Browse all practice questions for the Fortinet Network Security Expert (NSE) 4 Certification Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Fortinet NSE 4 Certification Practice Test 2026 – Comprehensive Exam Prep course image
All questions

These questions are part of the practice quiz. Start practicing

  • What feature allows FortiGate devices to separate different security policies for enhanced management?
  • In FortiGate, what does IPS stand for and what is its role?
  • What is an advantage of a hub and spoke IPsec VPN configuration over a fully-meshed configuration?
  • Which requirement pertains to a FortiGate device to support multiple VDOMs?
  • How does FSSO handle the login process in Windows networks?
  • What is a common use case for FortiGate’s Web Filtering feature?
  • What is a requirement for enabling two-factor authentication for local user accounts?
  • Which IPsec configuration mode is used for implementing GRE-over-IPsec VPNs?
  • How can FortiGate reduce network congestion?
  • What does SSL inspection in FortiGate involve?
  • Which statement is correct regarding users that have not authenticated when accessing the Internet through FortiGate?
  • What methods can be used to deliver the token code for two-factor authentication? (Choose three.)
  • What do the green status indicators signify next to the FortiGuard Distribution Network services?
  • What URL must an Internet browser use to download the PAC file from a FortiGate configured with specific settings?
  • What command can you use to check the status of the FortiGate device interfaces?
  • Which statement is correct regarding virus scanning on a FortiGate unit?
  • Which methods are supported by WPAD to automatically learn the URL of a PAC file?
  • What type of access rights can be assigned to FortiGate administrators?
  • What does the acronym NAT stand for in networking?
  • In which process states is it impossible to interrupt/kill a process?
  • What is the maximum number of FortiAnalyzer/FortiManager devices a FortiGate unit can send logs to?
  • Which command is often used to verify the status of an HA cluster?
  • In FortiGate, what is 'Fabric Connector'?
  • What type of web filtering inspection mode focuses on DNS traffic?
  • What is a common use for virtual IP addresses in FortiGate?
  • What is required for two VLAN sub-interfaces on the same physical interface in NAT/Route mode?
  • What is the correct order of criteria for selecting a master unit in a FortiGate HA cluster with override disabled?
  • What is the main outcome of using SSL inspection on a FortiGate device?
  • What is one feature of FortiGate's application control?
  • What is a main application of FortiGate's UTM features?
  • Which statements are true regarding the output from the diagnose sys top command?
  • What happens when a VPN client connects using the given FortiClient IPsec configuration?
  • What action can a FortiGate device take upon detecting a threat?
  • Which feature in FortiGate can automatically block IP addresses exhibiting malicious behavior?
  • How does FortiGate handle logging and reporting?
  • What is the function of Deep Packet Inspection (DPI) in FortiGate?
  • Data leak prevention archiving gives the ability to store files and message data onto a FortiAnalyzer unit for which of the following types of network traffic?
  • For a high availability cluster, which action is most effective in minimizing impact from a single link failure?
  • What is the CAPTCHA feature used for on FortiGate devices?
  • Which feature provides FortiGate devices with their next-generation firewall capabilities?
  • What are security policies in FortiGate used for?
  • Which IP packets can be hardware-accelerated by an NP6 processor?
  • Which statements regarding banned words are correct?
  • Examine the output from the diagnose sys session list command. What does it indicate about the IP address 192.168.1.110?
  • How can FortiGate ensure the integrity of a secure network?
  • From the IPsec diagnostics output, how is the connecting client identified?
  • Which statements accurately describe virtual domains (VDOMs)?
  • In a route-based site-to-site IPsec VPN, what is a correct statement about its configuration?
  • What does the 'FortiOS' operating system manage?
  • Which web filtering inspection modes are capable of inspecting the full URL? (Choose two.)
  • Which of the following statements are true regarding the factory default configuration? (Choose three.)
  • What major benefit does FortiGuard services provide to FortiGate devices?
  • Which statements accurately describe transparent mode operation? (Choose three.)
  • For traffic that does not match any configured firewall policy, what is the default action taken by the FortiGate?
  • Which statement is true regarding the setting "Reserve Management Port for Cluster Member" in HA?
  • How can FortiGate's endpoint control enhance network security?
  • Which of these is NOT a function usually associated with the IPS Sensor?
  • Which CLI command is used to reorder firewall policies?
  • What is a probable cause for dropped packets when using a FortiGate?
  • Which two statements are true regarding firewall policy disclaimers? (Choose two.)
  • Which feature of FortiGate enhances the overall user experience while maintaining security?
  • Which statements are correct regarding an IPv6 over IPv4 IPsec configuration?
  • What is the purpose of a FortiGate Web Proxy?
  • What defines the minimum privileges an administrator has in FortiGate?
  • What is a valid reason for using session-based authentication instead of IP-based authentication?
  • What is a key feature of FortiGate's firewall?
  • In the given routing setup, which statement accurately reflects the configuration?
  • What is the effect of the Disconnect Cluster Member command?
  • Which of the following firewall actions applies to all unauthenticated users attempting to access the network?
  • Which header field can be used in a firewall policy for traffic matching?
  • What methods can be used to access the FortiGate CLI?
  • What does the FortiGate feature 'IPS Sensor' do?
  • Regarding web-only mode SSL VPN, which statement is correct?
  • Which static route is automatically added to the client's routing table when tunnel mode is activated?
  • In a high availability cluster in active-active mode, how is the SYN packet of an HTTP session offloaded to a slave unit processed?
  • What does the FortiGate GUI provide in terms of network management?
  • Which methods are used to detect DoS attacks in IPsec?
  • In traffic shaping, what is typically adjusted to manage network load?
  • What task can a FortiGate device accomplish regarding traffic shaping?
  • What is the purpose of a VDOM in a FortiGate device?
  • What does a FortiGuard subscription typically provide?
  • What type of information does a FortiGate session table store?
  • Which tasks fall under the responsibility of the SSL proxy in a typical HTTPS connection?
  • What statements are true regarding the sessions that the master unit in an active-active cluster is offloading to the slave unit for inspection?
  • How does FortiGate perform antivirus scanning on files?
  • How does FortiGate classify incoming traffic?
  • What functions can the IPv6 Neighbor Discovery protocol accomplish?
  • Which actions are allowed for URL filtering on a FortiGate unit?
  • How does FortiGate protect against malware?
  • What primary function does Fortinet's FortiGate perform with its IPS feature?
  • What is true regarding the static route configuration for IPsec?
  • Which feature enhances the capability of firewall policies on a FortiGate?
  • Which settings need to be applied for traffic routing between multiple VDOMs?
  • What occurs when configuring multiple static routes with identical metrics?
  • Which statement is true regarding the firewall policy authentication timeout?
  • Regarding the IPsec phase 1 configuration, which statement is correct?
  • Which of the following statements is a requirement for session maintenance during failover in HA?
  • Which protocol can be used for remote authentication in FortiGate?
  • Which statements are valid regarding port pairing and forwarding domains? (Choose two.)
  • How can VPN tunnels be monitored on a FortiGate device?
  • What is the result of the configuration command 'set stp-forward enable' on a FortiGate in transparent mode?
  • How does FortiGate handle DoS attacks?
  • What configuration allows load sharing between two static routes on FortiGate?
  • Given two devices in an HA cluster, which statement can be concluded based on session statistics? (Choose two.)
  • When does a FortiGate perform a routing table lookup for TCP traffic in NAT/Route mode?
  • What best describes the role of an FSSO domain controller agent?
  • What is a ‘policy route’ in FortiGate?
  • What types of authentication can be configured for FortiGate firewall users?
  • Which statements are true regarding traffic shaping in an application sensor and firewall policy? (Choose two.)
  • Which firewall objects can be included in the Destination Address field of a firewall policy? (Choose three.)
  • Which statement is true regarding administrative access to a VDOM with FortiGate?
  • What is the main function of VDOMs in FortiGate?
  • What is the function of application control in network security?
  • How can you apply traffic shaping to P2P traffic like BitTorrent on a FortiGate?
  • How many types of NAT can generally be configured on FortiGate devices?
  • Which of the following is a characteristic of IPsec?
  • What is the main purpose of FortiGate's VPN technology?
  • What is a 'security fabric' in the context of FortiGate?
  • Which statement accurately describes the log message for the ICMP flood anomaly?
  • Which of the following describes a core capability of the FortiGate IPS feature?
  • Which type of filtering can FortiGate perform besides URL filtering?
  • When creating FortiGate administrative users, which configuration objects specify the account rights?
  • What best describes the process of regularly applying updates to FortiGate configurations?
  • What role does FortiClient play in network security?
  • Which statements are true about offloading antivirus inspection to a Security Processor (SP)?
  • What is a common characteristic of a fully meshed VPN configuration?
  • How can FortiGate segregate traffic between different departments in a company?
  • Which command would you use to gather system status information in a FortiGate device?
  • What is a potential outcome of effective IPS Sensor implementation?
  • Which IPsec mode includes peer ID information in the first packet?
  • Which protocol is used for monitoring Fortinet devices while ensuring secure communication?
  • Bob wants to send Alice a file that is encrypted using public key cryptography. Which of the following statements is correct regarding the use of public key cryptography in this scenario?
  • What is an advantage of using SNMP v3 instead of SNMP v1/v2 when querying a FortiGate unit?
  • What is one primary use of NAT in FortiGate devices?
  • What is the function of a management VDOM in FortiGate architecture?
  • Which antivirus inspection mode must be used to scan SMTP, FTP, POP3 and SMB protocols?
  • What is required to use SSL inspection on a FortiGate device?
  • In transparent mode, the forward-domain is a CLI setting associated with which component?
  • What does the command diagnose ips anomaly list provide?
  • In terms of security policy, how does FortiGate operate?
  • What is the outcome of executing the command 'diagnose sys ha reset-uptime'?
  • What is the advantage of using FortiAnalyzer alongside FortiGate?
  • What is a responsibility of the FSSO collector agent?
  • What type of attacks can FortiGate specifically identify and mitigate?
  • What primary type of network activity does the IPS Sensor focus on?
  • How can administrators ensure their FortiGate devices are up to date with security features?
  • Which of the following is a characteristic of static routes on FortiGate devices?
  • Why might a newly added static route not show up in the routing table?
  • Which service can be utilized to enhance FortiGate's logging capabilities?
  • Which condition must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?
  • When firewall policy authentication is enabled, which protocols can trigger an authentication challenge? (Choose two.)
  • How are Fortinet products positioned in the cybersecurity landscape?
  • Which statements are true regarding the use of a PAC file for web proxy settings?
  • What is the significance of configuring schedule in FortiGate firewall policies?
  • What does the IPS sensor filter configuration imply?
  • How is the FortiGate password recovery process initiated?
  • Which protocol is most commonly used for site-to-site VPNs in FortiGate?
  • What is the recommended method to secure remote access into a FortiGate unit?
  • What are the requirements for an HA cluster to maintain TCP connections after a device failover?
  • What is the effect of setting the default session timeout to 1800 seconds in the system configuration?
  • Which protocol does FortiGate typically use for VPN connections?
  • What are valid options for handling DNS requests sent directly to a FortiGate’s interface IP? (Choose three.)
  • What capabilities can a FortiGate provide?
  • What is the most likely reason for an HA cluster failure if two devices do not form a cluster?
  • What role does logging play in FortiGate security policies?
  • Which feature in Fortinet helps manage bandwidth allocation across a network?
  • Which of the following scenarios would most likely require the use of an IPS Sensor?
  • What feature enables FortiGate to encrypt traffic between its interfaces and external networks?
  • When the SSL proxy is NOT doing man-in-the-middle interception of SSL traffic, which certificate field can be used to determine the rating of a website?
  • What aspect of firewall policy users must accept before proceeding with Internet access?
  • Which of the following is a key purpose of intrusion prevention signatures in FortiGate?
  • Which of the following can trigger an authentication challenge for firewall policy?
  • Why is it important for IPS Sensors to analyze both incoming and outgoing traffic?
  • What is the primary benefit of using VLANs in FortiGate configurations?
  • Which method can be used for securing remote connections in a FortiGate environment?
  • Which network protocols are supported for administrative access to a FortiGate unit?
  • What is the purpose of web filtering in FortiGate?
  • Which statement is one disadvantage of using FSSO NetAPI polling mode over FSSO Security Event Log (WinSecLog) polling mode?
  • What happens during the re-keying of Phase 2 in an IPsec tunnel?
  • Which FortiGate command can be used to reset the device to factory defaults?
  • How does FortiGate's SD-WAN feature optimize traffic routing?
  • What is a condition required for a static route to be displayed in the FortiGate routing table?
  • What type of attacks can IPS Sensors help mitigate?
  • In terms of network security, what does the term 'vulnerabilities' refer to?
  • Which statement correctly describes the behavior of a static route configured on a FortiGate when using a blackhole route?
  • Which statements about FSSO in a Windows domain with agent mode are correct?
  • Which logging options are supported on a FortiGate unit? (Choose two.)
  • Which FortiGate feature is responsible for threat detection within network traffic?
  • Regarding the header and body sections in raw log messages, which statement is correct?
  • When authenticating with a domain controller using only the domain controller agent, what can occur?
  • What does the command diagnose vpn tunnel list show regarding the IPsec tunnels?
  • What is UTM in the context of Fortinet products?
  • What does the term 'high availability' signify in a FortiGate setup?
  • What is the difference between active-passive and active-active HA in FortiGate?
  • In an IPsec phase 2 configuration, what is determined regarding traffic flow?
  • For data leak prevention, which statement describes the difference between the block and quarantine actions?
  • Which output pertains to a phase 1 negotiation in IPsec?
  • What is the purpose of configuring user groups in FortiGate?
  • What information does the command 'get router info routing-table database' provide?
  • Which FortiGate feature helps in preventing unauthorized access to sensitive data?
  • What does a hard timeout for firewall policy authentication signify?
  • Which of the following is a function of the FortiGate dashboard?
  • In which order are firewall policies processed on a FortiGate unit?
  • What component works in tandem with IPS to enhance network security in FortiGate devices?
  • Which antivirus and attack definition update options are supported by FortiGate units?
  • What is the purpose of the CLI command diagnose debug authd fsso list?
  • How does the IPS Sensor contribute to a FortiGate firewall's functionality?
  • How can FortiGate's interface be accessed for configuration?
  • When using a web-mode SSL VPN bookmark to browse an internal web server, which IP address is used as the source of the HTTP request?
  • How does FortiGate ensure secure remote access for users?
  • What is the significance of an SSL VPN compared to an IPsec VPN?
  • Which statements are true regarding IPv6 anycast addresses?
  • What is the primary function of firewall policies in FortiGate devices?
  • Which type of FortiGate log would you examine to troubleshoot traffic issues?
  • What should you configure for VPN users before they can establish a connection through FortiGate?
  • Which statement about interface assignment in VDOMs is correct?
  • What feature enhances the security of a connection in IPsec by providing an additional verification step?
  • Why might an administrator be unable to reassign an interface to a new VDOM?
  • Which of the following is NOT a method for securing user access in FortiGate?
  • What does the Security Fabric feature in FortiGate provide?
  • What is the default administrative login for a new FortiGate unit?
  • What is the main function of the command diagnose debug authd fsso list?
  • Why is it important to utilize user groups in FortiGate?
  • Which statements about application control are correct? (Choose two.)
  • Which regular expression pattern makes the term "confidential data" case insensitive?
  • Which statements are true regarding local user authentication? (Choose two.)
  • Which method can IPS Sensors use to identify malicious traffic?
  • What does IPsec Perfect Forwarding Secrecy (PFS) ensure?
  • Which are two requirements for DC-agent mode FSSO to work properly in a Windows AD environment?
  • Which statements accurately describe a partial mesh VPN deployment?
  • How does FortiGate's application control feature function?
  • Why might a FortiGate not receive push updates from the FortiGuard Distribution Network?
  • Which directive would typically follow a detection of malicious traffic by the IPS Sensor?
  • What are the benefits of updating the FortiGate firmware regularly?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy