Leads4pass > Fortinet > NSE4 > NSE4_FGT-5.6 > NSE4_FGT-5.6 Online Practice Questions and Answers

NSE4_FGT-5.6 Online Practice Questions and Answers

Questions 4

Which traffic inspection features can be executed by a security processor (SP)?

(Choose three.)

Response:

A. TCP SYN proxy

B. SIP session helper

C. Proxy-based antivirus

D. Attack signature matching

E. Flow-based web filtering

Buy Now
Questions 5

What protocol can be used to dynamically assign an IP address to a physical interface? Response:

A. PPPoE

B. IP Config

C. BOOTP

D. ICMP

Buy Now
Questions 6

Which actions can be configured in an application control profile?

(Choose three.)

Response:

A. Monitor

B. Block

C. Warning

D. Authenticate

E. Quarantine

Buy Now
Questions 7

FortiGate scans packets for matches in a specific order for application control. Which option provides the correct sequence order?

Response:

A. Static domain overrides -> application overrides -> filter overrides

B. Categories -> application overrides -> filter overrides

C. Application overrides -> filter overrides -> categories

D. Rate based overrides -> filter overrides -> categories

Buy Now
Questions 8

When using firewall policy NAT, which statements are true regarding virtual IP (VIP)?

(Choose two.)

Response:

A. The default type is static NAT, which applies one-to-one mappings for incoming and outgoing connections.

B. The static NAT VIP can be restricted to forward only certain ports.

C. FortiGate does not respond to ARP requests for VIP, as ARP responses are non configurable for VIP.

D. The VIP is selected in the firewall policy source address field.

Buy Now
Questions 9

Which of the following statements is true regarding client integrity checking in SSL VPN? Response:

A. It detects the Windows client security applications running in the SSL VPN client's PCs.

B. It validates the SSL VPN user credentials on the remote authentication server.

C. It verifies which SSL VPN portal must be presented to each SSL VPN user.

D. It verifies that the latest SSL VPN client is installed in the client's PC.

Buy Now
Questions 10

Which ways can FortiGate deliver one-time passwords (OTPs) to two-factor authentication users in your

network?

(Choose three.)

Response:

A. Hardware FortiToken

B. Web portal

C. SMS

D. USB FortiToken

E. FortiToken Mobile

Buy Now
Questions 11

Which of the following protocols is used to encrypt the user data payload in an IPsec tunnel? Response:

A. AH

B. IKE

C. ISAKMP

D. ESP

Buy Now
Questions 12

Which statements best describe auto discovery VPN (ADVPN).

(Choose two.)

Response:

A. It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes.

B. ADVPN is only supported with IKEv2.

C. Tunnels are negotiated dynamically between spokes.

D. Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.

Buy Now
Questions 13

Which statements about high availability (HA) for FortiGates are true?

(Choose two.)

Response:

A. Virtual clustering can be configured between two FortiGate devices with multiple VDOM.

B. Heartbeat interfaces are not required on the primary device.

C. HA management interface settings are synchronized between cluster members.

D. Sessions handled by UTM proxy cannot be synchronized.

Buy Now
Exam Code: NSE4_FGT-5.6
Exam Name: Fortinet NSE 4 - FortiOS 5.6
Last Update: Dec 16, 2024
Questions: 114
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99