Free NSE4_FGT-5.6 Exam Braindumps (page: 11)

Page 10 of 47

Which protocols can be scanned by FortiGate antivirus scan? (Choose three.)

  1. HTTP
  2. FTP
  3. DNS
  4. SMTP
  5. TFTP

Answer(s): A,B,D



Which of the following statements about advanced AD access mode for FSSO collector agent are true?
(Choose two.)

  1. It is only supported if DC agents are deployed.
  2. FortiGate can act as an LDAP client configure the group filters.
  3. It supports monitoring of nested groups.
  4. It uses the Windows convention for naming, that is, Domain\Username.

Answer(s): A,C



Which statement about traffic flow in an active-active HA cluster is true? Response:

  1. The SYN packet from the client always arrives at the primary device first.
  2. The ACK from the client is received on the physical MAC address of the primary device.
  3. The secondary device responds to the primary device with a SYN/ACK, then the primary device forwards the SYN/ACK to the client.
  4. All FortiGate devices are assigned the same virtual MAC addresses for the HA heartbeat interfaces to redistribute to the sessions.

Answer(s): A



Review the log message.
What does the log indicate?
(Choose two.)

  1. Firewall policy ID 1 matched the traffic.
  2. 10.0.1.1C isthe IP for miniclip.com.
  3. FortiGate blocked the traffic.
  4. The log type is webfilter.

Answer(s): A,B






Post your Comments and Discuss Fortinet NSE4_FGT-5.6 exam with other Community members:

NSE4_FGT-5.6 Discussions & Posts