Free Fortinet NSE4_FGT-6.4 Exam Braindumps (page: 7)

Which of statement is true about SSL VPN web mode?

  1. The tunnel is up while the client is connected.
  2. It supports a limited number of protocols.
  3. The external network application sends data through the VPN.
  4. It assigns a virtual IP address to the client.

Answer(s): B

Explanation:

FortiGate_Security_6.4 page 575 - Web mode requires only a web browser, but supports a limited number of protocols.



Refer to the exhibit.





The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of diagnose sys virtual-wan-link health-check.
Which interface will be selected as an outgoing interface?

  1. port2
  2. port4
  3. port3
  4. port1

Answer(s): D

Explanation:

Port 1 shows the lowest latency.



Refer to the exhibit.



A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?

  1. On HQ-FortiGate, enable Auto-negotiate.
  2. On Remote-FortiGate, set Seconds to 43200.
  3. On HQ-FortiGate, enable Diffie-Hellman Group 2.
  4. On HQ-FortiGate, set Encryption to AES256.

Answer(s): D


Reference:

https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/168495



Refer to the web filter raw logs.



Based on the raw logs shown in the exhibit, which statement is correct?

  1. Social networking web filter category is configured with the action set to authenticate.
  2. The action on firewall policy ID 1 is set to warning.
  3. Access to the social networking web filter category was explicitly blocked to all users.
  4. The name of the firewall policy is all_users_web.

Answer(s): A



Viewing page 7 of 43
Viewing questions 25 - 28 out of 163 questions



Post your Comments and Discuss Fortinet NSE4_FGT-6.4 exam prep with other Community members:

NSE4_FGT-6.4 Exam Discussions & Posts