Free NSE4-FGT-62 Fortinet NSE4-FGT-62 Practice Test Question

Loading demo links...

Showing 7–9 of 12 questions

Question 7 (Topic 1)

An administrator has configured a route-based IPsec VPN between two FortiGate devices. Which statement about this IPsec VPN configuration is true?

Select an option, then click Submit answer.

  • A phase 2 configuration is not required.
  • This VPN cannot be used as part of a hub-and-spoke topology.
  • A virtual IPsec interface is automatically created after the phase 1 configuration is completed.
  • The IPsec firewall policies must be placed at the top of the list.
Question 8 (Topic 1)

Refer to the exhibit. The exhibit shows two static routes. Which option accurately describes how FortiGate will handle these two routes to the same destination?

Select an option, then click Submit answer.

  • FortiGate will only activate the port1 route in the routing table.
  • FortiGate will use the port1 route as the primary candidate.
  • FortiGate will load balance all traffic across both routes.
  • FortiGate will route twice as much traffic to the port2 route.
Question 9 (Topic 1)

Why must you use aggressive mode when a local FortiGate IPsec gateway hosts multiple dialup tunnels?

Select an option, then click Submit answer.

  • Main mode does not support XAuth for user authentication.
  • In aggressive mode, the remote peers are able to provide their peer IDs in the first message.
  • FortiGate is able to handle NATed connections only in aggressive mode.
  • FortiClient supports only aggressive mode.