Want to pass your Fortinet NSE 4 - FortiOS 5.6 NSE4_FGT-5.6 exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
Which statements about FortiGate inspection modes are true?
(Choose two.)
Response:
A. The default inspection mode is proxy based.
B. Switching from proxy-based mode to flow-based, then back to proxy-based mode, will not result in the original configuration.
C. Proxy-based inspection is not available in VDOMs operating in transparent mode.
D. Flow-based profiles must be manually converted to proxy-based profiles before changing the inspection mode from flow based to proxy based.
View the exhibit.
In this scenario, FGT1 has the following routing table: S*0. 0. 0. 0/0 [10/0] via 10. 40.
72. 2, port1 C172. 16. 32. 0/24 is directly connected, port2
C10. 40. 72. 0/30 is directly connected, port1
A user at 192.168.32.15 is trying to access the web server at 172.16.32.254. Which of the following
statements best describe how the FortiGate will perform reverse path forwarding checks on this traffic?
(Choose two.)
Response:
A. Strict RPF check will deny the traffic.
B. Strict RPF check will allow the traffic.
C. Loose RPF check will allow the traffic.
D. Loose RPF check will deny the traffic.
What is eXtended Authentication (XAuth)? Response:
A. It is an IPsec extension that forces remote VPN users to authenticate using their credentials (user name and password).
B. It is an IPsec extension that authenticates remote VPN peers using digital certificates.
C. It is an IPsec extension that forces remote VPN users to authenticate using their local ID.
D. It is an IPsec extension that authenticates remote VPN peers using a preshared key.