[Jan 09, 2022] ValidBraindumps NSE4_FGT-6.4 dumps & Fortinet NSE 4 sure practice dumps
Fortinet NSE4_FGT-6.4 Actual Questions and Braindumps
Understanding functional and technical aspects of Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam
The following will be dicussed in FORTINET NSE4_FGT-6.4 dumps:
- Gain experience to configure security profiles to offset threats and ill-usage, including viruses, torrents, and improper websites
- SSL VPN
- Executing a meshed or partially redundant VPN
- Learn about SSL/TLS-secured traffic
- Identify users using firewall policies
- Understanding network access to configured networks
- Understand encryption uses and certificates
- Diagnosing declined IKE exchanges
- Proposing Fortinet Single Sign-On access to network services, integrated with Microsoft Active Directory
- Standard or non-standard protocols and ports
- Learn application control methods to monitor and control network applications
- Understanding of encryption used to bypass security policies
- Learn to load balance traffic amid multiple WAN links efficiently
- Gain knowledge on how to utilize the GUI and CLI for management
- How to Deploy implicit and explicit proxy with firewall policies, authentication, and caching
- Deploying FortiGate devices as an HA cluster for high performance
- Learn examining traffic transparently, forwarding
- Modes of hacking and denial of service (DoS) attacks
- Learn features of the Fortinet Security Fabric
- Authorizing an IPsec VPN tunnel connecting two FortiGate devices
- Deploying FortiGate devices as an HA cluster for fault tolerance
- Learn port forwarding, source NAT, and destination NAT
- Collection of log entries
- Learn partitioning FortiGate into two or more virtual devices
- Learn the deployment of proper operation mode for any network
NEW QUESTION 71
Which of the following statements about backing up logs from the CLI and downloading logs from the GUI are true? (Choose two.)
- A. Log backups from the CLI cannot be restored to another FortiGate.
- B. Log downloads from the GUI are stored as LZ4 compressed files.
- C. Log downloads from the GUI are limited to the current filter view
- D. Log backups from the CLI can be configured to upload to FTP as a scheduled time
Answer: A,C
NEW QUESTION 72
Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)
- A. Firewall policy
- B. SSL inspection and authentication policy
- C. Policy rule
- D. Security policy
Answer: A,C
NEW QUESTION 73
Examine the two static routes shown in the exhibit, then answer the following question.
Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?
- A. FortiGate will only actuate the port1 route in the routing table
- B. FortiGate will route twice as much traffic to the port2 route
- C. FortiGate will use the port1 route as the primary candidate.
- D. FortiGate will load balance all traffic across both routes.
Answer: C
Explanation:
Explanation
"If multiple static routes have the same distance, they are all active; however, only the one with the lowest priority is considered the best path."
NEW QUESTION 74
Which two statements about IPsec authentication on FortiGate are correct? (Choose two.)
- A. For a stronger authentication, you can also enable extended authentication (XAuth) to request the remote peer to provide a username and password
- B. A certificate is not required on the remote peer when you set the signature as the authentication method.
- C. FortiGate supports pre-shared key and signature as authentication methods.
- D. Enabling XAuth results in a faster authentication because fewer packets are exchanged.
Answer: A,C
NEW QUESTION 75
Why does FortiGate keep TCP sessions in the session table for some seconds even after both sides (client and server) have terminated the session?
- A. To finish any inspection operations.
- B. To allow for out-of-order packets that could arrive after the FIN/ACK packets.
- C. To generate logs
- D. To remove the NAT operation.
Answer: B
NEW QUESTION 76
Examine the exhibit, which contains a virtual IP and firewall policy configuration.


The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?
- A. Any available IP address in the WAN (port1) subnet 10.200.1.0/24
- B. 10.0.1.254
- C. 10.200.1.1
- D. 10.200.1.10
Answer: A
Explanation:
Explanation: https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall- 52/Firewall%20Objects/Virtual%20IPs.htm
NEW QUESTION 77
Which three statements about a flow-based antivirus profile are correct? (Choose three.)
- A. IPS engine handles the process as a standalone.
- B. Optimized performance compared to proxy-based inspection.
- C. If the virus is detected, the last packet is delivered to the client.
- D. Flow-based inspection uses a hybrid of scanning modes available in proxy-based inspection.
- E. FortiGate buffers the whole file but transmits to the client simultaneously.
Answer: B,C,D
NEW QUESTION 78
Refer to the web filter raw logs.
Based on the raw logs shown in the exhibit, which statement is correct?
- A. Access to the social networking web filter category was explicitly blocked to all users.
- B. The action on firewall policy ID 1 is set to warning.
- C. Social networking web filter category is configured with the action set to authenticate.
- D. The name of the firewall policy is all_users_web.
Answer: D
NEW QUESTION 79
Refer to the exhibit. Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
- A. The IPS engine was blocking all traffic.
- B. The IPS engine was unable to prevent an intrusion attack.
- C. The IPS engine was inspecting high volume of traffic.
- D. The IPS engine will continue to run in a normal state.
Answer: A
NEW QUESTION 80
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
- A. The collector agent uses a Windows API to query DCs for user logins.
- B. NetAPI polling can increase bandwidth usage in large networks.
- C. The collector agent must search security event logs.
- D. The NetSessionEnum function is user] to track user logouts.
Answer: D
NEW QUESTION 81
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. Antivirus in flow-based inspection
- B. DNS filter
- C. Application control
- D. Web application firewall
- E. Web filter in flow-based inspection
Answer: B,C,E
NEW QUESTION 82
What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?
- A. Certificate inspection
- B. Flow-based inspection
- C. Full Content inspection
- D. Proxy-based inspection
Answer: D
NEW QUESTION 83
An administrator must disable RPF check to investigate an issue.
Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?
- A. Disable the RPF check at the FortiGate interface level for the source check.
- B. Enable asymmetric routing, so the RPF check will be bypassed.
- C. Disable the RPF check at the FortiGate interface level for the reply check.
- D. Enable asymmetric routing at the interface level.
Answer: D
NEW QUESTION 84
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. Application control
- B. Web application firewall
- C. Antivirus in flow-based inspection
- D. DNS filter
- E. Web filter in flow-based inspection
Answer: A,C,E
NEW QUESTION 85
An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must an administrator do to achieve this objective?
- A. The administrator must use the user self-registration server.
- B. The administrator must use a FortiAuthenticator device.
- C. The administrator can use a third-party radius OTP server.
- D. The administrator can register the same FortiToken on more than one FortiGate.
Answer: B
NEW QUESTION 86
A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.
Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
- A. The two VLAN sub interfaces must have different VLAN IDs.
- B. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
FortiGate_Infrastructure_6.0_Study_Guide_v2-Online.pdf -> page 147
"Multiple VLANs can coexist in the same physical interface, provide they have different VLAN ID" - C. The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.
- D. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
Answer: A
NEW QUESTION 87
Examine this FortiGate configuration:
Examine the output of the following debug command:
Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection?
- A. It is dropped.
- B. It is allowed, but with no inspection
- C. It is allowed and inspected, as long as the only inspection required is antivirus.
- D. It is allowed and inspected as long as the inspection is flow based
Answer: A
NEW QUESTION 88
To complete the final step of a Security Fabric configuration, an administrator must authorize all the devices on which device?
- A. FortiAnalyzer
- B. FortiManager
- C. Downstream FortiGate
- D. Root FortiGate
Answer: D
NEW QUESTION 89
Which three statements about security associations (SA) in IPsec are correct? (Choose three.)
- A. A phase 1 SA is bidirectional, while a phase 2 SA is directional.
- B. Both the phase 1 SA and phase 2 SA are bidirectional.
- C. Phase 2 SA expiration can be time-based, volume-based, or both.
- D. An SA never expires.
- E. Phase 2 SAs are used for encrypting and decrypting the data exchanged through the tunnel.
Answer: A,C,D
NEW QUESTION 90
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
- A. To dynamically change phase 1 negotiation mode aggressive mode.
- B. To encapsulation ESP packets in UDP packets using port 4500.
- C. To force a new DH exchange with each phase 2 rekey.
- D. To delete intermediary NAT devices in the tunnel path.
Answer: B,D
NEW QUESTION 91
......
Latest NSE4_FGT-6.4 Pass Guaranteed Exam Dumps with Accurate & Updated Questions: https://www.validbraindumps.com/NSE4_FGT-6.4-exam-prep.html