exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 47 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 47
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2.
The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver.
Which two configuration changes can the administrator make to the policy to deny Webserver access for Remote-User2? (Choose two.)

  • A. Enable match-vip in the Deny policy.
  • B. Set the Destination address as Webserver in the Deny policy.
  • C. Disable match-vip in the Deny policy.
  • D. Set the Destination address as Deny_IP in the Allow_access policy.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sxcap
2 weeks, 5 days ago
Selected Answer: AB
Enable match-vip (if not enabled already) set webserver as destination
upvoted 1 times
...
vuhidus
1 month, 2 weeks ago
Selected Answer: AB
A & B
upvoted 1 times
...
s4mu3l007
2 months ago
¿ A & B ?
upvoted 1 times
...
066c9f3
2 months, 4 weeks ago
A bit confusing, because match-vip is enabled by default after FortiOS 7.2.3 and these are 7.4 questions. So technically, we should assume it's already enabled which makes A an invalid answer. But since this question is copied from 7.2, A is still correct.
upvoted 1 times
...
3101a6a
3 months, 1 week ago
Selected Answer: AB
Page 64 Study Guide 7.4
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago