Fortinet NSE4-5.4 Exam Practice Questions (P. 1)
- Full Access (575 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
A FortiGate interface is configured with the following commands:

What statements about the configuration are correct? (Choose two.)

What statements about the configuration are correct? (Choose two.)
- AIPv6 clients connected to port1 can use SLAAC to generate their IPv6 addresses.
- BFortiGate can provide DNS settings to IPv6 clients.
- CFortiGate can send IPv6 router advertisements (RAs.)
- DFortiGate can provide IPv6 addresses to DHCPv6 client.
Correct Answer:
AC
AC
send
light_mode
delete
Question #2
Which of the following Fortinet hardware accelerators can be used to offload flow-based antivirus inspection? (Choose two.)
send
light_mode
delete
Question #3
Under what circumstance would you enable LEARN as the Action on a firewall policy?
- AYou want FortiGate to compile security feature activity from various security-related logs, such as virus and attack logs.
- BYou want FortiGate to monitor a specific security profile in a firewall policy, and provide recommendations for that profile.
- CYou want to capture data across all traffic and security vectors, and receive learning logs and a report with recommendations.
- DYou want FortiGate to automatically modify your firewall policies as it learns your networking behavior.
Correct Answer:
C
C
send
light_mode
delete
Question #4
What methods can be used to deliver the token code to a user who is configured to use two-factor authentication? (Choose three.)
- ACode blocks
- BSMS phone message
- CFortiToken
- DBrowser pop-up window
- EEmail
Correct Answer:
BCE
BCE
send
light_mode
delete
Question #5
You are tasked to architect a new IPsec deployment with the following criteria:
- There are two HQ sites that all satellite offices must connect to.
- The satellite offices do not need to communicate directly with other satellite offices.
- No dynamic routing will be used.
- The design should minimize the number of tunnels being configured.
Which topology should be used to satisfy all of the requirements?
- There are two HQ sites that all satellite offices must connect to.
- The satellite offices do not need to communicate directly with other satellite offices.
- No dynamic routing will be used.
- The design should minimize the number of tunnels being configured.
Which topology should be used to satisfy all of the requirements?
send
light_mode
delete
Question #6
View the exhibit.


Which of the following statements are correct? (Choose two.)


Which of the following statements are correct? (Choose two.)
- AThis is a redundant IPsec setup.
- BThe TunnelB route is the primary one for searching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
- CThis setup requires at least two firewall policies with action set to IPsec.
- DDead peer detection must be disabled to support this type of IPsec setup.
Correct Answer:
AB
AB
send
light_mode
delete
Question #7
Which statements about DNS filter profiles are true? (Choose two.)
- AThey can inspect HTTP traffic.
- BThey must be applied in firewall policies with SSL inspection enabled.
- CThey can block DNS request to known botnet command and control servers.
- DThey can redirect blocked requests to a specific portal.
Correct Answer:
CD
CD
send
light_mode
delete
Question #8
An administrator needs to offload logging to FortiAnalyzer from a FortiGate with an internal hard drive. Which statements are true? (Choose two.)
- ALogs must be stored on FortiGate first, before transmitting to FortiAnalyzer
- BFortiGate uses port 8080 for log transmission
- CLog messages are transmitted as plain text in LZ4 compressed format (store-and-upload method).
- DFortiGate can encrypt communications using SSL encrypted OFTP traffic.
Correct Answer:
AC
AC
send
light_mode
delete
Question #9
Which of the following statements describe WMI polling mode for FSSO collector agent? (Choose two.)
- AThe collector agent does not need to search any security event logs.
- BWMI polling can increase bandwidth usage with large networks.
- CThe NetSessionEnum function is used to track user logoffs.
- DThe collector agent uses a Windows API to query DCs for user logins.
Correct Answer:
BD
BD
send
light_mode
delete
Question #10
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
- AThe interface has been configured for one-arm sniffer.Most Voted
- BThe interface is a member of a virtual wire pair.Most Voted
- CThe operation mode is transparent.Most Voted
- DThe interface is a member of a zone.
- ECaptive portal is enabled in the interface.
Correct Answer:
ABC
ABC
send
light_mode
delete
All Pages