Fortinet NSE4_FGT-6.4 Exam Questions
Fortinet NSE 4 - FortiOS 6.4 (Page 2 )

Updated On: 21-Feb-2026

Which three statements about a flow-based antivirus profile are correct? (Choose three.)

  1. IPS engine handles the process as a standalone.
  2. FortiGate buffers the whole file but transmits to the client simultaneously.
  3. If the virus is detected, the last packet is delivered to the client.
  4. Optimized performance compared to proxy-based inspection.
  5. Flow-based inspection uses a hybrid of scanning modes available in proxy-based inspection.

Answer(s): B,D,E



Refer to the exhibit.



Which contains a session list output. Based on the information shown in the exhibit, which statement is true?

  1. Destination NAT is disabled in the firewall policy.
  2. One-to-one NAT IP pool is used in the firewall policy.
  3. Overload NAT IP pool is used in the firewall policy.
  4. Port block allocation IP pool is used in the firewall policy.

Answer(s): B



Which two statements are correct regarding FortiGate FSSO agentless polling mode? (Choose two.)

  1. FortiGate points the collector agent to use a remote LDAP server.
  2. FortiGate uses the AD server as the collector agent.
  3. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
  4. FortiGate queries AD by using the LDAP to retrieve user group information.

Answer(s): C,D



Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)

  1. FortiCache
  2. FortiSIEM
  3. FortiAnalyzer
  4. FortiSandbox
  5. FortiCloud

Answer(s): B,C,E



Refer to the exhibit.



The exhibit contains a network diagram, virtual IP, IP pool, and firewall policies configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10 .0.1.254. /24. The first firewall policy has NAT enabled using IP Pool. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0.1.10?

  1. 10.200.1.1
  2. 10.200.3.1
  3. 10.200.1.100
  4. 10.200.1.10

Answer(s): A


Reference:

https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-firewall/Concepts%20- %20Firewall/Static%20NAT.htm






Post your Comments and Discuss Fortinet NSE4_FGT-6.4 exam dumps with other Community members:

Join the NSE4_FGT-6.4 Discussion