Fortinet NSE4_FGT-6.4 Exam Practice Questions (P. 1)
- Full Access (121 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Which two statements are true when FortiGate is in transparent mode? (Choose two.)
- ABy default, all interfaces are part of the same broadcast domain.Most Voted
- BThe existing network IP schema must be changed when installing a transparent mode FortiGate in the network.
- CStatic routes are required to allow traffic to the next hop.
- DFortiGate forwards frames without changing the MAC address.Most Voted
Correct Answer:
AD
Reference:
https://kb.fortinet.com/kb/viewAttachment.do?
attachID=Fortigate_Transparent_Mode_Technical_Guide_FortiOS_4_0_version1.2.pdf&documentID=FD33113
AD
Reference:
https://kb.fortinet.com/kb/viewAttachment.do?
attachID=Fortigate_Transparent_Mode_Technical_Guide_FortiOS_4_0_version1.2.pdf&documentID=FD33113
send
light_mode
delete
Question #2
What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?
- AFull Content inspection
- BProxy-based inspection
- CCertificate inspection
- DFlow-based inspectionMost Voted
Correct Answer:
D
D
send
light_mode
delete
Question #3
Which two statements about IPsec authentication on FortiGate are correct? (Choose two.)
- AFor a stronger authentication, you can also enable extended authentication (XAuth) to request the remote peer to provide a username and password.Most Voted
- BFortiGate supports pre-shared key and signature as authentication methods.Most Voted
- CEnabling XAuth results in a faster authentication because fewer packets are exchanged.
- DA certificate is not required on the remote peer when you set the signature as the authentication method.
Correct Answer:
AB
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/100552/using-xauth-authentication
AB
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/100552/using-xauth-authentication
send
light_mode
delete
Question #4
Which scanning technique on FortiGate can be enabled only on the CLI?
- AHeuristics scanMost Voted
- BTrojan scan
- CAntivirus scan
- DRansomware scan
Correct Answer:
A
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/927086/examples
A
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/927086/examples
send
light_mode
delete
Question #5
Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)
- AFirewall policy
- BPolicy rule
- CSecurity policyMost Voted
- DSSL inspection and authentication policyMost Voted
Correct Answer:
AB
Reference:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-mode
AB
Reference:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-mode
send
light_mode
delete
All Pages