Latest [Oct 05, 2021] NSE4_FGT-6.4 Exam with Accurate Fortinet NSE 4 - FortiOS 6.4 PDF Questions
Take a Leap Forward in Your Career by Earning Fortinet 165 Questions
NEW QUESTION 55
Refer to the exhibit.
An administrator is running a sniffer command as shown in the exhibit.
Which three pieces of information are included in the sniffer output? (Choose three.)
- A. Application header
- B. Interface name
- C. IP header
- D. Ethernet header
- E. Packet payload
Answer: B,C,E
Explanation:
Explanation
FortiGate_Infrastructure_6.4 page 58
NEW QUESTION 56
Refer to the exhibit.
The exhibit shows proxy policies and proxy addresses, the authentication rule and authentication scheme, users, and firewall address.
An explicit web proxy is configured for subnet range 10.0.1.0/24 with three explicit web proxy policies.
The authentication rule is configured to authenticate HTTP requests for subnet range 10.0.1.0/24 with a form-based authentication scheme for the FortiGate local user database. Users will be prompted for authentication.
How will FortiGate process the traffic when the HTTP request comes from a machine with the source IP 10.0.1.10 to the destination http://www.fortinet.com? (Choose two.)
- A. If a Microsoft Internet Explorer browser is used with User-B credentials, the HTTP request will be allowed.
- B. If a Google Chrome browser is used with User-B credentials, the HTTP request will be allowed.
- C. If a Mozilla Firefox browser is used with User-B credentials, the HTTP request will be allowed.
- D. If a Mozilla Firefox browser is used with User-A credentials, the HTTP request will be allowed.
Answer: A,C
NEW QUESTION 57
An administrator has configured the following settings:
- A. A session for denied traffic is created.
- B. Device detection on all interfaces is enforced for 30 minutes.
- C. The number of logs generated by denied traffic is reduced.
- D. Denied users are blocked for 30 minutes.
Answer: A,C
NEW QUESTION 58
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?
- A. Interface Pair view will be disabled.
- B. By Sequence view will be disabled.
- C. Search option will be disabled
- D. Policy lookup will be disabled.
Answer: D
NEW QUESTION 59
View the exhibit. Which the FortiGate handle web proxy traffic rue? (Choose two.)
- A. port1-VLAN10 and port2-VLAN10 can be assigned to different VDOMs.
- B. Broadcast traffic received in port1-VLAN10 will not be forwarded to port2-VLAN10.
- C. Traffic between port1-VLAN1 and port2-VLAN1 is allowed by default.
- D. port-VLAN1 is the native VLAN for the port1 physical interface.
Answer: A,B
NEW QUESTION 60
Refer to the exhibit.
Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)
- A. port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.
- B. port1 is a native VLAN.
- C. port1-vlan10 and port2-vlan10 are part of the same broadcast domain.
- D. Traffic between port2 and port2-vlan1 is allowed by default.
Answer: A,D
NEW QUESTION 61
Refer to the FortiGuard connection debug output.
Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
- A. One server was contacted to retrieve the contract information.
- B. There is at least one server that lost packets consecutively.
- C. A local FortiManager is one of the servers FortiGate communicates with.
- D. FortiGate is using default FortiGuard communication settings.
Answer: A,D
NEW QUESTION 62
Refer to the exhibit to view the firewall policy.
Which statement is correct if well-known viruses are not being blocked?
- A. The firewall policy must be configured in proxy-based inspection mode.
- B. The action on the firewall policy must be set to deny.
- C. Web filter should be enabled on the firewall policy to complement the antivirus profile.
- D. The firewall policy does not apply deep content inspection.
Answer: C
NEW QUESTION 63
Refer to the exhibit.
Given the security fabric topology shown in the exhibit, which two statements are true? (Choose two.)
- A. This security fabric topology is a logical topology view.
- B. There are 19 security recommendations for the security fabric.
- C. Device detection is disabled on all FortiGate devices.
- D. There are five devices that are part of the security fabric.
Answer: A,C
Explanation:
Explanation/Reference:
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 3
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions
NEW QUESTION 64
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. Application control
- B. DNS filter
- C. Web application firewall
- D. Web filter in flow-based inspection
- E. Antivirus in flow-based inspection
Answer: A,D,E
NEW QUESTION 65
Refer to the exhibit.
Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
- A. Traffic matching the signature will be silently dropped and logged.
- B. The signature setting uses a custom rating threshold.
- C. The signature setting includes a group of other signatures.
- D. Traffic matching the signature will be allowed and logged.
Answer: C
NEW QUESTION 66
An administrator must disable RPF check to investigate an issue.
Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?
- A. Disable the RPF check at the FortiGate interface level for the source check.
- B. Enable asymmetric routing, so the RPF check will be bypassed.
- C. Disable the RPF check at the FortiGate interface level for the reply check.
- D. Enable asymmetric routing at the interface level.
Answer: A
NEW QUESTION 67
When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
- A. Log ID
- B. Policy ID
- C. Sequence ID
- D. Universally Unique Identifier
Answer: D
Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/554066/firewall-policies
NEW QUESTION 68
Which statements about antivirus scanning mode are true? (Choose two.)
- A. In proxy-based inspection mode antivirus buffers the whole file for scarring before sending it to the client.
- B. In quick scan mode, you can configure antivirus profiles to use any of the available signature data bases.
- C. In flow-based inspection mode, you can use the CLI to configure antivirus profiles to use protocol option profiles.
- D. In proxy-based inspection mode, if a virus is detected, a replacement message may not be displayed immediately.
Answer: A,C
NEW QUESTION 69
Refer to the exhibit to view the application control profile.
Users who use Apple FaceTime video conferences are unable to set up meetings.
In this scenario, which statement is true?
- A. The category of Apple FaceTime is being blocked.
- B. Apple FaceTime belongs to the custom blocked filter.
- C. The category of Apple FaceTime is being monitored.
- D. Apple FaceTime belongs to the custom monitored filter.
Answer: D
NEW QUESTION 70
Which of the following SD-WAN load -balancing method use interface weight value to distribute traffic?
(Choose two.)
- A. Source IP
- B. Volume
- C. Spillover
- D. Session
Answer: B,D
Explanation:
Explanation
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/49719/configuring-sd-wan-load-balancing
NEW QUESTION 71
Consider the topology:
Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout.
The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.
What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)
- A. Create a new service object for TELNET and set the maximum session TTL.
- B. Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not happen after 90 minutes.
- C. Set the maximum session TTL value for the TELNET service object.
- D. Create a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic, and set the new TELNET service object in the policy.
Answer: B,C
NEW QUESTION 72
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?
- A. Add user accounts to the FortiGate group fitter.
- B. Add user accounts to Active Directory (AD).
- C. Add user accounts to the Ignore User List.
- D. Add the support of NTLM authentication.
Answer: C
NEW QUESTION 73
An administrator has configured a route-based IPsec VPN between two FortiGate devices. Which statement about this IPsec VPN configuration is true?
- A. The IPsec firewall policies must be placed at the top of the list.
In a route-based configuration, FortiGate automatically adds a virtual interface eith the VPN name (Infrastructure Study Guide, 206) - B. This VPN cannot be used as part of a hub-and-spoke topology.
- C. A virtual IPsec interface is automatically created after the phase 1 configuration is completed.
- D. A phase 2 configuration is not required.
Answer: C
NEW QUESTION 74
......
Authentic Best resources for NSE4_FGT-6.4 Online Practice Exam: https://www.trainingdump.com/Fortinet/NSE4_FGT-6.4-practice-exam-dumps.html