Official Bank 0/173

Fortinet NSE 4 – FortiOS 7.0 (NSE4_FGT-7.0) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
173 Total Questions
1
Question
A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.

Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
Options
A The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.
B The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
C The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
D The two VLAN sub interfaces must have different VLAN IDs.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibit.

Exhibit

Exhibit

Exhibit

Exhibit

The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
Options
A 10.200.1.49
B 10.200.1.99
C 10.200.1.149
D 10.200.1.1
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
Options
A Flow engine
B Detection engine
C Antivirus engine
D Intrusion prevention system engine
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to the exhibit.

Exhibit

The exhibits show a network diagram and the explicit web proxy configuration. In the command diagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?
Options
A ‘host 192.168.0.1 and port 80’
B ‘host 10.0.0.50 and port 8080’
C ‘host 192.168.0.2 and port 8080’
D ‘host 10.0.0.50 and port 80’
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)
Select 2
Options
A NTP
B DNS
C FortiGuard web filter cache
D FortiGate hostname
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.