Free NSE4_FGT-6.2 Exam Braindumps (page: 5)

Page 4 of 32

In a high availability (HA) cluster operating in active-active mode, which of the following correctly describes the path taken by the SYN packet of an HTTP session that is offloaded to a secondary FortiGate?

  1. Client > primary FortiGate> secondary FortiGate> primary FortiGate> web server.
  2. Client > secondary FortiGate> web server.
  3. Client >secondary FortiGate> primary FortiGate> web server.
  4. Client> primary FortiGate> secondary FortiGate> web server.

Answer(s): D



An administrator is configuring an IPsec between site A and site B. The Remotes Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.16.1.0/24 and the remote quick mode selector is 192.16.2.0/24. How must the administrator configure the local quick mode selector for site B?

  1. 192.168.3.0.24
  2. 192.168.2.0.24
  3. 192.168.1.0.24
  4. 192.168.0.0.8

Answer(s): A



Which of the following are purposes of NAT traversal in IPsec? (Choose two.)

  1. To delete intermediary NAT devices in the tunnel path.
  2. To dynamically change phase 1 negotiation mode aggressive mode.
  3. To encapsulation ESP packets in UDP packets using port 4500.
  4. To force a new DH exchange with each phase 2 rekey.

Answer(s): A,C



Which of the following statements correctly describes FortiGates route lookup behavior when searching for a suitable gateway? (Choose two)

  1. Lookup is done on the trust packet from the session originator
  2. Lookup is done on the last packet sent from the CK spender
  3. Lookup is done on every packet, regardless of direction
  4. Lookup is done on the trust reply packet from the CK spender

Answer(s): A,B






Post your Comments and Discuss Fortinet NSE4_FGT-6.2 exam with other Community members:

NSE4_FGT-6.2 Discussions & Posts