Official Bank 0/173

Fortinet NSE 4 – FortiOS 7.0 (NSE4_FGT-7.0) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
173 Total Questions
1
Question
Consider the topology:
Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout. The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.

What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)
Select 2
Options
A Create a new service object for TELNET and set the maximum session TTL.
B Create a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic,
and set the new TELNET service object in the policy.
C Set the maximum session TTL value for the TELNET service object.
D Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not happen after 90 minutes.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibit.

Exhibit

Exhibit

Exhibit

Exhibit

The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
Options
A 10.200.1.49
B 10.200.1.99
C 10.200.1.149
D 10.200.1.1
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which three methods are used by the collector agent for AD polling? (Choose three.)
Select 3
Options
A WinSecLog
B Novell API
C WMI
D FortiGate polling
E NetAPI
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to Exhibit. Refer to the FortiGuard connection debug output.

Exhibit

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
Select 2
Options
A There is at least one server that lost packets consecutively.
B FortiGate is using default FortiGuard communication settings.
C A local FortiManager is one of the servers FortiGate communicates with.
D One server was contacted to retrieve the contract information.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
In an explicit proxy setup, where is the authentication method and database configured?
Options
A Firewall Policy
B Authentication scheme
C Proxy Policy
D Authentication Rule
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.