100% Pass Top-selling NSE4_FGT-6.4 Exams - New 2021 Fortinet Pratice Exam
Fortinet NSE 4 Dumps NSE4_FGT-6.4 Exam for Full Questions - Exam Study Guide
NEW QUESTION 13
Which feature in the Security Fabric takes one or more actions based on event triggers?
- A. Automation Stitches
- B. Fabric Connectors
- C. Security Rating
- D. Logical Topology
Answer: C
NEW QUESTION 14
In consolidated firewall policies, IPv4 and IPv6 policies are combined in a single consolidated policy. Instead of separate policies.
Which three statements are true about consolidated IPv4 and IPv6 policy configuration? (Choose three.)
- A. The IP version of the sources and destinations in a policy must match.
- B. The policy table in the GUI can be filtered to display policies with IPv4, IPv6 or IPv4 and IPv6 sources and destinations.
- C. The Incoming Interface. Outgoing Interface. Schedule, and Service fields can be shared with both IPv4 and IPv6.
- D. The IP version of the sources and destinations in a firewall policy must be different.
- E. The policy table in the GUI will be consolidated to display policies with IPv4 and IPv6 sources and destinations.
Answer: B,D,E
NEW QUESTION 15
Examine this output from a debug flow:
Why did the FortiGate drop the packet?
- A. It matched an explicitly configured firewall policy with the action DENY.
- B. The next-hop IP address is unreachable.
- C. It failed the RPF check.
- D. It matched the default implicit firewall policy.
Answer: D
Explanation:
Explanation
https://kb.fortinet.com/kb/documentLink.do?externalID=13900
NEW QUESTION 16
Refer to the web filter raw logs.
Based on the raw logs shown in the exhibit, which statement is correct?
- A. Access to the social networking web filter category was explicitly blocked to all users.
- B. The name of the firewall policy is all_users_web.
- C. Social networking web filter category is configured with the action set to authenticate.
- D. The action on firewall policy ID 1 is set to warning.
Answer: B
NEW QUESTION 17
Refer to the exhibit.
Given the security fabric topology shown in the exhibit, which two statements are true? (Choose two.)
- A. This security fabric topology is a logical topology view.
- B. There are 19 security recommendations for the security fabric.
- C. Device detection is disabled on all FortiGate devices.
- D. There are five devices that are part of the security fabric.
Answer: A,C
Explanation:
Explanation/Reference:
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 3
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions
NEW QUESTION 18
Examine the network diagram shown in the exhibit, and then answer the following question:
A firewall administrator must configure equal cost multipath (ECMP) routing on FGT1 to ensure both port1 and port3 links are used at the same time for all traffic destined for 172.20.2.0/24. Which of the following static routes will satisfy this requirement on FGT1? (Choose two.)
- A. 172.20.2.0/24 (1/150) via 10.30.3.2, port3 [10/0]
- B. 172.20.2.0/24 (1/0) via 10.10.1.2, port1 [0/0]
- C. 172.20.2.0/24 (1/150) via 10.10.3.2, port3 [10/0]
- D. 172.20.2.0/24 (25/0) via 10.10.3.2, port3 [5/0]
Answer: A,C
NEW QUESTION 19
Which statements are true regarding firewall policy NAT using the outgoing interface IP address with fixed port disabled? (Choose two.)
- A. This is known as many-to-one NAT.
- B. Source IP is translated to the outgoing interface IP.
- C. Connections are tracked using source port and source MAC address.
- D. Port address translation is not used.
Answer: A,B
NEW QUESTION 20
Refer to the exhibit.
Why did FortiGate drop the packet?
- A. It matched an explicitly configured firewall policy with the action DENY.
- B. The next-hop IP address is unreachable.
- C. It failed the RPF check.
- D. It matched the default implicit firewall policy.
Answer: B
Explanation:
Explanation/Reference:
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 14
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions
NEW QUESTION 21
Refer to the exhibit.

The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of diagnose sys virtual-wan-link health-check.
Which interface will be selected as an outgoing interface?
- A. port3
- B. port1
- C. port2
- D. port4
Answer: D
NEW QUESTION 22
Refer to the exhibit, which contains a session diagnostic output.
Which statement is true about the session diagnostic output?
- A. The session is in TCP ESTABLISHED state.
- B. The session is a bidirectional UDP connection.
- C. The session is a bidirectional TCP connection.
- D. The session is a UDP unidirectional state.
Answer: A
NEW QUESTION 23
View the exhibit.
Which of the following statements are correct? (Choose two.)
- A. Dead peer detection must be disabled to support this type of IPsec setup.
- B. The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
- C. This setup requires at least two firewall policies with the action set to IPsec.
- D. This is a redundant IPsec setup.
Answer: B,D
NEW QUESTION 24
Which of the following statements is true regarding SSL VPN settings for an SSL VPN portal?
- A. By default, FortiGate uses WINS servers to resolve names.
- B. By default, split tunneling is enabled.
- C. By default, the admin GUI and SSL VPN portal use the same HTTPS port.
- D. By default, the SSL VPN portal requires the installation of a client's certificate.
Answer: C
NEW QUESTION 25
Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)
- A. SSL inspection and authentication policy
- B. Firewall policy
- C. Policy rule
- D. Security policy
Answer: B,C
NEW QUESTION 26
Refer to the exhibit.
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 4
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions
https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 5
Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions The exhibit shows proxy policies and proxy addresses, the authentication rule and authentication scheme, users, and firewall address.
An explicit web proxy is configured for subnet range 10.0.1.0/24 with three explicit web proxy policies.
The authentication rule is configured to authenticate HTTP requests for subnet range 10.0.1.0/24 with a form- based authentication scheme for the FortiGate local user database. Users will be prompted for authentication.
How will FortiGate process the traffic when the HTTP request comes from a machine with the source IP
10.0.1.10to the destination http://www.fortinet.com? (Choose two.)
- A. If a Microsoft Internet Explorer browser is used with User-B credentials, the HTTP request will be allowed.
- B. If a Google Chrome browser is used with User-B credentials, the HTTP request will be allowed.
- C. If a Mozilla Firefox browser is used with User-B credentials, the HTTP request will be allowed.
- D. If a Mozilla Firefox browser is used with User-A credentials, the HTTP request will be allowed.
Answer: A,C
NEW QUESTION 27
Refer to the exhibit.
Which contains a Performance SLA configuration.
An administrator has configured a performance SLA on FortiGate. Which failed to generate any traffic. Why is FortiGate not generating any traffic for the performance SLA?
- A. Participants configured are not SD-WAN members.
- B. There may not be a static route to route the performance SLA traffic.
- C. The Ping protocol is not supported for the public servers that are configured.
- D. You need to turn on the Enable probe packets switch.
Answer: A
NEW QUESTION 28
Refer to the exhibit.



The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
- A. 10.200.1.49
- B. 10.200.1.99
- C. 10.200.1.1
- D. 10.200.1.149
Answer: B
NEW QUESTION 29
......
Authentic Best resources for NSE4_FGT-6.4 Online Practice Exam: https://www.exam4tests.com/NSE4_FGT-6.4-valid-braindumps.html