Fortinet NSE4_FGT-6.0 - Fortinet NSE4 - FortiOS 6.0 Exam

Question #6 (Topic: Topic 1)
An administrator has configured central DNAT and virtual IPs. Which of the following can be selected in the firewall policy Destination field?
A. A VIP group B. The mapped IP address object of the VIP object C. A VIP object D. An IP pool
Answer: C
Question #7 (Topic: Topic 1)
An administrator needs to strengthen the security for SSL VPN access. Which of the following statements are best practices to do so? (Choose three.)
A. Configure split tunneling for content inspection. B. Configure host restrictions by IP or MAC address. C. Configure two-factor authentication using security certificates. D. Configure SSL offloading to a content processor (FortiASIC). E. Configure a client integrity check (host-check).
Answer: CDE
Question #8 (Topic: Topic 1)
Which statement about FortiGuard services for FortiGate is true?
A. The web filtering database is downloaded locally on FortiGate. B. Antivirus signatures are downloaded locally on FortiGate. C. FortiGate downloads IPS updates using UDP port 53 or 8888. D. FortiAnalyzer can be configured as a local FDN to provide antivirus and IPS updates.
Answer: B
Question #9 (Topic: Topic 1)
Which of the following route attributes must be equal for static routes to be eligible for equal cost multipath (ECMP) routing? (Choose two.)
A. Priority B. Metric C. Distance D. Cost
Answer: AC
Question #10 (Topic: Topic 1)
View the exhibit.
[Fortinet-NSE4-FGT-6.0-1.0/xmlfile-7_1.jpg]
Based on this output, which statements are correct? (Choose two.)
A. The all VDOM is not synchronized between the primary and secondary FortiGate devices. B. The root VDOM is not synchronized between the primary and secondary FortiGate devices. C. The global configuration is synchronized between the primary and secondary FortiGate devices. D. The FortiGate devices have three VDOMs.
Answer: BC
Download Exam
Page: 2 / 26
Total 127 questions