Fortinet NSE4_FGT-5.6 Exam
Fortinet NSE 4 - FortiOS 5.6 (Page 4 )

Updated On: 7-Feb-2026

Examine the partial output from the diagnose sys session list CLI command.
What does this output state?

  1. proto_state=05 is the TCP state.
  2. proto_state=05 is the U DP state.
  3. proto_state=05 is the ICMP state.
  4. timeout=3600 reflects the maximum length of time a session can be opened.

Answer(s): A



Which statement about firewall policy NAT is true?

  1. DNAT is not supported.
  2. DNAT can automatically apply to multiple firewall policies, based on DNAT rules.
  3. You must configure SNAT for each firewall policy.
  4. SNAT can automatically apply to multiple firewall policies, based on SNAT rules.

Answer(s): C



Which statements are true regarding firewall policy NAT using the Outgoing Interface Address with Fixed Port disabled?
(Choose two.)

  1. Source IP is translated to outgoing interface IP
  2. Port address translation is not used
  3. This is known as many-to-one NAT.
  4. Connections are tracked using source port and source MAC address.

Answer(s): A,C



Which statements are true regarding blocking botnet command and control traffic? (Choose two.)

  1. DNS lookups are checked against the Botnet Command and Control database.
  2. The botnet command and control domains can be enabled on the web filter profile
  3. This service requires a FortiGuard web filtering license.
  4. The Botnet Command and Control database cannot be downloaded -it's only available on FortiGuard servers.

Answer(s): A,C



What methods can be used to deliver the token code to a user who is configured to use two-factor authentication?
(Choose three.)

  1. SMS text message
  2. Instant message app
  3. Voicemail message
  4. Email
  5. FortiToken

Answer(s): A,D,E






Post your Comments and Discuss Fortinet NSE4_FGT-5.6 exam prep with other Community members:

Join the NSE4_FGT-5.6 Discussion