Fortinet Network Security Expert 4 Written Exam (400) - NSE4 Exam Practice Test

Examine the exhibit below; then answer the question following it.

In this scenario. The FortiGate unit in Ottawa has the following routing table:
s*0.0.0.0/0 [10/0] via 172.20.170.254, port2
c172.20.167.0/24 is directly connected, port1
c172.20.170.0/24 is directly connected, port2
Sniffer tests show that packets sent from the source IP address 170.20.168.2 to the destination IP address 172.20.169.2 are being dropped by the FortiGate located in Ottawa.
Which of the following correctly describes the cause for the dropped packets?
Correct Answer: C
Which define device identification? (Choose two.)
Correct Answer: A,C
Examine the exhibit; then answer the question below.

Which statement describes the green status indicators that appear next to the different
FortiGuard Distribution Network services as illustrated in the exhibit?
Correct Answer: C
Examine the following FortiGate web proxy configuration; then answer the question below:
config web-proxy explicit
set pac-file-server-status enable
set pac-file-server-port 8080
set pac-file-name wpad.dat
end
Assuming that the FortiGate proxy IP address is 10.10.1.1, which URL must an Internet browser use to download the PAC file?
Correct Answer: B
What methods can be used to deliver the token code to a user that is configured to use two-factor authentication? (Choose three.)
Correct Answer: C,D,E
Which of the following statements are true regarding the web filtering modes? (Choose two.)
Correct Answer: B,D
Which of the following authentication methods are supported in an IPsec phase 1?
(Choose two.)
Correct Answer: C,D
Which statement best describes the objective of the SYN proxy feature available in SP processors?
Correct Answer: D
Which of the following items is NOT a packet characteristic matched by a firewall service object?
Correct Answer: B