Fortinet Network Security Expert 4 Written Exam (400) Sample Questions:
1. Which of the following actions can be used with the FortiGuard quota feature? (Choose three.)
A) Allow
B) Authenticate
C) Warning
D) Block
E) Monitor
2. Which of the following statements are correct regarding SSL VPN Web-only mode?
(Choose two.)
A) It is not possible to connect to SSH servers through the VPN.
B) It can only be used to connect to web services.
C) Access to internal network resources is possible from the SSL VPN portal.
D) IP traffic is encapsulated over HTTPS.
E) The standalone FortiClient SSL VPN client CANNOT be used to establish a Web-only
SSL VPN.
3. Which statement is not correct regarding SSL VPN Tunnel mode?
A) A limited amount of IP applications are supported.
B) The FortiGate device will dynamically assign an IP address to the SSL VPN network adapter.
C) IP traffic is encapsulated over HTTPS.
D) The standalone FortiClient SSL VPN client can be used to establish a Tunnel mode SSL
VPN.
4. FSSO provides a single sign on solution to authenticate users transparently to a FortiGate unit using credentials stored in Windows active directory.
Which of the following statements are correct regarding FSSO in a Windows domain environment when DC-agent mode is used? (Choose two.)
A) The FSSO collector agent will receive user logon information from the domain controller agent and will send it to the FortiGate unit.
B) An FSSO collector agent must be installed on every domain controller.
C) An FSSO domain controller agent must be installed on every domain controller.
D) The FSSO domain controller agent will regularly update user logon information on the
FortiGate unit.
5. Examine the network topology diagram in the exhibit; the workstation with the IP address
2 12.10.11.110 sends a TCP SYN packet to the workstation with the IP address
2 12.10.11.20.
Which of the following sentences best describes the result of the reverse path forwarding
(RFP) check executed by the FortiGate on the SYN packets? (Choose two).
A) Packets is allowed if RPF is configured as strict.
B) Packets is blocked if RPF is configured as loose.
C) Packets is blocked if RPF is configured as strict.
D) Packets is allowed if RPF is configured as loose.
Solutions:
Question # 1 Answer: B,C,E | Question # 2 Answer: C,D | Question # 3 Answer: A | Question # 4 Answer: A,C | Question # 5 Answer: C,D |