Fortinet

NSE4_FGT-6.4 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 101-question bank.

Provider
Fortinet
Question bank
101
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE4_FGT-6.4, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which two statements are true when FortiGate is in transparent mode? (Choose two.)

    Choose all answers that apply.

    • By default, all interfaces are part of the same broadcast domain.
    • The existing network IP schema must be changed when installing a transparent mode FortiGate in the network.
    • Static routes are required to allow traffic to the next hop.
    • FortiGate forwards frames without changing the MAC address.
  2. Question 2 · 1

    What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?

    Choose one answer.

    • FortiGate automatically negotiates different local and remote addresses with the remote peer.
    • FortiGate automatically negotiates a new security association after the existing security association expires.
    • FortiGate automatically negotiates different encryption and authentication algorithms with the remote peer.
    • FortiGate automatically brings up the IPsec tunnel and keeps it up, regardless of activity on the IPsec tunnel.
  3. Question 3 · 1

    An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel. Which DPD mode on FortiGate will meet the above requirement?

    Choose one answer.

    • Disabled
    • On Demand
    • Enabled
    • On Idle
  4. Question 4 · 1

    In an explicit proxy setup, where is the authentication method and database configured?

    Choose one answer.

    • Proxy Policy
    • Authentication Rule
    • Firewall Policy
    • Authentication scheme
  5. Question 5 · 1

    Refer to the exhibit. Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The port3 default route has the lowest metric
    • The port3 default route has the highest distance
    • The port1 and port2 default routes are active in the routing table
    • There will be eight routes active in the routing table
  6. Question 6 · 1

    Which three statements about a flow-based antivirus profile are correct? (Choose three.)

    Choose all answers that apply.

    • Flow-based inspection uses a hybrid of scanning modes available in proxy-based inspection
    • Optimized performance compared to proxy-based inspection
    • FortiGate buffers the whole file but transmits for the client simultaneously
    • If the virus is detected, the last packet is delivered to the client
    • IPS engine handles the process as a standalone
  7. Question 7 · 1

    Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)

    Choose all answers that apply.

    • udp-echo
    • DNS
    • TWAMP
    • ping
  8. Question 8 · 1

    Which two inspection modes can you use to configure a firewall policy on a profile-based next-generation firewall (NGFW)? (Choose two.)

    Choose all answers that apply.

    • Proxy-based inspection
    • Certificate inspection
    • Flow-based inspection
    • Full Content inspection
  9. Question 9 · 1

    Refer to the exhibit to view the application control profile. Based on the configuration, what will happen to Apple FaceTime?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    Question illustration 3
    Question illustration 4
    • Apple FaceTime will be allowed, based on the Apple filter configuration.
    • Apple FaceTime will be allowed, based on the Categories configuration.
    • Apple FaceTime will be allowed, based on the Excessive-Bandwidth filter configuration.
    • Apple FaceTime will be allowed only if the filter in Application and Filter Overrides is set to Learn.
  10. Question 10 · 1

    Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)

    Choose all answers that apply.

    • Web filter in flow-based inspection
    • Antivirus in flow-based inspection
    • DNS filter
    • Web application firewall
    • Application control
  11. Question 11 · 1

    Refer to the exhibit - In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit. What should the administrator do next to troubleshoot the problem?

    Choose one answer.

    Question illustration 1
    • Run a sniffer on the web server.
    • Capture the traffic using an external sniffer connected to port1.
    • Execute another sniffer in the FortiGate, this time with the filter ג€host 10.0.1.10ג€
    • Execute a debug flow.
  12. Question 12 · 1

    Refer to the exhibit - The exhibit shows a FortiGate configuration. How does FortiGate handle web proxy traffic coming from the IP address 10.2.1.200, that requires authorization?

    Choose one answer.

    Question illustration 1
    • It authenticates the traffic using the authentication scheme SCHEME2.
    • It drops the traffic.
    • It authenticates the traffic using the authentication scheme SCHEME1.
    • It always authorizes the traffic without requiring authentication.
  13. Question 13 · 1

    IPS Engine is used by which three security features? (Choose three.)

    Choose all answers that apply.

    • Application control
    • Antivirus in flow-based inspection
    • Web filter in flow-based inspection
    • DNS filter
    • Web application firewall
  14. Question 14 · 1

    If Internet Service is already selected as Destination in a firewall policy, which other configuration objects can be selected to the Destination field of a firewall policy?

    Choose one answer.

    • User or User Group
    • IP address
    • No other object can be added
    • FQDN address
  15. Question 15 · 1

    What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?

    Choose one answer.

    • It limits the scanning of application traffic to the DNS protocol only.
    • It limits the scanning of application traffic to use parent signatures only.
    • It limits the scanning of application traffic to the browser-based technology category only.
    • It limits the scanning of application traffic to the application category only.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free