Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Web Filtering Inspection Modes And Profiles Practice Test
This Fortinet NSE4_FGT_AD-7.6 practice test focuses on web filtering inspection modes and profiles through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.
Question 1
VanArsdel is standardizing its FortiGate 7.6 operations. Which approach should it use to use web filtering with a flow-based policy when all required controls are supported in flow mode? The solution must preserve the existing production design where possible.
- Use certificate inspection with the web filter profile for the applicable policy
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
Correct answer: B
Explanation
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- The policy inspection mode and profile capabilities must be compatible. This directly satisfies the stated requirement.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
Learning point: For this FortiOS 7.6 scenario, configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy. The policy inspection mode and profile capabilities must be compatible.
Question 2
A production ticket for Northwind Health states that administrators must use a proxy-only web filtering behavior that requires full proxy processing. Which choice is correct? The change is being made during a controlled production window.
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
Correct answer: A
Explanation
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
Learning point: For this FortiOS 7.6 scenario, set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode. Proxy-based inspection provides supported proxy-specific web filtering behaviors.
Question 3
The security team at Blue Yonder Airlines wants to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use certificate inspection with the web filter profile for the applicable policy
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
Correct answer: B
Explanation
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This directly satisfies the stated requirement.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
Learning point: For this FortiOS 7.6 scenario, use certificate inspection with the web filter profile for the applicable policy. Certificate inspection can provide certificate and hostname visibility without full payload decryption.
Question 4
An incident at Trey Research requires the security engineer to enforce web-category policy on traffic allowed by a firewall rule. What should be done first? No unrelated security controls should be changed.
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
Correct answer: C
Explanation
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This directly satisfies the stated requirement.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
Learning point: For this FortiOS 7.6 scenario, attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility. The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection.
Question 5
For a FortiGate 7.6 deployment at Nod Publishers, which option correctly addresses the need to apply different web access rules to two user populations using different firewall policies? The administrator wants a configuration that is easy to audit later.
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Use certificate inspection with the web filter profile for the applicable policy
Correct answer: A
Explanation
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This directly satisfies the stated requirement.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
Learning point: For this FortiOS 7.6 scenario, use separate web filter profiles or policy context so each population receives the intended category and URL actions. Profiles attached to the matching policy let FortiGate apply different web controls to different traffic.
Question 6
Contoso Finance has validated routing and basic reachability. The remaining requirement is to troubleshoot a web-filter option that is unavailable in the selected policy mode. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Use certificate inspection with the web filter profile for the applicable policy
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
Correct answer: E
Explanation
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Some web-filter functions differ between flow and proxy inspection modes. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it. Some web-filter functions differ between flow and proxy inspection modes.
Question 7
At Litware Logistics, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled. What should the administrator do? The team wants the smallest change that directly addresses the requirement.
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Use full SSL inspection when encrypted payload must be scanned by antivirus
Correct answer: E
Explanation
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use full SSL inspection when encrypted payload must be scanned by antivirus. Certificate inspection does not decrypt the HTTPS payload for antivirus scanning.
Question 8
During a maintenance window at Wide World Importers, the team must prove which web profile handled a blocked request. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Use certificate inspection with the web filter profile for the applicable policy
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
Correct answer: A
Explanation
- Security-event logs show the web-filter decision and profile context for the request. This directly satisfies the stated requirement.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
Learning point: For this FortiOS 7.6 scenario, review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields. Security-event logs show the web-filter decision and profile context for the request.
Question 9
A change review at Graphic Design Institute identifies one requirement: use web filtering with a flow-based policy when all required controls are supported in flow mode. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.
- Use certificate inspection with the web filter profile for the applicable policy
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
Correct answer: B
Explanation
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- The policy inspection mode and profile capabilities must be compatible. This directly satisfies the stated requirement.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
Learning point: For this FortiOS 7.6 scenario, configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy. The policy inspection mode and profile capabilities must be compatible.
Question 10
While troubleshooting at Lamna Healthcare, the security engineer needs to use a proxy-only web filtering behavior that requires full proxy processing. What is the best next step? The change is being made during a controlled production window.
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
Correct answer: D
Explanation
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
Learning point: For this FortiOS 7.6 scenario, set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode. Proxy-based inspection provides supported proxy-specific web filtering behaviors.
Question 11
Tailspin Toys is standardizing its FortiGate 7.6 operations. Which approach should it use to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient? The team will validate the result immediately after the change.
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Use certificate inspection with the web filter profile for the applicable policy
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
Correct answer: D
Explanation
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
Learning point: For this FortiOS 7.6 scenario, use certificate inspection with the web filter profile for the applicable policy. Certificate inspection can provide certificate and hostname visibility without full payload decryption.
Question 12
A production ticket for Humongous Insurance states that administrators must enforce web-category policy on traffic allowed by a firewall rule. Which choice is correct? No unrelated security controls should be changed.
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Use certificate inspection with the web filter profile for the applicable policy
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
Correct answer: E
Explanation
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility. The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection.
Question 13
The security team at Coho Winery wants to apply different web access rules to two user populations using different firewall policies. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
Correct answer: B
Explanation
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
Learning point: For this FortiOS 7.6 scenario, use separate web filter profiles or policy context so each population receives the intended category and URL actions. Profiles attached to the matching policy let FortiGate apply different web controls to different traffic.
Question 14
An incident at Relecloud requires the security engineer to troubleshoot a web-filter option that is unavailable in the selected policy mode. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Use full SSL inspection when encrypted payload must be scanned by antivirus
Correct answer: B
Explanation
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Some web-filter functions differ between flow and proxy inspection modes. This directly satisfies the stated requirement.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
Learning point: For this FortiOS 7.6 scenario, confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it. Some web-filter functions differ between flow and proxy inspection modes.
Question 15
For a FortiGate 7.6 deployment at Woodgrove Bank, which option correctly addresses the need to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled? The team wants the smallest change that directly addresses the requirement.
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
Correct answer: A
Explanation
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This directly satisfies the stated requirement.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
Learning point: For this FortiOS 7.6 scenario, use full SSL inspection when encrypted payload must be scanned by antivirus. Certificate inspection does not decrypt the HTTPS payload for antivirus scanning.
Question 16
Alpine Ski House has validated routing and basic reachability. The remaining requirement is to prove which web profile handled a blocked request. Which action should the team take? The choice should follow normal FortiOS administration practice.
- Use certificate inspection with the web filter profile for the applicable policy
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
Correct answer: D
Explanation
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Security-event logs show the web-filter decision and profile context for the request. This directly satisfies the stated requirement.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
Learning point: For this FortiOS 7.6 scenario, review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields. Security-event logs show the web-filter decision and profile context for the request.
Question 17
At Datum Corporation, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to use web filtering with a flow-based policy when all required controls are supported in flow mode. What should the administrator do? The solution must preserve the existing production design where possible.
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
Correct answer: B
Explanation
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- The policy inspection mode and profile capabilities must be compatible. This directly satisfies the stated requirement.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
Learning point: For this FortiOS 7.6 scenario, configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy. The policy inspection mode and profile capabilities must be compatible.
Question 18
During a maintenance window at Southridge Video, the team must use a proxy-only web filtering behavior that requires full proxy processing. Which action is the most appropriate? The change is being made during a controlled production window.
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Use certificate inspection with the web filter profile for the applicable policy
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
Correct answer: E
Explanation
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use a proxy-only web filtering behavior that requires full proxy processing.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode. Proxy-based inspection provides supported proxy-specific web filtering behaviors.
Question 19
A change review at Fabrikam Manufacturing identifies one requirement: categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient. Which FortiGate action best satisfies it? The team will validate the result immediately after the change.
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Use certificate inspection with the web filter profile for the applicable policy
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
Correct answer: C
Explanation
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to categorize HTTPS destinations without decrypting the full encrypted payload when that visibility is sufficient.
Learning point: For this FortiOS 7.6 scenario, use certificate inspection with the web filter profile for the applicable policy. Certificate inspection can provide certificate and hostname visibility without full payload decryption.
Question 20
While troubleshooting at Wingtip Energy, the security engineer needs to enforce web-category policy on traffic allowed by a firewall rule. What is the best next step? No unrelated security controls should be changed.
- Use certificate inspection with the web filter profile for the applicable policy
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Use full SSL inspection when encrypted payload must be scanned by antivirus
Correct answer: D
Explanation
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This directly satisfies the stated requirement.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to enforce web-category policy on traffic allowed by a firewall rule.
Learning point: For this FortiOS 7.6 scenario, attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility. The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection.
Question 21
Lucerne Publishing is standardizing its FortiGate 7.6 operations. Which approach should it use to apply different web access rules to two user populations using different firewall policies? The administrator wants a configuration that is easy to audit later.
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
Correct answer: C
Explanation
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to apply different web access rules to two user populations using different firewall policies.
Learning point: For this FortiOS 7.6 scenario, use separate web filter profiles or policy context so each population receives the intended category and URL actions. Profiles attached to the matching policy let FortiGate apply different web controls to different traffic.
Question 22
A production ticket for School of Fine Art states that administrators must troubleshoot a web-filter option that is unavailable in the selected policy mode. Which choice is correct? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
Correct answer: A
Explanation
- Some web-filter functions differ between flow and proxy inspection modes. This directly satisfies the stated requirement.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a web-filter option that is unavailable in the selected policy mode.
Learning point: For this FortiOS 7.6 scenario, confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it. Some web-filter functions differ between flow and proxy inspection modes.
Question 23
The security team at Apex Retail wants to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled. Which FortiGate configuration or action most directly meets that goal? The team wants the smallest change that directly addresses the requirement.
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use certificate inspection with the web filter profile for the applicable policy
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
Correct answer: B
Explanation
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This directly satisfies the stated requirement.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
- The policy inspection mode and profile capabilities must be compatible. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why a downloaded HTTPS file is not available to antivirus while only certificate inspection is enabled.
Learning point: For this FortiOS 7.6 scenario, use full SSL inspection when encrypted payload must be scanned by antivirus. Certificate inspection does not decrypt the HTTPS payload for antivirus scanning.
Question 24
An incident at Proseware Media requires the security engineer to prove which web profile handled a blocked request. What should be done first? The choice should follow normal FortiOS administration practice.
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Confirm whether the feature requires proxy inspection and change the policy inspection mode only when the security requirement justifies it
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Set the policy and web filtering design to proxy-based inspection when the required feature depends on proxy mode
- Attach the appropriate web filter profile to the matching firewall policy and enable a compatible SSL inspection profile for HTTPS visibility
Correct answer: A
Explanation
- Security-event logs show the web-filter decision and profile context for the request. This directly satisfies the stated requirement.
- Some web-filter functions differ between flow and proxy inspection modes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- Proxy-based inspection provides supported proxy-specific web filtering behaviors. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
- The web filter profile is invoked through the firewall policy and depends on suitable HTTPS inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prove which web profile handled a blocked request.
Learning point: For this FortiOS 7.6 scenario, review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields. Security-event logs show the web-filter decision and profile context for the request.
Question 25
For a FortiGate 7.6 deployment at City Power & Light, which option correctly addresses the need to use web filtering with a flow-based policy when all required controls are supported in flow mode? The solution must preserve the existing production design where possible.
- Use full SSL inspection when encrypted payload must be scanned by antivirus
- Use certificate inspection with the web filter profile for the applicable policy
- Review web-filter and traffic logs for the session and identify the profile, category, URL, and policy fields
- Use separate web filter profiles or policy context so each population receives the intended category and URL actions
- Configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy
Correct answer: E
Explanation
- Certificate inspection does not decrypt the HTTPS payload for antivirus scanning. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Certificate inspection can provide certificate and hostname visibility without full payload decryption. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Security-event logs show the web-filter decision and profile context for the request. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- Profiles attached to the matching policy let FortiGate apply different web controls to different traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use web filtering with a flow-based policy when all required controls are supported in flow mode.
- The policy inspection mode and profile capabilities must be compatible. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, configure the web filter profile for flow-based operation and apply it to a flow-inspection firewall policy. The policy inspection mode and profile capabilities must be compatible.