Free Fortinet NSE6_FWF-6.4 Exam Actual Questions

The questions for NSE6_FWF-6.4 were last updated On Dec 20, 2024

Question No. 1
Question No. 3

Which statement is correct about security profiles on FortiAP devices?

Show Answer Hide Answer
Correct Answer: D

Security profiles are a feature that allows FortiAP devices to apply various security functions to the wireless traffic, such as antivirus, web filter, application control, intrusion prevention, and botnet scanning. Security profiles can be enabled on both tunnel-mode and bridge-mode SSIDs, and can be applied either through the wireless controller configuration or through firewall policies on the FortiGate device. Security profiles can also inspect encrypted wireless traffic, as long as the FortiAP device has access to the encryption keys.

Security profiles on FortiAP devices can use FortiGate subscription services to inspect the traffic, such as FortiGuard Antivirus, FortiGuard Web Filter, FortiGuard Application Control, and FortiGuard IPS. This means that the FortiAP device can leverage the latest threat intelligence and updates from Fortinet to protect the wireless network from malicious or unwanted content.

Therefore, the correct answer is D. Security profiles on FortiAP devices can use FortiGate subscription to inspect the traffic.


FortiAP-S and FortiAP-U bridge mode security profiles

Configuring security | FortiAP / FortiWiFi 6.4.2

Security profiles - Fortinet Document Library

Question No. 4

Which two statements about distributed automatic radio resource provisioning (DARRP) are correct? (Choose two.)

Show Answer Hide Answer
Correct Answer: B, C

According to Fortinet training: 'When using DARRP, the AP selects the best channel available to use based on the scan results of BSSID/receive signal strength (RSSI) to AC' and 'To set the running time for DARRP optimization, use the following CLI command within the wireless controller setting: set darrp-optimize {integer}. Note that DARRP doesn't do continuous spectrum analysis...'