nerdexam
Fortinet

NSE4_FGT-6.4 · Question #131

Refer to the exhibit. The exhibit contains a network diagram, firewall policies, and a firewall address object configuration. An administrator created a Deny policy with default settings to deny…

The correct answer is C. Enable match vip in the Deny policy. D. Set the Destination address as Web_server in the Deny policy. See the full explanation below for the reasoning.

Question

Refer to the exhibit. The exhibit contains a network diagram, firewall policies, and a firewall address object configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-user2. Remote-user2 is still able to access Webserver. Which two changes can the administrator make to deny Webserver access for Remote-User2? (Choose two.)

Exhibits

NSE4_FGT-6.4 question #131 exhibit 1
NSE4_FGT-6.4 question #131 exhibit 2
NSE4_FGT-6.4 question #131 exhibit 3

Options

  • ADisable match-vip in the Deny policy.
  • BSet the Destination address as Deny_IP in the Allow-access policy.
  • CEnable match vip in the Deny policy.
  • DSet the Destination address as Web_server in the Deny policy.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    83% (20)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.4 Practice