Authentic Fortinet NSE4_FGT_AD-7.6 Exam Dumps PDF - 2026 Updated
Get Prepared for Your NSE4_FGT_AD-7.6 Exam With Actual 100 Questions
NEW QUESTION # 18
A network administrator has configured an SSL/SSH inspection profile defined for full SSL inspection and set with a private CA certificate. The firewall policy that allows the traffic uses this profile for SSL inspection and performs web filtering. When visiting any HTTPS websites, the browser reports certificate warning errors.
What is the reason for the certificate warning errors?
- A. With full SSL inspection it is not possible to avoid certificate warning errors at the browser level.
- B. The SSL cipher compliance option is not enabled on the SSL inspection profile. This setting is required when the SSL inspection profile is defined with a private CA certificate.
- C. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
- D. The browser does not recognize the certificate in use as signed by a trusted CA.
Answer: D
Explanation:
The certificate warning errors occur because the SSL inspection profile is configured to use a private CA certificate that is not recognized by the browser as being signed by a trusted CA. For the browser to trust the FortiGate's re-signed certificates, the CA certificate used by FortiGate for SSL inspection must be installed in the browser's trusted certificate store. Until the browser recognizes the certificate authority (CA) as trusted, it will continue to display warning errors when accessing HTTPS websites.
NEW QUESTION # 19
Refer to the exhibit. Which two statements about the FortiGuard connection are true? (Choose two.)
- A. The weight increases as the number of failed packets rises.
- B. FortiGate identified the FortiGuard Server using DNS lookup.
- C. You can configure unreliable protocols to communicate with FortiGuard Server.
- D. FortiGate is using the default port for FortiGuard communication.
Answer: A,B
Explanation:
FortiGate identified the FortiGuard Server using DNS lookup → The server is shown with a private IP (10.0.1.241), which indicates FortiGate resolved it via DNS or explicit override rather than using default FortiGuard anycast servers.
The weight value reflects server reliability. It decreases with good performance and increases as packet loss or failures rise, meaning higher weight indicates more failures.
NEW QUESTION # 20
Refer to the exhibit. Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
- A. Administrators cannot change the configuration.
- B. Administrators must restart FortiGate to allow new session.
- C. FortiGate drops new sessions requiring inspection.
- D. FortiGate skips quarantine actions.
Answer: C,D
Explanation:
In fail-open mode, FortiGate skips quarantine actions to maintain traffic flow despite IPS or antivirus failures.
FortiGate drops new sessions that require inspection when in conserve mode and fail-open is enabled, to protect the network from potentially harmful traffic.
NEW QUESTION # 21
An administrator wanted to configure an IPS sensor to block traffic that triggers a signature set number of times during a specific time period.
How can the administrator achieve the objective?
- A. Use IPS filter, rate-mode periodical option.
- B. Use IPS filter, rate-mode periodical option.
- C. Use IPS packet logging option with periodical filter option.
- D. Use IPS group signatures, set rate-mode 60.
Answer: B
Explanation:
The IPS filter with the rate-mode set to "periodical" allows the administrator to block traffic that triggers a signature a specified number of times within a defined time period, meeting the requirement.
NEW QUESTION # 22
Refer to the exhibit. Which two statements are true about the routing entries in this database table? (Choose two.)
- A. All of the entries in the routing database table are installed in the FortiGate routing table.
- B. The default route on port2 is marked as the standby route.
- C. The port2 interface is marked as inactive.
- D. Both default routes have different administrative distances.
Answer: B,D
Explanation:
The routing table in the exhibit shows two default routes (0.0.0.0/0) with different administrative distances:
The default route through port2 has an administrative distance of 20. The default route through port1 has an administrative distance of 10. Administrative distance determines the priority of the route; a lower value is preferred. Here, the route through port1 with an administrative distance of
10 is the preferred route. The route through port2 with an administrative distance of 20 acts as a standby or backup route. If the primary route (port1) fails or is unavailable, traffic will then be routed through port2. Regarding the statement that the port2 interface is marked as inactive, there is no indication in the routing table that port2 is inactive. Similarly, all the routes displayed are not necessarily installed in the FortiGate routing table, as the table could include both active and backup routes.
NEW QUESTION # 23
When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate.
Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choose three.)
- A. Trust & Allow
- B. Block
- C. Block & Warning
- D. Allow & Warning
- E. Allow
Answer: B,D,E
Explanation:
When FortiGate performs SSL/SSH full inspection, it can be configured to take one of several actions upon detecting an invalid certificate:
Allow → Lets the traffic through without restriction.
Allow & Warning → Permits the traffic but warns the user about the certificate issue.
Block → Denies the traffic outright to prevent insecure connections.
NEW QUESTION # 24
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate device.
The WAN (port2) interface has the IP address 100.65.0.101/24.
The LAN (port4) interface has the IP address 10.0.11.254/24.
The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.11.50?



- A. 10.0.11.254
- B. 100.65.0.102
- C. 100.65.0.200
- D. 100.65.0.101
Answer: B
Explanation:
Traffic from the workstation 10.0.11.50 going to the internet matches the Internet(1) policy (LAN
→ WAN) which has NAT enabled and is configured to use the IP Pool. The IP pool specifies the external address 100.65.0.102.
FortiGate will perform source NAT (SNAT) on the outbound traffic, translating the source IP of the workstation to 100.65.0.102.
NEW QUESTION # 25
An administrator wants to form an HA cluster using the FGCP protocol.
Which two requirements must the administrator ensure both members fulfill? (Choose two.)
- A. They must have the same number of configured VDOMs.
- B. They must have the heartbeat interfaces in the same subnet.
- C. They must have the same hard drive configuration.
- D. They must have the same HA group ID.
Answer: A,D
Explanation:
They must have the same HA group ID → Both FortiGate units must use the same HA group ID to join the same FGCP cluster.
They must have the same number of configured VDOMs → VDOM configurations must match across cluster members to ensure configuration and state synchronization.
NEW QUESTION # 26
You have created a web filter profile named restrict_media-profile with a daily category usage quota. When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.
What could be the reason?
- A. The web filter profile is already referenced in another firewall policy.
- B. The firewall policy is in no-inspection mode instead of deep-inspection.
- C. The naming convention used in the web filter profile is restricting it in the firewall policy.
- D. The inspection mode in the firewall policy is not matching with web filter profile feature set.
Answer: D
Explanation:
Web filter profiles with category usage quotas require the firewall policy to be in proxy-based (deep) inspection mode; if the inspection mode does not match this requirement, the profile will not appear in the drop-down list.
NEW QUESTION # 27
Refer to the exhibit. Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?
- A. None of the inspected protocols are active in this profile.
- B. Antivirus scan is disabled under System -> Feature visibility.
- C. FortiGate, with less than 2 GB RAM, does not support the Antivirus scan feature.
- D. The Feature Set for the profile is Flow-based but it must be Proxy-based.
Answer: A
Explanation:
The Antivirus scan switch is grayed out because none of the inspected protocols (HTTP, SMTP, POP3, IMAP, FTP, CIFS) have been enabled in the new antivirus profile. Until at least one protocol is turned on, FortiGate does not allow activation of the antivirus scan.
NEW QUESTION # 28
Which three statements about SD-WAN performance SLAs are true? (Choose three.)
- A. They monitor the state of the FortiGate device.
- B. All the SLAtargets can be configured.
- C. They rely on session loss and jitter.
- D. They are applied in a SD-WAN rule lowest cost strategy.
- E. They can be measured actively or passively.
Answer: B,C,E
Explanation:
SD-WAN SLAs monitor metrics like packet loss and jitter to evaluate link performance. SLA measurements can be performed using active probing or passive monitoring. Administrators can configure all SLA target parameters to define performance criteria.
NEW QUESTION # 29
You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied.
What should the administrator check first?
- A. The FortiGate firewall policy settings for SSL decryption.
- B. Whether the user is assigned to the correct AD group.
- C. The windows event viewer for failed login attempts.
- D. The FortiGate FSSO active users list for user's IP address.
Answer: D
Explanation:
Checking the active users list verifies if FortiGate correctly associates the user with their IP address, ensuring proper policy enforcement for internet access.
NEW QUESTION # 30
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.
What is the reason for the certificate warning errors?
- A. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
- B. The matching firewall policy is set to proxy inspection mode.
- C. The browser does not trust the certificate used by FortiGate for SSL inspection.
- D. The option invalid SSL certificates is set to allow on the SSL/SSH inspection profile
Answer: C
Explanation:
When full SSL inspection is enabled, FortiGate decrypts and re-signs HTTPS traffic using its own SSL inspection certificate. If the FortiGate CA certificate is not imported and trusted by the client's browser or OS, the browser sees it as untrusted and displays certificate warning errors. HTTP traffic is unaffected since it does not use certificates.
NEW QUESTION # 31
Refer to the exhibit. The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD- WAN Rule Name.
FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows.
What could be the reason?
- A. FortiGate load balanced the traffic according to the implicit SD-WAN rule.
- B. There is no application control profile applied to the firewall policy.
- C. Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled.
- D. SD-WAN rule names do not appear immediately. The administrator must refresh the page.
Answer: A
Explanation:
The SD-WAN traffic log does not display an SD-WAN rule name because the traffic is being forwarded by the implicit SD-WAN rule. If no explicit SD-WAN rule matches the traffic, FortiGate falls back to the default implicit rule, which balances traffic based on the configured strategy (such as volume or sessions). Since no explicit rule applied, the rule name field remains blank in the logs.
NEW QUESTION # 32
An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled.
However, the static route is not showing in the routing table.
Which two statements about this scenario are correct? (Choose two.)
- A. The administrator must ensure phase 2 is successfully established.
- B. The administrator must define the remote network correctly in the phase 2 selectors.
- C. The administrator must enable a dynamic routing protocol on the dialup interface.
- D. The administrator must use a policy route instead of a static route for add-route to work properly.
Answer: A,B
Explanation:
The administrator must ensure phase 2 is successfully established → The static route for the dialup VPN is only added after Phase 2 negotiation completes successfully.
The administrator must define the remote network correctly in the phase 2 selectors → The add- route feature installs a route based on the Phase 2 selectors; if they are incorrect, no route will appear in the routing table.
NEW QUESTION # 33
Refer to the exhibits. An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access Facebook.com, they are redirected to a FortiGuard web filtering block page.
Based on the exhibits, which configuration change must the administrator make to allow Facebook while blocking all other social networking sites?

- A. Set the Action as Exempt for www.facebook.com in the Static URL Filter.
- B. Change the type as Simple in the Static URL Filter section.
- C. Set the Social Networking action as warning in the FortiGuard Category Based Filter.
- D. Change the Feature set of Web Filter Profile as Proxy-based.
Answer: A
Explanation:
The FortiGuard category filter is blocking Social Networking, which includes Facebook. Although a static URL filter entry for www.facebook.com exists, its action is set to Monitor, so it does not override the category block. To allow Facebook while blocking other social networking sites, the action for www.facebook.com in the Static URL Filter must be set to Exempt. This explicitly bypasses category filtering for that URL.
NEW QUESTION # 34
When configuring a FortiGate in a multi-WAN setup, why would an administrator enable session preservation on an interface?
- A. To allow the FortiGate to dynamically change interfaces for all active sessions when a WAN link fails
- B. To ensure that existing SSL VPN connections remain on the same interface even if route changes occur
- C. To improve security by forcing users to authenticate again when the WAN link changes
- D. To make sure all sessions without source NAT enabled always use the primary WAN link
Answer: B
Explanation:
Session preservation keeps active sessions, such as SSL VPNs, tied to the original interface to prevent disruption when WAN routes change.
NEW QUESTION # 35
Refer to the exhibits. An administrator has observed the performance status outputs on an HA cluster for 55 seconds.
Which FortiGate is the primary?
- A. HQ-NGFW-2 with the parameter priority setting
- B. HQ-NGFW-2 with the parameter memory-failover-threshold setting
- C. HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting
- D. HQ-NGFW-1 with the parameter override setting
Answer: D
Explanation:
The HA configuration shows that override is disabled (set override disable), but despite this, HQ- NGFW-1 has the higher priority (200) and is acting as the primary, as indicated by its higher resource usage and uptime. Override allows the device with higher priority to take over as primary, so HQ- NGFW-1 is the primary device.
NEW QUESTION # 36
Refer to the exhibits. An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access Facebook.com, they are redirected to a FortiGuard web filtering block page.
Based on the exhibits, which configuration change must the administrator make to allow Facebook while blocking all other social networking sites?
- A. Set the Action as Exempt for www.facebook.com
in the Static URL Filter. - B. Change the type as Simple in the Static URL Filter section.
- C. Set the Social Networking action as warning in the FortiGuard Category Based Filter.
- D. Change the Feature set of Web Filter Profile as Proxy-based.
Answer: A
NEW QUESTION # 37
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
- A. A session for denied traffic is created.
- B. Session helpers are disabled for denied traffic.
- C. The number of logs generated by denied traffic is reduced.
- D. Denied users are blocked for 30 minutes.
Answer: A,C
Explanation:
set ses-denied-traffic enable → ensures FortiGate creates a session entry even for denied traffic.
set block-session-timer 30 → sets the duration (30 seconds) that denied sessions remain in the session table. This prevents repeated logging for every packet in the same denied flow, thereby reducing the number of logs generated.
NEW QUESTION # 38
Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.
You cannot access any of the Google applications, but you are able to access www.fortinet.com.
What would you do to resolve this issue?

- A. Change the Inspection mode to Proxy-based.
- B. Set SSL inspection to deep-content-inspection.
- C. Add *Google*.com to the URL category in the security profile.
- D. Move up Google in the Application and Filter Overrides section to set its priority to 1.
Answer: D
Explanation:
In the Application and Filter Overrides, the Excessive-Bandwidth filter (set to Block) is priority 1, and Google (set to Monitor) is priority 2. Since overrides are evaluated by priority, Google traffic is being blocked by the higher-priority rule. Moving Google to the top (priority 1) ensures it is matched first, allowing access while still monitoring it.
NEW QUESTION # 39
Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.)
- A. Incremental configuration synchronization can occur from changes made on any FortiGate device within the HA cluster.
- B. Checksums of devices will be different from each other because some configuration items are not synced to other HA members.
- C. Incremental configuration synchronization can occur only from changes made on the primary FortiGate device.
- D. Checksums of devices are compared against each other to ensure configurations are the same.
Answer: A,D
Explanation:
After the initial synchronization is complete, whenever a change is made to the configuration of an HA cluster device (primary or secondary), incremental synchronization sends the same configuration change to all other cluster devices over the HA heartbeat link.
NEW QUESTION # 40
Refer to the exhibit. Why did the FortiGate device drop the packet?
- A. It matched an explicitly configured firewall policy with the action DENY.
- B. It cannot reach the next-hop IP.
- C. It failed the RPF check.
- D. It matched the default implicit firewall policy.
Answer: A
Explanation:
The packet trace shows policy-0 is matched, act-drop and Denied by forward policy check (policy
0). This means the packet matched an explicitly configured firewall policy (policy ID 0 in this case) whose action is set to DENY, and the traffic was dropped accordingly.
NEW QUESTION # 41
......
Accurate & Verified New NSE4_FGT_AD-7.6 Answers As Experienced in the Actual Test!: https://www.real4dumps.com/NSE4_FGT_AD-7.6_examcollection.html
Valid NSE4_FGT_AD-7.6 Test Answers Full-length Practice Certification Exams: https://drive.google.com/open?id=1KaZk4nsS5Rp7b-6fCG6Kmux5lCxwufcG

