최신 FCP_FGT_AD-7.4 무료덤프 - Fortinet FCP - FortiGate 7.4 Administrator
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)
All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)
정답: C,D
설명: (DumpTOP 회원만 볼 수 있음)
An employee needs to connect to the office through a high-latency internet connection.
Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
정답: A
설명: (DumpTOP 회원만 볼 수 있음)
Refer to the exhibits.

The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy. and the sniffer CLI output on the FortiGate device.
The WAN (port1) interface has the IP address 10.200.1.1 /24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The webserver host (10. 0.1. 10) must use its VIP external IP address as the source NAT (SNAT) when It pings remote server (10.200.3.1).
Which two statements are valid to achieve this goal? (Choose two.)

The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy. and the sniffer CLI output on the FortiGate device.
The WAN (port1) interface has the IP address 10.200.1.1 /24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The webserver host (10. 0.1. 10) must use its VIP external IP address as the source NAT (SNAT) when It pings remote server (10.200.3.1).
Which two statements are valid to achieve this goal? (Choose two.)
정답: A,C
설명: (DumpTOP 회원만 볼 수 있음)
Refer to the exhibit.

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
정답: B
설명: (DumpTOP 회원만 볼 수 있음)
Which two pieces of information are synchronized between FortiGate HA members? (Choose two.)
정답: C,D
설명: (DumpTOP 회원만 볼 수 있음)
Refer to the exhibit.

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?
정답: B
설명: (DumpTOP 회원만 볼 수 있음)
A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad.
Which IPsec Wizard template must the administrator apply?
Which IPsec Wizard template must the administrator apply?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
There are multiple dial-up IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels.
Which phase 1 setting you can configure to match the user to the tunnel?
Which phase 1 setting you can configure to match the user to the tunnel?
정답: A
설명: (DumpTOP 회원만 볼 수 있음)
What is the primary FortiGate election process when the HA override setting is disabled?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)