Pass Your Next Certification Exam Fast! - ITBraindumps

Everything you need to prepare, learn & pass your certification exam easily.

Exam NSE4 Valid Test Cram Materials Braindumps

Valid NSE4 Dumps shared by NewPassLeader for Helping Passing NSE4 Exam! NewPassLeader now offer the newest NSE4 exam dumps, the NewPassLeader NSE4 exam questions have been updated and answers have been corrected get the newest NewPassLeader NSE4 dumps with Test Engine here:

http://https://www.newpassleader.com/Fortinet/NSE4-exam-preparation-materials.html (303 Q&As Dumps, 30%OFF Special Discount: 30free )


NEW QUESTION NO: 7
If traffic matches a DLP filter with the action set to Quarantine IP Address, what action does the FortiGate take?
A. It archives the data for that IP address.
B. It blocks all future traffic for that IP address for a configured interval.
C. It provides a DLP block replacement page with a link to download the file.
D. It notifies the administrator by sending an email.
Answer: B

NEW QUESTION NO: 8
Which statements about antivirus scanning using flow-based full scan are true? (Choose two.)
A. It does not support FortiSandbox inspection.
B. The antivirus engine starts scanning a file after the last packet arrives.
C. FortiGate can insert the block replacement page during the first connection attempt only if a virus is detected at the start of the TCP stream.
D. It uses the compact antivirus database.
Answer: B,C

NEW QUESTION NO: 9
View the exhibit.

Based on this output, which statements are correct? (Choose two.)
A. By default, the FortiGate blocks new sessions.
B. FortiGate changed the global av-failopen settings to idledrop.
C. FortiGate has entered in to system conserve mode.
D. FortiGate generated an event log for system conserve mode.
Answer: A,C

NEW QUESTION NO: 10
What information is flushed when the chunk-size value is changed in the config dlp settings?
A. The supported file types in the DLP filters
B. The file name patterns in the DLP filters
C. The archived files and messages
D. The database for DLP document fingerprinting
Answer: D

NEW QUESTION NO: 11
An administrator has configured a dialup IPsec VPN with XAuth. Which method statement best describes this scenario?
A. Dialup clients must provide their local ID during phase 2 negotiations.
B. Dialup clients must provide a username and password for authentication.
C. Phase 1 negotiations will skip pre-shared key exchange.
D. Only digital certificates will be accepted as an authentication method in phase 1.
Answer: B

NEW QUESTION NO: 12
Which statements about IP-based explicit proxy authentication are true? (Choose two.)
A. Sessions from the same source address are treated as a single user.
B. IP-based authentication consumes less FortiGate's memory than session-based authentication.
C. FortiGate remembers authenticated sessions using browser cookies.
D. IP-based authentication is best suited to authenticating users behind a NAT device.
Answer: A,B

NEW QUESTION NO: 13
Which traffic sessions can be offloaded to a NP6 processor? (Choose two.)
A. RIP
B. GRE
C. IPv6
D. NAT64
Answer: C,D

NEW QUESTION NO: 14

What does the configuration do? (Choose two.)
A. Blocks denied users for 30 minutes.
B. Reduces the amount of logs generated by denied traffic.
C. Creates a session for traffic being denied.
D. Enforces device detection on all interfaces for 30 minutes.
Answer: B,C

NEW QUESTION NO: 15
Which file names will match the *.tiff file name pattern configured in a data leak prevention filter? (Choose two.)
A. tiff.tiff
B. tiff.jpeg
C. tiff.png
D. gif.tiff
Answer: A,D

NEW QUESTION NO: 16
Which of the following statements about policy-based IPsec tunnels are true? (Choose two.)
A. They can be configured in both NAT/Route and transparent operation modes.
B. They support L2TP-over-IPsec.
C. They support GRE-over-IPsec.
D. They require two firewall policies: one for each direction of traffic flow.
Answer: A,D

NEW QUESTION NO: 17
What step is required to configure an SSL VPN to access to an internal server using port forward mode?
A. Create a SSL VPN realm reserved for clients using port forward mode.
B. Install FortiClient SSL VPN client
C. Configure the virtual IP addresses to be assigned to the SSL VPN users.
D. Configure the client application to forward IP traffic to a Java applet proxy.
Answer: D


Posted 2018/7/3 15:04:11  |  Category: Fortinet  |  Tag: NSE4 Valid Test Cram MaterialsNSE4 Latest Exam Collection SheetNSE4Fortinet