View the exhibit:

Which the FortiGate handle web proxy traffic rue? (Choose two.)
A. Traffic between port1-VLAN1 and port2-VLAN1 is allowed by default.
B. port-VLAN1 is the native VLAN for the port1 physical interface.
C. port1-VLAN10 and port2-VLAN10 can be assigned to different VDOMs.
D. Broadcast traffic received in port1-VLAN10 will not be forwarded to port2-VLAN10.
正解:C,D
質問 2:
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
A. Detection engine
B. Antivirus engine
C. Flow engine
D. Intrusion prevention system engine
正解:D
質問 3:
Refer to the exhibits.


The exhibits show the SSL and authentication policy (Exhibit A) and the security policy (Exhibit B) tor Facebook.
Users are given access to the Facebook web application. They can play video content hosted on Facebook but they are unable to leave reactions on videos or other types of posts.
Which part of the policy configuration must you change to resolve the issue?
A. Force access to Facebook using the HTTP service.
B. Add Facebook in the URL category in the security policy.
C. Additional application signatures are required to add to the security policy.
D. The SSL inspection needs to be a deep content inspection.
正解:D
質問 4:
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?
A. Add user accounts to Active Directory (AD).
B. Add user accounts to the Ignore User List.
C. Add the support of NTLM authentication.
D. Add user accounts to the FortiGate group fitter.
正解:B
質問 5:
Which two statements are correct about a software switch on FortiGate? (Choose two.)
A. It can group only physical interfaces
B. All interfaces in the software switch share the same IP address
C. It can be configured only when FortiGate is operating in NAT mode
D. Can act as a Layer 2 switch as well as a Layer 3 router
正解:B,C
質問 6:
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)
A. auth-on-demand
B. new-session
C. soft-timeout
D. hard-timeout
E. Idle-timeout
正解:B,D,E
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.
What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
A. Dynamic DNS
B. Pre-shared Key
C. Static IP Address
D. Dialup User
正解:D
铃木** -
一度試験にNSE4_FGT-6.4合格しました。今後、引き続く参考書を利用します。一発合格を目的にした問題集だけあります。効率よく勉強ができました!