Free NSE4-54 Fortinet NSE4-54 Practice Test Question

Loading demo links...

Showing 4–6 of 7 questions

Question 4 (Topic 1)

An administrator wants to create a policy-based IPsec VPN tunnel between two FortiGate devices. Which configuration steps must be performed on both units to support this scenario? (Choose three.)

Select an option, then click Submit answer.

  • Define the phase 2 parameters.
  • Set the phase 2 encapsulation method to transport mode.
  • Define at least one firewall policy, with the action set to IPsec.
  • Define a route to the remote network over the IPsec tunnel.
  • Define the phase 1 parameters, without enabling IPsec interface mode.
Question 5 (Topic 1)

View the exhibit. In this scenario, FGT1 has the following routing table: S* 0. 0. 0. 0/0 [10/0] via 10. 40. 72. 2, port1 C 172. 16. 32. 0/24 is directly connected, port2 C 10. 40. 72. 0/30 is directly connected, port1 A user at 192.168.32.15 is trying to access the web server at 172.16.32.254. Which of the following statements best describe how the FortiGate will perform reverse path forwarding checks on this traffic? (Choose two.)

Select an option, then click Submit answer.

  • Strict RPF check will deny the traffic.
  • Strict RPF check will allow the traffic.
  • Loose RPF check will allow the traffic.
  • Loose RPF check will deny the traffic.
Question 6 (Topic 1)

Which statements about the firmware upgrade process on an active-active high availability (HA) cluster are true? (Choose two.)

Select an option, then click Submit answer.

  • The firmware image must be manually uploaded to each FortiGate.
  • Only secondary FortiGate devices are rebooted.
  • Uninterruptable upgrade is enabled by default.
  • Traffic load balancing is temporally disabled while upgrading the firmware.