Free NSE4-54 Fortinet NSE4-54 Practice Test Question

Loading demo links...

Showing 1–3 of 7 questions

Question 1 (Topic 1)

Which of the following statements about central NAT are true? (Choose two.)

Select an option, then click Submit answer.

  • IP tool references must be removed from existing firewall policies before enabling central NAT.
  • Central NAT can be enabled or disabled from the CLI only.
  • Source NAT, using central NAT, requires at least one central SNAT policy.
  • Destination NAT, using central NAT, requires a VIP object as the destination address in a firewall policy.
Question 2 (Topic 1)

Why must you use aggressive mode when a local FortiGate IPsec gateway hosts multiple dialup tunnels?

Select an option, then click Submit answer.

  • The FortiGate is able to handle NATed connections only with aggressive mode.
  • FortiClient supports aggressive mode.
  • The remote peers are able to provide their peer IDs in the first message with aggressive mode.
  • Main mode does not support XAuth for user authentication.
Question 3 (Topic 1)

An administrator has configured the following settings: What does the configuration do? (Choose two.)

Select an option, then click Submit answer.

  • Reduces the amount of logs generated by denied traffic.
  • Enforces device detection on all interfaces for 30 minutes.
  • Blocks denied users for 30 minutes.
  • Creates a session for traffic being denied.