exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 103 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 103
Topic #: 1
[All NSE4_FGT-7.0 Questions]

An administrator has a requirement to keep an application session from timing out on port 80.
What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)

  • A. Set the TTL value to never under config system-ttl.
  • B. Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
  • C. Create a new service object for HTTP service and set the session TTL to never.
  • D. Set the session TTL on the HTTP policy to maximum.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nomeursy
Highly Voted 9 months, 4 weeks ago
Selected Answer: BC
key is: without affecting any existing services So define new service on TCP80 with no session-ttl expire. Make new FW policy and place above other HTTP policy
upvoted 8 times
...
h0p3l3ss
Highly Voted 10 months, 2 weeks ago
Selected Answer: BC
This need some testing, I would go with B and C, reference: https://docs.fortinet.com/document/fortigate/6.4.0/new-features/743069/no-session-timeout
upvoted 6 times
Babnav
10 months, 1 week ago
Just a new HTTP service and policy above the existing one will not change anything without the session-ttl set to never or increased to max. CD seems like the most correct out of these.
upvoted 3 times
PabloSL
7 months, 1 week ago
Thing is if you just set it to max, you're not preventing the session from expiring it just takes longer
upvoted 1 times
...
AngraMainyu
9 months, 1 week ago
@Babnav, you can configure TTL for service objects in the CLI
upvoted 1 times
...
...
...
Bombast
Most Recent 3 months ago
Selected Answer: BC
.!!!!!!!!!!!!
upvoted 1 times
...
Power_Shell
10 months, 1 week ago
Selected Answer: BC
I would go with B and C https://community.fortinet.com/t5/FortiGate/Technical-Tip-Session-timeout-settings/ta-p/191228
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago