Fortinet · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Which TWO conditions must be met to successfully use an 'Install Config' wizard for device-level settings?
The device must be running the latest firmware.
All policies must be deleted.
The configuration database must be synchronized.
FMG must have the latest config state to calculate changes.
The device must be in an 'up' state.
Device must be reachable.
The device must be in 'backup' mode.
Which object type should you use in FortiManager to ensure a consistent naming convention for address objects across multiple ADOMs?
Provisioning templates.
Local ADOM objects.
CLI templates.
Global objects.
Global objects are designed for cross-ADOM usage.
When using 'Provisioning Templates', which setting allows you to automatically apply CLI commands to new devices as soon as they are added to the FortiManager?
Auto-Link
Device Templates
Device Templates allow for the binding of scripts and settings to new devices.
ADOM Policies
Install On Install
A FortiManager administrator needs to migrate an existing local FortiGate policy into a shared policy package. Which process must be followed?
Manually re-import the config
Use the Policy Import tool to move to Global ADOM
Global ADOM policies allow for central policy management across multiple ADOMs.
Disable policy management
Delete local policy and recreate
You have imported a new FortiGate into FortiManager. Which operation must you perform to synchronize the existing policy package with the new device?
Upgrade the firmware.
Re-install the device settings.
Perform an Import Policy operation.
Import Policy is required to bring local policies into the FortiManager ADOM.
Run a script to update the policy database.
You are deploying a new policy package to multiple FortiGate devices. Which FortiManager feature allows you to verify that the policies are syntactically correct before pushing them to the production environment?
Install Wizard
Revision History
Policy Check
Policy Check verifies the integrity and validity of the policy package.
Device Manager
Want more Nse5 Fortimanager Operations practice?
Practice this domainWhat is the primary function of the Security Fabric's 'Automation Stitch' feature?
To synchronize user databases
To trigger actions based on system events
Automation stitches use triggers and actions for automated response.
To scan for vulnerabilities
To load balance traffic
A FortiADC is load balancing an HTTPS application. You need to offload SSL processing to the ADC to reduce server load. What is the correct object to configure for this?
Content Routing Policy
Client SSL Profile
The Client SSL profile allows the ADC to act as the SSL endpoint for incoming client connections.
Server SSL Profile
Layer 7 Persistence Rule
You are configuring a FortiWeb policy to protect a web application. You need to ensure that the WAF blocks SQL injection attempts while allowing legitimate traffic. Which operational mode should you configure in the server policy?
Prevention mode
Prevention mode actively drops traffic that matches configured security signatures.
Transparent mode
Learning mode
Detection mode
Which TWO of the following steps are required to integrate FortiAuthenticator with a FortiGate for RADIUS authentication?
Install a web certificate on the FortiGate
Enable LDAP on the FortiAuthenticator
Configure FortiAuthenticator as a RADIUS Server on FortiGate
FortiGate needs to know where to send the auth request.
Configure SAML on the FortiGate
Add the FortiGate IP as a RADIUS Client on FortiAuthenticator
FortiAuthenticator must trust the FortiGate.
You are configuring FortiWeb in reverse proxy mode. A client is receiving 403 Forbidden errors for legitimate traffic due to a SQL injection false positive. Which feature should you modify to allow this traffic while maintaining security?
Enable Auto Learning
Disable the SQL Injection scanner entirely
Switch to Transparent mode
Create a WAF Exception for the specific signature ID
WAF exceptions allow administrators to bypass specific signature triggers for known legitimate traffic patterns.
You are configuring a FortiWeb WAF policy for a web application. You need to ensure that the WAF blocks requests that contain SQL injection patterns. Which feature should you enable in the WAF profile?
Enable SQL Injection in the WAF profile
This feature specifically targets SQL injection patterns.
Enable Buffer Overflow protection
Enable HTTP Protocol Validation
Enable Cross-site Scripting protection
Want more Nse6 Security Fabric Specialist Topics practice?
Practice this domainWhich THREE components are required to create a functional FortiSoC Playbook?
Workflow Actions
Actions define what the playbook does.
Report Template
Log retention policy
Target Connector/Device
The playbook must have a destination to execute commands.
Playbook Trigger
The trigger defines when the playbook starts.
You are configuring an Event Handler to monitor for failed login attempts. To ensure you do not receive too many alerts for the same source IP in a short duration, what should you configure?
Log aggregation
Event rate limiting
Setting a rate limit or threshold in the event handler allows suppression of duplicate alerts.
Database auto-delete
Log forwarding filter
You are troubleshooting a scenario where an Event Handler is not triggering as expected. What is the most effective way to verify if the logs are matching the filter criteria defined in the handler?
Run a manual report
Use the 'Test' button in the Event Handler definition
The test tool allows you to validate the logic against existing logs.
Rebuild the SQL database
Check the FortiAnalyzer system logs
When configuring log forwarding from FortiAnalyzer to a remote Syslog server, which TWO of the following parameters must be correctly configured to ensure the remote server accepts the logs?
Remote server IP address
This is required for the connection to be established.
Log filter criteria
Enable compression for all logs
Syslog server port
The port must match the listener on the remote server.
Include device hostname in logs
An administrator needs to identify which application is consuming the most bandwidth on the network. Which feature in FortiView provides the most efficient visual representation for this task?
FortiView Applications
FortiView Applications allows sorting by bandwidth to identify high consumers.
Log View
FortiView Sources
FortiView Destinations
Reports
A FortiAnalyzer is failing to receive logs from a FortiGate. After verifying the IP connectivity and the FortiGate registration status, which setting should be checked next?
FortiGate log-server configuration
The FortiGate must explicitly point to the FortiAnalyzer to send logs.
Report scheduling
FortiView update interval
FortiAnalyzer Device registration status
Want more Nse5 Fortianalyzer Operations practice?
Practice this domainAn administrator wants to prevent email spoofing by verifying the sender's domain. Which policy should be configured to check the DNS TXT record of the sending domain?
SPF validation
SPF checks the DNS TXT record for authorized sending IPs.
DKIM verification
DMARC policy
Sender Reputation
When configuring DMARC on FortiMail, which THREE components are required to successfully implement a 'reject' policy?
A valid DKIM public key in DNS.
DKIM is a prerequisite for DMARC alignment.
A custom antispam filter for all emails.
An LDAP server for user authentication.
A valid SPF record in DNS.
SPF is a prerequisite for DMARC alignment.
A DMARC TXT record in the domain's DNS.
The DNS record defines the policy (p=reject).
A customer is experiencing false positives with the FortiMail Antispam engine. Which feature should be configured to allow trusted sender domains while still performing virus scanning?
Disable the Antispam engine globally.
Add the sender to the Global Whitelist in the Antispam Profile.
Modify the recipient's personal whitelist.
Create an Access Control List (ACL) policy with the 'Bypass antispam' action.
ACL policies allow granular control to bypass specific modules without disabling virus scanning.
You are configuring DKIM signing on FortiMail. The administrator has generated the public/private key pair. Where must the public key be published to ensure the receiving MTA validates the email correctly?
On the SMTP server of the recipient's domain.
In the FortiMail's relay host configuration.
On the FortiMail server's local certificate store.
In the public DNS records for the domain.
Receiving servers query DNS to verify the signature using the published public key.
You are deploying FortiMail in Transparent mode. Which configuration step is mandatory to ensure traffic is inspected without modifying the IP headers of the email packets?
Configure the Bridge pair and disable IP forwarding.
Configure the Bridge pair under Network > Interface.
In transparent mode, you must bridge two interfaces so that traffic flows through the FortiMail without IP layer changes.
Configure static IP routing on the management interface.
Assign a virtual IP to the WAN interface.
A user reports that legitimate emails are being quarantined due to a high spam score. You want to add the sender's email address to a whitelist. Where should this be configured to be effective for the specific user?
AntiSpam profile block list
Personal Safe List in the quarantine portal
The user-level Safe List is the correct place to whitelist senders for individual accounts.
Recipient policy whitelist
System global whitelist
Want more Nse6 Fortimail Secure Email Gateway practice?
Practice this domainThe FORTINET-NSE56 exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Nse5 Fortimanager Operations, Nse6 Security Fabric Specialist Topics, Nse5 Fortianalyzer Operations, Nse6 Fortimail Secure Email Gateway. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Fortinet FORTINET-NSE56 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.