Fortinet NSE4_FGT-7.2 Exam
Fortinet NSE 4 - FortiOS 7.2 (Page 3 )

Updated On: 12-Feb-2026

An administrator wants to configure timeouts for users. Regardless of the userTMs behavior, the timer should start as soon as the user authenticates and expire after the configured value.
Which timeout option should be configured on FortiGate?

  1. auth-on-demand
  2. soft-timeout
  3. idle-timeout
  4. new-session
  5. hard-timeout

Answer(s): E

Explanation:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Explanation-of-auth-timeout-types-for- Firewall/ta-p/189423


Reference:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221#:~:text=Hard%20timeout%3A%2 0User%20



Why does FortiGate Keep TCP sessions in the session table for several seconds, even after both sides (client and server) have terminated the session?

  1. To allow for out-of-order packets that could arrive after the FIN/ACK packets
  2. To finish any inspection operations
  3. To remove the NAT operation
  4. To generate logs

Answer(s): A

Explanation:

TCP provides the ability for one end of a connection to terminate its output while still receiving data from the other end. This is called a half-close. FortiGate unit implements a specific timer before removing an entry in the firewall session table.



Which two protocols are used to enable administrator access of a FortiGate device? (Choose two.)

  1. SSH
  2. HTTPS
  3. FTM
  4. FortiTelemetry

Answer(s): A,B


Reference:

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your- fortigate/995103/buildingsecurity-into-fortios



Refer to the exhibit.



Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?

  1. The IPS engine was inspecting high volume of traffic.
  2. The IPS engine was unable to prevent an intrusion attack .
  3. The IPS engine was blocking all traffic.
  4. The IPS engine will continue to run in a normal state.

Answer(s): A

Explanation:

fortinet-fortigate-security-study-guide-for-fortios-72 page 417 If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode. In this mode, the IPS engine is still running, but it is not inspecting traffic. If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model.


Reference:

https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/232929/troubleshooting-high-cpu- usage



By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers.
Which CLI command will cause FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering?

  1. set fortiguard-anycast disable
  2. set webfilter-force-off disable
  3. set webfilter-cache disable
  4. set protocol tcp

Answer(s): A

Explanation:

y default, "fortiguard-anycast" is enabled, and this setting only works with "set protocol https". To use udp (ie. "set protocol udp"), "fortiguard-anycast" must be disabled.


Reference:

https://kb.fortinet.com/kb/documentLink .do?externalID=FD48294

"By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."






Post your Comments and Discuss Fortinet NSE4_FGT-7.2 exam prep with other Community members:

Join the NSE4_FGT-7.2 Discussion