Fortinet NSE4-5.4 Exam Practice Questions (P. 3)
- Full Access (575 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
A company needs to provide SSL VPN access to two user groups. The company also needs to display different welcome messages on the SSL VPN login screen for both user groups.
What is required in the SSL VPN configuration to meet these requirements?
What is required in the SSL VPN configuration to meet these requirements?
- ATwo separated SSL VPNs in different interfaces of the same VDOM
- BDifferent SSL VPN realms for each group
- CDifferent virtual SSLVPN IP addresses for each group
- DTwo firewall policies with different captive portals
Correct Answer:
B
B

send
light_mode
delete
Question #22
Examine the routing database.

Which of the following statements are correct? (Choose two.)

Which of the following statements are correct? (Choose two.)
- AThe port3 default route has the lowest metric, making it the best route.
- BThere will be eight routes active in the routing table.
- CThe port3 default has a higher distance than the port1 and port2 default routes.
- DBoth port1 and port2 default routers are active in the routing table.
Correct Answer:
CD
CD
send
light_mode
delete
Question #23
View the exhibit.

When a user attempts to connect to an HTTPS site, what is the expected result with this configuration?

When a user attempts to connect to an HTTPS site, what is the expected result with this configuration?
- AThe user is required to authenticate before accessing sites with untrusted SSL certificates.
- BThe user is presented with certificate warnings when connecting to sites that have untrusted SSL certificates.
- CThe user is allowed access all sites with untrusted SSL certificates, without certificate warnings.
- DThe user is blocked from connecting to sites that have untrusted SSL certificates (no exception provided).
Correct Answer:
B
B
send
light_mode
delete
Question #24
View the exhibit.

When Role is set to Undefined, which statement is true?

When Role is set to Undefined, which statement is true?
- AThe GUI provides all the configuration options available for the port1 interface.
- BYou cannot configure a static IP address for the port1 interface because it allows only DHCP addressing mode.
- CFirewall policies can be created from only the port1 interface to any interface.
- DThe port1 interface is reserved for management only.
Correct Answer:
A
A
send
light_mode
delete
Question #25
Which statement is true regarding the policy ID numbers of firewall policies?
- AChange when firewall policies are re-ordered.
- BDefines the order in which rules are processed.
- CAre required to modify a firewall policy from the CLI.
- DRepresent the number of objects used in the firewall policy.
Correct Answer:
C
The ID no change when re-ordered and the rules are processed to top to bottom not by ID.
C
The ID no change when re-ordered and the rules are processed to top to bottom not by ID.

send
light_mode
delete
Question #26
An administrator needs to inspect all web traffic (including Internet web traffic) coming from users connecting to SSL VPN. How can this be achieved?
- ADisabling split tunneling
- BConfiguring web bookmarks
- CAssigning public IP addresses to SSL VPN clients
- DUsing web-only mode
Correct Answer:
A
A

send
light_mode
delete
Question #27
Which traffic inspection features can be executed by a security processor (SP)? (Choose three.)
- ATCP SYN proxy
- BSIP session helper
- CProxy-based antivirus
- DAttack signature matching
- EFlow-based web filtering
Correct Answer:
CDE
CDE
send
light_mode
delete
Question #28
An administrator has configured two VLAN interfaces:

A DHCP server is connected to the VLAN10 interface. A DHCP client is connected to the VLAN5 interface. However, the DHCP client cannot get a dynamic IP address from the DHCP server. What is the cause of the problem?

A DHCP server is connected to the VLAN10 interface. A DHCP client is connected to the VLAN5 interface. However, the DHCP client cannot get a dynamic IP address from the DHCP server. What is the cause of the problem?
- ABoth interfaces must be in different VDOMs
- BBoth interfaces must have the same VLAN ID.
- CThe role of the VLAN10 interface must be set to server.
- DBoth interfaces must belong to the same forward domain.
Correct Answer:
D

D


send
light_mode
delete
Question #29
View the exhibit.

A user behind the FortiGate is trying to go to http://www.addictinggames.com (Addicting.Games). Based on this configuration, which statement is true?

A user behind the FortiGate is trying to go to http://www.addictinggames.com (Addicting.Games). Based on this configuration, which statement is true?
- AAddicting.Games is allowed based on the Application Overrides configuration.
- BAddicting.Games is blocked based on the Filter Overrides configuration.
- CAddicting.Games can be allowed only if the Filter Overrides actions is set to Exempt.
- DAddicting.Games is allowed based on the Categories configuration.
Correct Answer:
A
A
send
light_mode
delete
Question #30
What are the purposes of NAT traversal in IPsec? (Choose two.)
- ATo detect intermediary NAT devices in the tunnel path.
- BTo encapsulate ESP packets in UDP packets using port 4500.
- CTo force a new DH exchange with each phase 2 re-key
- DTo dynamically change phase 1 negotiation mode to Aggressive.
Correct Answer:
AB
AB
send
light_mode
delete
All Pages