[Jan 09, 2022] Get to the Top with NSE4_FGT-6.4 Practice Exam Questions [Q61-Q80]

Share

[Jan 09, 2022] Get to the Top with NSE4_FGT-6.4 Practice Exam Questions

Use Real NSE4_FGT-6.4 Dumps Free Sample Questions and Practice Test Engine

NEW QUESTION 61
Refer to the FortiGuard connection debug output.

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)

  • A. One server was contacted to retrieve the contract information.
  • B. A local FortiManager is one of the servers FortiGate communicates with.
  • C. There is at least one server that lost packets consecutively.
  • D. FortiGate is using default FortiGuard communication settings.

Answer: A,C

 

NEW QUESTION 62
If Internet Service is already selected as in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy?

  • A. Once Internet Service is selected, no other object can be added
  • B. User or User Group
  • C. FQDN address
  • D. IP address

Answer: A

 

NEW QUESTION 63
Which security feature does FortiGate provide to protect servers located in the internal networks from attacks such as SQL injections?

  • A. Web application firewall
  • B. Antivirus
  • C. Denial of Service
  • D. Application control

Answer: C

 

NEW QUESTION 64
Refer to the exhibits.

The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?

  • A. Change the SSL VPN portal to the tunnel.
  • B. Change the idle-timeout.
  • C. Change the SSL VPN port on the client.
  • D. Change the Server IP address.

Answer: A

 

NEW QUESTION 65
Which two statements are correct about NGFW Policy-based mode? (Choose two.)

  • A. NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy
  • B. NGFW policy-based mode does not require the use of central source NAT policy
  • C. NGFW policy-based mode can only be applied globally and not on individual VDOMs
  • D. NGFW policy-based mode policies support only flow inspection

Answer: A,D

 

NEW QUESTION 66
An administrator is running the following sniffer command:

Which three pieces of Information will be Included in me sniffer output? {Choose three.)

  • A. Interface name
  • B. Packet payload
  • C. Application header
  • D. Ethernet header
  • E. IP header

Answer: B,C,D

 

NEW QUESTION 67
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic, in addition, the remote peer does not support a dynamic DNS update service. What type of remote gateway should tie administrator configure on FortiGate for the new IPsec VPN tunnel to work?

  • A. Pre-shared Key
  • B. Static IP Address
  • C. Dialup User
  • D. Dynamic DNS

Answer: C

 

NEW QUESTION 68
Refer to the exhibit showing a debug flow output.

Which two statements about the debug flow output are correct? (Choose two.)

  • A. A firewall policy allowed the connection.
  • B. The debug flow is of ICMP traffic.
  • C. A new traffic session is created.
  • D. The default route is required to receive a reply.

Answer: A

 

NEW QUESTION 69
Refer to the exhibit.



The exhibit contains a network interface configuration, firewall policies, and a CLI console configuration.
How will FortiGate handle user authentication for traffic that arrives on the LAN interface?

  • A. Users from the Sales group will be prompted for authentication and can authenticate successfully with the correct credentials.
  • B. Authentication is enforced at a policy level; all users will be prompted for authentication.
  • C. Users from the HR group will be prompted for authentication and can authenticate successfully with the correct credentials.
  • D. If there is a full-through policy in place, users will not be prompted for authentication.

Answer: B

 

NEW QUESTION 70
Refer to the FortiGuard connection debug output.

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)

  • A. One server was contacted to retrieve the contract information.
  • B. A local FortiManager is one of the servers FortiGate communicates with.
  • C. FortiGate is using default FortiGuard communication settings.
  • D. There is at least one server that lost packets consecutively.

Answer: A,C

 

NEW QUESTION 71
Exhibit:

Refer to the exhibit to view the authentication rule configuration In this scenario, which statement is true?

  • A. Route-based authentication is enabled
  • B. Session-based authentication is enabled.
  • C. IP-based authentication is enabled
  • D. Policy-based authentication is enabled

Answer: B

 

NEW QUESTION 72
Refer to the exhibit.

Which contains a session list output. Based on the information shown in the exhibit, which statement is true?

  • A. One-to-one NAT IP pool is used in the firewall policy.
  • B. Destination NAT is disabled in the firewall policy.
  • C. Overload NAT IP pool is used in the firewall policy.
  • D. Port block allocation IP pool is used in the firewall policy.

Answer: B

 

NEW QUESTION 73
Refer to the exhibit.

Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)

  • A. port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.
  • B. Traffic between port2 and port2-vlan1 is allowed by default.
  • C. port1-vlan10 and port2-vlan10 are part of the same broadcast domain.
  • D. port1 is a native VLAN.

Answer: A,D

 

NEW QUESTION 74
Refer to the exhibit.

The exhibit shows a CLI output of firewall policies, proxy policies, and proxy addresses.
How does FortiGate process the traffic sent to http://www.fortinet.com?

  • A. Traffic will be redirected to the transparent proxy and it will be allowed by proxy policy ID 3.
  • B. Traffic will be redirected to the transparent proxy and It will be allowed by proxy policy ID 1.
  • C. Traffic will not be redirected to the transparent proxy and it will be allowed by firewall policy ID 1.
  • D. Traffic will be redirected to the transparent proxy and it will be denied by the proxy implicit deny policy.

Answer: D

 

NEW QUESTION 75
Refer to the exhibit.

The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)

  • A. FortiGate SN FGVM010000064692 has the higher HA priority.
  • B. FortiGate devices are not in sync because one device is down.
  • C. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
  • D. FortiGate SN FGVM010000065036 HA uptime has been reset.
    https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 16
    Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions

Answer: A,D

 

NEW QUESTION 76
Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.


An administrator has configured the WINDOWS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?

  • A. A DoS policy should be used, instead of an IPS sensor.
  • B. The HTTPS signatures have not been added to the sensor.
  • C. A DoS policy should be used, instead of an IPS sensor.
  • D. The firewall policy is not using a full SSL inspection profile.
  • E. The IPS filter is missing the Protocol: HTTPS option.

Answer: D

 

NEW QUESTION 77
View the exhibit.

A
user behind the FortiGate is trying to go to http://www.addictinggames.com (Addicting Games). Based on this configuration, which statement is true?

  • A. Addcting.Games is allowed based on the Categories configuration.
  • B. Addicting.Games is allowed based on the Application Overrides configuration.
  • C. Addicting.Games can be allowed only if the Filter Overrides actions is set to Exempt.
  • D. Addicting.Games is blocked on the Filter Overrides configuration.

Answer: B

 

NEW QUESTION 78
Refer to the exhibit.

Given the interfaces shown in the exhibit, which two statements are true? (Choose two.)

  • A. Traffic between port2 and port2-vlan1 is allowed by default.
  • B. port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.
  • C. port1 is a native VLAN.
  • D. port1-vlan10 and port2-vlan10 are part of the same broadcast domain.

Answer: A,B

 

NEW QUESTION 79
Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)

  • A. System time
  • B. Operating mode
  • C. NGFW mode
  • D. FortiGuaid update servers

Answer: B,C

Explanation:
Explanation
C: "Operating mode is per-VDOM setting. You can combine transparent mode VDOM's with NAT mode VDOMs on the same physical Fortigate.
D: "Inspection-mode selection has moved from VDOM to firewall policy, and the default inspection-mode is flow, so NGFW Mode can be changed from Profile-base (Default) to Policy-base directly in System > Settings from the VDOM" Page 125 of FortiGate_Infrastructure_6.4_Study_Guide

 

NEW QUESTION 80
......

Pass Fortinet NSE4_FGT-6.4 exam - questions - convert Tets Engine to PDF: https://crucialexams.lead1pass.com/Fortinet/NSE4_FGT-6.4-practice-exam-dumps.html