Exam Dumps NSE4_FGT-6.4 Practice Free Latest Fortinet Practice Tests [Q66-Q85]

Rate this post

Exam Dumps NSE4_FGT-6.4 Practice Free Latest Fortinet Practice Tests

NSE4_FGT-6.4 Exam Questions | Real NSE4_FGT-6.4 Practice Dumps

NO.66 Refer to the exhibit.

The exhibits show a network diagram and the explicit web proxy configuration.
In the commanddiagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?

 
 
 
 

NO.67 Refer to the exhibit, which contains a session diagnostic output.

Which statement is true about the session diagnostic output?

 
 
 
 

NO.68 Refer to the exhibit.

Which contains a network diagram and routing table output.
The Student is unable to access Webserver.
What is the cause of the problem and what is the solution for the problem?

 
 
 
 

NO.69 Which three statements about security associations (SA) in IPsec are correct? (Choose three.)

 
 
 
 
 

NO.70 Refer to the exhibit.




The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?

 
 
 
 

NO.71 Refer to the web filter raw logs.

Based on the raw logs shown in the exhibit, which statement is correct?

 
 
 
 

NO.72 An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel.
Which DPD mode on FortiGate will meet the above requirement?

 
 
 
 

NO.73 Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)

 
 
 
 

NO.74 If theServicesfield is configured in a Virtual IP (VIP), which statement is true when central NAT is used?

 
 
 
 

NO.75 Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)

 
 
 
 

NO.76 Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)

 
 
 
 

NO.77 Refer to the exhibit showing a debug flow output.

Which two statements about the debug flow output are correct? (Choose two.)

 
 
 
 

NO.78 Refer to the exhibit showing a debug flow output.

Which two statements about the debug flow output are correct? (Choose two.)

 
 
 
 

NO.79 An administrator must disable RPF check to investigate an issue.
Which method is best suited to disable RPF without affecting features like antivirus and intrusion prevention system?

 
 
 
 

NO.80 Refer to the exhibit, which contains a static route configuration.

An administrator created a static route for Amazon Web Services.
What CLI command must the administrator use to view the route?

 
 
 
 

NO.81 Examine the exhibit, which contains a virtual IP and firewall policy configuration.



The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address
10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?

 
 
 
 

NO.82 Examine the two static routes shown in the exhibit, then answer the following question.

Which of the following is the expected FortiGate behavior regarding these two routes to the same destination?

 
 
 
 

NO.83 Which two statements are true about collector agent advanced mode? (Choose two.)

 
 
 
 

NO.84 If Internet Service is already selected as Destination in a firewall policy, which other configuration objects can be selected to the Destination field of a firewall policy?

 
 
 
 

NO.85 Consider the topology:
Application on a Windows machine <–{SSL VPN} –>FGT–> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout.
The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.
What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)

 
 
 
 

Verified NSE4_FGT-6.4 Exam Dumps Q&As – Provide NSE4_FGT-6.4 with Correct Answers: https://www.it-tests.com/NSE4_FGT-6.4.html

         

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw