Sep 26, 2021 Step by Step Guide to Prepare for NSE4_FGT-6.4 Exam BrainDumps
Fortinet NSE 4 NSE4_FGT-6.4 Real Exam Questions and Answers FREE Updated on 2021
NEW QUESTION 26
Refer to the exhibit.
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)
- A. FortiGate SN FGVM010000065036 HA uptime has been reset.
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 16
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions - B. FortiGate devices are not in sync because one device is down.
- C. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
- D. FortiGate SN FGVM010000064692 has the higher HA priority.
Answer: A,D
NEW QUESTION 27
Examine this PAC file configuration.
Which of the following statements are true? (Choose two.)
- A. Any web request fortinet.com is allowed to bypass the proxy.
- B. Any web request to the 172.25.120.0/24 subnet is allowed to bypass the proxy.
- C. All requests not made to Fortinet.com or the 172.25.120.0/24 subnet, have to go through altproxy.corp.com: 8060.
- D. Browsers can be configured to retrieve this PAC file from the FortiGate.
Answer: A,D
NEW QUESTION 28
Examine the following web filtering log.
Which statement about the log message is true?
- A. The web site miniclip.com matches a static URL filter whose action is set to Warning.
- B. The name of the applied web filter profile is default.
- C. The usage quota for the IP address 10.0.1.10 has expired
- D. The action for the category Games is set to block.
Answer: B
NEW QUESTION 29
Examine this FortiGate configuration:
How does the FortiGate handle web proxy traffic coming from the IP address 10.2.1.200 that requires authorization?
- A. It authenticates the traffic using the authentication scheme SCHEME2.
- B. It drops the traffic.
- C. It authenticates the traffic using the authentication scheme SCHEME1.
- D. It always authorizes the traffic without requiring authentication.
Answer: C
Explanation:
Explanation
"What happens to traffic that requires authorization, but does not match any authentication rule? The active and passive SSO schemes to use for those cases is defined under config authentication setting"
NEW QUESTION 30
Refer to the exhibit.
The exhibit contains a network diagram, virtual IP, IP pool, and firewall policies configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10 .0.1.254. /24.
The first firewall policy has NAT enabled using IP Pool.
The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0.1.10?
- A. 10.200.1.1
- B. 10.200.1.10
- C. 10.200.3.1
- D. 10.200.1.100
Answer: A
NEW QUESTION 31
Refer to the exhibit.
The exhibit shows proxy policies and proxy addresses, the authentication rule and authentication scheme, users, and firewall address.
An explicit web proxy is configured for subnet range 10.0.1.0/24 with three explicit web proxy policies.
The authentication rule is configured to authenticate HTTP requests for subnet range 10.0.1.0/24 with a form-based authentication scheme for the FortiGate local user database. Users will be prompted for authentication.
How will FortiGate process the traffic when the HTTP request comes from a machine with the source IP 10.0.1.10 to the destination http://www.fortinet.com? (Choose two.)
- A. If a Microsoft Internet Explorer browser is used with User-B credentials, the HTTP request will be allowed.
- B. If a Google Chrome browser is used with User-B credentials, the HTTP request will be allowed.
- C. If a Mozilla Firefox browser is used with User-B credentials, the HTTP request will be allowed.
- D. If a Mozilla Firefox browser is used with User-A credentials, the HTTP request will be allowed.
Answer: A,C
NEW QUESTION 32
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?
- A. The public IP address of the FortiGate device.
- B. The remote user's virtual IP address.
- C. The internal IP address of the FortiGate device.
Source IP seen by the remote resources is FortiGate's internal IP address and not the user's IP address - D. remote user's public IP address
Answer: C
NEW QUESTION 33
Examine this FortiGate configuration:
How does the FortiGate handle web proxy traffic coming from the IP address 10.2.1.200 that requires authorization?
- A. It authenticates the traffic using the authentication scheme SCHEME2.
- B. It drops the traffic.
- C. It authenticates the traffic using the authentication scheme SCHEME1.
- D. It always authorizes the traffic without requiring authentication.
Answer: C
Explanation:
Explanation
"What happens to traffic that requires authorization, but does not match any authentication rule? The active and passive SSO schemes to use for those cases is defined under config authentication setting"
NEW QUESTION 34
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On HQ-FortiGate, set IKE mode to
- B. On both FortiGate devices, set
- C. On HQ-FortiGate, disable Diffie-Helman group 2
- D. On Remote-FortiGate, set port2
Answer: A,D
NEW QUESTION 35
Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below.
When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?
- A. ip_src_session
- B. IMAP.Login.brute.Force
- C. Location: server Protocol: SMTP
- D. SMTP.Login.Brute.Force
Answer: B
NEW QUESTION 36
An administrator has configured the following settings:
What does the configuration do? (Choose two.)
- A. Creates a session for traffic being denied.
- B. Enforces device detection on all interfaces for 30 minutes.
- C. Reduces the amount of logs generated by denied traffic.
- D. Blocks denied users for 30 minutes.
Answer: A,C
NEW QUESTION 37
Refer to the exhibit.
Based on the raw log, which two statements are correct? (Choose two.)
- A. This is a security log.
- B. Log severity is set to erroron FortiGate.
- C. Traffic is blocked because Action is set to DENY in the firewall policy.
- D. Traffic belongs to the root VDOM.
Answer: A,C
NEW QUESTION 38
Refer to the exhibits.
The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?
- A. Change the SSL VPN port on the client.
- B. Change the SSL VPN portal to the tunnel.
- C. Change the idle-timeout.
- D. Change the Server IP address.
Answer: B
NEW QUESTION 39
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
- A. It limits the scope of application control to scan application traffic using parent signatures only
- B. It limits the scope of application control to scan application traffic based on application category only.
- C. It limits the scope of application control to scan application traffic on DNS protocol only.
- D. It limits the scope of application control to the browser-based technology category only.
Answer: B
NEW QUESTION 40
Which two statements are correct about a software switch on FortiGate? (Choose two.)
- A. It can group only physical interfaces
- B. All interfaces in the software switch share the same IP address
- C. It can be configured only when FortiGate is operating in NAT mode
- D. Can act as a Layer 2 switch as well as a Layer 3 router
Answer: B,C
NEW QUESTION 41
Refer to the exhibit to view the application control profile.
Based on the configuration, what will happen to Apple FaceTime?
- A. Apple FaceTime will be allowed, based on the Categories configuration.
- B. Apple FaceTime will be allowed, based on the Apple filter configuration.
- C. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration
- D. Apple FaceTime will be allowed only if the filter in Application and Filter Overrides is set to Learn
Answer: C
NEW QUESTION 42
......
Ultimate Guide to Prepare NSE4_FGT-6.4 Certification Exam for Fortinet NSE 4: https://www.lead2passed.com/Fortinet/NSE4_FGT-6.4-practice-exam-dumps.html