Fortinet

NSE4_FGT-6.2 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 102-question bank.

Provider
Fortinet
Question bank
102
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE4_FGT-6.2, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which statement about a One-to-One IP pool is true?

    Choose one answer.

    • It is used for destination NAT.
    • It limits the client to 64 connections per IP pool.
    • It allows the fixed mapping of an internal address range to an external address range.
    • It does not use port address translation.
  2. Question 2 · 1

    Refer to the exhibit. The exhibit shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The sensor will allow attackers matching the NTP.Spoofed.KoD.DoS signature.
    • The sensor will block all attacks aimed at Windows servers.
    • The sensor will reset all connections that match these signatures.
    • The sensor will gather a packet log for all matched traffic.
  3. Question 3 · 1

    An administrator wants to throttle the total volume of SMTP sessions to their email server. Which DoS sensor can the administrator use to achieve this?

    Choose one answer.

    • ip_src_session
    • ip_dst_session
    • udp_flood
    • tcp_port_scan
  4. Question 4 · 1

    A FortiGate device has multiple VDOMs. Which statement about an administrator account configured with the default prof_admin profile is true?

    Choose one answer.

    • It can upgrade the firmware on the FortiGate device.
    • It can reset the password for the admin account.
    • It can create administrator accounts with access to the same VDOM.
    • It cannot have access to more than one VDOM.
  5. Question 5 · 1

    During the digital verification process, comparing the original and fresh hash results satisfies which security requirement?

    Choose one answer.

    • Signature verification
    • Authentication
    • Data integrity
    • Non-deniability
  6. Question 6 · 1

    Which three statements correctly describe transparent mode operation? (Choose three.)

    Choose all answers that apply.

    • The transparent FortiGate is visible to network hosts in an IP traceroute.
    • FortiGate acts as a transparent bridge and forwards traffic at Layer 2.
    • Ethernet packets are forwarded based on destination MAC addresses, not IP addresses.
    • It permits inline traffic inspection and firewalling without changing the IP scheme of the network.
    • All interfaces on the transparent mode FortiGate device must be on different IP subnets.
  7. Question 7 · 1

    Which two statements about conserve mode are true? (Choose two.)

    Choose all answers that apply.

    • Administrators can access the FortiGate only through the console port.
    • FortiGate stops doing RPF checks over incoming packets.
    • FortiGate stops sending files to FortiSandbox for inspection.
    • Administrators cannot change the configuration.
  8. Question 8 · 1

    Which two features are supported by web filter in flow-based inspection mode with NGFW mode set to profile-based? (Choose two.)

    Choose all answers that apply.

    • Search engines
    • FortiGuard Quotas
    • Static URL
    • Rating option
  9. Question 9 · 1

    Refer to the exhibit. Given the FortiGate CLI output, why is the administrator getting the error shown in the exhibit?

    Choose one answer.

    Question illustration 1
    • The administrator must first enter the command edit global.
    • The administrator admin does not have the privileges required to configure global settings.
    • The command config system global does not exist in FortiGate.
    • The global settings cannot be configured from the root VDOM context.
  10. Question 10 · 1

    An administrator has configured a dialup IPsec VPN with XAuth. Which statement best describes what occurs during this scenario?

    Choose one answer.

    • Dialup clients must provide their local ID during phase 2 negotiations.
    • Only digital certificates will be accepted as an authentication method in phase 1.
    • Phase 1 negotiations will skip preshared key exchange.
    • Dialup clients must provide a username and password for authentication.
  11. Question 11 · 1

    Consider a new IPsec deployment with the following criteria: ✑ All satellite offices must connect to the two HQ sites. ✑ The satellite offices do not need to communicate directly with other satellite offices. ✑ Backup VPN is not required. ✑ The design should minimize the number of tunnels being configured. Which topology should you use to satisfy all of the requirements?

    Choose one answer.

    • Partial mesh
    • Redundant
    • Full mesh
    • Hub-and-spoke
  12. Question 12 · 1

    When override is enabled, which option shows the process and selection criteria that is used to elect the primary FortiGate in an HA cluster?

    Choose one answer.

    • Connected monitored ports > HA uptime > priority > serial number
    • HA uptime > priority > Connected monitored ports > serial number
    • Priority > Connected monitored ports > HA uptime > serial number
    • Connected monitored ports > priority > HA uptime > serial number
  13. Question 13 · 1

    HTTP public key pinning (HPKP) can be an obstacle to implementing full SSL inspection. In which two ways can you resolve this problem? (Choose two.)

    Choose all answers that apply.

    • Enable Allow Invalid SSL Certificates for the relevant security profile.
    • Exempt those web sites that use HPKP from full SSL inspection.
    • Install the CA certificate (that is required to verify the web server certificate) in the certificate stores of users' computers.
    • Use a web browser that does not support HPKP.
  14. Question 14 · 1

    A company needs to provide SSL VPN access to two user groups. The company also needs to display a different welcome message for each group, on the SSL VPN login. To meet these requirements, what is required in the SSL VPN configuration?

    Choose one answer.

    • Different virtual SSL VPN IP addresses for each group
    • Two separate SSL VPNs in different interfaces mapping the same ssl.root
    • Two firewall policies with different captive portals
    • Different SSL VPN realms for each group
  15. Question 15 · 1

    Which two route attributes must be equal for static routes to be eligible for equal cost multipath (ECMP) routing? (Choose two.)

    Choose all answers that apply.

    • Metric
    • Priority
    • Cost
    • Distance

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free