Free NSE4_FGT-5.6 Exam Braindumps (page: 8)

Page 7 of 47

View the exhibit.



What behavior results from this full (deep) SSL configuration? (Choose two.)

  1. A temporary trusted FortiGate certificate replaces the server certificate when the server certificate is trusted.
  2. A temporary untrusted FortiGate certificate replaces the server certificate when the server certificate is untrusted.
  3. A temporary trusted FortiGate certificate replaces the server certificate, even when the server certificate is untrusted.
  4. The browser bypasses all certificate warnings and allows the connection.

Answer(s): A,B



Which of the following statements are true regarding Cloud Access Security Inspection (CASI)? (Choose two.)

  1. CASI requires an activated FortiCloud account.
  2. A CASI license is required on FortiGate.
  3. CASI requires a subscription to FortiGuard IPS and Application Control.
  4. CASI is always proxy-based scanning.
  5. CASI requires SSL deep inspection on a firewall policy.

Answer(s): C,E



Which of the following statements describe WMI polling mode for FSSO collector agent? (Choose two.)

  1. The collector agent does not need to search any security event logs.
  2. WMI polling can increase bandwidth usage with large networks.
  3. The NetSessionEnum function is used to track user logoffs.
  4. The collector agent uses a Windows API to query DCs for user logins.

Answer(s): B,D



FortiGate has been configured for Firewall Authentication.
When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?

  1. The user was authenticated using passive authentication.
  2. No matching user account exists for this user.
  3. The user is using a super admin account.
  4. The user is using a guest account profile.

Answer(s): A






Post your Comments and Discuss Fortinet NSE4_FGT-5.6 exam with other Community members:

NSE4_FGT-5.6 Discussions & Posts