20 January, 2021
Down To Date NSE4_FGT-6.4 Exam Dumps For Fortinet NSE 4 - FortiOS 6.4 Certification
We provide real NSE4_FGT-6.4 exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Fortinet NSE4_FGT-6.4 Exam quickly & easily. The NSE4_FGT-6.4 PDF type is available for reading and printing. You can print more and practice many times. With the help of our Fortinet NSE4_FGT-6.4 dumps pdf and vce product and material, you can easily pass the NSE4_FGT-6.4 exam.
Check NSE4_FGT-6.4 free dumps before getting the full version:
Question 1
Examine this PAC file configuration.
Which of the following statements are true? (Choose two.)
Which of the following statements are true? (Choose two.)
Question 2
Refer to the exhibit.
Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?
Question 3
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?
Question 4
An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
Question 5
Refer to the exhibit.
The exhibits show a network diagram and the explicit web proxy configuration.
In the commanddiagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?
The exhibits show a network diagram and the explicit web proxy configuration.
In the commanddiagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?
Question 6
Refer to the exhibits.
The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?
The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?
Question 7
How do you format the FortiGate flash disk?
Question 8
Refer to the exhibit showing a debug flow output.
Which two statements about the debug flow output are correct? (Choose two.)
Which two statements about the debug flow output are correct? (Choose two.)
Question 9
What types of traffic and attacks can be blocked by a web application firewall (WAF) profile? (Choose three.)
Question 10
View the exhibit.
A user behind the FortiGate is trying to go to http://www.addictinggames.com (Addicting Games). Based on this configuration, which statement is true?
A user behind the FortiGate is trying to go to http://www.addictinggames.com (Addicting Games). Based on this configuration, which statement is true?
Question 11
To complete the final step of a Security Fabric configuration, an administrator must authorize all the devices on which device?
Question 12
In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)
Question 13
Refer to the exhibit.
According to the certificate values shown in the exhibit, which type of entity was the certificate issued to?
According to the certificate values shown in the exhibit, which type of entity was the certificate issued to?
Question 14
If theServicesfield is configured in a Virtual IP (VIP), which statement is true when central NAT is used?
Question 15
Which of the following statements about central NAT are true? (Choose two.)
Question 16
Refer to the exhibit.
Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
Question 17
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
*All traffic must be routed through the primary tunnel when both tunnels are up
*The secondary tunnel must be used only if the primary tunnel goes down
*In addition, FortiGate should be able to detect a dead tunnel to speed up tunnelfailover
Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)
*All traffic must be routed through the primary tunnel when both tunnels are up
*The secondary tunnel must be used only if the primary tunnel goes down
*In addition, FortiGate should be able to detect a dead tunnel to speed up tunnelfailover
Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)
Question 18
Which statements best describe auto discovery VPN (ADVPN). (Choose two.)
Question 19
Which CLI command will display sessions both from client to the proxy and from the proxy to the servers?
Question 20
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL Inspection? (Choose two.)
Question 21
By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers. Which two CLI commands will cause FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering? (Choose two.)