New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

NSE4 NSE4_FGT-6.2 Syllabus Exam Questions Answers

Fortinet NSE 4 - FortiOS 6.2 Questions and Answers

Question 5

Examine the routing database shown in the exhibit, and then answer the following question:

Which of the following statements are correct? (Choose two.)

Options:

A.

The port3 default route has the highest distance.

B.

The port3 default route has the lowest metric.

C.

There will be eight routes active in the routing table.

D.

The port1 and port2 default routes are active in the routing table.

Question 6

HTTP Public Key Pinning (HPKP) can be an obstacle to implementing full SSL inspection. What solutions could resolve this problem? (Choose two.)

Options:

A.

Enable Allow Invalid SSL Certificates for the relevant security profile.

B.

Change web browsers to one that does not support HPKP.

C.

Exempt those web sites that use HPKP from full SSL inspection.

D.

Install the CA certificate (that is required to verify the web server certificate) stores of users’ computers.

Question 7

Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.

What are the expected actions if traffic matches this IPS sensor? (Choose two.)

Options:

A.

The sensor will gather a packet log for all matched traffic.

B.

The sensor will not block attackers matching the A32S.Botnet signature.

C.

The sensor will block all attacks for Windows servers.

D.

The sensor will reset all connections that match these signatures.

Question 8

Which of the following statements are true when using WPAD with the DHCP discovery method? (Choose two.)

Options:

A.

If the DHCP method fails, browsers will try the DNS method.

B.

The browser needs to be preconfigured with the DHCP server’s IP address.

C.

The browser sends a DHCPONFORM request to the DHCP server.

D.

The DHCP server provides the PAC file for download.