Courseiva
← Back to Fortinet NSE 4 Network Security Professional NSE4 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Fortinet NSE 4 Network Security Professional NSE4 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

9
scenario questions
NSE4
exam code
Fortinet
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related NSE4 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

An administrator has configured the policy shown in the exhibit. Traffic to the web server at 10.0.1.10 over HTTPS is allowed, but users complain that they cannot access the web server's login page. The IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts. The application list 'Block_Social_Media' blocks Facebook and Twitter. What is the most likely cause of the issue?

Exhibit

Refer to the exhibit.

config firewall policy
    edit 1
        set name "Web-Server"
        set srcintf "port1"
        set dstintf "port2"
        set srcaddr "all"
        set dstaddr "10.0.1.10"
        set action accept
        set schedule "always"
        set service "HTTPS"
        set utm-status enable
        set ips-sensor "High_Security_Sensor"
        set application-list "Block_Social_Media"
    next
end
Question 2easymultiple choice
Full question →

Refer to the exhibit. An administrator has created an IPS sensor with two entries. The first entry sets severity 'medium' and action 'block'. The second entry sets severity 'critical' and action 'block'. What will happen when a packet triggers an IPS signature with severity 'low'?

Exhibit

Refer to the exhibit.

config ips sensor
    edit "sensor1"
        config entries
            edit 1
                set severity medium
                set action block
            next
            edit 2
                set severity critical
                set action block
            next
        end
    next
end
Question 3hardmultiple choice
Read the full VPN explanation →

A FortiGate in a hub-and-spoke VPN topology is configured with a single IPsec tunnel to each spoke. The hub has a route-based VPN with a tunnel interface for each spoke. After a reboot, traffic between spoke A and spoke B fails, although each spoke can reach the hub. What is the likely cause?

Question 4easymultiple choice
Full question →

Refer to the exhibit. An administrator has configured the SSL/SSH profile shown. However, users are unable to access HTTPS websites. What is the most likely cause?

Exhibit

Refer to the exhibit.

```
config firewall ssl-ssh-profile
    edit "deep-inspection"
        set caname "Fortinet_CA_SSL"
        config https
            set ports 443
            set status deep-inspection
        end
        set untrusted-caname ""
        set whitelist-mode disable
    next
end
```
Question 5hardmultiple choice
Review the full routing breakdown →

Refer to the exhibit. The FortiGate has two default routes. The administrator attempts to ping 8.8.8.8 from the CLI and receives no response. What is the most likely reason?

Exhibit

Refer to the exhibit.
config router static
    edit 1
        set device port1
        set gateway 203.0.113.1
        set dst 0.0.0.0 0.0.0.0
        set distance 10
    next
    edit 2
        set device port2
        set gateway 10.0.0.1
        set dst 0.0.0.0 0.0.0.0
        set distance 20
    next
end
Question 6hardmultiple choice
Read the full VPN explanation →

A FortiGate in a hub-and-spoke VPN topology has multiple spoke sites connecting via IPsec. The hub administrator wants to enable direct spoke-to-spoke communication without routing traffic through the hub. What technology should be used?

Question 7hardmultiple choice
Full question →

An administrator runs the command shown in the exhibit and sees anomalies detected from 10.1.1.100 to 10.2.2.200. The IPS sensor's anomaly settings are configured with the default actions. What will be the default action for the ICMP Flood anomaly?

Exhibit

Refer to the exhibit.

diagnose ips anomaly list

IPS anomalies detected:
  1. ICMP Flood from 10.1.1.100 to 10.2.2.200: 5000 pps (threshold: 1000 pps)
  2. TCP Scan from 10.1.1.100 to 10.2.2.200: 1000 pps (threshold: 500 pps)
  3. UDP Flood from 10.1.1.100 to 10.2.2.200: 3000 pps (threshold: 2000 pps)
Question 8hardmultiple choice
Full question →

Refer to the exhibit. An administrator configures the policies as shown. Traffic from 10.0.0.0/8 to the internet on HTTP is denied. What is the most likely reason?

Exhibit

config firewall policy
    edit 0
        set name "Deny-All"
        set srcintf "any"
        set dstintf "any"
        set srcaddr "all"
        set dstaddr "all"
        set action deny
        set schedule "always"
        set service "ALL"
        set logtraffic all
    next
    edit 1
        set name "Allow-HTTP"
        set srcintf "internal"
        set dstintf "wan1"
        set srcaddr "10.0.0.0/8"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "HTTP"
        set logtraffic all
    next
end

Refer to the exhibit. An administrator wants to enable SNMP access on the wan1 interface. Which of the following is the most efficient method?

Exhibit

config system interface
    edit "wan1"
        set vdom "root"
        set ip 10.0.0.1 255.255.255.0
        set allowaccess ping https ssh
        set type wan
        set role wan
        set snmp-index 1
    next
end

These NSE4 practice questions are part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style NSE4 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.