Jun 24, 2026 PASS Fortinet NSE4_FGT_AD-7.6 EXAM WITH UPDATED DUMPS
NSE4_FGT_AD-7.6 Questions PDF [2026] Use Valid New dump to Clear Exam
Fortinet NSE4_FGT_AD-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 59
Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy, and the sniffer CLI output on the FortiGate device.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The webserver host (10.0.1.10) must use its VIP external IP address as the source NAT (SNAT) when it pings remote server (10.200.3.1).
Which two statements are valid to achieve this goal? (Choose two.)
- A. Disable port forwarding on the VIP object.
- B. Enable NAT on the Allow_access firewall policy.
- C. Create a new firewall policy before Internet_Access for the webserver and apply the IP pool.
- D. Disable NAT on the Internet_Access firewall policy.
Answer: A,C
Explanation:
The current VIP is configured with port forwarding, so it only applies to TCP/80 traffic. To use the VIP's external address (10.200.1.200) as the source for any outbound sessions (such as ICMP ping), the VIP must be a full static 1-to-1 NAT, which requires disabling port forwarding.
You then need a dedicated firewall policy for the webserver that is placed before the generic Internet_Access policy and that uses an IP pool with 10.200.1.200. Traffic from 10.0.1.10 will match this policy first and be SNATed to 10.200.1.200, so the remote server 10.200.3.1 sees the VIP external IP as the source.
NEW QUESTION # 60
What is the primary FortiGate election process when the HA override setting is enabled?
- A. Connected monitored ports > System uptime > Priority > FortiGate serial number
- B. Connected monitored ports > Priority > HA uptime > FortiGate serial number
- C. Connected monitored ports > HA uptime > Priority > FortiGate serial number
- D. Connected monitored ports > Priority > System uptime > FortiGate serial number
Answer: B
Explanation:
If Override DISABLED then: ports > HA Uptime > Priority > SN.
If Overrrid ENABLED then: ports > Priority > HA Uptime > SN.
NEW QUESTION # 61
There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels. Which phase
1 setting you can configure to match the user to the tunnel?
- A. IKE Mode Config
- B. Peer ID
- C. Dead Peer Detection
- D. Local Gateway
Answer: B
Explanation:
Peer ID is used in aggressive mode dialup IPsec VPNs to identify and match incoming VPN connections to their correct phase 1 configuration/tunnel. This allows each department or user to have a unique identifier, ensuring users are connected to the correct VPN tunnel. This is the recommended approach for environments with multiple dial-up users or tunnels.
NEW QUESTION # 62
Refer to the exhibits. An administrator configured both members of an HA cluster at the same time. After one week of monitoring, the administrator wants to verify the HA failover performance.
How can the administrator force a failover?

- A. The administrator must set the parameter override to enable on HQ-NGFW-2.
- B. The administrator must increase the HA priority on HQ-NGFW-2.
- C. The administrator must reset the HA uptime on HQ-NGFW-1.
- D. The administrator must set the monitored port to down on HQ-NGFW-1.
Answer: D
Explanation:
Both FortiGates are in an active-passive (a-p) HA cluster with override disabled. This means failover is triggered only if the primary (HQ-NGFW-1) becomes unavailable or monitored interfaces fail. To test failover performance, the administrator can set the monitored interface (port1) down on HQ-NGFW-1, which will force a failover to HQ-NGFW-2.
NEW QUESTION # 63
Refer to the exhibits.

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.
Which two factors can you observe from these configurations? (Choose two.)
- A. Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings.
- B. YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings.
- C. YouTube search is allowed based on the Google Application and Filter override settings.
- D. Facebook access is blocked based on the category filter settings.
Answer: B,D
Explanation:
From the exhibits:
The Application Control sensor has these key settings:
Application and Filter Overrides
Priority 1: Excessive-Bandwidth (Type: Filter) with Action Block
Priority 2: Google (Type: Filter) with Action Monitor
Category actions shown include Social Media set to Block (this category includes Facebook).
The firewall policy is using:
Flow-based inspection
Application control enabled (profile: default)
Deep inspection enabled (helps identify applications inside HTTPS)
Logging enabled
FortiOS applies Application Control as follows (top-down within the Application Control profile):
Overrides are evaluated by priority (highest priority first).
The first matching override determines the action (block/monitor/allow) for that traffic.
Category-based actions apply to applications that fall into those categories unless an override matches first.
Why A is correct
A). YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings.
The profile explicitly blocks the Excessive-Bandwidth behavior filter at the highest override priority.
When YouTube traffic is detected as matching the Excessive-Bandwidth behavior, FortiGate will apply the Block action due to the override.
Because this is a priority override, it is enforced before lower-priority entries.
Why B is correct
B). Facebook access is blocked based on the category filter settings.
The Application Sensor shows Social Media configured with a Block action.
Facebook is categorized under Social Media, so it will be blocked when matched by Application Control.
Why C is not correct
C). Facebook access is allowed but you cannot play Facebook videos...
Since the Social Media category is set to Block, Facebook would be blocked at the category level (not merely video playback).
Why D is not correct
D). YouTube search is allowed based on the Google override...
The Google override action is Monitor, not Allow.
"Monitor" logs/detects but does not override a block condition to "allow" traffic.
Also, YouTube traffic is not guaranteed to be treated as "Google" in a way that would permit it, and any matching block condition (such as Excessive-Bandwidth) would still take precedence.
NEW QUESTION # 64
You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied. What should the administrator check first?
- A. The windows event viewer for failed login attempts.
- B. The FortiGate FSSO active users list for user's IP address.
- C. The FortiGate firewall policy settings for SSL decryption.
- D. Whether the user is assigned to the correct AD group.
Answer: B
Explanation:
Checking the active users list verifies if FortiGate correctly associates the user with their IP address, ensuring proper policy enforcement for internet access.
NEW QUESTION # 65
Refer to the exhibit.
An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times.
Why are there no logs generated under security logs for ABC.Com?
- A. The ABC.Com is configured under application profile, which must be configured as a web filter profile.
- B. The ABC.Com Type is set as Application instead of Filter.
- C. The ABC Com Action is set to Allow
- D. The ABC Com is hitting the category Excessive-Bandwidth.
Answer: C
Explanation:
In FortiOS 7.6 Application Control, security logs are generated primarily for actions such as Block or Monitor, not for Allow actions.
What is happening in the exhibit
An Application Override is configured for ABC.Com
Type: Application
Action: Allow
The application control profile is applied to a firewall policy
Logging is enabled on the firewall policy
Traffic to ABC.Com is successfully allowed
However, no security logs appear for ABC.Com.
Why no logs are generated
In FortiOS 7.6:
Application Control logs are written to Security Logs when:
An application is Blocked
An application is Monitored
When an application action is set to Allow:
The traffic is permitted silently
No application control security log is generated
Even if policy logging is enabled
This is expected and documented behavior.
To generate logs for allowed applications, the action must be set to Monitor, not Allow.
Why the other options are incorrect
A). ABC.Com is hitting the category Excessive-Bandwidth
Incorrect. ABC.Com has a higher-priority explicit override (priority 1), so it is not evaluated against the Excessive-Bandwidth filter.
B). The ABC.Com Type is set as Application instead of Filter
Incorrect. Application-type overrides are valid and commonly used; this does not suppress logging.
C). The ABC.Com must be configured as a web filter profile
Incorrect. This traffic is being evaluated by Application Control, not Web Filter.
NEW QUESTION # 66
Refer to the exhibits. Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibit.
What would be the expected outcome in the HA cluster?
- A. HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.
- B. The HA cluster will become out of sync because the override setting must match on all HA members.
- C. HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.
- D. HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority.
Answer: C
Explanation:
With override enabled on HQ-NGFW-2 and its higher priority (110 vs. 90), HQ-NGFW-2 will become the primary device, preempting HQ-NGFW-1 despite the current primary status.
NEW QUESTION # 67
Refer to the exhibit showing a FortiGuard connection debug output.
Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
- A. FortiGate is using default FortiGuard communication settings.
- B. A local FortiManager is one of the servers FortiGate communicates with.
- C. One server was contacted to retrieve the contract information.
- D. There is at least one server that lost packets consecutively.
Answer: A,C
Explanation:
The output shows that one server was contacted to retrieve FortiGuard contract information, as indicated under "Service : Web-filter" with "License : Contract" and "Num. of servers : 1." The entry "Default servers : Included" confirms that FortiGate is using the default FortiGuard communication settings, meaning it communicates directly with Fortinet's public FortiGuard servers instead of a custom or local override.
NEW QUESTION # 68
Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.)
- A. The proxy auto-configuration (PAC) file
- B. VPN policies
- C. FortiExtender
- D. FortiSASE Firewall-as-a-Service (FWaaS)
Answer: B,D
Explanation:
In FortiSASE Secure Internet Access (SIA) agent-based mode, traffic steering and security enforcement rely on components integrated with the FortiClient agent.
Components used in SIA agent-based mode
A . FortiSASE Firewall-as-a-Service (FWaaS)
Correct.
FWaaS is a core security component of FortiSASE.
It enforces firewall policies, security inspection, and access control for agent-based users.
All user traffic tunneled by the agent is inspected by FWaaS.
C . VPN policies
Correct.
In agent-based mode, the FortiClient establishes a secure tunnel to FortiSASE.
VPN policies define:
Authentication
Access control
Traffic steering
These policies are fundamental to agent-based connectivity.
Why the other options are incorrect
B . Proxy auto-configuration (PAC) file
PAC files are used in agentless or proxy-based modes, not agent-based SIA.
D). FortiExtender
FortiExtender is a WAN extension device and is unrelated to FortiSASE SIA agent-based architecture.
NEW QUESTION # 69
Refer to the exhibit.
Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
- A. FortiGate drops new sessions requiring inspection.
- B. Administrators must restart FortiGate to allow new sessions.
- C. Administrators cannot change the configuration.
- D. FortiGate skips quarantine actions.
Answer: C,D
NEW QUESTION # 70
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re- entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)
- A. On HQ-FortiGate, set IKE mode to Main (ID protection).
- B. On Remote-FortiGate, set port2 as Interface.
- C. On both FortiGate devices, set Dead Peer Detection to On Demand.
- D. On HQ-FortiGate, disable Diffie-Helman group 2.
Answer: A,B
Explanation:
On the HQ-FortiGate the IKE phase 1 mode is set to Aggressive, while on the Remote-FortiGate it is set to Main (ID protection). Both sides must use the same IKE mode for phase 1 to come up, so changing HQ-FortiGate to Main mode resolves this mismatch.
On the Remote-FortiGate, the phase 1 Interface is configured as port1, but according to the diagram the WAN-facing interface with IP 10.10.200.10 is port2. The local interface in the IPsec configuration must match the physical WAN interface, so changing it to port2 is required for the tunnel to establish.
NEW QUESTION # 71
An administrator wants to ensure that a specific firewall policy on FortiGate is matched before any other policies for the same traffic. Which configuration change is most appropriate?
- A. Change the policy schedule to always
- B. Move the policy higher in the policy list
- C. Increase the policy ID number
- D. Enable central NAT
Answer: B
Explanation:
FortiGate processes policies from top to bottom, matching traffic against the first policy whose criteria are satisfied. By moving a policy above others that might also match the traffic, you ensure it is evaluated first. On the exam, always remember that the visual order in the policy list governs evaluation, not the policy ID or creation time.
NEW QUESTION # 72
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
- A. On BR1-FGT, set Seconds to 43200.
- B. On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.
- C. On HQ-NGFW, enable Diffie-Hellman Group 2.
- D. On HQ-NGFW, set Encryption to AES256.
Answer: B,D
Explanation:
Check the IP address
The remote subnet selectors don't match. Set BR1-FGT's Remote Address to
10.0.11.0/255.255.255.0 (C).
The phase-2 proposal algorithms don't match. Change HQ-NGFW Encryption from AES128 to AES256 to match BR1-FGT (D).
NEW QUESTION # 73
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?
- A. On Idle
- B. Enabled
- C. On Demand
- D. Usabled
Answer: C
Explanation:
Based on the FortiOS 7.6 Infrastructure and IPsec VPN documentation, Dead Peer Detection (DPD) can be configured in three primary modes: On Demand, On Idle, and Disabled.
On Demand (Default Mode): This mode is specifically designed to minimize unnecessary traffic. In this mode, FortiGate sends DPD probes only when there is no inbound traffic but the FortiGate is attempting to send outbound traffic. Because network communication is typically bidirectional, the absence of inbound traffic while outbound traffic is being sent is a primary indicator of a potentially dead tunnel. This matches the specific requirement described in the question.
On Idle: In this mode, DPD probes are sent if no traffic (neither inbound nor outbound) has been observed in the tunnel for a specific period. It verifies the tunnel status even when the connection is completely idle.
Enabled: In older versions or specific CLI contexts, "Enabled" may refer to periodic DPD, but in the current FortiOS 7.x/7.6 GUI and CLI terminology for Phase 1 settings, the active modes are defined as on-demand or on-idle.
Disabled: In this mode, the FortiGate does not send DPD probes but will still respond to DPD probes sent by the remote peer.
The requirement that the administrator wants probes sent only when there is no inbound traffic (usually implying the FortiGate is sending but not receiving) is the fundamental definition of the On Demand mechanism in the Fortinet curriculum.
NEW QUESTION # 74
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?
- A. On Idle
- B. Enabled
- C. On Demand
- D. Usabled
Answer: C
Explanation:
Based on the FortiOS 7.6 Infrastructure and IPsec VPN documentation, Dead Peer Detection (DPD) can be configured in three primary modes: On Demand, On Idle, and Disabled.
On Demand (Default Mode): This mode is specifically designed to minimize unnecessary traffic. In this mode, FortiGate sends DPD probes only when there is no inbound traffic but the FortiGate is attempting to send outbound traffic. Because network communication is typically bidirectional, the absence of inbound traffic while outbound traffic is being sent is a primary indicator of a potentially dead tunnel. This matches the specific requirement described in the question.
On Idle: In this mode, DPD probes are sent if no traffic (neither inbound nor outbound) has been observed in the tunnel for a specific period. It verifies the tunnel status even when the connection is completely idle.
Enabled: In older versions or specific CLI contexts, "Enabled" may refer to periodic DPD, but in the current FortiOS 7.x/7.6 GUI and CLI terminology for Phase 1 settings, the active modes are defined as on-demand or on-idle.
Disabled: In this mode, the FortiGate does not send DPD probes but will still respond to DPD probes sent by the remote peer.
The requirement that the administrator wants probes sent only when there is no inbound traffic (usually implying the FortiGate is sending but not receiving) is the fundamental definition of the On Demand mechanism in the Fortinet curriculum.
NEW QUESTION # 75
Refer to the exhibit.
As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit What could be the possible reason of the diagnose output shown in the exhibit?
- A. Administrator entered the command diagnose test application ipsmonitor 5.
- B. There is a no firewall policy configured with an IPS security profile.
- C. FortiGate entered into IPS fail open state.
- D. Administrator entered the command diagnose test application ipsmonitor 99.
Answer: B
Explanation:
The exhibit shows the output of the following command:
diagnose test application ipsmonitor 1
pid = 2044, engine count = 0 (+1)
0 - pid:2074:2074 cfg:1 master:0 run:1
How to interpret this output (FortiOS 7.6 - IPS internals)
ipsmonitor displays the status of IPS engines running on the FortiGate.
engine count = 0 means:
No IPS scanning engines are currently active
IPS is not processing any traffic
In FortiOS, IPS engines are started on demand.
Critical documented behavior
IPS processes are only spawned when at least one firewall policy is configured with an IPS profile and traffic matches that policy.
If no firewall policy references an IPS profile, the IPS engine:
Does not start
Shows engine count = 0
Appears "not working," even though the IPS profile exists
This is exactly what the diagnose output indicates.
Why option A is correct
A . There is no firewall policy configured with an IPS security profile.
Creating an IPS profile alone is not sufficient
IPS must be applied to an active firewall policy
Traffic must match that policy for the IPS engine to run
Otherwise, ipsmonitor will show engine count = 0
This matches FortiOS 7.6 IPS operational behavior.
Why the other options are incorrect
B . Administrator entered the command diagnose test application ipsmonitor 5.
Incorrect.
The exhibit clearly shows ipsmonitor 1
Using a different argument would not explain engine count = 0
C . FortiGate entered into IPS fail open state.
Incorrect.
In fail-open, IPS engines may be bypassed, but they still initialize
engine count = 0 specifically indicates IPS is not in use at all
D . Administrator entered the command diagnose test application ipsmonitor 99.
Incorrect.
The command argument affects debug level, not engine creation
Again, the exhibit shows ipsmonitor 1
NEW QUESTION # 76
Refer to the exhibit to view the firewall policy.
Why would the firewall policy not block a well-known virus, for example eicar?
- A. The action on the firewall policy is not set to deny.
- B. The firewall policy is not configured in proxy-based inspection mode.
- C. Web filter is not enabled on the firewall policy to complement the antivirus profile.
- D. The firewall policy does not apply deep content inspection.
Answer: D
Explanation:
The firewall policy uses certificate-inspection under SSL inspection and flow-based inspection mode. Certificate inspection does not decrypt HTTPS traffic; it only checks the certificate fields.
Because of this, FortiGate cannot perform deep content inspection, which is required for antivirus to detect and block threats such as the EICAR test virus within encrypted HTTPS sessions.
NEW QUESTION # 77
Refer to the exhibits. An administrator creates a new address object on the root FortiGate (HQ- NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW).
What must the administrator do to synchronize the address object?



- A. Change the csfsetting on both devices to set downstream-access enable.
- B. Change the csfsetting on HQ-ISFW (downstream) to set saml-configuration-sync default.
- C. Change the csfsetting on HQ-NGFW-1 (root) to set fabric-object-unification default.
- D. Change the csfsetting on HQ-ISFW (downstream) to set configuration-sync local.
Answer: C
Explanation:
The CLI command fabric-object-unificationis available only on the root FortiGate device. When set to local, global objects are not synchronized to downstream devices in the Security Fabric.
The default value isdefault.
NEW QUESTION # 78
Refer to the exhibits.


You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS.
While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS.
What could be the cause?
- A. The SSL inspection mode in the firewall policy is not deep content inspection.
- B. The action on the firewall policy is not set to deny.
- C. Web filter is not enabled on the firewall policy to complement the antivirus profile.
- D. The feature set in the antivirus profile is not set to Flow-based.
Answer: A
Explanation:
The SSL inspection mode in the firewall policy is set to certificate-inspection, which only examines SSL certificates without decrypting HTTPS traffic. Because of this, FortiGate cannot inspect or block files downloaded over HTTPS, as the content remains encrypted. To enable antivirus scanning on HTTPS traffic, the SSL inspection mode must be set to deep-inspection, allowing the FortiGate to decrypt, inspect, and re-encrypt the traffic.
NEW QUESTION # 79
Refer to the exhibit. What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?
- A. FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.
- B. FortiGate will close the connection if the SNI does not match the CN and SAN fields
- C. FortiGate will close the connection if the SNI does not match the CN or SAN fields.
- D. FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.
Answer: B
Explanation:
With the Server certificate SNI check set to Strict, FortiGate enforces that the SNI must match either the Common Name (CN) or Subject Alternative Name (SAN) in the server certificate; otherwise, it closes the connection.
NEW QUESTION # 80
Refer to the exhibit.
A partial cloud topology is shown.
You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS.
During the deployment, which components must the FortiGate CNF create to handle traffic from the EC2 instance?
- A. The customer VPC and GWLBe
- B. The GWLB. GWLBe, and the internet gateway (IGW) in the customer VPC
- C. The CNF VPC. customer VPC. and GWLB
- D. The gateway load balancer endpoint (GWLBe) in the customer virtual private cloud (VPC)
Answer: D
Explanation:
In the FortiGate Cloud-Native Firewall (CNF) for AWS architecture, traffic from workloads (such as an EC2 instance) in the customer VPC is redirected to the security service (FortiGate CNF) using AWS Gateway Load Balancer (GWLB) technology.
The key AWS component that must exist inside the customer VPC to steer workload traffic to the GWLB is the:
Gateway Load Balancer Endpoint (GWLBe)
This endpoint is what the customer VPC routes point to (for example, default route or subnet route entries), enabling transparent insertion of the FortiGate CNF inspection path for EC2 traffic.
Why the other options are not correct:
A: CNF does not "create the customer VPC" (that is customer-owned), and "GWLBe" is the only relevant created item here, not the whole VPC.
C: Customer VPC is not created by CNF, and GWLB is typically part of the CNF service side; the question specifically asks what must be created to handle traffic from the EC2 instance (that requires GWLBe in the customer VPC).
D: CNF does not create the Internet Gateway (IGW) in the customer VPC, and IGW is not the required CNF-created component for steering traffic to FortiGate CNF.
NEW QUESTION # 81
Refer to the exhibits. A web filter profile configuration and firewall policy configuration are shown.
You are trying to access www.facebook.com, but you are redirected to a FortiGuard web filtering block page.
Based on the exhibits, what is the possible cause of the issue?


- A. The web rating override configuration is incorrect.
- B. For www.facebook.com, the URL filter action is incorrect.
- C. The web filter profile feature set is configured incorrectly.
- D. The firewall policy inspection mode is incorrect.
Answer: A
Explanation:
The web filter profile shows a URL filter override for www.facebook.com with action Monitor, which should allow access. However, the block page shows FortiGuard categorizing www.facebook.com as Malicious Websites and blocking it. This indicates that the web rating override configuration is incorrect (the override is not applied properly), so FortiGuard's default category action takes precedence and blocks the site.
NEW QUESTION # 82
You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied.
What should the administrator check first?
- A. The windows event viewer for failed login attempts.
- B. The FortiGate FSSO active users list for user's IP address.
- C. The FortiGate firewall policy settings for SSL decryption.
- D. Whether the user is assigned to the correct AD group.
Answer: B
Explanation:
Checking the active users list verifies if FortiGate correctly associates the user with their IP address, ensuring proper policy enforcement for internet access.
NEW QUESTION # 83
......
NSE4_FGT_AD-7.6 Study Guide Brilliant NSE4_FGT_AD-7.6 Exam Dumps PDF: https://prep4tests.pass4sures.top/Fortinet-NSE-4/NSE4_FGT_AD-7.6-testking-braindumps.html