Certification Provider: Fortinet
Exam: NSE 4
Exam Code: NSE4 v7.0
Total Question : 131
Question per Quiz: 60
Updated On: 21 March 2023
Note: In order to practice all the Q/A's, you have to practice multiple time. Question's and Answer's will be presented randomly and will help you get hands-on for real exam.
1.
An administrator must disable RPF check to investigate an issue. Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?
2.
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?
3.
Refer to the FortiGuard connection debug output. Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
4.
Based on the raw logs shown in the exhibit, which statement is correct?
5.
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded. What is the reason for the failed virus detection by FortiGate?
6.
In which two ways can RPF checking be disabled? (Choose two.)
7.
What is the primary FortiGate election process when the HA override setting is disabled?
8.
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
9.
How does FortiGate act when using SSL VPN in web mode?
10.
An administrator needs to increase network bandwidth and provide redundancy. What interface type must the administrator select to bind multiple FortiGate interfaces?
11.
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?
12.
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL Inspection? (Choose two.)
13.
Refer to the exhibit, which contains a static route configuration. An administrator created a static route for Amazon Web Services. What CLI command must the administrator use to view the route?
14.
Which two statements are correct about SLA targets? (Choose two.)
15.
Which two statements about SSL VPN between two FortiGate devices are true? (Choose two.)
16.
Refer to the exhibit. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
17.
An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
18.
Examine the two static routes shown in the exhibit, then answer the following question. Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?
19.
Which statement regarding the firewall policy authentication timeout is true?
20.
Why does FortiGate keep TCP sessions in the session table for several seconds, even after both sides (client and server) have terminated the session?
21.
Which of the following are valid actions for FortiGuard category based filter in a web filter profile UI proxy-based inspection mode? (Choose two.)
22.
What are the two results of this configuration? (Choose two.)
An administrator has configured the following settings: config system setting
set ses-denied-traffic enable end config system global set block -session-timer 30 end
23.
What devices form the core of the security fabric?
24.
An administrator has configured outgoing interface any in a firewall policy. Which statement is true about the policy list view?
25.
IPS Engine is used by which three security features? (Choose three.)
26.
FortiGate is configured as a policy-based next-generation firewall (NGFW) and is applying web filtering and application control directly on the security policy. Which two other security profiles can you apply to the security policy? (Choose two.)
27.
When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
28.
In an explicit proxy setup, where is the authentication method and database configured?
29.
Refer to the exhibit. The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?
30.
Which two statements are true about the Security Fabric rating?
31.
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?
32.
If the Services field is configured in a Virtual IP (VIP), which statement is true when central NAT is used?
33.
An administrator wants to configure timeouts for users. Regardless of the user’s behavior, the timer should start as soon as the user authenticates and expire after the configured value. Which timeout option should be configured on FortiGate?
34.
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
35.
Refer to the exhibits. Based on the system performance output, which two statements are correct? (Choose two.)
Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default configuration of high memory usage thresholds.
36.
A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not Which configuration option is the most effective way to support this request?
37.
An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24. Which subnet must the administrator configure for the local quick mode selector for site B?
38.
Refer to the exhibit. How will FortiGate process the traffic when the HTTP request comes from a machine with the source IP 10.0.1.10 to the destination http:// www.fortinet.com? (Choose two.)
The exhibit shows proxy policies and proxy addresses, the authentication rule and authentication scheme, users, and firewall address. An explicit web proxy is configured for subnet range 10.0.1.0/24 with three explicit web proxy policies. The authentication rule is configured to authenticate HTTP requests for subnet range 10.0.1.0/24 with a form-based authentication scheme for the FortiGate local user database. Users will be prompted for authentication.
39.
Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)
40.
Refer to the exhibit. The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode. The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the Internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem. Which two statements are true? (Choose two.)
41.
Refer to the exhibits to view the firewall policy and the antivirus profile. Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?
42.
Which security feature does FortiGate provide to protect servers located in the internal networks from attacks such as SQL injections?
43.
An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What must an administrator do to achieve this objective?
44.
Refer to the exhibit. Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
45.
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)
46.
Refer to the exhibit. What should the administrator do next to troubleshoot the problem?
In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit.
47.
In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)
48.
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service. What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
49.
Which two statements are true about the RPF check? (Choose two.)
50.
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
51.
Which two protocols are used to enable administrator access of a FortiGate device? (Choose two.)
52.
Which of the following SD-WAN load -balancing method use interface weight value to distribute traffic? (Choose two.)
53.
Which statements are true regarding firewall policy NAT using the outgoing interface IP address with fixed port disabled? (Choose two.)
54.
If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source field of a firewall policy?
55.
Refer to the exhibit, which contains a session list output. Based on the information shown in the exhibit, which statement is true?
56.
Which two statements about IPsec authentication on FortiGate are correct? (Choose two.)
57.
What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?
58.
Which feature in the Security Fabric takes one or more actions based on event triggers?
59.
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?
60.
How do you format the FortiGate flash disk?
2 Comments
after submit ,need to show the correct answers
I took NSE4 few days before and Passed. Many question from this Quiz are in Exam. Recommend to take this practice test along with Guide. Quite helpful.
Thank You Practonet 🙂