[2024] Valid NSE4_FGT-6.2 test answers & Fortinet NSE4_FGT-6.2 exam pdf [Q78-Q98]

Share

[2024] Valid NSE4_FGT-6.2 test answers & Fortinet NSE4_FGT-6.2 exam pdf

Verified NSE4_FGT-6.2 dumps Q&As - Pass Guarantee or Full Refund

NEW QUESTION # 78
Refer to the following exhibit.



Why is FortiGate not blocking the test file over FTP download?

  • A. FortiGate needs to be operating in flow-based inspection mode in order to scan FTP traffic.
  • B. Deep-inspection must be enabled for FortiGate to fully scan FTP traffic.
  • C. The proxy options profile needs to scan FTP traffic on a non-standard port.
  • D. The FortiSandbox signature database is required to successfully scan FTP traffic.

Answer: C


NEW QUESTION # 79
Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below.

When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?

  • A. Location: server Protocol: SMTP
  • B. ip_src_session
  • C. IMAP.Login.brute.Force
  • D. SMTP.Login.Brute.Force

Answer: C


NEW QUESTION # 80
Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below.

When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?

  • A. Location: server Protocol: SMTP
  • B. ip_src_session
  • C. IMAP.Login.brute.Force
  • D. SMTP.Login.Brute.Force

Answer: C


NEW QUESTION # 81
A team manager has decided that while some members of the team need access to particular website, the majority of the team does not. Which configuration option is the most effective option to support this request?

  • A. Implement web filter authentication for the specified website
  • B. Implement DNS filter for the specified website.
  • C. Implement a web filter category override for the specified website.
  • D. Implement web filter quotas for the specified website.

Answer: C


NEW QUESTION # 82
A company needs to provide SSL VPN access to two user groups. The company also needs to display a different welcome message for each group, on the SSL VPN login.
To meet these requirements, what is required in the SSL VPN configuration?

  • A. Two separate SSL VPNs in different interfaces mapping the same ssl.root
  • B. Different SSL VPN realms for each group
  • C. Different virtual SSL VPN IP addresses for each group
  • D. Two firewall policies with different captive portals

Answer: B


NEW QUESTION # 83
An administrator is investigating a report of users having intermittent issues with browsing the web. The administrator ran diagnostics and received the output shown in the exhibit.

Examine the diagnostic output shown exhibit. Which of the following options is the most likely cause of this issue?

  • A. High memory usage
  • B. High CPU usage
  • C. NAT port exhaustion
  • D. High session timeout value

Answer: C


NEW QUESTION # 84
A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.
Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.

  • A. The two VLAN sub interfaces must have different VLAN IDs.
  • B. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
  • C. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
  • D. The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.

Answer: A

Explanation:
Explanation
FortiGate_Infrastructure_6.0_Study_Guide_v2-Online.pdf -> page 147
"Multiple VLANs can coexist in the same physical interface, provide they have different VLAN ID"


NEW QUESTION # 85
The FSSO collector agent set to advanced access mode for the Windows Active Directory uses which convention?

  • A. RSSO
  • B. NTLM
  • C. LDAP
  • D. Windows

Answer: C


NEW QUESTION # 86
An administrator wants to configure a FortiGate as a DNS server. FotiGate must use a DNS database first, and then relay all irresolvable queries to an external DNS server. Which of the following DNS methods must you use?

  • A. Forward to primary and secondary DNS
  • B. Non-recursive
  • C. Recursive
  • D. Forward to system DNS

Answer: C


NEW QUESTION # 87
Examine the exhibit, which shows the partial output of an IKE real-time debug.

Which of the following statement about the output is true?

  • A. Remote is the host name of the remote IPsec peer.
  • B. Phase 1 went down.
  • C. The VPN is configured to use pre-shared key authentication.
  • D. Extended authentication (XAuth) was successful.

Answer: C


NEW QUESTION # 88
A FortiGate device has multiple VDOMs. Which statement about an administrator account configured with the default prof_admin profile is true?

  • A. It cannot have access to more than one VDOM.
  • B. It can create administrator accounts with access to the same VDOM.
  • C. It can upgrade the firmware on the FortiGate device.
  • D. It can reset the password for the admin account.

Answer: A


NEW QUESTION # 89
Refer to the exhibit.

A firewall administrator must configure equal cost multipath (ECMP) routing on FGT1 to ensure both port1 and port3 links are used, at the same time, for all traffic destined for 172.20.2.0/24.
Given the network diagram shown in the exhibit, which two static routes will satisfy this requirement on FGT1?
(Choose two.)

  • A. 172.20.2.0/24 [1/0] via 10.10.1.2, port1 [0/0]
  • B. 172.20.2.0/24 [25/0] via 10.30.3.2, port3 [5/0]
  • C. 172.20.2.0/24 [25/0] via 10.10.1.2, port1 [5/0]
  • D. 172.20.2.0/24 [1/150] via 10.30.3.2, port3 [10/0]

Answer: B,C


NEW QUESTION # 90
How do you format the FortiGate flash disk?

  • A. Load the hardware test (HQIP) image.
  • B. Load a debug FortiOS image.
  • C. Select the format boot device option from the BIOS menu.
  • D. Execute the CLI command execute formatlogdisk.

Answer: C


NEW QUESTION # 91
Examine the routing database shown in the exhibit, and then answer the following question:

Which of the following statements are correct? (Choose two.)

  • A. There will be eight routes active in the routing table.
  • B. The port1 and port2 default routes are active in the routing table.
  • C. The port3 default route has the highest distance.
  • D. The port3 default route has the lowest metric.

Answer: B,C


NEW QUESTION # 92
What three FortiGate components are tested during the hardware test? (Choose three.)

  • A. Network interfaces
  • B. Hard disk
  • C. Administrative access
  • D. CPU
  • E. HA heartbeat

Answer: A,B,D


NEW QUESTION # 93
You are configuring the root FortiGate to implement the security fabric. You are configuring port10 to communicate with a downstream FortiGate. View the default Edit Interface in the exhibit below:

When configuring the root FortiGate to communicate with a downstream FortiGate, which settings are required to be configured? (Choose two.)

  • A. IP/Network Mask.
  • B. Administrative Access: FortiTelemetry.
  • C. Device detection enabled.
  • D. Role: Security Fabric.

Answer: A,B


NEW QUESTION # 94
Which of the following statements about the FSSO collector agent timers is true?

  • A. The workstation verify interval is used to periodically check of a workstation is still a domain member.
  • B. The dead entry timeout interval is used to age out entries with an unverified status.
  • C. The user group cache expiry is used to age out the monitored groups.
  • D. The IP address change verify interval monitors the server IP address where the collector agent is installed, and the updates the collector agent configuration if it changes.

Answer: B


NEW QUESTION # 95
An administrator has enabled the DHCP Server on the port1 interface and configured the following based on the exhibit.

Which statement is correct based on this configuration?
Response:

  • A. The MAC address 00:0c:29:29:38:da belongs to the port1 interface.
  • B. The IP address 10.0.1.254 is reserves for the device with the MAC address 00:0c:29:29:38:da.
  • C. 00:0c:29:29:38:da is the virtual MAC address assigned to the secondary IP address (10.0.1.254) of the port1 interface.
  • D. Access to the network is blocked for the devices with the MAC address 00:0c:29:29:38:da and the IP address 10.0.1.254.

Answer: B


NEW QUESTION # 96
View the exhibit.

VDOM1 is operating in transparent mode VDOM2 is operating in NAT Route mode. There is an inteface VDOM link between both VDOMs. A client workstation with the IP address 10.0.1.10/24 is connected to port2. A web server with the IP address 10.200.1.2/24 is connected to port1.
What is required in the FortiGate configuration to route and allow connections from the client workstation to the web server? (Choose two.)

  • A. A static or dynamic route in VDOM1 with the subnet 10.200.1.0/24 as the destination.
  • B. One firewall policy in VDOM2 with InterVDOM1 as the source interface and port1 as the destination interface.
  • C. One firewall policy in VDOM1 with port2 as the source interface and InterVDOM0 as the destination interface.
  • D. A static or dynamic route in VDOM2 with the subnet 10.0.1.0/24 as the destination.

Answer: B,C


NEW QUESTION # 97
Examine the network diagram shown in the exhibit, then answer the following question:

Which one of the following routes is the best candidate route for FGT1 to route traffic from the Workstation to the Web server?

  • A. 172.16.32.0/24 is directly connected, port1
  • B. 10.4.200.0/30 is directly connected, port2
  • C. 0.0.0.0/0 [20/0] via 10.4.200.2, port2
  • D. 172.16.0.0/16 [50/0] via 10.4.200.2, port2 [5/0]

Answer: A


NEW QUESTION # 98
......

NSE4_FGT-6.2 Exam Questions – Valid NSE4_FGT-6.2 Dumps Pdf: https://www.testkingpdf.com/NSE4_FGT-6.2-testking-pdf-torrent.html