Fortinet · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An administrator notices that hardware acceleration (NP6) is failing to offload traffic for a specific policy. Which command is best used to verify if hardware offloading is actually occurring for a specific session?
get hardware npu np6
get system performance status
diagnose npu np6 status
diagnose sys session list
The session list output includes flags like 'offload' which indicate if the NP is handling the session.
An administrator is troubleshooting an issue where hardware acceleration is not working after upgrading firmware. Which command identifies if the NP configuration has changed?
diag hardware npu np6 port-list
This allows verification of the port-to-NPU mapping.
config system npu
diagnose firewall npu
get hardware status
What is the impact of changing the 'set vdom-mode' from 'no-vdom' to 'multi-vdom'?
Automatic disablement of HA
Loss of all firewall policies
No impact, immediate change
System reboot required
The configuration migration requires a system reload.
You need to ensure that session synchronization between HA nodes is as efficient as possible. Which parameter should be tuned in the HA configuration?
monitor-interface
override
heartbeat-interval
session-pickup-delay
This setting allows delaying session pickup, which can reduce CPU utilization during high-frequency session creation.
A network administrator is configuring an HA cluster with two FortiGates in Active-Passive mode. Which parameter must be identical on both devices to ensure a successful cluster formation?
Device Hostname
Serial Number
HA Group ID
The HA Group ID must match to allow devices to discover each other.
Priority value
A FortiGate is operating in transparent mode. What is the default behavior when the device receives a frame with an unknown MAC address?
Drop the packet
Flood to all ports
Standard bridging behavior for unknown unicast/broadcast frames.
Forward to the management interface
Send an ICMP unreachable message
Want more System Configuration practice?
Practice this domainA FortiManager administrator needs to ensure that logs from all enterprise FortiGates are aggregated and purged based on storage thresholds. Where is this configured?
FortiAnalyzer/Log Settings under Device Manager
Log settings define disk management for logs.
System settings under 'Network' tab
Global Policy settings
ADOM management settings
An enterprise firewall administrator needs to deploy different security profiles to branch offices while sharing the same firewall policy structure. Which feature should be used?
Creating multiple ADOMs for every branch
Manual copy-paste of rules
Using CLI templates exclusively
Policy Package inheritance and mapping
Inheritance allows sharing of policy structures.
You are setting up an SD-WAN configuration via FortiManager. Which object type is used to group multiple WAN interfaces for SD-WAN member assignment?
IP Pool
Virtual Wire Pair
SD-WAN Zone
Zones allow grouping of SD-WAN members.
Interface Group
What is the primary purpose of an ADOM in FortiManager?
To logically group devices for delegated administration and policy management
ADOMs provide administrative segmentation.
To provide high availability for the FortiGate
To allow external API access to the FortiGate
To increase the storage capacity of the FortiManager
You are troubleshooting a policy installation failure where the FortiManager reports a 'Configuration conflict'. Which action should you perform to identify the root cause of the mismatch?
Force an 'Import Policy' operation
Reboot the FortiManager
Disable the policy package entirely
Use the 'Diff' feature in the Policy & Objects tab to compare the database and device config
The Diff tool is the standard method for resolving conflicts.
When adding a FortiGate to FortiManager, which mode must the FortiGate be in to allow the FortiManager to manage its configuration and policies?
Registration-only mode
Backup mode
Normal mode
Normal mode is required for full management.
Read-only mode
Want more Central Management practice?
Practice this domainYou are configuring an IPsec VPN tunnel between two FortiGates. Phase 2 fails to come up. What is the most likely cause?
Mismatched Phase 2 selectors
Phase 2 requires matching local and remote subnets/selectors.
Incorrect IKE version
Expired certificate
Mismatched pre-shared key
You are configuring an IPS policy to protect a web server. You notice that traffic is being dropped due to a false positive. Which action is the most efficient way to resolve this while maintaining security?
Change the IPS mode from blocking to monitoring
Disable the entire IPS sensor profile
Create an IPS sensor override for the specific signature ID
This allows targeted tuning of individual signatures.
Increase the IPS packet buffer size
A FortiGate is performing OSPF routing. You want to redistribute connected routes into OSPF, but only for a specific subnet. How can this be achieved?
Configure a distribute-list in the OSPF process
Use an IP prefix list under the OSPF area command
Use a route map in the OSPF redistribute configuration
Route maps provide the necessary granularity to filter prefixes during redistribution.
Use an access list under the interface configuration
What is the default behavior of a FortiGate firewall policy when no explicit policy matches the traffic?
Send to local DNS
Implicit Deny
The implicit deny policy is the default safety catch-all.
Route to DMZ
Allow
In a BGP deployment, your FortiGate is receiving routes from two different ISPs. You want to influence outbound traffic to prefer ISP1 for specific destinations. Which BGP attribute should you modify?
Weight
Local Preference
Local Preference is the standard BGP attribute for controlling outbound path selection.
AS-Path
Multi-Exit Discriminator (MED)
A network administrator is configuring SSL inspection for a group of users. Which certificate must be installed on the client endpoints to prevent browser certificate warnings?
The FortiGate CA certificate used for SSL inspection
Clients must trust the CA that signs the re-issued certificates.
The FortiGate's local device certificate
The Fortinet_Factory CA certificate
A third-party public CA certificate
Want more Security And VPN practice?
Practice this domainThe NSE7_EFW exam has 200 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 3 domains: System Configuration, Central Management, Security And VPN. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Fortinet NSE7_EFW exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.