Fortinet

NSE4_FGT-6.0 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 111-question bank.

Provider
Fortinet
Question bank
111
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE4_FGT-6.0, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    What files are sent to FortiSandbox for inspection in flow-based inspection mode?

    Choose one answer.

    • All suspicious files that do not have their hash value in the FortiGuard antivirus signature database.
    • All suspicious files that are above the defined oversize limit value in the protocol options.
    • All suspicious files that match patterns defined in the antivirus profile.
    • All suspicious files that are allowed to be submitted to FortiSandbox in the antivirus profile.
  2. Question 2 · 1

    View the exhibit. Based on this output, which statements are correct? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The all VDOM is not synchronized between the primary and secondary FortiGate devices.
    • The root VDOM is not synchronized between the primary and secondary FortiGate devices.
    • The global configuration is synchronized between the primary and secondary FortiGate devices.
    • The FortiGate devices have three VDOMs.
  3. Question 3 · 1

    Examine the IPS sensor configuration shown in the exhibit, and then answer the question below. An administrator has configured the WINDOS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic. What is a possible reason for this?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • The IPS filter is missing the Protocol: HTTPS option.
    • The HTTPS signatures have not been added to the sensor.
    • A DoS policy should be used, instead of an IPS sensor.
    • A DoS policy should be used, instead of an IPS sensor.
    • The firewall policy is not using a full SSL inspection profile.
  4. Question 4 · 1

    Which statement about DLP on FortiGate is true?

    Choose one answer.

    • It can archive files and messages.
    • It can be applied to a firewall policy in a flow-based VDOM
    • Traffic shaping can be applied to DLP sensors.
    • Files can be sent to FortiSandbox for detecting DLP threats.
  5. Question 5 · 1

    Examine this PAC file configuration. Which of the following statements are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Browsers can be configured to retrieve this PAC file from the FortiGate.
    • Any web request to the 172.25.120.0/24 subnet is allowed to bypass the proxy.
    • All requests not made to Fortinet.com or the 172.25.120.0/24 subnet, have to go through altproxy.corp.com: 8060.
    • Any web request fortinet.com is allowed to bypass the proxy.
  6. Question 6 · 1

    Which statements about the firmware upgrade process on an active-active HA cluster are true? (Choose two.)

    Choose all answers that apply.

    • The firmware image must be manually uploaded to each FortiGate.
    • Only secondary FortiGate devices are rebooted.
    • Uninterruptable upgrade is enabled by default.
    • Traffic load balancing is temporally disabled while upgrading the firmware.
  7. Question 7 · 1

    Which statements best describe auto discovery VPN (ADVPN). (Choose two.)

    Choose all answers that apply.

    • It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes.
    • ADVPN is only supported with IKEv2.
    • Tunnels are negotiated dynamically between spokes.
    • Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.
  8. Question 8 · 1

    An administrator needs to create an SSL-VPN connection for accessing an internal server using the bookmark Port Forward. What step is required for this configuration?

    Choose one answer.

    • Configure an SSL VPN realm for clients to use the port forward bookmark.
    • Configure the client application to forward IP traffic through FortiClient.
    • Configure the virtual IP address to be assigned t the SSL VPN users.
    • Configure the client application to forward IP traffic to a Java applet proxy.
  9. Question 9 · 1

    What FortiGate configuration is required to actively prompt users for credentials?

    Choose one answer.

    • You must enable one or more protocols that support active authentication on a firewall policy.
    • You must position the firewall policy for active authentication before a firewall policy for passive authentication
    • You must assign users to a group for active authentication
    • You must enable the Authentication setting on the firewall policy
  10. Question 10 · 1

    Which statement is true regarding the policy ID number of a firewall policy?

    Choose one answer.

    • Defines the order in which rules are processed.
    • Represents the number of objects used in the firewall policy.
    • Required to modify a firewall policy using the CLI.
    • Changes when firewall policies are reordered.
  11. Question 11 · 1

    What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

    Choose one answer.

    • It limits the scope of application control to the browser-based technology category only.
    • It limits the scope of application control to scan application traffic based on application category only.
    • It limits the scope of application control to scan application traffic using parent signatures only
    • It limits the scope of application control to scan application traffic on DNS protocol only.
  12. Question 12 · 1

    The FSSO Collector Agent set to advanced access mode for the Windows Active Directory uses which of the following?

    Choose one answer.

    • LDAP convention
    • NTLM convention
    • Windows convention "" NetBios\Username
    • RSSO convention
  13. Question 13 · 1

    Examine the following web filtering log. Which statement about the log message is true?

    Choose one answer.

    Question illustration 1
    • The action for the category Games is set to block.
    • The usage quota for the IP address 10.0.1.10 has expired
    • The name of the applied web filter profile is default.
    • The web site miniclip.com matches a static URL filter whose action is set to Warning.
  14. Question 14 · 1

    Which of the following SD-WAN load ""balancing method use interface weight value to distribute traffic? (Choose two.)

    Choose all answers that apply.

    • Source IP
    • Spillover
    • Volume
    • Session
  15. Question 15 · 1

    Which is a requirement for creating an inter-VDOM link between two VDOMs?

    Choose one answer.

    • The inspection mode of at least one VDOM must be proxy-based.
    • At least one of the VDOMs must operate in NAT mode.
    • The inspection mode of both VDOMs must match.
    • Both VDOMs must operate in NAT mode.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free