Fortinet NSE4_FGT-7.2 Exam
Fortinet NSE 4 - FortiOS 7.2 (Page 8 )

Updated On: 12-Feb-2026

Which two statements are correct about SLA targets? (Choose two.)

  1. You can configure only two SLA targets per one Performance SL
  2. SLA targets are optional.
  3. SLA targets are required for SD-WAN rules with a Best Quality strategy.
  4. SLA targets are used only when referenced by an SD-WAN rule.

Answer(s): B,D


Reference:

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/382233/performance-sla-

sla-targets



Refer to the exhibit.



Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)

  1. The port3 default route has the lowest metric.
  2. The port1 and port2 default routes are active in the routing table.
  3. The ports default route has the highest distance.
  4. There will be eight routes active in the routing table.

Answer(s): B,C

Explanation:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-identify-Inactive-Routes-in-the- Routing/ta-p/197595



When configuring a firewall virtual wire pair policy, which following statement is true?

  1. Any number of virtual wire pairs can be included, as long as the policy traffic direction is the same.
  2. Only a single virtual wire pair can be included in each policy.
  3. Any number of virtual wire pairs can be included in each policy, regardless of the policy traffic direction settings.
  4. Exactly two virtual wire pairs need to be included in each policy.

Answer(s): A


Reference:

https://kb.fortinet.com/kb/documentLink .do?externalID=FD48690



Refer to the exhibit.



An administrator is running a sniffer command as shown in the exhibit.
Which three pieces of information are included in the sniffer output? (Choose three.)

  1. Interface name
  2. Ethernet header
  3. IP header
  4. Application header
  5. Packet payload

Answer(s): A,C,E


Reference:

https://kb.fortinet.com/kb/documentLink .do?externalID=11186

Study Guide ­ Routing ­ Diagnostics ­ Packet Capture Verbosity Level.

# diagnose sniffer packet <interface> `<filter>' <verbosity> <count> <timestamp> <frame size>

In the example, verbosity is 5.

The verbosity level specifies how much info you want to display.

1 (default): IP Headers.
2: IP Headers, Packet Payload.
3. IP Headers, Packet Payload, Ethernet Headers.
4: IP Headers, Interface Name.
5: IP Headers, Packet Payload, Interface Name.
6: IP Headers, Packet Payload, Ethernet Headers, Interface Name.



An administrator does not want to report the logon events of service accounts to FortiGate.
What setting on the collector agent is required to achieve this?

  1. Add the support of NTLM authentication.
  2. Add user accounts to Active Directory (AD).
  3. Add user accounts to the FortiGate group fitter.
  4. Add user accounts to the Ignore User List.

Answer(s): D


Reference:

https://community.fortinet.com/t5/Support-Forum/Collector-Agent-and-problem- getting-login-info/m-p/95481






Post your Comments and Discuss Fortinet NSE4_FGT-7.2 exam prep with other Community members:

Join the NSE4_FGT-7.2 Discussion