Exam Details

  • Exam Code
    :NSE4_FGT-6.4
  • Exam Name
    :Fortinet NSE 4 - FortiOS 6.4
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :163 Q&As
  • Last Updated
    :Jun 11, 2025

Fortinet Fortinet Certifications NSE4_FGT-6.4 Questions & Answers

  • Question 111:

    An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What must an administrator do to achieve this objective?

    A. The administrator can register the same FortiToken on more than one FortiGate.

    B. The administrator must use a FortiAuthenticator device.

    C. The administrator can use a third-party radius OTP server.

    D. The administrator must use the user self-registration server.

  • Question 112:

    Which statements best describe auto discovery VPN (ADVPN). (Choose two.)

    A. It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes.

    B. ADVPN is only supported with IKEv2.

    C. Tunnels are negotiated dynamically between spokes.

    D. Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.

  • Question 113:

    Which two types of traffic are managed only by the management VDOM? (Choose two.)

    A. FortiGuard web filter queries

    B. PKI

    C. Traffic shaping

    D. DNS

  • Question 114:

    What types of traffic and attacks can be blocked by a web application firewall (WAF) profile? (Choose three.)

    A. Traffic to botnetservers

    B. Traffic to inappropriate web sites

    C. Server information disclosure attacks

    D. Credit card data leaks

    E. SQL injection attacks

  • Question 115:

    An administrator is running the following sniffer command:

    diagnose sniffer packet any "host 192.168.2.12" 5

    Which three pieces of Information will be Included in me sniffer output? {Choose three.)

    A. Interface name

    B. Packet payload

    C. Ethernet header

    D. IP header

    E. Application header

  • Question 116:

    Which of the following statements about backing up logs from the CLI and downloading logs from the GUI are true? (Choose two.)

    A. Log downloads from the GUI are limited to the current filter view

    B. Log backups from the CLI cannot be restored to another FortiGate.

    C. Log backups from the CLI can be configured to upload to FTP as a scheduled time

    D. Log downloads from the GUI are stored as LZ4 compressed files.

  • Question 117:

    An administrator has configured the following settings: What are the two results of this configuration? (Choose two.)

    A. Device detection on all interfaces is enforced for 30 minutes.

    B. Denied users are blocked for 30 minutes.

    C. A session for denied traffic is created.

    D. The number of logs generated by denied traffic is reduced.

  • Question 118:

    An organization's employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent the SSL VPN negotiation failure?

    A. Change the session-ttl.

    B. Change the login timeout.

    C. Change the idle-timeout.

    D. Change the udp idle timer.

  • Question 119:

    Exhibit:

    Refer to the exhibit to view the authentication rule configuration In this scenario, which statement is true?

    A. IP-based authentication is enabled B. Route-based authentication is enabled

    C. Session-based authentication is enabled.

    D. Policy-based authentication is enabled

  • Question 120:

    Which CLI command will display sessions both from client to the proxy and from the proxy to the servers?

    A. diagnose wad session list

    B. diagnose wad session list | grep hook-preandandhook-out

    C. diagnose wad session list | grep hook=preandandhook=out

    D. diagnose wad session list | grep "hook=pre"and"hook=out"

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE4_FGT-6.4 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.