Free NSE4_FGT-6.2 Exam Braindumps (page: 4)

Page 3 of 32

Examine this output from a debug flow:

Which statements about the output are correct? (Choose two.)

  1. FortiGate received a TCP SYN/ACK packet.
  2. The source IP address of the packet was translated to 10.0.1.10.
  3. FortiGate routed the packet through port 3.
  4. The packet was allowed by the firewall policy with the ID 00007fc0.

Answer(s): A,C



Examine this FortiGate configuration:

How does the FortiGate handle web proxy traffic coming from the IP address 10.2.1.200 that requires authorization?

  1. It always authorizes the traffic without requiring authentication.
  2. It drops the traffic.
  3. It authenticates the traffic using the authentication scheme SCHEME2.
  4. It authenticates the traffic using the authentication scheme SCHEME1.

Answer(s): C



Which of the following statements are best practices for troubleshooting FSSO? (Choose two.)

  1. Include the group of guest users in a policy.
  2. Extend timeout timers.
  3. Guarantee at least 34 Kbps bandwidth between FortiGate and domain controllers.
  4. Ensure all firewalls allow the FSSO required ports.

Answer(s): A,D



Which statements about antivirus scanning mode are true? (Choose two.)

  1. In proxy-based inspection mode antivirus buffers the whole file for scarring before sending it to the client.
  2. In flow-based inspection mode, you can use the CLI to configure antivirus profiles to use protocol option profiles.
  3. In proxy-based inspection mode, if a virus is detected, a replacement message may not be displayed immediately.
  4. In quick scan mode, you can configure antivirus profiles to use any of the available signature data bases.

Answer(s): B,D






Post your Comments and Discuss Fortinet NSE4_FGT-6.2 exam with other Community members:

NSE4_FGT-6.2 Discussions & Posts