良質なNSE4_FGT-6.4のPDF問題集でNSE4_FGT-6.4試験問題を試せます [Q42-Q59]

Share

良質なNSE4_FGT-6.4のPDF問題集でNSE4_FGT-6.4試験問題を試せます

一番最新のFortinet NSE4_FGT-6.4試験問題集PDF2022年更新


Fortinet NSE4_FGT-6.4 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • IPS、DoS、およびWAFを構成して、ネットワークをハッキングやDDoS攻撃から保護します
  • マルウェアの脅威を中和するためのウイルス対策スキャンモードを説明および構成します
トピック 2
  • FortiGateインターフェースまたはVDOMをレイヤー2デバイスとして機能しすぎるように構成する
  • フォーティネットセキュリティファブリックを実装する
トピック 3
  • ネットワークアプリケーションを監視および制御するためのアプリケーション制御の構成
  • ファイアウォールポリシーNATおよび中央NATの動作の特定と構成
トピック 4
  • FortiGateデバイスを複数の仮想デバイスに分割するためのVDOMの説明と設定
  • 証明書を使用した暗号化されたトラフィックの説明と検査
トピック 5
  • プライベートネットワークへの安全なアクセスを提供するために、さまざまなSSL-VPNモードを構成および実装します
  • 初期構成を実行します
トピック 6
  • 静的およびポリシーベースのルートを使用してパケットを構成およびルーティングします
  • ログ設定を構成し、ログを使用して問題を診断します

 

質問 42
Examine this output from a debug flow:

Why did the FortiGate drop the packet?

  • A. It failed the RPF check.
  • B. It matched the default implicit firewall policy.
  • C. The next-hop IP address is unreachable.
  • D. It matched an explicitly configured firewall policy with the action DENY.

正解: B

解説:
https://kb.fortinet.com/kb/documentLink.do?externalID=13900

 

質問 43
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile.
What order must FortiGate use when the web filter profile has features enabled, such as safe search?

  • A. Static URL filter, FortiGuard category filter, and advanced filters
  • B. FortiGuard category filter and rating filter
  • C. DNS-based web filter and proxy-based web filter
  • D. Static domain filter, SSL inspection filter, and external connectors filters

正解: D

解説:
Explanation/Reference: https://fortinet121.rssing.com/chan-67705148/all_p1.html

 

質問 44
Refer to the exhibit.

Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct If option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?

  • A. The IPS engine was inspecting high volume of traffic.
  • B. The IPS engine was blocking all traffic.
  • C. The IPS engine was unable to prevent an intrusion attack.
  • D. The IPS engine will continue to run in a normal state.

正解: B

 

質問 45
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

  • A. Captive portal is enabled in the interface.
  • B. The interface has been configured for one-arm sniffer.
  • C. The operation mode is transparent.
  • D. The interface is a member of a virtual wire pair.
  • E. The interface is a member of a zone.

正解: B,C,D

解説:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new- 54/Top_VirtualWirePair.htm

 

質問 46
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?

  • A. The CA certificate that signed the web-server certificate must be installed on the browser.
  • B. The public key of the web servercertificate must be installed on the browser.
  • C. The web-server certificate must be installed on the browser.
  • D. The private key of the CA certificate that signed the browser certificate must be installed on the browser.

正解: A

 

質問 47
Which three criteria can a FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)

  • A. Highest to lowest priority defined in the firewall policy.
  • B. Lowest to highest policy ID number.
  • C. Services defined in the firewall policy.
  • D. Destination defined as Internet Services in the firewall policy.
  • E. Source defined as Internet Services in the firewall policy.

正解: C,D,E

 

質問 48
Refer to the exhibit.

Which contains a Performance SLA configuration.
An administrator has configured a performance SLA on FortiGate. Which failed to generate any traffic. Why is FortiGate not generating any traffic for the performance SLA?

  • A. There may not be a static route to route the performance SLA traffic.
  • B. The Ping protocol is not supported for the public servers that are configured.
  • C. Participants configured are not SD-WAN members.
  • D. You need to turn on the Enable probe packets switch.

正解: C

 

質問 49
Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below.

When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?

  • A. ip_src_session
  • B. IMAP.Login.brute.Force
  • C. SMTP.Login.Brute.Force
  • D. Location: server Protocol: SMTP

正解: B

 

質問 50
Refer to the exhibit.

The exhibit shows the IPS sensor configuration.
If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will gather a packet log for all matched traffic.
  • B. The sensor will allow attackers matching the NTP.Spoofed.KoD.DoS signature.
  • C. The sensor will reset all connections that match these signatures.
  • D. The sensor will block all attacks aimed at Windows servers.

正解: B,D

 

質問 51
Refer to the exhibit.

Which contains a session list output. Based on the information shown in the exhibit, which statement is true?

  • A. Overload NAT IP pool is used in the firewall policy.
  • B. Destination NAT is disabled in the firewall policy.
  • C. One-to-one NAT IP pool is used in the firewall policy.
  • D. Port block allocation IP pool is used in the firewall policy.

正解: B

 

質問 52
Which three methods are used by the collector agent for AD polling? (Choose three.)

  • A. FortiGate polling
  • B. WinSecLog
  • C. WMI
  • D. Novell API
  • E. NetAPI

正解: B,C,E

 

質問 53
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

  • A. The subject field in the server certificate
  • B. The server name indication (SNI) extension in the client hello message
  • C. The serial number in the server certificate
  • D. The host field in the HTTP header
  • E. The subject alternative name (SAN) field in the server certificate

正解: C,D,E

 

質問 54
A FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) sub interfaces added to the physical interface.
Which statements about the VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.

  • A. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
  • B. The two VLAN sub interfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
    FortiGate_Infrastructure_6.0_Study_Guide_v2-Online.pdf -> page 147
    "Multiple VLANs can coexist in the same physical interface, provide they have different VLAN ID"
  • C. The two VLAN sub interfaces can have the same VLAN ID, only if they belong to different VDOMs.
  • D. The two VLAN sub interfaces must have different VLAN IDs.

正解: D

 

質問 55
An administrator has configured a strict RPF check on FortiGate. Which statement is true about the strict RPF check?

  • A. Strict RPF checks only for the existence of at cast one active route back to the source using the incoming interface.
  • B. Strict RPF allows packets back to sources with all active routes.
  • C. The strict RPF check is run on the first sent and reply packet of any new session.
  • D. Strict RPF checks the best route back to the sourceusingtheincoming interface.

正解: C

 

質問 56
Exhibit:

Refer to the exhibit to view the authentication rule configuration In this scenario, which statement is true?

  • A. IP-based authentication is enabled
  • B. Session-based authentication is enabled.
  • C. Policy-based authentication is enabled
  • D. Route-based authentication is enabled

正解: B

 

質問 57
An administrator has configured a route-based IPsec VPN between two FortiGate devices. Which statement about this IPsec VPN configuration is true?

  • A. A phase 2 configuration is not required.
  • B. The IPsec firewall policies must be placed at the top of the list.
    In a route-based configuration, FortiGate automatically adds a virtual interface eith the VPN name (Infrastructure Study Guide, 206)
  • C. This VPN cannot be used as part of a hub-and-spoke topology.
  • D. A virtual IPsec interface is automatically created after the phase 1 configuration is completed.

正解: D

 

質問 58
Examine the exhibit, which contains a virtual IP and firewall policy configuration.



The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?

  • A. 10.200.1.10
  • B. 10.200.1.1
  • C. Any available IP address in the WAN (port1) subnet 10.200.1.0/24
  • D. 10.0.1.254
    https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Objects/Virtual%20IPs.htm

正解: C

 

質問 59
......

100%無料Fortinet NSE 4 NSE4_FGT-6.4問題集PDFお試しサンプル認定ガイドカバー率:https://www.passtest.jp/Fortinet/NSE4_FGT-6.4-shiken.html