2021 100% Free NSE4_FGT-6.4 Daily Practice Exam With 165 Questions [Q48-Q66]

Share

2021 100% Free NSE4_FGT-6.4 Daily Practice Exam With 165 Questions

NSE4_FGT-6.4 exam torrent Fortinet study guide


How to book the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam

To apply for the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam, You have to follow these steps:

  • Step 1: Go to the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam Official Site
  • Step 2: Read the instruction Carefully
  • Step 3: Follow the given steps
  • Step 4: Apply for the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam

 

NEW QUESTION 48
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?

  • A. Flow engine
  • B. Antivirus engine
  • C. Intrusion prevention system engine
  • D. Detection engine

Answer: C

 

NEW QUESTION 49
View the exhibit.

Which of the following statements are correct? (Choose two.)

  • A. Dead peer detection must be disabled to support this type of IPsec setup.
  • B. This is a redundant IPsec setup.
  • C. This setup requires at least two firewall policies with the action set to IPsec.
  • D. The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.

Answer: B,D

 

NEW QUESTION 50
An administrator has configured the following settings:

What are the two results of this configuration? (Choose two.)

  • A. The number of logs generated by denied traffic is reduced.
  • B. Device detection on all interfaces is enforced for 30 minutes.
  • C. Denied users are blocked for 30 minutes.
  • D. A session for denied traffic is created.

Answer: A,D

 

NEW QUESTION 51
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded.
What is the reason for the failed virus detection by FortiGate?

  • A. Application control is not enabled
  • B. SSL/SSH Inspection profile is incorrect
  • C. Antivirus profile configuration is incorrect
  • D. Antivirus definitions are not up to date

Answer: B

 

NEW QUESTION 52
Refer to the exhibit to view the firewall policy.

Which statement is correct if well-known viruses are not being blocked?

  • A. The firewall policy does not apply deep content inspection.
  • B. The firewall policy must be configured in proxy-based inspection mode.
  • C. The action on the firewall policy must be set to deny.
  • D. Web filter should be enabled on the firewall policy to complement the antivirus profile.

Answer: A

 

NEW QUESTION 53
Consider the topology:
Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout.
The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.
What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 10
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions

  • A. Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not happen after
    90 minutes.
  • B. Set the maximum session TTL value for the TELNET service object.
  • C. Create a new service object for TELNET and set the maximum session TTL.
  • D. Create a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic, and set the new TELNET service object in the policy.

Answer: A,C

 

NEW QUESTION 54
If the Services field is configured in a Virtual IP (VIP), which statement is true when central NAT is used?

  • A. The Services field prevents multiple sources of traffic from using multiple services to connect to a single
  • B. The Services field removes the requirement to create multiple VIPs for different services.
  • C. The Services field prevents SNAT and DNAT from being combined in the same policy.
  • D. The Services field is used when you need to bundle several VIPs into VIP groups.

Answer: B

Explanation:
computer.

 

NEW QUESTION 55
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

  • A. The interface has been configured for one-arm sniffer.
  • B. The interface is a member of a zone.
  • C. Captive portal is enabled in the interface.
  • D. The interface is a member of a virtual wire pair.
  • E. The operation mode is transparent.

Answer: A,D,E

Explanation:
Explanation
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm

 

NEW QUESTION 56
Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)

  • A. NGFW mode
  • B. Operating mode
  • C. FortiGuaid update servers
  • D. System time

Answer: A,D

 

NEW QUESTION 57
To complete the final step of a Security Fabric configuration, an administrator must authorize all the devices on which device?

  • A. FortiAnalyzer
  • B. FortiManager
  • C. Downstream FortiGate
  • D. Root FortiGate

Answer: D

 

NEW QUESTION 58
Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. Traffic matching the signature will be allowed and logged.
  • B. The signature setting includes a group of other signatures.
  • C. The signature setting uses a custom rating threshold.
  • D. Traffic matching the signature will be silently dropped and logged.

Answer: B

 

NEW QUESTION 59
Refer to the exhibit.

Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?

  • A. CLI diagnostics commands permission
  • B. Read/Write permission for Log & Report
  • C. Custom permission for Network
  • D. Read/Write permission for Firewall

Answer: C

 

NEW QUESTION 60
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)

  • A. new-session
  • B. hard-timeout
  • C. auth-on-demand
  • D. Idle-timeout
  • E. soft-timeout

Answer: A,B,D

Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=FD37221

 

NEW QUESTION 61
Examine the two static routes shown in the exhibit, then answer the following question.

Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?

  • A. FortiGate will only actuate the port1 route in the routing table
  • B. FortiGate will route twice as much traffic to the port2 route
  • C. FortiGate will use the port1 route as the primary candidate.
  • D. FortiGate will load balance all traffic across both routes.

Answer: C

Explanation:
Explanation
"If multiple static routes have the same distance, they are all active; however, only the one with the lowest priority is considered the best path."

 

NEW QUESTION 62
Examine this output from a debug flow:

Why did the FortiGate drop the packet?

  • A. The next-hop IP address is unreachable.
  • B. It matched the default implicit firewall policy.
  • C. It failed the RPF check.
  • D. It matched an explicitly configured firewall policy with the action DENY.

Answer: B

Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=13900

 

NEW QUESTION 63
Refer to the exhibits.


Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default configuration of high memory usage thresholds. Based on the system performance output, which two statements are correct? (Choose two.)

  • A. Administrators cannot change the configuration.
  • B. Administrators can access FortiGate only through the console port.
  • C. FortiGate will start sending all files to FortiSandbox for inspection.
  • D. FortiGate has entered conserve mode.

Answer: A,D

 

NEW QUESTION 64
Which feature in the Security Fabric takes one or more actions based on event triggers?

  • A. Security Rating
  • B. Fabric Connectors
  • C. Automation Stitches
  • D. Logical Topology

Answer: A

 

NEW QUESTION 65
Which of the following SD-WAN load balancing method use interface weight value to distribute traffic? (Choose two.)

  • A. Source IP
  • B. Session
  • C. Spillover
  • D. Volume

Answer: B,D

 

NEW QUESTION 66
......

Use Valid New NSE4_FGT-6.4 Test Notes & NSE4_FGT-6.4 Valid Exam Guide: https://www.pass4suresvce.com/NSE4_FGT-6.4-pass4sure-vce-dumps.html