Easily To Pass New Fortinet NSE4_FGT-6.4 Dumps with 165 Questions
Latest NSE4_FGT-6.4 Study Guides 2021 - With Test Engine PDF
NEW QUESTION 21
A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.
Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
- A. The two VLAN sub interfaces must have different VLAN IDs.
- B. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
- C. The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.
- D. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
Answer: A
Explanation:
Explanation
FortiGate_Infrastructure_6.0_Study_Guide_v2-Online.pdf -
"Multiple VLANs can coexist in the same physical interface, provide they have different VLAN ID"
NEW QUESTION 22
Refer to the exhibit.
The exhibit shows proxy policies and proxy addresses, the authentication rule and authentication scheme, users, and firewall address.
An explicit web proxy is configured for subnet range 10.0.1.0/24 with three explicit web proxy policies.
The authentication rule is configured to authenticate HTTP requests for subnet range 10.0.1.0/24 with a form-based authentication scheme for the FortiGate local user database. Users will be prompted for authentication.
How will FortiGate process the traffic when the HTTP request comes from a machine with the source IP
10.0.1.10 to the destination http://www.fortinet.com? (Choose two.)
- A. If a Microsoft Internet Explorer browser is used with User-B credentials, the HTTP request will be allowed.
- B. If a Mozilla Firefox browser is used with User-B credentials, the HTTP request will be allowed.
- C. If a Mozilla Firefox browser is used with User-A credentials, the HTTP request will be allowed.
- D. If a Google Chrome browser is used with User-B credentials, the HTTP request will be allowed.
Answer: A,D
NEW QUESTION 23
Refer to the exhibit.
Based on the raw log, which two statements are correct? (Choose two.)
- A. Traffic belongs to the root VDOM.
- B. Log severity is set to error on FortiGate.
- C. Traffic is blocked because Action is set to DENY in the firewall policy.
- D. This is a security log.
Answer: C,D
NEW QUESTION 24
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
* All traffic must be routed through the primary tunnel when both tunnels are up.
* The secondary tunnel must be used only if the primary tunnel goes down.
* In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two.)
- A. Configure a high distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
- B. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
- C. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
- D. Enable Dead Peer Detection.
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 8
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions
Answer: C,D
NEW QUESTION 25
Which statements best describe auto discovery VPN (ADVPN). (Choose two.)
- A. ADVPN is only supported with IKEv2.
- B. Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.
- C. Tunnels are negotiated dynamically between spokes.
- D. It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes.
Answer: C,D
NEW QUESTION 26
View the exhibit:
Which the FortiGate handle web proxy traffic rue? (Choose two.)
- A. port1-VLAN10 and port2-VLAN10 can be assigned to different VDOMs.
- B. Broadcast traffic received in port1-VLAN10 will not be forwarded to port2-VLAN10.
- C. port-VLAN1 is the native VLAN for the port1 physical interface.
- D. Traffic between port1-VLAN1 and port2-VLAN1 is allowed by default.
Answer: A,B
NEW QUESTION 27
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
- A. The number of logs generated by denied traffic is reduced.
- B. Device detection on all interfaces is enforced for 30 minutes.
- C. Denied users are blocked for 30 minutes.
- D. A session for denied traffic is created.
Answer: A,D
NEW QUESTION 28
Refer to the exhibit.
Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
- A. Traffic matching the signature will be allowed and logged.
- B. The signature setting includes a group of other signatures.
- C. The signature setting uses a custom rating threshold.
- D. Traffic matching the signature will be silently dropped and logged.
Answer: A
NEW QUESTION 29
Refer to the exhibits.

Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default configuration of high memory usage thresholds. Based on the system performance output, which two statements are correct? (Choose two.)
- A. Administrators cannot change the configuration.
- B. Administrators can access FortiGate only through the console port.
- C. FortiGate will start sending all files to FortiSandbox for inspection.
- D. FortiGate has entered conserve mode.
Answer: A,D
NEW QUESTION 30
Refer to the exhibit to view the application control profile.
Users who use Apple FaceTime video conferences are unable to set up meetings.
In this scenario, which statement is true?
- A. Apple FaceTime belongs to the custom blocked filter.
- B. The category of Apple FaceTime is being monitored.
- C. The category of Apple FaceTime is being blocked.
- D. Apple FaceTime belongs to the custom monitored filter.
Answer: A
NEW QUESTION 31
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
- A. The server name indication (SNI) extension in the client hello message
- B. The host field in the HTTP header
- C. The subject alternative name (SAN) field in the server certificate
- D. The serial number in the server certificate
- E. The subject field in the server certificate
Answer: B,C,D
NEW QUESTION 32
Refer to the exhibit showing a debug flow output.
Which two statements about the debug flow output are correct? (Choose two.)
- A. The debug flow is of ICMP traffic.
- B. A new traffic session is created.
- C. The default route is required to receive a reply.
- D. A firewall policy allowed the connection.
Answer: D
NEW QUESTION 33
If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy?
- A. FQDN address
- B. User or User Group
- C. IP address
- D. Once Internet Service is selected, no other object can be added
Answer: D
NEW QUESTION 34
Refer to the exhibit.
The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access internet. The To_lnternet VDOM is the only VDOM with internet access and is directly connected to ISP modem.
Which two statements are true? (Choose two.)
- A. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
- B. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.
- C. A static route is required on the To_Internet VDOM to allow LAN users to access the internet.
- D. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
Answer: B,D
NEW QUESTION 35
View the exhibit.
Which of the following statements are correct? (Choose two.)
- A. Dead peer detection must be disabled to support this type of IPsec setup.
- B. This is a redundant IPsec setup.
- C. This setup requires at least two firewall policies with the action set to IPsec.
- D. The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
Answer: B,D
NEW QUESTION 36
Refer to the exhibit to view the application control profile.
Based on the configuration, what will happen to Apple FaceTime?
- A. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration
- B. Apple FaceTime will be allowed only if the filter in Application and Filter Overrides is set to Learn
- C. Apple FaceTime will be allowed, based on the Categories configuration.
- D. Apple FaceTime will be allowed, based on the Apple filter configuration.
Answer: A
NEW QUESTION 37
Which two statements about IPsec authentication on FortiGate are correct? (Choose two.)
- A. FortiGate supports pre-shared key and signature as authentication methods.
- B. A certificate is not required on the remote peer when you set the signature as the authentication method.
- C. For a stronger authentication, you can also enable extended authentication (XAuth) to request the remote peer to provide a username and password
- D. Enabling XAuth results in a faster authentication because fewer packets are exchanged.
Answer: A,B
Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/913287/ipsec-vpn-authenticating-a- remote-fortigate-peer-with-a-pre-shared-key
NEW QUESTION 38
An administrator Is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A.
the local quick mode selector is 192.160.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
- A. 192.168.2.0/24
- B. 192.168.0.0/24
- C. 192.168.1.0/24
- D. 192.168.3.0/24
Answer: B
NEW QUESTION 39
Which of the following SD-WAN load -balancing method use interface weight value to distribute traffic?
(Choose two.)
- A. Source IP
- B. Session
- C. Volume
- D. Spillover
Answer: C,D
NEW QUESTION 40
Which two statements are true about collector agent standard access mode? (Choose two.)
- A. Standard access mode supports nested groups.
- B. Standard mode uses Windows convention-NetBios: Domain\Username.
- C. Standard mode security profiles apply to organizational units (OU).
- D. Standard mode security profiles apply to user groups.
Answer: B,D
NEW QUESTION 41
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)
- A. new-session
- B. Idle-timeout
https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221 - C. hard-timeout
- D. auth-on-demand
- E. soft-timeout
Answer: A,B,C
NEW QUESTION 42
Examine the following web filtering log.
Which statement about the log message is true?
- A. The web site miniclip.com matches a static URL filter whose action is set to Warning.
- B. The action for the category Games is set to block.
- C. The name of the applied web filter profile is default.
- D. The usage quota for the IP address 10.0.1.10 has expired
Answer: C
NEW QUESTION 43
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. get system status
- B. get system performance status
- C. get system arp
- D. diagnose sys top
Answer: D
NEW QUESTION 44
......
How much Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam Cost
The cost of the Network Security Professional (Fortinet NSE4_FGT-6.4) Exam is 400 USD. For more information related to exam price, please visit the official website AWS Website as the cost of exams may be subjected to vary county-wise.
NSE4_FGT-6.4 Dumps and Exam Test Engine: https://www.lead2passed.com/Fortinet/NSE4_FGT-6.4-practice-exam-dumps.html