Exam Details

  • Exam Code
    :NSE4_FGT-6.4
  • Exam Name
    :Fortinet NSE 4 - FortiOS 6.4
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :163 Q&As
  • Last Updated
    :Jun 11, 2025

Fortinet Fortinet Certifications NSE4_FGT-6.4 Questions & Answers

  • Question 51:

    Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below.

    When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?

    A. SMTP.Login.Brute.Force

    B. IMAP.Login.brute.Force

    C. ip_src_session

    D. Location: server Protocol: SMTP

  • Question 52:

    Refer to the exhibit.

    Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)

    A. Traffic between port2 and port2-vlan1 is allowed by default.

    B. port1-vlan10 and port2-vlan10 are part of the same broadcast domain.

    C. port1 is a native VLAN.

    D. port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.

  • Question 53:

    Which type of logs on FortiGate record information about traffic directly to and from the FortiGate management IP addresses?

    A. System event logs

    B. Forward traffic logs

    C. Local traffic logs

    D. Security logs

  • Question 54:

    How do you format the FortiGate flash disk?

    A. Load a debug FortiOS image.

    B. Load the hardware test (HQIP) image.

    C. Execute the CLI command execute formatlogdisk.

    D. Select the format boot device option from the BIOS menu.

  • Question 55:

    Which three criteria can a FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)

    A. Source defined as Internet Services in the firewall policy.

    B. Destination defined as Internet Services in the firewall policy.

    C. Highest to lowest priority defined in the firewall policy.

    D. Services defined in the firewall policy.

    E. Lowest to highest policy ID number.

  • Question 56:

    An administrator wants to configure timeouts for users. Regardless of the userTMs behavior, the timer should start as soon as the user authenticates and expire after the configured value.

    Which timeout option should be configured on FortiGate?

    A. auth-on-demand

    B. soft-timeout

    C. idle-timeout

    D. new-session

    E. hard-timeout

  • Question 57:

    Why does FortiGate Keep TCP sessions in the session table for several seconds, even after both sides (client and server) have terminated the session?

    A. To allow for out-of-order packets that could arrive after the FIN/ACK packets

    B. To finish any inspection operations

    C. To remove the NAT operation

    D. To generate logs

  • Question 58:

    An administrator must disable RPF check to investigate an issue.

    Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?

    A. Enable asymmetric routing, so the RPF check will be bypassed.

    B. Disable the RPF check at the FortiGate interface level for the source check.

    C. Disable the RPF check at the FortiGate interface level for the reply check.

    D. Enable asymmetric routing at the interface level.

  • Question 59:

    To complete the final step of a Security Fabric configuration, an administrator must authorize all the devices on which device?

    A. FortiManager

    B. Root FortiGate

    C. FortiAnalyzer

    D. Downstream FortiGate

  • Question 60:

    FortiGuard categories can be overridden and defined in different categories. To create a web rating override for example.com home page, the override must be configured using a specific syntax.

    Which two syntaxes are correct to configure web rating for the home page? (Choose two.)

    A. www.example.com:443

    B. www.example.com

    C. example.com

    D. www.example.com/index.html

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE4_FGT-6.4 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.