Official Bank 0/165

Fortinet NSE 4 – FortiOS 6.4 Exam (NSE4_FGT-6.4) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
165 Total Questions
1
Question
Refer to the exhibit.

Exhibit

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up. but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?
Options
A On HQ-FortiGate, set Encryption to AES256.
B On HQ-FortiGate, enable Auto-negotiate.
C On Remote-FortiGate, set Seconds to 43200.
D On HQ-FortiGate, enable Diffie-Hellman Group 2.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not Which configuration option is the most effective way to support this request?
Options
A Implement web filter authentication for the specified website.
B Implement a DNS filter for the specified website.
C Implement a web filter category override for the specified website
D Implement web filter quotas for the specified website
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which of the following statements about central NAT are true? (Choose two.)
Select 2
Options
A Destination NAT, using central NAT, requires a VIP object as the destination address in a firewall.
B Central NAT can be enabled or disabled from the CLI only.
C IP tool references must be removed from existing firewall policies before enabling central NAT.
D Source NAT, using central NAT, requires at least one central SNAT policy.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service.

What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
Options
A Pre-shared Key
B Static IP Address
C Dialup User
D Dynamic DNS
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Exhibit:

Refer to the exhibit to view the authentication rule configuration In this scenario, which statement is true?
Options
A Policy-based authentication is enabled
B Route-based authentication is enabled
C IP-based authentication is enabled
D Session-based authentication is enabled.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.