Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

Note! Following NSE4_FGT-6.4 Exam is Retired now. Please select the alternative replacement for your Exam Certification. The new exam code is NSE4_FGT-7.2

NSE4_FGT-6.4 Exam Dumps - Fortinet NSE 4 - FortiOS 6.4

Go to page:
Question # 17

Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)

A.

FortiGuard web filter cache

B.

FortiGate hostname

C.

NTP

D.

DNS

Full Access
Question # 18

Refer to the exhibit.

Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)

A.

Traffic between port2 and port2-vlan1 is allowed by default.

B.

port1-vlan10 and port2-vlan10 are part of the same broadcast domain.

C.

port1 is a native VLAN.

D.

port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.

Full Access
Question # 19

Examine the network diagram shown in the exhibit, then answer the following question:

Which one of the following routes is the best candidate route for FGT1 to route traffic from the Workstation to the Web server?

A.

172.16.0.0/16 [50/0] via 10.4.200.2, port2 [5/0]

B.

0.0.0.0/0 [20/0] via 10.4.200.2, port2

C.

10.4.200.0/30 is directly connected, port2

D.

172.16.32.0/24 is directly connected, port1

Full Access
Question # 20

In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies. Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)

A.

The IP version of the sources and destinations in a firewall policy must be different.

B.

The Incoming Interface. Outgoing Interface. Schedule, and Service fields can be shared with both IPv4 and IPv6.

C.

The policy table in the GUI can be filtered to display policies with IPv4, IPv6 or IPv4 and IPv6 sources and destinations.

D.

The IP version of the sources and destinations in a policy must match.

E.

The policy table in the GUI will be consolidated to display policies with IPv4 and IPv6 sources and destinations.

Full Access
Question # 21

Which of the following statements about backing up logs from the CLI and downloading logs from the GUI are true? (Choose two.)

A.

Log downloads from the GUI are limited to the current filter view

B.

Log backups from the CLI cannot be restored to another FortiGate.

C.

Log backups from the CLI can be configured to upload to FTP as a scheduled time

D.

Log downloads from the GUI are stored as LZ4 compressed files.

Full Access
Question # 22

Which two statements about antivirus scanning mode are true? (Choose two.)

A.

In proxy-based inspection mode, files bigger than the buffer size are scanned.

B.

In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.

C.

In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.

D.

In flow-based inspection mode, files bigger than the buffer size are scanned.

Full Access
Question # 23

A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded.

What is the reason for the failed virus detection by FortiGate?

A.

Application control is not enabled

B.

SSL/SSH Inspection profile is incorrect

C.

Antivirus profile configuration is incorrect

D.

Antivirus definitions are not up to date

Full Access
Question # 24

Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)

A.

System time

B.

FortiGuaid update servers

C.

Operating mode

D.

NGFW mode

Full Access
Go to page: