Exam Details

  • Exam Code
    :NSE4_FGT-6.4
  • Exam Name
    :Fortinet NSE 4 - FortiOS 6.4
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :163 Q&As
  • Last Updated
    :Jun 11, 2025

Fortinet Fortinet Certifications NSE4_FGT-6.4 Questions & Answers

  • Question 101:

    Refer to the exhibit.

    Which contains a network diagram and routing table output.

    The Student is unable to access Webserver.

    What is the cause of the problem and what is the solution for the problem?

    A. The first packet sent from Student failed the RPF check. This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.

    B. The first reply packet for Student failed the RPF check. This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.

    C. The first reply packet for Student failed the RPF check. This issue can be resolved by adding a static route to 203.0.114.24/32 through port3.

    D. The first packet sent from Student failed the RPF check. This issue can be resolved by adding a static route to 203.0.114.24/32 through port3.

  • Question 102:

    Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?

    A. get system status

    B. get system performance status

    C. diagnose sys top

    D. get system arp

  • Question 103:

    When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?

    A. remote user's public IP address

    B. The public IP address of the FortiGate device.

    C. The remote user's virtual IP address.

    D. The internal IP address of the FortiGate device.

  • Question 104:

    Examine the following web filtering log.

    Which statement about the log message is true?

    A. The action for the category Games is set to block.

    B. The usage quota for the IP address 10.0.1.10 has expired

    C. The name of the applied web filter profile is default.

    D. The web site miniclip.com matches a static URL filter whose action is set to Warning.

  • Question 105:

    Which two statements about antivirus scanning mode are true? (Choose two.)

    A. In proxy-based inspection mode, files bigger than the buffer size are scanned.

    B. In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.

    C. In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.

    D. In flow-based inspection mode, files bigger than the buffer size are scanned.

  • Question 106:

    A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.

    What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?

    A. Static IP Address

    B. Dialup User

    C. Dynamic DNS

    D. Pre-shared Key

  • Question 107:

    Refer to the FortiGuard connection debug output.

    Based on the output shown in the exhibit, which two statements are correct? (Choose two.)

    A. A local FortiManager is one of the servers FortiGate communicates with.

    B. One server was contacted to retrieve the contract information.

    C. There is at least one server that lost packets consecutively.

    D. FortiGate is using default FortiGuard communication settings.

  • Question 108:

    A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.

    Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.

    A. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.

    B. The two VLAN sub interfaces must have different VLAN IDs.

    C. The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.

    D. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.

  • Question 109:

    A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.

    *

    All traffic must be routed through the primary tunnel when both tunnels are up

    *

    The secondary tunnel must be used only if the primary tunnel goes down

    *

    In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover

    Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)

    A. Configure a high distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.

    B. Enable Dead Peer Detection.

    C. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.

    D. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.

  • Question 110:

    Which two statements are true about the FGCP protocol? (Choose two.)

    A. Not used when FortiGate is in Transparent mode

    B. Elects the primary FortiGate device

    C. Runs only over the heartbeat links

    D. Is used to discover FortiGate devices in different HA groups

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE4_FGT-6.4 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.