Exam Details

  • Exam Code
    :NSE4-5.4
  • Exam Name
    :Fortinet Network Security Expert 4 Written Exam - FortiOS 5.4
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :576 Q&As
  • Last Updated
    :Dec 30, 2024

Fortinet Fortinet Certifications NSE4-5.4 Questions & Answers

  • Question 251:

    A FortiAnalyzer device could use which security method to secure the transfer of log data from FortiGate devices?

    A. SSL

    B. IPSec

    C. direct serial connection

    D. S/MIME

  • Question 252:

    Which of the following pieces of information can be included in the Destination Address field of a firewall policy? (Select all that apply.)

    A. An IP address pool.

    B. A virtual IP address.

    C. An actual IP address or an IP address group.

    D. An FQDN or Geographic value(s).

  • Question 253:

    The ordering of firewall policies is very important. Policies can be re-ordered within the FortiGate unit's GUI and also using the CLI. The command used in the CLI to perform this function is _________.

    A. set order

    B. edit policy

    C. reorder

    D. move

  • Question 254:

    You wish to create a firewall policy that applies only to traffic intended for your web server. The web server has an IP address of 192.168.2.2 and a /24 subnet mask. When defining the firewall address for use in this policy, which one of the following addresses is correct?

    A. 192.168.2.0 / 255.255.255.0

    B. 192.168.2.2 / 255.255.255.0

    C. 192.168.2.0 / 255.255.255.255

    D. 192.168.2.2 / 255.255.255.255

  • Question 255:

    In NAT/Route mode when there is no matching firewall policy for traffic to be forwarded by the Firewall, which of the following statements describes the action taken on traffic?

    A. The traffic is blocked.

    B. The traffic is passed.

    C. The traffic is passed and logged.

    D. The traffic is blocked and logged.

  • Question 256:

    In which order are firewall policies processed on the FortiGate unit?

    A. They are processed from the top down according to their sequence number.

    B. They are processed based on the policy ID number shown in the left hand column of the policy window.

    C. They are processed on best match.

    D. They are processed based on a priority value assigned through the priority column in the policy window.

  • Question 257:

    Caching improves performance by reducing FortiGate unit requests to the FortiGuard server. Which of the following statements are correct regarding the caching of FortiGuard responses? (Select all that apply.)

    A. Caching is available for web filtering, antispam, and IPS requests.

    B. The cache uses a small portion of the FortiGate system memory.

    C. When the cache is full, the least recently used IP address or URL is deleted from the cache.

    D. An administrator can configure the number of seconds to store information in the cache before the FortiGate unit contacts the FortiGuard server again.

    E. The size of the cache will increase to accommodate any number of cached queries.

  • Question 258:

    Which of the following Fortinet products can receive updates from the FortiGuard Distribution Network? (Select all that apply.)

    A. FortiGate

    B. FortiClient

    C. FortiMail

    D. FortiAnalyzer

  • Question 259:

    How can DLP file filters be configured to detect Office 2010 files? (Select all that apply.)

    A. File TypE. Microsoft Office(msoffice)

    B. File TypE. Archive(zip)

    C. File TypE. Unknown Filetype(unknown)

    D. File NamE. "*.ppt", "*.doc", "*.xls"

    E. File NamE. "*.pptx", "*.docx", "*.xlsx"

  • Question 260:

    What are the valid sub-types for a Firewall type policy? (Select all that apply)

    A. Device Identity

    B. Address

    C. User Identity

    D. Schedule

    E. SSL VPN

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE4-5.4 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.