Fortinet NSE4-5.4 Exam Practice Questions (P. 2)
- Full Access (575 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
View the example routing table.

Which route will be selected when trying to reach 10.20.30.254?

Which route will be selected when trying to reach 10.20.30.254?
- A10.20.30.0/26 [10/0] via 172.20.168.254, port2
- BThe traffic will be dropped because it cannot be routed.
- C10.20.30.0/24 [10/0] via 172.20.167.254, port3
- D0.0.0.0/0 [10/0] via 172.20.121.2, port1
Correct Answer:
C

C


send
light_mode
delete
Question #12
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?
- AThe FortiGate unit's public IP address
- BThe FortiGate unit's internal IP address
- CThe remote user's virtual IP address
- DThe remote user's public IP address
Correct Answer:
B
B
send
light_mode
delete
Question #13
What is FortiGate's behavior when local disk logging is disabled?
- AOnly real-time logs appear on the FortiGate dashboard.
- BNo logs are generated.
- CAlert emails are disabled.
- DRemote logging is automatically enabled.
Correct Answer:
A
A
send
light_mode
delete
Question #14
What traffic and attacks can be blocked by a web application firewall (WAF) profile? (Choose three.)
- ATraffic to inappropriate web sites
- BSQL injection attacks
- CServer information disclosure attacks
- DCredit card data leaks
- ETraffic to botnet command and control (C&C) servers
Correct Answer:
BCE
BCE
send
light_mode
delete
Question #15
Which statements about One-to-One IP pool are true? (Choose two.)
- AIt allows configuration of ARP replies.
- BIt allows fixed mapping of an internal address range to an external address range.
- CIt is used for destination NAT.
- DIt does not use port address translation.
Correct Answer:
BD
BD
send
light_mode
delete
Question #16
Which statements correctly describe transparent mode operation? (Choose three.)
- AAll interfaces of the transparent mode FortiGate device must be on different IP subnets.
- BThe transparent FortiGate is visible to network hosts in an IP traceroute.
- CIt permits inline traffic inspection and firewalling without changing the IP scheme of the network.
- DEthernet packets are forwarded based on destination MAC addresses, not IP addresses.
- EThe FortiGate acts as transparent bridge and forwards traffic at Layer-2.
Correct Answer:
CDE
CDE
send
light_mode
delete
Question #17
View the exhibit.

What is the effect of the Disconnect Cluster Member operation as shown in the exhibit? (Choose two.)

What is the effect of the Disconnect Cluster Member operation as shown in the exhibit? (Choose two.)
- AThe HA mode changes to standalone.
- BThe firewall policies are deleted on the disconnected member.
- CThe system hostname is set to the FortiGate serial number.
- DThe port3 is configured with an IP address for management access.
Correct Answer:
AD
AD
send
light_mode
delete
Question #18
What step is required to configure an SSL VPN to access to an internal server using port forward mode?
- AConfigure the virtual IP addresses to be assigned to the SSL VPN users.
- BInstall FortiClient SSL VPN client
- CCreate a SSL VPN realm reserved for clients using port forward mode.
- DConfigure the client application to forward IP traffic to a Java applet proxy.
Correct Answer:
D
D
send
light_mode
delete
Question #19
View the exhibit.

This is a sniffer output of a telnet connection request from 172.20.120.186 to the port1 interface of FGT1.

In this scenario. FGT1 has the following routing table:

Assuming telnet service is enabled for port1, which of the following statements correctly describes why FGT1 is not responding?

This is a sniffer output of a telnet connection request from 172.20.120.186 to the port1 interface of FGT1.

In this scenario. FGT1 has the following routing table:

Assuming telnet service is enabled for port1, which of the following statements correctly describes why FGT1 is not responding?
- AThe port1 cable is disconnected.
- BThe connection is dropped due to reverse path forwarding check.
- CThe connection is denied due to forward policy check.
- DFGT1's port1 interface is administratively down.
Correct Answer:
B
B
send
light_mode
delete
Question #20
An administrator needs to be able to view logs for application usage on your network. What configurations are required to ensure that FortiGate generates logs for application usage activity? (Choose two.)
- AEnable a web filtering profile on the firewall policy.
- BCreate an application control policy.
- CEnable logging on the firewall policy.
- DEnable an application control security profile on the firewall policy.
Correct Answer:
CD
By default the fortigate have one app control to monitor and for that not need create other app control and it necessary active logs in the policy to monitoring.
CD
By default the fortigate have one app control to monitor and for that not need create other app control and it necessary active logs in the policy to monitoring.

send
light_mode
delete
All Pages