Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Firewall Policies Inspection Modes And Traffic Logging Practice Test
This Fortinet NSE4_FGT_AD-7.6 practice test focuses on firewall policies inspection modes and traffic logging through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.
Question 1
For a FortiGate 7.6 deployment at Litware Logistics, which option correctly addresses the need to allow a new transit flow through FortiGate? The team will validate the result immediately after the change.
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Check policy order and whether an earlier rule already matches the traffic
- Place the more specific policy above the broader matching policy
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Use flow-based inspection when its supported features meet the security requirement
Correct answer: D
Explanation
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This directly satisfies the stated requirement.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
Learning point: For this FortiOS 7.6 scenario, create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic. A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements.
Question 2
Wide World Importers has validated routing and basic reachability. The remaining requirement is to prevent a broad allow rule from shadowing a more restrictive rule. Which action should the team take? No unrelated security controls should be changed.
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Account for the implicit deny at the end of the policy list
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Place the more specific policy above the broader matching policy
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
Correct answer: D
Explanation
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This directly satisfies the stated requirement.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
Learning point: For this FortiOS 7.6 scenario, place the more specific policy above the broader matching policy. FortiGate evaluates firewall policies in order and uses the first matching policy.
Question 3
At Graphic Design Institute, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to understand why traffic matching no explicit allow rule is denied. What should the administrator do? The administrator wants a configuration that is easy to audit later.
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Place the more specific policy above the broader matching policy
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Account for the implicit deny at the end of the policy list
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
Correct answer: D
Explanation
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This directly satisfies the stated requirement.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
Learning point: For this FortiOS 7.6 scenario, account for the implicit deny at the end of the policy list. Traffic that does not match an earlier accept policy is denied by the implicit policy.
Question 4
During a maintenance window at Lamna Healthcare, the team must apply antivirus, web filtering, or application control to permitted traffic. Which action is the most appropriate? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Enable the policy logging option appropriate for logging all sessions
- Account for the implicit deny at the end of the policy list
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
Correct answer: B
Explanation
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Security profiles are enforced through the firewall policy handling the session. This directly satisfies the stated requirement.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
Learning point: For this FortiOS 7.6 scenario, attach the required security profiles to the matching accept policy and use compatible inspection settings. Security profiles are enforced through the firewall policy handling the session.
Question 5
A change review at Tailspin Toys identifies one requirement: favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior. Which FortiGate action best satisfies it? The team wants the smallest change that directly addresses the requirement.
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Use flow-based inspection when its supported features meet the security requirement
- Check policy order and whether an earlier rule already matches the traffic
- Enable the policy logging option appropriate for logging all sessions
Correct answer: C
Explanation
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This directly satisfies the stated requirement.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
Learning point: For this FortiOS 7.6 scenario, use flow-based inspection when its supported features meet the security requirement. Flow-based inspection processes traffic as it passes without fully proxying each supported protocol.
Question 6
While troubleshooting at Humongous Insurance, the security engineer needs to use behavior that depends on a full proxy for supported security functions. What is the best next step? The choice should follow normal FortiOS administration practice.
- Place the more specific policy above the broader matching policy
- Check policy order and whether an earlier rule already matches the traffic
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Use flow-based inspection when its supported features meet the security requirement
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
Correct answer: E
Explanation
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use proxy-based inspection for the policy when the required feature or handling depends on proxy mode. Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior.
Question 7
Coho Winery is standardizing its FortiGate 7.6 operations. Which approach should it use to record every accepted session for later traffic analysis? The solution must preserve the existing production design where possible.
- Place the more specific policy above the broader matching policy
- Account for the implicit deny at the end of the policy list
- Enable the policy logging option appropriate for logging all sessions
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Check policy order and whether an earlier rule already matches the traffic
Correct answer: C
Explanation
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- Policy-level traffic logging controls whether allowed session records are generated. This directly satisfies the stated requirement.
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
Learning point: For this FortiOS 7.6 scenario, enable the policy logging option appropriate for logging all sessions. Policy-level traffic logging controls whether allowed session records are generated.
Question 8
A production ticket for Relecloud states that administrators must identify which policy handled a suspicious session. Which choice is correct? The change is being made during a controlled production window.
- Use flow-based inspection when its supported features meet the security requirement
- Place the more specific policy above the broader matching policy
- Account for the implicit deny at the end of the policy list
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
Correct answer: D
Explanation
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
- Traffic logs provide the policy reference used for the session. This directly satisfies the stated requirement.
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
Learning point: For this FortiOS 7.6 scenario, filter traffic logs by the session addresses and inspect the policy ID or policy name field. Traffic logs provide the policy reference used for the session.
Question 9
The security team at Woodgrove Bank wants to troubleshoot a new policy that looks correct but is never hit. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Check policy order and whether an earlier rule already matches the traffic
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Enable the policy logging option appropriate for logging all sessions
Correct answer: B
Explanation
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This directly satisfies the stated requirement.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
Learning point: For this FortiOS 7.6 scenario, check policy order and whether an earlier rule already matches the traffic. A syntactically correct policy can remain unused when an earlier rule captures the same flow.
Question 10
An incident at Alpine Ski House requires the security engineer to protect the FortiGate management plane rather than transit traffic. What should be done first? No unrelated security controls should be changed.
- Enable the policy logging option appropriate for logging all sessions
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Check policy order and whether an earlier rule already matches the traffic
- Place the more specific policy above the broader matching policy
Correct answer: C
Explanation
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This directly satisfies the stated requirement.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
Learning point: For this FortiOS 7.6 scenario, use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy. Traffic terminating on the FortiGate is handled differently from traffic passing through it.
Question 11
For a FortiGate 7.6 deployment at Datum Corporation, which option correctly addresses the need to allow a new transit flow through FortiGate? The administrator wants a configuration that is easy to audit later.
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Use flow-based inspection when its supported features meet the security requirement
- Account for the implicit deny at the end of the policy list
Correct answer: B
Explanation
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This directly satisfies the stated requirement.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
Learning point: For this FortiOS 7.6 scenario, create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic. A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements.
Question 12
Southridge Video has validated routing and basic reachability. The remaining requirement is to prevent a broad allow rule from shadowing a more restrictive rule. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Use flow-based inspection when its supported features meet the security requirement
- Place the more specific policy above the broader matching policy
- Check policy order and whether an earlier rule already matches the traffic
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
Correct answer: C
Explanation
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This directly satisfies the stated requirement.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
Learning point: For this FortiOS 7.6 scenario, place the more specific policy above the broader matching policy. FortiGate evaluates firewall policies in order and uses the first matching policy.
Question 13
At Fabrikam Manufacturing, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to understand why traffic matching no explicit allow rule is denied. What should the administrator do? The team wants the smallest change that directly addresses the requirement.
- Place the more specific policy above the broader matching policy
- Use flow-based inspection when its supported features meet the security requirement
- Account for the implicit deny at the end of the policy list
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
Correct answer: C
Explanation
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This directly satisfies the stated requirement.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
Learning point: For this FortiOS 7.6 scenario, account for the implicit deny at the end of the policy list. Traffic that does not match an earlier accept policy is denied by the implicit policy.
Question 14
During a maintenance window at Wingtip Energy, the team must apply antivirus, web filtering, or application control to permitted traffic. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.
- Place the more specific policy above the broader matching policy
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Enable the policy logging option appropriate for logging all sessions
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
Correct answer: B
Explanation
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Security profiles are enforced through the firewall policy handling the session. This directly satisfies the stated requirement.
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
Learning point: For this FortiOS 7.6 scenario, attach the required security profiles to the matching accept policy and use compatible inspection settings. Security profiles are enforced through the firewall policy handling the session.
Question 15
A change review at Lucerne Publishing identifies one requirement: favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.
- Use flow-based inspection when its supported features meet the security requirement
- Place the more specific policy above the broader matching policy
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
Correct answer: A
Explanation
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This directly satisfies the stated requirement.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
Learning point: For this FortiOS 7.6 scenario, use flow-based inspection when its supported features meet the security requirement. Flow-based inspection processes traffic as it passes without fully proxying each supported protocol.
Question 16
While troubleshooting at School of Fine Art, the security engineer needs to use behavior that depends on a full proxy for supported security functions. What is the best next step? The change is being made during a controlled production window.
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Place the more specific policy above the broader matching policy
- Use flow-based inspection when its supported features meet the security requirement
Correct answer: C
Explanation
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This directly satisfies the stated requirement.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use behavior that depends on a full proxy for supported security functions.
Learning point: For this FortiOS 7.6 scenario, use proxy-based inspection for the policy when the required feature or handling depends on proxy mode. Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior.
Question 17
Apex Retail is standardizing its FortiGate 7.6 operations. Which approach should it use to record every accepted session for later traffic analysis? The team will validate the result immediately after the change.
- Account for the implicit deny at the end of the policy list
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Place the more specific policy above the broader matching policy
- Enable the policy logging option appropriate for logging all sessions
Correct answer: E
Explanation
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to record every accepted session for later traffic analysis.
- Policy-level traffic logging controls whether allowed session records are generated. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, enable the policy logging option appropriate for logging all sessions. Policy-level traffic logging controls whether allowed session records are generated.
Question 18
A production ticket for Proseware Media states that administrators must identify which policy handled a suspicious session. Which choice is correct? No unrelated security controls should be changed.
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Enable the policy logging option appropriate for logging all sessions
- Place the more specific policy above the broader matching policy
- Account for the implicit deny at the end of the policy list
Correct answer: B
Explanation
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
- Traffic logs provide the policy reference used for the session. This directly satisfies the stated requirement.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which policy handled a suspicious session.
Learning point: For this FortiOS 7.6 scenario, filter traffic logs by the session addresses and inspect the policy ID or policy name field. Traffic logs provide the policy reference used for the session.
Question 19
The security team at City Power & Light wants to troubleshoot a new policy that looks correct but is never hit. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.
- Check policy order and whether an earlier rule already matches the traffic
- Account for the implicit deny at the end of the policy list
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Enable the policy logging option appropriate for logging all sessions
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
Correct answer: A
Explanation
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This directly satisfies the stated requirement.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a new policy that looks correct but is never hit.
Learning point: For this FortiOS 7.6 scenario, check policy order and whether an earlier rule already matches the traffic. A syntactically correct policy can remain unused when an earlier rule captures the same flow.
Question 20
An incident at Margie Travel requires the security engineer to protect the FortiGate management plane rather than transit traffic. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Place the more specific policy above the broader matching policy
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Check policy order and whether an earlier rule already matches the traffic
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Enable the policy logging option appropriate for logging all sessions
Correct answer: B
Explanation
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This directly satisfies the stated requirement.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to protect the FortiGate management plane rather than transit traffic.
Learning point: For this FortiOS 7.6 scenario, use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy. Traffic terminating on the FortiGate is handled differently from traffic passing through it.
Question 21
For a FortiGate 7.6 deployment at Bellows College, which option correctly addresses the need to allow a new transit flow through FortiGate? The team wants the smallest change that directly addresses the requirement.
- Use flow-based inspection when its supported features meet the security requirement
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Place the more specific policy above the broader matching policy
- Account for the implicit deny at the end of the policy list
Correct answer: B
Explanation
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This directly satisfies the stated requirement.
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a new transit flow through FortiGate.
Learning point: For this FortiOS 7.6 scenario, create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic. A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements.
Question 22
Adventure Works has validated routing and basic reachability. The remaining requirement is to prevent a broad allow rule from shadowing a more restrictive rule. Which action should the team take? The choice should follow normal FortiOS administration practice.
- Use flow-based inspection when its supported features meet the security requirement
- Check policy order and whether an earlier rule already matches the traffic
- Place the more specific policy above the broader matching policy
- Use proxy-based inspection for the policy when the required feature or handling depends on proxy mode
- Account for the implicit deny at the end of the policy list
Correct answer: C
Explanation
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This directly satisfies the stated requirement.
- Proxy-based inspection terminates and proxies supported sessions to provide proxy-mode security behavior. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a broad allow rule from shadowing a more restrictive rule.
Learning point: For this FortiOS 7.6 scenario, place the more specific policy above the broader matching policy. FortiGate evaluates firewall policies in order and uses the first matching policy.
Question 23
At Fourth Coffee, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to understand why traffic matching no explicit allow rule is denied. What should the administrator do? The solution must preserve the existing production design where possible.
- Account for the implicit deny at the end of the policy list
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Enable the policy logging option appropriate for logging all sessions
- Place the more specific policy above the broader matching policy
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
Correct answer: A
Explanation
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This directly satisfies the stated requirement.
- Security profiles are enforced through the firewall policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- Policy-level traffic logging controls whether allowed session records are generated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why traffic matching no explicit allow rule is denied.
Learning point: For this FortiOS 7.6 scenario, account for the implicit deny at the end of the policy list. Traffic that does not match an earlier accept policy is denied by the implicit policy.
Question 24
During a maintenance window at Consolidated Messenger, the team must apply antivirus, web filtering, or application control to permitted traffic. Which action is the most appropriate? The change is being made during a controlled production window.
- Place the more specific policy above the broader matching policy
- Attach the required security profiles to the matching accept policy and use compatible inspection settings
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Use flow-based inspection when its supported features meet the security requirement
- Check policy order and whether an earlier rule already matches the traffic
Correct answer: B
Explanation
- FortiGate evaluates firewall policies in order and uses the first matching policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Security profiles are enforced through the firewall policy handling the session. This directly satisfies the stated requirement.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
- A syntactically correct policy can remain unused when an earlier rule captures the same flow. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply antivirus, web filtering, or application control to permitted traffic.
Learning point: For this FortiOS 7.6 scenario, attach the required security profiles to the matching accept policy and use compatible inspection settings. Security profiles are enforced through the firewall policy handling the session.
Question 25
A change review at VanArsdel identifies one requirement: favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior. Which FortiGate action best satisfies it? The team will validate the result immediately after the change.
- Filter traffic logs by the session addresses and inspect the policy ID or policy name field
- Use the management or local-in controls appropriate to traffic destined to the FortiGate itself instead of relying on a transit firewall policy
- Account for the implicit deny at the end of the policy list
- Create an accept firewall policy whose incoming interface, outgoing interface, source, destination, service, and schedule match the traffic
- Use flow-based inspection when its supported features meet the security requirement
Correct answer: E
Explanation
- Traffic logs provide the policy reference used for the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Traffic terminating on the FortiGate is handled differently from traffic passing through it. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Traffic that does not match an earlier accept policy is denied by the implicit policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- A transit session is permitted only when it matches an applicable accept policy and other forwarding requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to favor stream-oriented inspection and lower proxy overhead for a policy that does not require proxy-only behavior.
- Flow-based inspection processes traffic as it passes without fully proxying each supported protocol. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use flow-based inspection when its supported features meet the security requirement. Flow-based inspection processes traffic as it passes without fully proxying each supported protocol.