Exam Details

  • Exam Code
    :NSE4-5.4
  • Exam Name
    :Fortinet Network Security Expert 4 Written Exam - FortiOS 5.4
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :576 Q&As
  • Last Updated
    :Dec 30, 2024

Fortinet Fortinet Certifications NSE4-5.4 Questions & Answers

  • Question 511:

    In a FSSO agentless polling mode solution, where must the collector agent be?

    A. In any Windows server

    B. In any of the AD domain controllers

    C. In the master AD domain controller

    D. The FortiGate device polls the AD domain controllers

  • Question 512:

    What is required in a FortiGate configuration to have more than one dialup IPsec VPN using aggressive mode?

    A. All the aggressive mode dialup VPNs MUST accept connections from the same peer ID.

    B. Each peer ID MUST match the FQDN of each remote peer.

    C. Each aggressive mode dialup MUST accept connections from different peer ID.

    D. The peer ID setting must NOT be used.

  • Question 513:

    Examine the network topology diagram in the exhibit; the workstation with the IP address 212.10.11.110 sends a TCP SYN packet to the workstation with the IP address 212.10.11.20.

    Which of the following sentences best describes the result of the reverse path forwarding (RFP) check executed by the FortiGate on the SYN packets? (Choose two).

    A. Packets is allowed if RPF is configured as loose.

    B. Packets is allowed if RPF is configured as strict.

    C. Packets is blocked if RPF is configured as loose.

    D. Packets is blocked if RPF is configured as strict.

  • Question 514:

    If you enable the option "Generate Logs when Session Starts", what effect does this have on the number of traffic log messages generated for each session?

    A. No traffic log message is generated.

    B. One traffic log message is generated.

    C. Two traffic log messages are generated.

    D. A log message is only generated if there is a security event.

  • Question 515:

    Which of the following actions that can be taken by the Data Leak Prevention scanning? (Choose three.)

    A. Block

    B. Reject

    C. Tag

    D. Log only

    E. Quarantine IP address

  • Question 516:

    What configuration objects are automatically added when using the FortiGate's FortiClient VPN Configurations Wizard?(Choose two)

    A. Static route

    B. Phase 1

    C. Users group

    D. Phase 2

  • Question 517:

    Which protocol can an Internet browser use to download the PAC file with the web proxy configuration?

    A. HTTPS

    B. FTP

    C. TFTP

    D. HTTP

  • Question 518:

    Which of the following statements are correct concerning layer 2 broadcast domains in transparent mode VDOMs?(Choose two)

    A. The whole VDOM is a single broadcast domain even when multiple VLAN are used.

    B. Each VLAN is a separate broadcast domain.

    C. Interfaces configured with the same VLAN ID can belong to different broadcast domains.

    D. All the interfaces in the same broadcast domain must use the same VLAN ID.

  • Question 519:

    Which action is taken by the FortiGate device when a file matches more than one rule in a Data Leak Prevention sensor?

    A. The actions specified by the rule that most specifically matched the file

    B. The actions specified in the first rule from top to bottom

    C. All actions specified by all the matched rules.

    D. The actions specified in the rule with the higher priority number

  • Question 520:

    A FortiGate device is configured with two VDOMs. The management VDOM is 'root' , and is configured in transparent mode,'vdom1' is configured as NAT/route mode. Which traffic is generated only by 'root' and not 'vdom1'? (Choose three.)

    A. SNMP traps

    B. FortiGaurd

    C. ARP

    D. NTP

    E. ICMP redirect

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE4-5.4 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.