Fortinet NSE4_FGT-6.2 Exam Practice Questions (P. 1)
- Full Access (119 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Examine the FortiGate configuration:

What will happen to unauthenticated users when an active authentication policy is followed by a fall through policy without authentication?

What will happen to unauthenticated users when an active authentication policy is followed by a fall through policy without authentication?
- AThe user must log in again to authenticate.
- BThe user will be denied access to resources without authentication.
- CThe user will not be prompted for authentication.
- DUser authentication happens at an interface level.
Correct Answer:
A
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46875
A
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46875
send
light_mode
delete
Question #2
Which downstream FortiGate VDOM is used to join the Security Fabric when split-task VDOM is enabled on all FortiGate devices?
- AFG-traffic VDOM
- BRoot VDOM
- CCustomer VDOM
- DGlobal VDOM
Correct Answer:
B
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/new-features/287377/split-task-vdom-support
B
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/new-features/287377/split-task-vdom-support
send
light_mode
delete
Question #3
In an HA cluster operating in active-active mode, which path is taken by the SYN packet of an HTTP session that is offloaded to a secondary FortiGate?
- AClient > secondary FortiGate > primary FortiGate > web server
- BClient > primary FortiGate > secondary FortiGate > primary FortiGate > web server
- CClient > primary FortiGate > secondary FortiGate > web server
- DClient > secondary FortiGate > web server
Correct Answer:
C
C
send
light_mode
delete
Question #4
Which two statements about antivirus scanning mode are true? (Choose two.)
- AIn proxy-based inspection mode, antivirus buffers the whole file for scanning, before sending it to the client.Most Voted
- BIn full scan flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.Most Voted
- CIn proxy-based inspection mode, files bigger than the buffer size are scanned.
- DIn quick scan mode, you can configure antivirus profiles to use any of the available antivirus signature databases.
Correct Answer:
AB
AB
send
light_mode
delete
Question #5
The FSSO collector agent set to advanced access mode for the Windows Active Directory uses which convention?
send
light_mode
delete
All Pages