Exit demo NSE4-5.4 Fortinet Network Security Expert 4 Written Exam - FortiOS 5.4 PDF format · free preview

Fortinet NSE4-5.4 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/nse4-54.html

Question 1
Single choice

When performing a log search on a FortiAnalyzer, it is generally recommended to use the Quick Search option.

What is a valid reason for using the Full Search option, instead?

A.

The search items you are looking for are not contained in indexed log fields.

B.

A quick search only searches data received within the last 24 hours.

C.

You want the search to include the FortiAnalyzer's local logs.

D.

You want the search to include content archive data as well.

Question 2
Single choice

The diag sys session list command is executed in the CLI. The output of this command is shown in the exhibit.

Based on the output from this command, which of the following statements is correct?

A.

This is a UDP session.

B.

Traffic shaping is being applied to this session.

C.

This is an ICMP session.

D.

This traffic has been authenticated.

E.

This session matches a firewall policy with ID 5.

Question 3
Single choice

What protocol cannot be used with the active authentication type?

A.

Local

B.

RADIUS

C.

LDAP

D.

RSSO

Question 4
Single choice

Review the exhibit of an explicit proxy policy configuration.
If there is a proxy connection attempt coming from the IP address 10.0.1.5, and from a user that has not authenticated yet, what action does the FortiGate proxy take?

A.

User is prompted to authenticate. Traffic from the user Student will be allowed by the policy #1. Traffic from any other user will be allowed by the policy #2.

B.

User is not prompted to authenticate. The connection is allowed by the proxy policy #2.

C.

User is not prompted to authenticate. The connection will be allowed by the proxy policy #1.

D.

User is prompted to authenticate. Only traffic from the user Student will be allowed. Traffic from any other user will be blocked.

Question 5
Multiple choice

Which of the following statements are true regarding DLP File Type Filtering? (Choose two.)

A.

Filters based on file extension

B.

Filters based on fingerprints

C.

Filters based on file content

D.

File types are hard coded in the FortiOS

Question 6
Multiple choice

Which of the following settings can be configured per VDOM? (Choose three.)

A.

Operating mode (NAT/route or transparent)

B.

Static routes

C.

Hostname

D.

System time

E.

Firewall Policies

Question 7
Multiple choice

Which protocols can you use for secure administrative access to a FortiGate? (Choose two)

A.

SSH

B.

Telnet

C.

NTLM

D.

HTTPS

Question 8
Multiple choice

What are examples of correct syntax for the session table diagnostics command? (Choose two.)

A.

diagnose sys session filter clear

B.

diagnose sys session src 10.0.1.254

C.

diagnose sys session filter

D.

diagnose sys session filter list dst.

Question 9
Single choice

Which statement best describes the objective of the SYN proxy feature available in SP processors?

A.

Accelerate the TCP 3-way handshake

B.

Collect statistics regarding traffic sessions

C.

Analyze the SYN packet to decide if the new session can be offloaded to the SP processor

D.

Protect against SYN flood attacks.

Question 10
Multiple choice

Which of the following are possible actions for static URL filtering? (Choose three.)

A.

Allow

B.

Block

C.

Exempt

D.

Warning

E.

Shape

Showing 10 of 575 questions · Unlock the full set