Fortinet

NSE4-5.4 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 40-question bank.

Provider
Fortinet
Question bank
40
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE4-5.4, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

    Choose all answers that apply.

    • The interface has been configured for one-arm sniffer.
    • The interface is a member of a virtual wire pair.
    • The operation mode is transparent.
    • The interface is a member of a zone.
    • Captive portal is enabled in the interface.
  2. Question 2 · 1

    Examine the following web filtering log. Which statement about the log message is true?

    Choose one answer.

    Question illustration 1
    • The action for the category Games is set to block.
    • The usage quota for the IP address 10.0.1.10 has expired.
    • The name of the applied web filter profile is default.
    • The web site miniclip.com matches a static URL filter whose action is set to Warning.
  3. Question 3 · 1

    View the exhibit. Which users and user groups are allowed access to the network through captive portal?

    Choose one answer.

    Question illustration 1
    • Only individual usersג€"not groupsג€"defined in the captive portal configuration.
    • Groups defined in the captive portal configuration
    • All users
    • Users and groups defined in the firewall policy.
  4. Question 4 · 1

    View the exhibit. Why is the administrator getting the error shown in the exhibit?

    Choose one answer.

    Question illustration 1
    • The administrator admin does not have the privileges required to configure global settings.
    • The global settings cannot be configured from the root VDOM context.
    • The command config system global does not exist in FortiGate.
    • The administrator must first enter the command edit global.
  5. Question 5 · 1

    What FortiGate feature can be used to block a ping sweep scan from an attacker?

    Choose one answer.

    • Web application firewall (WAF)
    • Rate based IPS signatures
    • One-arm sniffer
    • DoS policies
  6. Question 6 · 1

    Which statements about the firmware upgrade process on an active-active high availability (HA) cluster are true? (Choose two.)

    Choose all answers that apply.

    • The firmware image must be manually uploaded to each FortiGate.
    • Only secondary FortiGate devices are rebooted.
    • Uninterruptable upgrade is enabled by default.
    • Traffic load balancing is temporally disabled while upgrading the firmware.
  7. Question 7 · 1

    View the example routing table. Which route will be selected when trying to reach 10.20.30.254?

    Choose one answer.

    Question illustration 1
    • 10.20.30.0/26 [10/0] via 172.20.168.254, port2
    • The traffic will be dropped because it cannot be routed.
    • 10.20.30.0/24 [10/0] via 172.20.167.254, port3
    • 0.0.0.0/0 [10/0] via 172.20.121.2, port1
  8. Question 8 · 1

    What IPv6 extension header can be used to provide encryption and data confidentiality?

    Choose one answer.

    • Mobility
    • ESP
    • Authentication
    • Destination options
  9. Question 9 · 1

    Which two statements are true about IPsec VPNs and SSL VPNs? (Choose two.)

    Choose all answers that apply.

    • SSL VPN creates a HTTPS connection. IPsec does not.
    • Both SSL VPNs and IPsec VPNs are standard protocols.
    • Either a SSL VPN or an IPsec VPN can be established between two FortiGate devices.
    • Either a SSL VPN or an IPsec VPN can be established between an end-user workstation and a FortiGate device.
  10. Question 10 · 1

    What is a valid reason for using session based authentication instead of IP based authentication in a FortiGate web proxy solution?

    Choose one answer.

    • Users are required to manually enter their credentials each time they connect to a different web site.
    • Proxy users are authenticated via FSSO.
    • There are multiple users sharing the same IP address.
    • Proxy users are authenticated via RADIUS.
  11. Question 11 · 1

    Which of the following regular expression patterns make the terms "confidential data" case insensitive?

    Choose one answer.

    • [confidential data]
    • /confidential data/i
    • i/confidential data/
    • "confidential data"
  12. Question 12 · 1

    Which statements are correct for port pairing and forwarding domains? (Choose two.)

    Choose all answers that apply.

    • They both create separate broadcast domains.
    • Port Pairing works only for physical interfaces.
    • Forwarding Domain only applies to virtual interfaces.
    • They may contain physical and/or virtual interfaces.
  13. Question 13 · 1

    In transparent mode, forward-domain is an CLI setting associate with ___________.

    Choose one answer.

    • static route
    • a firewall policy
    • an interface
    • a virtual domain
  14. Question 14 · 1

    Which of the following sequences describes the correct order of criteria used for the selection of a master unit within a FortiGate high availability (HA) cluster when override is disabled?

    Choose one answer.

    • 1. port monitor, 2. unit priority, 3. up time, 4. serial number.
    • 1. port monitor, 2. up time, 3. unit priority, 4. serial number.
    • 1. unit priority, 2. up time, 3. port monitor, 4. serial number.
    • 1. up time, 2. unit priority, 3. port monitor, 4. serial number.
  15. Question 15 · 1

    Which of the following statements are correct about the HA command diagnose sys ha reset- uptime? (Choose two.)

    Choose all answers that apply.

    • The device this command is executed on is likely to switch from master to slave status if override is disabled.
    • The device this command is executed on is likely to switch from master to slave status if override is enabled.
    • This command has no impact on the HA algorithm.
    • This command resets the uptime variable used in the HA algorithm so it may cause a new master to become elected.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free