Complete list of current Q & A>> Download Fortinet Network Security Professional (Expert) (NSE-4) – Quiz 1 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 1. Which three statements about a flow-based antivirus profile are correct? (Choose three.) A. IPS engine handles the process as a standalone. B. FortiGate buffers the whole file but transmits to the client simultaneously. C. If the virus is detected, the last packet is delivered to the client. D. Optimized performance compared to proxy-based inspection. E. Flow-based inspection uses a hybrid of scanning modes available in proxy- based inspection 2 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 2. If Internet Service is already selected as Source in a firewall policy, which other configuration objects can beadded to the Source filed of a firewall policy? A. IP address B. Once Internet Service is selected, no other object can be added C. User or User Group D. FQDN address 3 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 3. Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.) A. DNS B. ping C. udp-echo D. TWAMP 4 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 4. A team manager has decided that, while some members of the team need access to a particular website, themajority of the team does not Which configuration option is the most effective way to support this request? A. Implement a web filter category override for the specified website B. Implement a DNS filter for the specified website. C. Implement web filter quotas for the specified website D. Implement web filter authentication for the specified website. 5 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 5. Which two types of traffic are managed only by the management VDOM? (Choose two.) A. FortiGuard web filter queries B. PKI C. Traffic shaping D. DNS 6 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 6. An organization’s employee needs to connect to the office through a high-latency internet connection.Which SSL VPN setting should the administrator adjust to prevent the SSL VPN negotiation failure? A. Change the session-ttl. B. Change the login timeout. C. Change the idle-timeout. D. Change the udp idle timer. 7 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 7. Which two statements are true about the RPF check? (Choose two.) A. The RPF check is run on the first sent packet of any new session. B. The RPF check is run on the first reply packet of any new session. C. The RPF check is run on the first sent and reply packet of any new session. D. RPF is a mechanism that protects FortiGate and your network from IP spoofing attacks. 8 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 8. Which three CLI commands can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.) A. diagnose sys top B. execute ping C. execute traceroute D. diagnose sniffer packet any E. get system arp 9 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 9. What inspection mode does FortiGate use if it is configured as a policy-based next-generation firewall(NGFW)? A. Full Content inspection B. Proxy-based inspection C. Certificate inspection D. Flow-based inspection 10 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 10. In an explicit proxy setup, where is the authentication method and database configured? A. Proxy Policy B. Authentication Rule C. Firewall Policy D. Authentication scheme 11 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 11. Which two statements are true when FortiGate is in transparent mode? (Choose two.) A. By default, all interfaces are part of the same broadcast domain. B. The existing network IP schema must be changed when installing a transparent mode. C. Static routes are required to allow traffic to the next hop. D. FortiGate forwards frames without changing the MAC address. 12 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 12. On FortiGate, which type of logs record information about traffic directly to and from the FortiGate management IP addresses? A. System event logs B. Forward traffic logs C. Local traffic logs D. Security logs 13 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 13. An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement? A. Configure Source IP Pools. B. Configure split tunneling in tunnel mode. C. Configure different SSL VPN realms. D. Configure host check 14 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 14. Which CLI command will display sessions both from client to the proxy and from the proxy to the servers? A. diagnose wad session list B. diagnose wad session list | grep hook-pre&&hook-out C. diagnose wad session list | grep hook=pre&&hook=out D. diagnose wad session list | grep "hook=pre"&"hook=out" 15 / 15 Category: Fortinet Network Security Expert 4 (NSE-4) 15. How does FortiGate act when using SSL VPN in web mode? A. FortiGate acts as an FDS server. B. FortiGate acts as an HTTP reverse proxy. C. FortiGate acts as DNS server. D. FortiGate acts as router. Your score is 0% Restart quiz Send feedback