- C. デフォルトでは、スプリット トンネリングが有効になっています。
- D. デフォルトでは、管理 GUI と SSL VPN ポータルは同じ HTTPS ポートを使用します。
正解:D
質問 # 82
ネットワーク管理者は、FortiGate で SSL 証明書の検査とウイルス対策を有効にしました。HTTP 経由で EICAR テスト ファイルをダウンロードすると、FortiGate はウイルスを検出し、ファイルをブロックします。HTTPS 経由で同じファイルをダウンロードすると、FortiGate はウイルスを検出せず、ファイルをダウンロードできます。
FortiGate によるウイルス検出に失敗した理由は何ですか?
- A. Web サイトは SSL 検査を免除されています。
- B. EICAR テスト ファイルがプロトコル オプションのサイズ制限を超えています。
- C. ブラウザは、FortiGate の自己署名 CA 証明書を信頼していません。
- D. 選択した SSL 検査プロファイルでは、証明書検査が有効になっています。
正解:A、C
解説:
Explanation
https traffic requires SSL decryption. Check the ssh inspection profile
質問 # 83
管理者は、ユーザーにユーザー資格情報の入力を求めずにリモート アクセスを簡素化したいと考えています。
このソリューションを提供するアクセス制御方法はどれですか?
- A. L2TP
- B. ZTNA アクセスプロキシ
- C. SSL VPN
- D. ZTNA IP/MAC フィルタリング モード
正解:B
解説:
FortiGate Infrastructure 7.2 Study Guide (p.165): "ZTNA access proxy allows users to securely access resources through an SSL-encrypted access proxy. This simplifies remote access by eliminating the use of VPNs." This is true because ZTNA access proxy is a feature that allows remote users to access internal applications without requiring VPN or user credentials. ZTNA access proxy uses a secure tunnel between the user's device and the FortiGate, and authenticates the user based on device identity and context. The user only needs to install a lightweight agent on their device, and the FortiGate will automatically assign them to the appropriate application group based on their device profile. This simplifies remote access and enhances security by reducing the attack surface12
質問 # 84
展示を参照してください。
展示物には、ネットワークに接続された FortiGate デバイスの図、FortiGate デバイス上のファイアウォール ポリシーと VIP 構成、および ISP ルーター上のルーティング テーブルが示されています。
管理者がインターネットから Web サーバーのパブリック アドレス (203.0.113.2) にアクセスしようとすると、接続がタイムアウトします。同時に、管理者は FortiGate でスニファーを実行して、サーバーへの受信 Web トラフィックをキャプチャしますが、出力は表示されません。
資料に示されている情報に基づいて、接続の問題を修正するために管理者が行う必要がある構成の変更はどれですか?
- A. アドレス 203.0.113.2/32 でループバック インターフェイスを構成します。
- B. サーバーでポート転送を有効にして、外部サービス ポートを内部サービス ポートにマップします。
- C. VIP 構成で、arp-reply を有効にします。
- D. ファイアウォール ポリシー構成で、match-vip を有効にします。
正解:D
質問 # 85
IPsec で使用される IP 認証ヘッダー (AH) について正しい記述はどれですか?
- A. AH はデータの整合性を提供しますが、暗号化は行いません。
- B. AH は、データの整合性や暗号化を提供しません。
- C. AH は、Perfect Forward Secrecy をサポートしていません。
- D. AH は強力なデータ整合性を提供しますが、暗号化は脆弱です。
正解:A
質問 # 86
管理 VDOM によってのみ管理される 2 種類のトラフィックはどれですか? (2つ選んでください。)
- A. トラフィック シェーピング
- B. PKI
- C. DNS
- D. FortiGuard Web フィルタ クエリ
正解:C、D
解説:
FortiGate Infrastructure 7.2 Study Guide (p.73): "What about traffic originating from FortiGate? Some system daemons, such as NTP and FortiGuard updates, generate traffic coming from FortiGate. Traffic coming from FortiGate to those global services originates from the management VDOM. One, and only one, of the VDOMs on a FortiGate device is assigned the role of the management VDOM. It is important to note that the management VDOM designation is solely for traffic originated by FortiGate, such as FortiGuard updates, and has no effect on traffic passing through FortiGate."
質問 # 87
展示を参照してください。



展示物には、ネットワーク ダイアグラム、中央の SNAT ポリシー、および IP プールの構成が含まれています。
WAN (ポート 1) インターフェイスの IP アドレスは 10.200. 1. 1/24。
LAN (ポート 3) インターフェースの IP アドレスは 10.0.0.0 です。1.254/24。
ファイアウォール ポリシーは、LAN (ポート 3) から WAN (ポート 1) への宛先を許可するように構成されています。
セントラル NAT が有効になっているため、一致するセントラル SNAT ポリシーからの NAT 設定が適用されます。
Local-Client (10.0.1.10) のユーザーが Remote-FortiGate (10.200.3.1) の IP アドレスに ping を実行する場合、トラフィックのソース NAT に使用される IP アドレスはどれですか?
- A. 10.200。1.99
- B. 10.200. 1.149
- C. 10.200。1.49
- D. 10.200. 1.1
正解:A
質問 # 88
FortiGuard カテゴリは、別のカテゴリで上書きおよび定義できます。example.com ホームページの Web 評価オーバーライドを作成するには、特定の構文を使用してオーバーライドを構成する必要があります。
ホームページの Web 評価を構成するための正しい構文はどれですか? (2つ選んでください。)
- A. example.com
- B. www.example.com:443
- C. www.example.com
- D. www.example.com/index.html
正解:A、C
解説:
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names - no URLs or wildcard characters are allowed.
OK: google.com or www.google.com
NO OK: www.google.com/index.html or google.*
FortiGate_Security_6.4 page 384
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names-- "no URLs or wildcard characters are allowed".
質問 # 89
FortiAnalyzer または FortiManager へのログの記録をサポートし、FortiGate がこれらのデバイスと統合されたときに機能を改善するために、ファイアウォール ポリシーが作成されるときにポリシーに追加される属性はどれですか?
- A. シーケンス ID
- B. ログ ID
- C. ポリシー ID
- D. 普遍的に一意の識別子
正解:D
質問 # 90
RPF チェックについて正しい説明はどれですか? (2つ選んでください。)
- A. RPF は、FortiGate とネットワークを IP スプーフィング攻撃から保護するメカニズムです。
- B. RPF チェックは、新しいセッションの最初の送信パケットと応答パケットで実行されます。
- C. RPF チェックは、新しいセッションの最初に送信されたパケットで実行されます。
- D. RPF チェックは、新しいセッションの最初の応答パケットで実行されます。
正解:A、C
質問 # 91
Web フィルター プロファイルで複数の機能が有効になっている場合、Web フィルタリングの HTTP 検査プロセスは特定の順序に従います。Web フィルタ プロファイルでセーフ サーチなどの機能が有効になっている場合、FortiGate はどのような順序で使用する必要がありますか?
- A. DNS ベースの Web フィルターとプロキシベースの Web フィルター
- B. 静的ドメイン フィルター、SSL インスペクション フィルター、および外部コネクタ フィルター
- C. FortiGuard カテゴリ フィルタおよび評価フィルタ
- D. 静的 URL フィルター、FortiGuard カテゴリ フィルター、および高度なフィルター
正解:D
質問 # 92
コレクタ エージェントが AD ポーリングに使用する 3 つの方法はどれですか? (3つ選んでください。)
- A. FortiGate ポーリング
- B. NetAPI
- C. WinSecLog
- D. WMI
- E. Novell API
正解:B、C、D
質問 # 93
FortiGate は NAT モードで動作し、同じ物理インターフェイスに追加された 2 つの仮想 LAN (VLAN) サブインターフェイスで構成されています。
このシナリオでは、VLAN ID に対する 2 つの要件は何ですか? (2つお選びください。)
- A. 2 つの VLAN サブインターフェイスは、異なる VDOM に属している場合にのみ、同じ VLAN ID を持つことができます。
- B. 2 つの VLAN サブインターフェイスは、同じサブネット内に IP アドレスがある場合にのみ、同じ VLAN ID を持つことができます。
- C. 2 つの VLAN サブインターフェイスは、異なるサブネットに IP アドレスがある場合にのみ、同じ VLAN ID を持つことができます。
- D. 2 つの VLAN サブインターフェイスには異なる VLAN ID が必要です。
正解:A、D
解説:
https://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-use-emac-vlan-to-share-the-same-VLAN/ta-p/192843?externalID=FD43883 When FortiGate is operating in NAT mode, it means that it uses network address translation (NAT) to modify the source or destination IP addresses of the traffic passing through it1. NAT mode allows FortiGate to hide the IP addresses of the internal network from the external network, and to conserve IP addresses by using a single public IP address for multiple private IP addresses1.
A virtual LAN (VLAN) subinterface is a logical interface that allows traffic from different VLANs to enter and exit the FortiGate unit2. A VLAN subinterface is created by adding a VLAN ID to a physical interface or an aggregate interface2. A VLAN ID is a numerical identifier that distinguishes one VLAN from another2.
In this scenario, there are two requirements for the VLAN ID of the VLAN subinterfaces added to the same physical interface:
The two VLAN subinterfaces must have different VLAN IDs. This is because the VLAN ID is used to tag the traffic with the appropriate VLAN information, and to separate the traffic into different VLANs2. If the two VLAN subinterfaces have the same VLAN ID, they will not be able to distinguish the traffic from each other, and they will not be able to forward the traffic to the correct destination.
The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs. This is because VDOMs are virtual instances of FortiGate that can have their own interfaces, policies, and routing tables3. Each VDOM operates independently from other VDOMs, and can have its own VLAN subinterfaces with different or identical VLAN IDs3. However, this requires inter-VDOM links to allow traffic between different VDOMs3.
質問 # 94
FortiGate で選択できる 3 つの認証タイムアウト タイプはどれですか? (3つ選んでください。)
- A. アイドルタイムアウト
- B. 新しいセッション
- C. ソフトタイムアウト
- D. オンデマンド認証
- E. ハードタイムアウト
正解:A、B、E
解説:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221
質問 # 95
両側 (クライアントとサーバー) がセッションを終了した後でも、FortiGate が数秒間 TCP セッションをセッション テーブルに保持するのはなぜですか?
- A. NAT 操作を削除します。
- B. 検査操作を終了します。
- C. FIN/ACK パケットの後に到着する可能性のある順不同のパケットを許可します。
- D. ログを生成するには
正解:C
質問 # 96
次の SD-WAN 負荷分散方法のうち、インターフェイスの重み値を使用してトラフィックを分散するのはどれですか? (2つ選んでください。)
- A. ソース IP
- B. スピルオーバー
- C. セッション
- D. ボリューム
正解:C、D
解説:
Explanation
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/49719/configuring-sd-wan-load-balancing
質問 # 97
管理者は、ネットワーク帯域幅を増やして冗長性を提供する必要があります。
管理者が複数の FortiGate インターフェースをバインドするために選択する必要があるインターフェース タイプはどれですか?
- A. 冗長インターフェース
- B. VLAN インターフェース
- C. ソフトウェア スイッチ インターフェイス
- D. 集約インターフェース
正解:D
解説:
An aggregate interface is a logical interface that combines two or more physical interfaces into one virtual interface1. An aggregate interface can increase network bandwidth and provide redundancy by distributing traffic across multiple physical interfaces using a load balancing algorithm1. An aggregate interface can also support link aggregation control protocol (LACP) to negotiate the link aggregation settings with the connected device1.
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/567758/aggregation-and-redundancy
質問 # 98
RPF チェックを無効にできる 2 つの方法はどれですか? (2つ選択)
- A. ファイアウォール ポリシーでアンチ リプレイを有効にします。
- B. 非対称ルーティングを有効にします。
- C. ソース チェックの FortiGate インターフェイス レベルで RPF チェックを無効にします。
- D. システム設定で strict-arc-check を無効にします。
正解:B、D
質問 # 99
問題が物理層にもリンク層にもない場合に、レイヤー 3 の問題をトラブルシューティングするために使用できる 3 つの CLI コマンドはどれですか? (3つ選んでください。)
- A. スニファ パケットの診断
- B. システム arp を取得
- C. システムトップの診断
- D. ping を実行
- E. traceroute を実行
正解:A、D、E
質問 # 100
......
100%無料NSE4_FGT-7.2日本語日常練習試験には175問があります:https://www.passtest.jp/Fortinet/NSE4_FGT-7.2-JPN-shiken.html