Certification Provider: Fortinet
Exam: NSE 4
Exam Code: NSE4 v7.0
Total Question: 131
Question per Quiz: 60
Updated On: 21 March 2023
Note: In order to practice all the Q/A's, you have to practice multiple time. Question's and Answer's will be presented randomly and will help you get hands-on for real exam.
1.
Refer to the exhibit. Which two changes can the administrator make to deny Webserver access for Remote-User2? (Choose two.)
The exhibit contains a network diagram, firewall policies, and a firewall address object configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-user2. Remote-user2 is still able to access Webserver.
2.
Which two statements are correct about a software switch on FortiGate? (Choose two.)
3.
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
4.
FortiGate is configured as a policy-based next-generation firewall (NGFW) and is applying web filtering and application control directly on the security policy. Which two other security profiles can you apply to the security policy? (Choose two.)
5.
Refer to the exhibit, which contains a session diagnostic output. Which statement is true about the session diagnostic output?
6.
Which two statements are true about collector agent advanced mode? (Choose two.)
7.
Refer to the exhibit. The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?
8.
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?
9.
An administrator wants to configure timeouts for users. Regardless of the user’s behavior, the timer should start as soon as the user authenticates and expire after the configured value. Which timeout option should be configured on FortiGate?
10.
Refer to the exhibit to view the firewall policy. Which statement is correct if well-known viruses are not being blocked?
11.
What is the primary FortiGate election process when the HA override setting is disabled?
12.
Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)
13.
An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
14.
Which two protocols are used to enable administrator access of a FortiGate device? (Choose two.)
15.
An organization's employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent the SSL VPN negotiation failure?
16.
Which of the following statements about backing up logs from the CLI and downloading logs from the GUI are true? (Choose two.)
17.
Which security feature does FortiGate provide to protect servers located in the internal networks from attacks such as SQL injections?
18.
Which Security rating scorecard helps identify configuration weakness and best practice violations in your network?
19.
Refer to the exhibit. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
20.
Refer to the exhibit. Examine the intrusion prevention system (IPS) diagnostic command. Which statement is correct if option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
21.
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
22.
An administrator has configured outgoing interface any in a firewall policy. Which statement is true about the policy list view?
23.
Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)
24.
Refer to the exhibit, which contains a Performance SLA configuration. An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic. Why is FortiGate not generating any traffic for the performance SLA?
25.
Which feature in the Security Fabric takes one or more actions based on event triggers?
26.
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
27.
An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel. Which DPD mode on FortiGate will meet the above requirement?
28.
Which two statements are true when FortiGate is in transparent mode? (Choose two.)
29.
Which two types of traffic are managed only by the management VDOM? (Choose two.)
30.
A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not. Which configuration option is the most effective way to support this request?
31.
In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)
32.
Refer to the exhibit. Given the security fabric topology shown in the exhibit, which two statements are true? (Choose two.)
33.
Refer to the exhibit. Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
34.
An administrator has configured outgoing interface any in a firewall policy. Which statement is true about the policy list view?
35.
You have enabled logging on your FortiGate device for Event logs and all Security logs, and you have set up logging to use the FortiGate local disk. What is the default behavior when the local disk is full?
36.
Which two statements are true about the FGCP protocol? (Choose two.)
37.
Which two statements are correct about NGFW Policy-based mode? (Choose two.)
38.
Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two.)
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
✑ All traffic must be routed through the primary tunnel when both tunnels are up.
✑ The secondary tunnel must be used only if the primary tunnel goes down.
✑ In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
39.
Refer to the exhibit. Based on the raw log, which two statements are correct? (Choose two.)
40.
Which two statements are true about collector agent standard access mode? (Choose two.)
41.
What devices form the core of the security fabric?
42.
Refer to the exhibit. Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)
43.
Refer to the exhibit. The exhibit shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)
44.
Which three statements are true regarding session-based authentication? (Choose three.)
45.
Refer to the exhibit, which contains a session list output. Based on the information shown in the exhibit, which statement is true?
46.
An administrator must disable RPF check to investigate an issue. Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?
47.
Refer to the exhibit. Given the interfaces shown in the exhibit, which two statements are true? (Choose two.)
48.
Which two VDOMs are the default VDOMs created when FortiGate is set up in split VDOM mode? (Choose two.)
49.
Which two statements are correct about SLA targets? (Choose two.)
50.
If Internet Service is already selected as Destination in a firewall policy, which other configuration objects can be selected to the Destination field of a firewall policy?
51.
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
52.
Which scanning technique on FortiGate can be enabled only on the CLI?
53.
Based on the raw logs shown in the exhibit, which statement is correct?
54.
Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)
55.
Refer to the exhibit. What should the administrator do next to troubleshoot the problem?
In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit.
56.
Which three statements about a flow-based antivirus profile are correct? (Choose three.)
57.
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
58.
What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall (NGFW)?
59.
An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)
60.
Examine the two static routes shown in the exhibit, then answer the following question. Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?