Free NSE4_FGT-6.2 Exam Braindumps (page: 12)

Page 11 of 32

Examine this PAC file configuration.

Which of the following statements are true? (Choose two.)

  1. Browsers can be configured to retrieve this PAC file from the FortiGate.
  2. Any web request to the 172.25.120.0/24 subnet is allowed to bypass the proxy.
  3. All requests not made to Fortinet.com or the 172.25.120.0/24 subnet, have to go through altproxy.corp.com: 8060.
  4. Any web request fortinet.com is allowed to bypass the proxy.

Answer(s): A,D



Which statements about the firmware upgrade process on an active-active HA cluster are true? (Choose two.)

  1. The firmware image must be manually uploaded to each FortiGate.
  2. Only secondary FortiGate devices are rebooted.
  3. Uninterruptable upgrade is enabled by default.
  4. Traffic load balancing is temporally disabled while upgrading the firmware.

Answer(s): B,D



Which statements best describe auto discovery VPN (ADVPN). (Choose two.)

  1. It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes.
  2. ADVPN is only supported with IKEv2.
  3. Tunnels are negotiated dynamically between spokes.
  4. Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.

Answer(s): A,C



An administrator needs to create an SSL-VPN connection for accessing an internal server using the bookmark Port Forward. What step is required for this configuration?

  1. Configure an SSL VPN realm for clients to use the port forward bookmark.
  2. Configure the client application to forward IP traffic through FortiClient.
  3. Configure the virtual IP address to be assigned t the SSL VPN users.
  4. Configure the client application to forward IP traffic to a Java applet proxy.

Answer(s): D






Post your Comments and Discuss Fortinet NSE4_FGT-6.2 exam with other Community members:

NSE4_FGT-6.2 Discussions & Posts