NSE4_FGT-6.4 Exam Dumps - PDF Questions and Testing Engine
NSE4_FGT-6.4 Dumps - The Sure Way To Pass Exam
NEW QUESTION 17
Refer to the exhibit, which contains a session diagnostic output.
Which statement is true about the session diagnostic output?
- A. The session is a UDP unidirectional state.
- B. The session is in TCP ESTABLISHED state.
- C. The session is a bidirectional TCP connection.
- D. The session is a bidirectional UDP connection.
Answer: D
NEW QUESTION 18
Examine this FortiGate configuration:
Examine the output of the following debug command:
Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection?
- A. It is dropped.
- B. It is allowed, but with no inspection
- C. It is allowed and inspected, as long as the only inspection required is antivirus.
- D. It is allowed and inspected as long as the inspection is flow based
Answer: A
NEW QUESTION 19
How do you format the FortiGate flash disk?
- A. Load a debug FortiOS image.
- B. Execute the CLI command execute formatlogdisk.
- C. Load the hardware test (HQIP) image.
- D. Select the format boot device option from the BIOS menu.
Answer: D
NEW QUESTION 20
Which two statements are true about the FGCP protocol? (Choose two.)
- A. Is used to discover FortiGate devices in different HA groups
- B. Not used when FortiGate is in Transparent mode
- C. Elects the primary FortiGate device
- D. Runs only over the heartbeat links
Answer: A,D
NEW QUESTION 21
How does FortiGate act when using SSL VPN in web mode?
- A. FortiGate acts as DNS server.
- B. FortiGate acts as an FDS server.
- C. FortiGate acts as router.
- D. FortiGate acts as an HTTP reverse proxy.
Answer: D
NEW QUESTION 22
Which three criteria can a FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)
- A. Destination defined as Internet Services in the firewall policy.
- B. Lowest to highest policy ID number.
- C. Highest to lowest priority defined in the firewall policy.
- D. Services defined in the firewall policy.
- E. Source defined as Internet Services in the firewall policy.
Answer: A,D,E
NEW QUESTION 23
Examine this PAC file configuration.
Which of the following statements are true? (Choose two.)
- A. All requests not made to Fortinet.com or the 172.25.120.0/24 subnet, have to go through altproxy.corp.com: 8060.
- B. Any web request fortinet.com is allowed to bypass the proxy.
- C. Browsers can be configured to retrieve this PAC file from the FortiGate.
- D. Any web request to the 172.25.120.0/24 subnet is allowed to bypass the proxy.
Answer: B,C
NEW QUESTION 24
View the exhibit. A user behind the FortiGate is trying to go to http://www.addictinggames.com (Addicting Games). Based on this configuration, which statement is true?
- A. Addcting.Games is allowed based on the Categories configuration.
- B. Addicting.Games is allowed based on the Application Overrides configuration.
- C. Addicting.Games can be allowed only if the Filter Overrides actions is set to Exempt.
- D. Addicting.Games is blocked on the Filter Overrides configuration.
Answer: B
NEW QUESTION 25
You have enabled logging on your FortiGate device for Event logs and all Security logs, and you have set up logging to use the FortiGate local disk.
What is the default behavior when the local disk is full?
- A. Logs are overwritten and the first warning is issued when log disk usage reaches the threshold of 75%.
- B. No new log is recorded until you manually clear logs from the local disk.
- C. Logs are overwritten and the only warning is issued when log disk usage reaches the threshold of 95%.
- D. No new log is recorded after the warning is issued when log disk usage reaches the threshold of 95%.
Answer: A
Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortigate/6.4.0/cli-reference/462620/log-disk-setting
NEW QUESTION 26
Refer to the exhibit.
The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?
- A. Change password
- B. Change Administrator profile
- C. Enable restrict access to trusted hosts
- D. Enable two-factor authentication
Answer: D
NEW QUESTION 27
Examine the exhibit, which contains a virtual IP and firewall policy configuration.


The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address
10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?
- A. Any available IP address in the WAN (port1) subnet 10.200.1.0/24
- B. 10.0.1.254
- C. 10.200.1.1
- D. 10.200.1.10
Answer: A
Explanation:
Explanation
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Objects/Virtual%20IPs.
NEW QUESTION 28
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic, in addition, the remote peer does not support a dynamic DNS update service. What type of remote gateway should tie administrator configure on FortiGate for the new IPsec VPN tunnel to work?
- A. Pre-shared Key
- B. Static IP Address
- C. Dynamic DNS
- D. Dialup User
Answer: C
NEW QUESTION 29
Which Security rating scorecard helps identify configuration weakness and best practice violations in your network?
- A. Automated Response
- B. Fabric Coverage
- C. Optimization
- D. Security Posture
Answer: B
NEW QUESTION 30
Refer to the exhibit.
According to the certificate values shown in the exhibit, which type of entity was the certificate issued to?
- A. A root CA
- B. A bridge CA
- C. A user
- D. A subordinate
Answer: C
NEW QUESTION 31
Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)
- A. NGFW mode
- B. Operating mode
- C. FortiGuaid update servers
- D. System time
Answer: A,D
NEW QUESTION 32
Refer to the exhibit to view the application control profile.
Users who use Apple FaceTime video conferences are unable to set up meetings.
In this scenario, which statement is true?
- A. Apple FaceTime belongs to the custom monitored filter.
- B. The category of Apple FaceTime is being monitored.
- C. Apple FaceTime belongs to the custom blocked filter.
- D. The category of Apple FaceTime is being blocked.
Answer: A
NEW QUESTION 33
Refer to the exhibit to view the application control profile.
Users who use Apple FaceTime video conferences are unable to set up meetings.
In this scenario, which statement is true?
- A. Apple FaceTime belongs to the custom monitored filter.
- B. The category of Apple FaceTime is being monitored.
- C. Apple FaceTime belongs to the custom blocked filter.
- D. The category of Apple FaceTime is being blocked.
Answer: A
NEW QUESTION 34
Examine this output from a debug flow:
Why did the FortiGate drop the packet?
- A. The next-hop IP address is unreachable.
- B. It matched the default implicit firewall policy.
- C. It failed the RPF check.
- D. It matched an explicitly configured firewall policy with the action DENY.
Answer: B
Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=13900
NEW QUESTION 35
How does FortiGate act when using SSL VPN in web mode?
- A. FortiGate acts as DNS server.
- B. FortiGate acts as an FDS server.
- C. FortiGate acts as router.
- D. FortiGate acts as an HTTP reverse proxy.
Answer: A
Explanation:
Explanation/Reference: https://pub.kb.fortinet.com/ksmcontent/Fortinet-Public/current/Fortigate_v4.0MR3/fortigate- sslvpn-40-mr3.pdf
NEW QUESTION 36
Which two statements are true about the RPF check? (Choose two.)
- A. The RPF check is run on the first sent and reply packet of any new session.
- B. The RPF check is run on the first reply packet of any new session.
- C. The RPF check is run on the first sent packet of any new session.
- D. RPF is a mechanism that protects FortiGate and your network from IP spoofing attacks.
Answer: C,D
NEW QUESTION 37
An administrator has configured the following settings:
- A. The number of logs generated by denied traffic is reduced.
Explanation Explanation/Reference: Reference: https://kb.fortinet.com/kb/documentLink.do?externalID=FD46328 Explanation/Reference:
Explanation Explanation/Reference: Reference: https://kb.fortinet.com/kb/documentLink.do?externalID=FD46328 - B. Device detection on all interfaces is enforced for 30 minutes.
- C. Denied users are blocked for 30 minutes.
- D. A session for denied traffic is created.
Answer: A,D
NEW QUESTION 38
Refer to the exhibit.
Which contains a network diagram and routing table output.
The Student is unable to access Webserver.
What is the cause of the problem and what is the solution for the problem?
- A. The first packet sent from Student failed the RPF check.
This issue can be resolved by adding a static route to 203.0.114.24/32 through port3. - B. The first reply packet for Student failed the RPF check.
This issue can be resolved by adding a static route to 203.0.114.24/32 through port3. - C. The first reply packet for Student failed the RPF check.
This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1. - D. The first packet sent from Student failed the RPF check.
This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.
Answer: A
NEW QUESTION 39
Examine the two static routes shown in the exhibit, then answer the following question.
Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?
- A. FortiGate will only actuate the port1 route in the routing table
- B. FortiGate will route twice as much traffic to the port2 route
- C. FortiGate will use the port1 route as the primary candidate.
- D. FortiGate will load balance all traffic across both routes.
Answer: C
Explanation:
"If multiple static routes have the same distance, they are all active; however, only the one with the lowest priority is considered the best path."
NEW QUESTION 40
Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)
- A. DNS
- B. TWAMP
- C. ping
- D. udp-echo
Answer: A,D
NEW QUESTION 41
Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.

An administrator has configured the WINDOWS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?
- A. A DoS policy should be used, instead of an IPS sensor.
- B. The firewall policy is not using a full SSL inspection profile.
- C. The HTTPS signatures have not been added to the sensor.
- D. A DoS policy should be used, instead of an IPS sensor.
- E. The IPS filter is missing the Protocol: HTTPS option.
Answer: B
NEW QUESTION 42
......
Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam Path
Test Preparation teaches how the exam questions can to be decoded. Our Exam Preparedness: DSCI DCPP-01 Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam FGT-6.4â Technical arrangement course is delivered in multiple configurations: study hall preparing for learning or taking an interest in a physical homeroom with an DSCI DCPP-01 Approved Learner. Free media preparing for learning whenever it is suitable for you. The course surveys test inquiries in each branch of knowledge and how the themes tried ought to be seen to such an extent that off base answers are easier to stay away from. Our course will help you in tracking down the correct answers.
How to book the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam
To apply for the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam, You have to follow these steps:
- Step 1: Go to the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam Official Site
- Step 2: Read the instruction Carefully
- Step 3: Follow the given steps
- Step 4: Apply for the Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam
What is the duration, language, and format of Network Security Professional (Fortinet NSE4_FGT-6.4) Professional Exam
- Duration of Exam: 130 minutes
- Passing score: 72%
- Type of Questions: Multiple choice (MCQs), multiple answers
- Language of Exam: English, Japanese, Korean and simplified Chinese
- Number of Questions: 65
- No negative marking for wrong answers
Pass Fortinet NSE4_FGT-6.4 Exam Quickly With PrepAwayTest: https://www.prepawaytest.com/Fortinet/NSE4_FGT-6.4-practice-exam-dumps.html