Fortinet NSE4_FGT-5.6 Exam
Fortinet NSE 4 - FortiOS 5.6 (Page 8 )

Updated On: 7-Feb-2026

Which of the following statements are true regarding Cloud Access Security Inspection (CASI)? (Choose two.)

  1. CASI requires an activated FortiCloud account.
  2. A CASI license is required on FortiGate.
  3. CASI requires a subscription to FortiGuard IPS and Application Control.
  4. CASI is always proxy-based scanning.
  5. CASI requires SSL deep inspection on a firewall policy.

Answer(s): C,E



Which of the following statements describe WMI polling mode for FSSO collector agent? (Choose two.)

  1. The collector agent does not need to search any security event logs.
  2. WMI polling can increase bandwidth usage with large networks.
  3. The NetSessionEnum function is used to track user logoffs.
  4. The collector agent uses a Windows API to query DCs for user logins.

Answer(s): B,D



FortiGate has been configured for Firewall Authentication.
When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?

  1. The user was authenticated using passive authentication.
  2. No matching user account exists for this user.
  3. The user is using a super admin account.
  4. The user is using a guest account profile.

Answer(s): A



Which statements correctly define Policy ID and policy Sequence number for firewall policies? (Choose two.)

  1. A policy sequence number defines the order in which rules are processed.
  2. A policy ID number is required to modify a firewall policy from the CLI.
  3. A policy ID number changes when policies are re-ordered.
  4. A policy sequence number reflects the number of objects used in the firewall policy.

Answer(s): A,B



An administrator wants to monitor their network for any probing attempts aimed to exploit existing vulnerabilities in their servers.
What must they configure on their FortiGate to accomplish this? (Choose two.)

  1. An application control profile and set all application signatures to monitor.
  2. A DoS policy, and log all UDP and TCP scan attempts.
  3. An IPS sensor to monitor all signatures applicable to the server.
  4. A web application firewall profile to check protocol constraints.

Answer(s): B,C






Post your Comments and Discuss Fortinet NSE4_FGT-5.6 exam prep with other Community members:

Join the NSE4_FGT-5.6 Discussion