13 January, 2020
Fortinet NSE 4 – FortiOS 6.0 NSE4_FGT-6.0 Training Materials
It is impossible to pass Fortinet NSE4_FGT-6.0 exam without any help in the short term. Come to Ucertify soon and find the most advanced, correct and guaranteed Fortinet NSE4_FGT-6.0 practice questions. You will get a surprising result by our Renew Fortinet NSE 4 – FortiOS 6.0 practice guides.
Question 1
An employee connects to the https://example.com on the Internet using a web browser. The web server’s certificate was signed by a private internal CA. The FortiGate that is inspecting this traffic is configured for full SSL inspection.
This exhibit shows the configuration settings for the SSL/SSH inspection profile that is applied to the policy that is invoked in this instance. All other settings are set to defaults. No certificates have been imported into FortiGate. View the exhibit and answer the question that follows.
Which certificate is presented to the employee’s web browser?
This exhibit shows the configuration settings for the SSL/SSH inspection profile that is applied to the policy that is invoked in this instance. All other settings are set to defaults. No certificates have been imported into FortiGate. View the exhibit and answer the question that follows.
Which certificate is presented to the employee’s web browser?
Question 2
Examine this output from a debug flow:
Why did the FortiGate drop the packet?
Why did the FortiGate drop the packet?
Question 3
Which of the following statements are best practices for troubleshooting FSSO? (Choose two.)
Question 4
Examine this FortiGate configuration:
Examine the output of the following debug command:
Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection?
Examine the output of the following debug command:
Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection?
Question 5
An administrator needs to create an SSL-VPN connection for accessing an internal server using the bookmark Port Forward. What step is required for this configuration?
Question 6
Examine the network diagram shown in the exhibit, then answer the following question:
Which one of the following routes is the best candidate route for FGT1 to route traffic from the Workstation to the Web server?
A)
B)
C)
D)
Which one of the following routes is the best candidate route for FGT1 to route traffic from the Workstation to the Web server?
A)
B)
C)
D)
Question 7
Which of the following conditions are required for establishing an IPSec VPN between two FortiGate devices? (Choose two.)
Question 8
Which statements about the firmware upgrade process on an active-active HA cluster are true? (Choose two.)
Question 9
Which statements best describe auto discovery VPN (ADVPN). (Choose two.)
Question 10
View the exhibit.
Based on the configuration shown in the exhibit, what statements about application control behavior are true? (Choose two.)
Based on the configuration shown in the exhibit, what statements about application control behavior are true? (Choose two.)
Question 11
Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below.
When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?
When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?
Question 12
Which configuration objects can be selected for the Source field of a firewall policy? (Choose two.)
Question 13
Examine the IPS sensor configuration and forward traffic logs shown in the exhibit; then, answer the question below.
An administrator has configured the WINDOS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?
An administrator has configured the WINDOS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?
Question 14
How does FortiGate select the central SNAT policy that is applied to a TCP session?
Question 15
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?
Question 16
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
Question 17
Which statements about antivirus scanning mode are true? (Choose two.)
Question 18
How do you format the FortiGate flash disk?
Question 19
Which statements about DNS filter profiles are true? (Choose two.)
Question 20
Examine the two static routes shown in the exhibit, then answer title following question.
Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?
Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?
Question 21
How does FortiGate verify the login credentials of a remote LDAP user?