NSE4_FGT-6.4 Exam Dumps, NSE4_FGT-6.4 Practice Test Questions [Q37-Q60]

Share

NSE4_FGT-6.4 Exam Dumps, NSE4_FGT-6.4 Practice Test Questions

PDF (New 2022) Actual Fortinet NSE4_FGT-6.4 Exam Questions


How much Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam Cost

The cost of the Network Security Professional (Fortinet NSE4_FGT-6.4) Exam is 400 USD. For more information related to exam price, please visit the official website AWS Website as the cost of exams may be subjected to vary county-wise.


Who should take the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam

A comprehensive range of The Network Security Professional (Fortinet NSE4_FGT-6.4) PROFESSIONAL dumps for Certification have been recognized. The truth that applicants need to prepare mindfully doesn’t make endorsements easy. It needs some investment to earn from Fortinet professional course. Each exam includes answers and questions that help candidates complete their final assessment. You will complete the evaluation after you have taken the exam and taken it in our modules. Yet, it doesn’t stop there; on account of our full aides, you will, in any situation, be admissible in your profession. You will deliver your results later on. To design any material for you, we have a high-level plan. In the progression of an object, we have utilized the most recent subtleties.

Hands-on experience is the most reliable form of preparation there is. Analyzing the exam guide for information about the competencies evaluated in the certification exam is a good practice to prepare for the certification.

  • Perform the exam from a Windows or macOS machine, with a camera and microphone
  • The candidate needs to have a room for the duration of the exam
  • Must have a phone and a government-issued document to validate your identity
  • Administrators pay attention to what’s appearing on the camera, and any interference can]result in a fail attempt
  • Camera position matters a lot. The candidate must sit in such a way that they appear in the middle of the screen and are clearly visible to the administrator
  • For the duration of the exam, phones, snacks, beverages must not be available within reach of the camera

 

NEW QUESTION 37
Refer to the web filter raw logs.

Based on the raw logs shown in the exhibit, which statement is correct?

  • A. Social networking web filter category is configured with the action set to authenticate.
  • B. The action on firewall policy ID 1 is set to warning.
  • C. The name of the firewall policy is all_users_web.
  • D. Access to the social networking web filter category was explicitly blocked to all users.

Answer: A

 

NEW QUESTION 38
In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)

  • A. The IP version of the sources and destinations in a firewall policy must be different.
  • B. The policy table in the GUI will be consolidated to display policies with IPv4 and IPv6 sources and destinations.
  • C. The policy table in the GUI can be filtered to display policies with IPv4, IPv6 or IPv4 and IPv6 sources and destinations.
  • D. The Incoming Interface. Outgoing Interface. Schedule, and Service fields can be shared with both IPv4 and IPv6.
  • E. The IP version of the sources and destinations in a policy must match.

Answer: A,B,C

 

NEW QUESTION 39
Which two statements are true about collector agent advanced mode? (Choose two.)

  • A. Advanced mode uses Windows convention-NetBios: Domain\Username.
  • B. Advanced mode supports nested or inherited groups
  • C. Security profiles can be applied only to user groups, not individual users.
  • D. FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate

Answer: B,D

 

NEW QUESTION 40
Refer to the exhibit.

The exhibit contains a network diagram, virtual IP, IP pool, and firewall policies configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10 .0.1.254. /24.
The first firewall policy has NAT enabled using IP Pool.
The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0.1.10?

  • A. 10.200.1.100
  • B. 10.200.1.10
  • C. 10.200.1.1
  • D. 10.200.3.1

Answer: C

 

NEW QUESTION 41
Which CLI command will display sessions both from client to the proxy and from the proxy to the servers?

  • A. diagnose wad session list | grep hook=pre&&hook=out
  • B. diagnose wad session list | grep "hook=pre"&"hook=out"
  • C. diagnose wad session list
  • D. diagnose wad session list | grep hook-pre&&hook-out

Answer: B

 

NEW QUESTION 42
An administrator has configured a route-based IPsec VPN between two FortiGate devices. Which statement about this IPsec VPN configuration is true?

  • A. A virtual IPsec interface is automatically created after the phase 1 configuration is completed.
  • B. This VPN cannot be used as part of a hub-and-spoke topology.
  • C. The IPsec firewall policies must be placed at the top of the list.
  • D. A phase 2 configuration is not required.

Answer: A

Explanation:
In a route-based configuration, FortiGate automatically adds a virtual interface eith the VPN name (Infrastructure Study Guide, 206)

 

NEW QUESTION 43
Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.


An administrator has configured the WINDOWS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?

  • A. The IPS filter is missing the Protocol: HTTPS option.
  • B. The HTTPS signatures have not been added to the sensor.
  • C. A DoS policy should be used, instead of an IPS sensor.
  • D. A DoS policy should be used, instead of an IPS sensor.
  • E. The firewall policy is not using a full SSL inspection profile.

Answer: E

 

NEW QUESTION 44
In a high availability (HA) cluster operating in active-active mode, which of the following correctly describes the path taken by the SYN packet of an HTTP session that is offloaded to a secondary FortiGate?

  • A. Client >secondary FortiGate> primary FortiGate> web server.
  • B. Client > secondary FortiGate> web server.
  • C. Client> primary FortiGate> secondary FortiGate> web server.
  • D. Client > primary FortiGate> secondary FortiGate> primary FortiGate> web server.

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 45
A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.
Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.

  • A. The two VLAN sub interfaces must have different VLAN IDs.
  • B. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
  • C. The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.
  • D. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.

Answer: A

Explanation:
Explanation
FortiGate_Infrastructure_6.0_Study_Guide_v2-Online.pdf -
"Multiple VLANs can coexist in the same physical interface, provide they have different VLAN ID"

 

NEW QUESTION 46
Which security feature does FortiGate provide to protect servers located in the internal networks from attacks such as SQL injections?

  • A. Antivirus
  • B. Application control
  • C. Denial of Service
  • D. Web application firewall

Answer: C

 

NEW QUESTION 47
Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. Traffic matching the signature will be allowed and logged.
  • B. The signature setting uses a custom rating threshold.
  • C. Traffic matching the signature will be silently dropped and logged.
  • D. The signature setting includes a group of other signatures.

Answer: A

 

NEW QUESTION 48
Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.


An administrator has configured the WINDOWS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?

  • A. The IPS filter is missing the Protocol: HTTPS option.
  • B. The HTTPS signatures have not been added to the sensor.
  • C. A DoS policy should be used, instead of an IPS sensor.
  • D. A DoS policy should be used, instead of an IPS sensor.
  • E. The firewall policy is not using a full SSL inspection profile.

Answer: E

 

NEW QUESTION 49
Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase
2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?

  • A. On HQ-FortiGate,enable Diffie-Hellman Group 2.
  • B. On HQ-FortiGate,enable Auto-negotiate.
  • C. On Remote-FortiGate, set Seconds to 43200.
  • D. On HQ-FortiGate, set Encryption to AES256.

Answer: D

 

NEW QUESTION 50
Examine the exhibit, which contains a virtual IP and firewall policy configuration.



The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?

  • A. 10.200.1.1
  • B. 10.200.1.10
  • C. 10.0.1.254
  • D. Any available IP address in the WAN (port1) subnet 10.200.1.0/24

Answer: D

Explanation:
Explanation: https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall- 52/Firewall%20Objects/Virtual%20IPs.htm

 

NEW QUESTION 51
Refer to the exhibit.




The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?

  • A. 10.200.1.49
  • B. 10.200.1.1
  • C. 10.200.1.99
  • D. 10.200.1.149

Answer: C

 

NEW QUESTION 52
Which two statements ate true about the Security Fabric rating? (Choose two.)

  • A. The Security Fabric rating is a free service that comes bundled with alt FortiGate devices.
  • B. Many of the security issues can befixed immediately by click ng Apply where available.
  • C. It provides executive summaries of the four largest areas of security focus.
  • D. The Security Fabric rating must be run on the root FortiGate device in the Security Fabric.

Answer: C,D

 

NEW QUESTION 53
Which two statements are correct about a software switch on FortiGate? (Choose two.)

  • A. Can act as a Layer 2 switch as well as a Layer 3 router
  • B. It can be configured only when FortiGate is operating in NAT mode
  • C. All interfaces in the software switch share the same IP address
  • D. It can group only physical interfaces

Answer: B,C

 

NEW QUESTION 54
Refer to the exhibit.

The exhibits show a network diagram and the explicit web proxy configuration.
In the command diagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?

  • A. 'host 192.168.0.2 and port 8080'
  • B. 'host 10.0.0.50 and port 8080'
  • C. 'host 10.0.0.50 and port 80'
  • D. 'host 192.168.0.1 and port 80'

Answer: A

 

NEW QUESTION 55
Refer to the exhibit.

The exhibits show a network diagram and the explicit web proxy configuration.
In the commanddiagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?

  • A. `host 192.168.0.2 and port 8080'
  • B. `host 10.0.0.50 and port 8080'
  • C. `host 10.0.0.50 and port 80'
  • D. `host 192.168.0.1 and port 80'

Answer: A

 

NEW QUESTION 56
Which two types of traffic are managed only by the management VDOM? (Choose two.)

  • A. DNS
  • B. PKI
  • C. Traffic shaping
  • D. FortiGuard web filter queries

Answer: A,D

 

NEW QUESTION 57
Refer to the exhibit.

Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)

  • A. port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.
  • B. port1 is a native VLAN.
  • C. port1-vlan10 and port2-vlan10 are part of the same broadcast domain.
  • D. Traffic between port2 and port2-vlan1 is allowed by default.

Answer: A,D

 

NEW QUESTION 58
An administrator Is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A.
the local quick mode selector is 192.160.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?

  • A. 192.168.2.0/24
  • B. 192.168.3.0/24
  • C. 192.168.0.0/24
  • D. 192.168.1.0/24

Answer: C

 

NEW QUESTION 59
Consider the topology:
Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout.
The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.
What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)

  • A. Create a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic, and set the new TELNET service object in the policy.
  • B. Create a new service object for TELNET and set the maximum session TTL.
  • C. Set the maximum session TTL value for the TELNET service object.
  • D. Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not happen after 90 minutes.

Answer: C,D

 

NEW QUESTION 60
......


What is the duration, language, and format of Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam

  • Language of Exam: English, Japanese, Korean and simplified Chinese
  • Number of Questions: 65
  • No negative marking for wrong answers
  • Type of Questions: Multiple choice (MCQs), multiple answers
  • Duration of Exam: 130 minutes
  • Passing score: 72%

 

Updated Jan-2022 Pass NSE4_FGT-6.4 Exam - Real Practice Test Questions: https://www.exams-boost.com/NSE4_FGT-6.4-valid-materials.html