Refer to the FortiGuard connection debug output.

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
Reveal answer details Close answer details
Correct answersB, D
Fortinet ยท NSE4_FGT-6.4
Review the question wording, option layout, and available explanations before choosing a study plan.
|
Multiple choice
Refer to the FortiGuard connection debug output. ![]() Based on the output shown in the exhibit, which two statements are correct? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, D
Multiple choice
Which of the following statements about central NAT are true? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B
Multiple choice
Refer to the exhibit. ![]() Based on the raw log, which two statements are correct? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Single choice
Refer to the exhibits. ![]() The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN? Reveal answer details Close answer detailsCorrect answerA Explanation References:
Single choice
What devices form the core of the security fabric? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Multiple choice
Which of the following statements correctly describes FortiGates route lookup behavior when searching for a suitable gateway? (Choose two) Reveal answer details Close answer detailsCorrect answersA, D
Multiple choice
What types of traffic and attacks can be blocked by a web application firewall (WAF) profile? (Choose three.) Reveal answer details Close answer detailsCorrect answersC, D, E
Single choice
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser What is the reason for the certificate warning errors? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
Which CLI command will display sessions both from client to the proxy and from the proxy to the servers? Reveal answer details Close answer detailsCorrect answerA
Single choice
How do you format the FortiGate flash disk? Reveal answer details Close answer detailsCorrect answerD
Single choice
If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Multiple choice
Which two statements are correct about a software switch on FortiGate? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Single choice
Refer to the exhibit. ![]() Which contains a session list output. Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which two types of traffic are managed only by the management VDOM? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, D
Single choice
Refer to the exhibit. ![]() Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel? Reveal answer details Close answer detailsCorrect answerD Explanation https://kb.fortinet.com/kb/documentLink.do?externalID=12069
Single choice
Refer to the exhibit. ![]() Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate? Reveal answer details Close answer detailsCorrect answerC Explanation https://kb.fortinet.com/kb/documentLink.do?externalID=FD50220
Single choice
Refer to the exhibit. ![]() ![]() ![]() ![]() The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)? Reveal answer details Close answer detailsCorrect answerD
Single choice
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to? Reveal answer details Close answer detailsCorrect answerD
Single choice
Refer to the exhibit. ![]() A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up? Reveal answer details Close answer detailsCorrect answerD Explanation References:
Multiple choice
Which two statements ate true about the Security Fabric rating? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, C Explanation FortiGate_Security_6.4_Study_Guide-Online. page 89
Multiple choice
Which two statements are true about the FGCP protocol? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, C
Multiple choice
Which two inspection modes can you use to configure a firewall policy on a profile-based next-generation firewall (NGFW)? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Multiple choice
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, C, D Explanation References:
Single choice
Which of statement is true about SSL VPN web mode? Reveal answer details Close answer detailsCorrect answerB Explanation FortiGate_Security_6.4 page 575-Web mode requires only a web browser, but supports a limited number of protocols. |