Fortinet NSE 4 - FortiOS 6.0 - NSE4_FGT-6.0 Exam Practice Test
View the following exhibit, which shows the firewall policies and the object uses in the firewall policies.


The administrator is using the Policy Lookup feature and has entered the search create shown in the following exhibit.

Which of the following will be highlighted based on the input criteria?


The administrator is using the Policy Lookup feature and has entered the search create shown in the following exhibit.

Which of the following will be highlighted based on the input criteria?
Correct Answer: B
Which of the following statements about policy-based IPsec tunnels are true? (Choose two.)
Correct Answer: C,D
Examine the exhibit, which shows the partial output of an IKE real-time debug.

Which of the following statement about the output is true?

Which of the following statement about the output is true?
Correct Answer: C
Examine the exhibit, which contains a virtual IP and firewall policy configuration.



The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address
10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?



The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address
10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?
Correct Answer: D
Examine the exhibit, which shows the partial output of an IKE real-time debug.

Which of the following statement about the output is true?

Which of the following statement about the output is true?
Correct Answer: C
If traffic matches a DLP filter with the action set to Quarantine IP Address, what action does FortiGate take?
Correct Answer: A
Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.


An administrator has configured the WINDOS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?


An administrator has configured the WINDOS_SERVERS IPS sensor in an attempt to determine whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this?
Correct Answer: A
Which statement is true regarding the policy ID number of a firewall policy?
Correct Answer: C
Examine this output from a debug flow:

Which statements about the output are correct? (Choose two.)

Which statements about the output are correct? (Choose two.)
Correct Answer: A,D
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
Correct Answer: C,D