Free NSE4_FGT-5.6 Exam Braindumps (page: 12)

Page 11 of 47

Examine the exhibit, which contains a screenshot of an explicit web proxy configuration.
What does FortiGate do when the setting Default Firewall Policy Action is set to Deny?

  1. Denies web proxy access to guest users
  2. Blocks any web proxy traffic that matches an explicit proxy policy without an action
  3. Blocks any web proxy traffic that does not match any explicit proxy policy
  4. Blocks any web proxy traffic that matches a firewall policy without a proxy profile

Answer(s): C



View the exhibit.
Which statement is true regarding Restrict Access in the SSL-VPN Settings?

  1. SSL VPN users will have access to only the REMOTE_ETH 1 subnet.
  2. Only users within the REMOTE_ETH1 subnet range will have access to the SSL VPN web portal login page.
  3. FortiGate will assign an IP address to the SSL VPN network adaptor from the REMOTE_ETH1 subnet.
  4. It enables client integrity check for the SSL VPN users in the REMOTE_ETH1 subnet.

Answer(s): B



Which statements about application control are true?
(Choose two.)

  1. Enabling application control profile in a security profile enables application control for all the traffic flowing through the FortiGate.
  2. It cannot take an action on unknown applications.
  3. It can inspect encrypted traffic.
  4. It can identify traffic from known applications, even when they are using non-standard TCP/UDP
    ports.

Answer(s): C,D



Under which circumstance is the IPsec ESP traffic encapsulated over UDP? Response:

  1. When using IKE version 2 (IKEv2).
  2. When NAT-T detects there is a device between both IPsec peers doing NAT over the IPsec traffic.
  3. When the IPsec VPN is configured as dial up.
  4. When the phase 1 is configured to use aggressive mode.

Answer(s): B






Post your Comments and Discuss Fortinet NSE4_FGT-5.6 exam with other Community members:

NSE4_FGT-5.6 Discussions & Posts