Exit demo NSE4_FGT-6.4 Fortinet NSE 4 - FortiOS 6.4 PDF format · free preview

Fortinet NSE4_FGT-6.4 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/nse4-fgt-64.html

Question 1
Single choice

Refer to the exhibit.

Examine the intrusion prevention system (IPS) diagnostic command.

Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?

A.

The IPS engine was inspecting high volume of traffic.

B.

The IPS engine was unable to prevent an intrusion attack.

C.

The IPS engine was blocking all traffic.

D.

The IPS engine will continue to run in a normal state.

Question 2
Multiple choice

Which of the following statements correctly describes FortiGates route lookup behavior when searching for a suitable gateway? (Choose two)

A.

Lookup is done on the first packet from the session originator

B.

Lookup is done on the last packet sent from the responder

C.

Lookup is done on every packet, regardless of direction

D.

Lookup is done on the trust reply packet from the responder

Question 3
Multiple choice

Which of the following statements about central NAT are true? (Choose two.)

A.

IP tool references must be removed from existing firewall policies before enabling central NAT.

B.

Central NAT can be enabled or disabled from the CLI only.

C.

Source NAT, using central NAT, requires at least one central SNAT policy.

D.

Destination NAT, using central NAT, requires a VIP object as the destination address in a firewall.

Question 4
Single choice

Which Security rating scorecard helps identify configuration weakness and best practice violations in your network?

A.

Fabric Coverage

B.

Automated Response

C.

Security Posture

D.

Optimization

Question 5
Single choice

Refer to the exhibit.

The exhibit shows a CLI output of firewall policies, proxy policies, and proxy addresses.

How does FortiGate process the traffic sent to http://www.fortinet.com?

A.

Traffic will be redirected to the transparent proxy and it will be allowed by proxy policy ID 3.

B.

Traffic will not be redirected to the transparent proxy and it will be allowed by firewall policy ID 1.

C.

Traffic will be redirected to the transparent proxy and It will be allowed by proxy policy ID 1.

D.

Traffic will be redirected to the transparent proxy and it will be denied by the proxy implicit deny policy.

Question 6
Single choice

The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile.

What order must FortiGate use when the web filter profile has features enabled, such as safe search?

A.

DNS-based web filter and proxy-based web filter

B.

Static URL filter, FortiGuard category filter, and advanced filters

C.

Static domain filter, SSL inspection filter, and external connectors filters

D.

FortiGuard category filter and rating filter

Question 7
Single choice

A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not

Which configuration option is the most effective way to support this request?

A.

Implement a web filter category override for the specified website

B.

Implement a DNS filter for the specified website.

C.

Implement web filter quotas for the specified website

D.

Implement web filter authentication for the specified website.

Question 8
Single choice

Refer to the exhibit.

Which contains a session diagnostic output.

Which statement is true about the session diagnostic output?

A.

The session is in SYN_SENT state.

B.

The session is in FIN_ACK state.

C.

The session is in FTN_WAIT state.

D.

The session is in ESTABLISHED state.

Question 9
Single choice

Which certificate value can FortiGate use to determine the relationship between the issuer and the certificate?

A.

Subject Key Identifier value

B.

SMMIE Capabilities value

C.

Subject value

D.

Subject Alternative Name value

Question 10
Multiple choice

Examine this PAC file configuration.

Which of the following statements are true? (Choose two.)

A.

Browsers can be configured to retrieve this PAC file from the FortiGate.

B.

Any web request to the 172.25.120.0/24 subnet is allowed to bypass the proxy.

C.

All requests not made to Fortinet.com or the 172.25.120.0/24 subnet, have to go through altproxy.corp.com: 8060.

D.

Any web request fortinet.com is allowed to bypass the proxy.

Showing 10 of 163 questions · Unlock the full set