Fortinet · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
20% of exam · 6 sample questions below
A FortiGate is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the process 'ipsengine' is using the most CPU. What is the most likely cause?
The firewall is experiencing a memory leak.
A large volume of traffic is being inspected by IPS, possibly due to a DoS attack.
The ipsengine process performs IPS inspection, so sustained high CPU points to heavy traffic volume passing through IPS inspection, such as a DoS flood. The stem's constraint is identifying the process consuming CPU, and ipsengine's workload scales directly with inspected sessions.
The antivirus engine is scanning large files.
There is a routing loop causing packet bouncing.
Based on the debug flow output, what is the reason the packet is dropped?
The route to the destination is missing.
There is no firewall policy that matches the traffic.
The debug flow output shows the packet reaching policy lookup and being denied because no firewall policy matches the source, destination, or service tuple. FortiGate drops unmatched traffic by default, so the absence of a matching policy is the drop reason.
The packet has an invalid source IP address.
The session table is full.
An administrator applies the above policy but users from 10.0.1.0/24 cannot access web servers at 10.0.2.0/24. However, they can ping the servers. What is the most likely cause?
The service 'HTTP' does not include port 443 or the web application is using HTTPS.
ICMP succeeds because ping is permitted, but the policy's HTTP service object covers only port 80. If the web application serves HTTPS on port 443, that traffic matches no allowing policy and is dropped, blocking access.
The destination address is incorrect.
The schedule 'always' is not correctly configured.
The source interface is incorrect.
A FortiGate cluster (A-P) has a session that is not synchronizing to the secondary unit. The administrator runs 'diagnose sys ha session-sync status' and sees that the session count is different between primary and secondary. Which is the most likely cause?
The session is using a custom application control profile that prevents synchronization.
The HA heartbeat interface is down.
The secondary unit has insufficient memory to accept new sessions.
The session was created by a local-in traffic (e.g., management traffic) which is not synchronized.
Local-in traffic terminates on the FortiGate itself, so those sessions are never replicated to the secondary unit. This explains the count mismatch without indicating an HA failure, since session synchronisation only covers transit traffic passing through the cluster.
A customer reports intermittent connectivity issues between two internal subnets separated by a FortiGate firewall. The traffic is allowed by the policy, but users experience timeouts during peak hours. Which troubleshooting step should you take first?
Run a packet sniffer on the FortiGate to capture traffic between the subnets.
Check the session table for session limits and session congestion.
Checking the session table reveals whether sessions are exhausting the FortiGate's session limits or hitting per-policy session thresholds during peak load, which directly explains intermittent timeouts despite a permit policy. This satisfies the stem's peak-hour congestion constraint, since session exhaustion manifests as dropped new connections rather than policy denials.
Disable hardware acceleration on the FortiGate.
Configure SNAT on the policy to translate the source IP.
Which TWO actions are appropriate when troubleshooting a slow network connection through a FortiGate?
Increase the session TTL to reduce session setup overhead.
Check the CPU and memory utilization on the FortiGate.
Slow throughput often stems from resource exhaustion, since FortiGate inspection, NP offload and session handling all consume CPU and memory. Checking utilisation identifies whether the appliance itself is the bottleneck before investigating upstream or downstream causes.
Verify the routing table for correct next-hop entries.
Incorrect or missing next-hop entries cause traffic to take suboptimal paths, be dropped, or loop, all of which present as slow connections. Verifying the routing table confirms packets egress the expected interface toward the correct gateway.
Disable flow control on the WAN interface.
Disable all security profiles to free resources.
Want more Troubleshooting and Diagnostics practice?
Practice this domain20% of exam · 6 sample questions below
A company is implementing a Security Fabric with multiple FortiGate devices. They want to use FortiAnalyzer for centralized logging and FortiManager for centralized management. Which of the following is a prerequisite for adding a FortiGate to the Security Fabric?
The FortiGate must have FortiAnalyzer configured as a log device
The FortiGate's management IP must be configured via DHCP
The FortiGate must have network connectivity to the FortiManager
Connectivity is required for management.
The FortiGate must be operating in transparent mode
Which THREE actions can an administrator perform using FortiManager in a Security Fabric environment? (Choose three.)
Upgrade the firmware of multiple FortiGates at once
Firmware upgrade can be done centrally.
View logs from all managed FortiGates in a single dashboard
FortiManager provides log viewing.
Terminate IPsec VPN tunnels on the FortiManager
Configure FortiGate to manage the FortiManager
Push firewall policies to multiple FortiGates simultaneously
Centralized policy management.
Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?
The Fabric Root serial number is incorrect
The FortiGate is not registered with FortiManager
The policy package on FortiManager is not assigned to the correct device group or policy target
FortiManager pushes policy only to devices covered by the installed policy package's assignment. If the FortiGate is absent from the target device group or policy target, installation silently skips it, so no updates arrive despite successful registration and Security Fabric membership.
The Security Fabric is not fully connected
An administrator needs to monitor traffic flows across multiple FortiGate devices in a Security Fabric. The administrator wants to see a unified view of all traffic, including inter-device traffic, from a single pane. Which Fortinet tool provides this capability?
FortiAP
FortiManager
FortiGate local logs
FortiAnalyzer
FortiAnalyzer aggregates logs and provides cross-device traffic visibility.
During a failover test in an HA cluster, the administrator observes that the secondary unit becomes primary but does not have the latest configuration. What is the most likely cause?
The password encryption is mismatched
Config sync is not enabled
Without configuration synchronisation enabled, the secondary device never receives configuration updates from the primary, so its stored configuration diverges. On failover it assumes the primary role using that stale configuration, exactly matching the stem's observation that the newly promoted unit lacks the latest configuration.
The HA priority is set too low
session-pickup is disabled
An administrator has configured two VDOMs on a FortiGate. One VDOM is in NAT mode and the other in transparent mode. The administrator wants traffic from the transparent mode VDOM to be routed through the NAT mode VDOM. What must be configured to allow inter-VDOM routing?
Use a physical interface to connect the VDOMs
Create an inter-VDOM link
An inter-VDOM link creates a virtual point-to-point Ethernet interface pairing two VDOMs, enabling traffic to pass between them regardless of operating mode. This satisfies the requirement to route traffic from the transparent VDOM into the NAT-mode VDOM, since the link provides the Layer 3 path that transparent mode alone cannot supply.
Enable NPU offloading
Configure firewall policies between the VDOMs
Want more Enterprise Firewall and VDOMs practice?
Practice this domain20% of exam · 6 sample questions below
A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?
Data Leak Prevention profile
Antivirus profile with SSL inspection
The antivirus profile, when combined with SSL inspection, decrypts TLS sessions so the malware signatures and CDR engines can examine payloads hidden inside encrypted channels. This satisfies the requirement to block advanced malware using encrypted command-and-control traffic.
Web Filtering profile
Intrusion Prevention profile
A network administrator notices that several endpoints are infected with ransomware despite having FortiGate ATP enabled. The logs show that the files were downloaded over HTTPS, and the antivirus profile did not detect them. What is the most likely reason?
SSL inspection was not enabled on the antivirus profile
FortiGate antivirus profiles inspect traffic only after decryption; without SSL inspection enabled, HTTPS payloads remain encrypted and bypass scanning entirely. Enabling deep inspection lets the profile decrypt, match signatures and block the ransomware downloads, addressing the undetected HTTPS vector.
Application control profile blocked the download
FortiSandbox was not configured to analyze the files
IPS signature database was outdated
A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?
Configure traffic shaping to rate limit the URL
Add a static URL filter with the exact URL and action 'block'
Enable DNS filter with botnet C2 domain blocking
Change the action for Malware category from 'monitor' to 'block' in the web filter profile
The profile currently only logs matching traffic, so FortiGate permits the malicious URL. Switching the Malware category action from monitor to block makes the firewall drop matching sessions, satisfying the requirement to stop access rather than merely record it.
A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?
Antivirus profile
Web Filtering profile
Data Leak Prevention profile
Email Filtering profile
The Email Filtering profile inspects SMTP, IMAP and POP3 traffic, blocking messages based on sender reputation and embedded malicious URLs. It satisfies the requirement to detect and block phishing emails containing malicious links, which antivirus or web filtering alone cannot fully address.
Refer to the exhibit. A user reports that accessing a legitimate HTTPS website is blocked. The FortiGate logs show that the connection was denied by the antivirus profile. What is the most likely cause?
The antivirus profile detected a false positive in the encrypted traffic
The antivirus profile performs deep inspection, including of HTTPS traffic after decryption, and can flag benign content as malicious. A false positive therefore causes the FortiGate to deny a legitimate site, matching the logged antivirus denial. This satisfies the stem's encrypted-traffic constraint, since inspection requires SSL decryption.
The application list blocked the HTTPS application
The IPS profile blocked a vulnerability in the website
The protocol options profile blocked the SSL handshake
What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?
To remove potentially malicious content from documents and rebuild them as safe files
CDR strips active content — macros, embedded scripts, hyperlinks — from documents, then rebuilds a clean, functional file, satisfying the requirement to neutralise threats rather than merely detect them. Unlike signature-based scanning, which fails against zero-day or polymorphic payloads, this reconstruction guarantees the delivered file contains no executable code.
To convert files into PDF format for safer viewing
To detect zero-day malware using sandboxing
To block all files containing macros
Want more Advanced Threat Protection practice?
Practice this domain20% of exam · 6 sample questions below
A network administrator is configuring SD-WAN on a FortiGate. The organization has two internet links: MPLS (primary) and broadband (backup). The administrator wants all traffic to use the MPLS link unless it fails, in which case traffic should fail over to the broadband link. Which SD-WAN configuration best achieves this requirement?
Set the MPLS link priority to 10 and the broadband link priority to 5, then configure an SD-WAN rule with the 'best quality' strategy.
Higher priority for MPLS ensures it is preferred. The 'best quality' strategy selects the member with the highest priority when available, providing failover.
Enable 'set role' on the MPLS link as 'primary' and on the broadband link as 'standby' with the 'redundant' strategy.
Configure both links in the SD-WAN zone with equal priority and use the 'lowest cost' strategy.
Create two static routes: one with higher distance for MPLS and one with lower distance for broadband.
Which THREE statements are true about FortiGate SD-WAN health-check configuration?
Health-check probes can be sent from any interface, including loopback.
Health-check can only be configured on physical interfaces, not VLANs or subinterfaces.
Health-check can be configured with multiple thresholds for jitter, latency, and packet loss.
SD-WAN health checks support separate SLA thresholds for latency, jitter and packet loss, and each member can be assigned multiple threshold values to define acceptable performance bands. This lets FortiGate mark a link degraded or dead when any measured metric breaches its configured limit.
Health-check can update the routing table by setting 'update-static-route' to enable fallback.
With update-static-route enabled, the health-check dynamically adds or withdraws the static route associated with the SD-WAN member, so traffic fails over to a healthy link when the monitored link goes down, providing the fallback behaviour described.
Health-check can be configured to use HTTP or DNS protocols to verify link health.
Health-check probes support several protocols, including HTTP and DNS, alongside ICMP and TCP echo. Using HTTP or DNS lets the check verify application-layer reachability rather than mere ICMP responsiveness, confirming the link can serve real traffic.
A FortiGate is deployed with two ISPs and SD-WAN. The organization uses OSPF to exchange routes with a remote branch. The administrator notices that the FortiGate is not installing OSPF-learned routes into the routing table. The OSPF configuration is verified to be correct, and neighbors are established. Which configuration could be causing the issue?
The SD-WAN health-check is configured with 'update-static-route' and is overriding OSPF routes.
The administrative distance of OSPF is set to 200, which is higher than the default 110.
A distribute-list configured under OSPF is filtering the routes from being installed.
A distribute-list applied under OSPF filters routes during installation into the routing table, so neighbours stay established and the config looks valid while prefixes are silently dropped. This directly explains why OSPF-learned routes never appear despite correct adjacency.
The OSPF interface is configured as 'passive', which prevents route exchange.
A company with a hub-and-spoke SD-WAN topology uses FortiGates at each site. The hub has two WAN links: MPLS (10 Mbps) and broadband (100 Mbps). The spokes connect only via MPLS. The company deploys a new real-time application that requires low latency and low jitter. The network administrator creates an SD-WAN rule for this application with 'best quality' strategy and both MPLS and broadband as members. The SLA for MPLS is configured with latency < 10 ms and jitter < 5 ms. The SLA for broadband is configured with latency < 50 ms and jitter < 20 ms. The actual measured latency on MPLS is 12 ms, and jitter is 4 ms. The broadband latency is 25 ms, jitter 10 ms. Which path will the application traffic take?
The traffic will use the broadband link because MPLS SLA fails and broadband SLA is met.
Broadband satisfies its configured SLA thresholds (25 ms latency, 10 ms jitter, both within 50 ms and 20 ms), while MPLS breaches its latency SLA at 12 ms against the 10 ms limit. FortiGate's best quality strategy selects the member meeting its SLA, so traffic fails over to broadband despite MPLS's lower measured latency.
The traffic will be load-balanced between MPLS and broadband.
The traffic will use the MPLS link because it is the preferred member.
The traffic will be dropped because no link meets the SLA.
A company has two internet connections: a primary fiber link (port1, 100 Mbps) and a backup DSL link (port2, 20 Mbps). They are using SD-WAN to load balance traffic based on volume, with a rule that sends 70% of traffic to port1 and 30% to port2. Recently, users report that video conferencing applications are experiencing high latency and jitter. The network team finds that the SD-WAN performance SLA for the fiber link shows 80% packet loss and high latency. The SD-WAN rule action is set to 'best quality' with a latency threshold of 150 ms. The current latency on port1 is 200 ms, and on port2 is 40 ms. What should the administrator do to ensure that video conferencing traffic uses the DSL link while the fiber link is degraded?
Increase the SLA latency threshold to 250 ms so that the fiber link is considered acceptable.
Change the SD-WAN rule action to 'lowest cost' to favor the DSL link.
Adjust the volume ratio to send 100% of traffic to port2 until the fiber link recovers.
No changes are needed; the SD-WAN rule with 'best quality' will automatically use port2 for new sessions because port1 does not meet the SLA.
The 'best quality' action evaluates SLA per session and steers new sessions to port2, which meets the 150 ms latency threshold while port1 at 200 ms does not. Existing sessions may need re-establishment, but new video sessions use the DSL link automatically.
Drag and drop the steps to configure a FortiGate to use an external authentication server (e.g., RADIUS) for admin login into the correct order.
Add RADIUS server, configure server details, create user group, assign group to admin, test
This order is correct because you must first define the authentication source (RADIUS server) before you can use it in a group, then assign that group to an admin profile, and finally verify the configuration.
Create user group, add RADIUS server, configure server details, assign group to admin, test
Add RADIUS server, create user group, assign group to admin, configure server details, test
Test, add RADIUS server, configure server details, create user group, assign group to admin
Want more Advanced Networking and SD-WAN practice?
Practice this domain20% of exam · 6 sample questions below
A company is implementing Zero Trust Network Access using Fortinet's ZTNA solution. They have deployed a FortiGate as the ZTNA gateway and are using FortiClient as the ZTNA agent. Users report that they can initiate ZTNA connections but the connections drop after a few minutes. The FortiGate logs show that the ZTNA session is being terminated due to a endpoint compliance check failure. Which action should the administrator take to resolve this issue?
Review and adjust the endpoint compliance rules in FortiClient EMS.
Endpoint compliance checks are evaluated by FortiClient EMS, which tags endpoints and signals the FortiGate ZTNA gateway; the gateway terminates sessions when a tag is revoked. Adjusting the compliance rules in EMS resolves the failing check that causes the recurring session teardown.
Disable endpoint compliance checks on the FortiGate.
Increase the session timeout on the FortiGate ZTNA gateway.
Change the authentication method from certificate to LDAP.
During a ZTNA deployment, an administrator notices that traffic from a specific internal application is being routed through the ZTNA gateway but is not reaching the destination server. The FortiGate policy allows the traffic, and the client has a valid ZTNA connection. What is the most likely cause of the issue?
The ZTNA proxy rule on the FortiGate is misconfigured, pointing to the wrong destination IP or port.
The ZTNA proxy rule defines the destination IP and port used when forwarding the client's request to the internal application. If these are wrong, the FortiGate accepts the session but forwards it to an unreachable or incorrect server, so traffic never arrives.
The client's FortiClient agent is not connected to the EMS server.
The destination server does not have internet connectivity.
The FortiGate policy is set to deny traffic from the client's subnet.
A company uses FortiGate ZTNA to provide remote access to an internal web application. The application requires client certificates for authentication. The administrator has configured the ZTNA rule to use certificate authentication. However, users report that they are prompted for credentials repeatedly. What is the most likely cause?
The user's password has expired.
The ZTNA rule is configured to use SAML authentication instead.
The client certificate is not trusted by the FortiGate.
FortiGate validates the client certificate against its trusted CA store during ZTNA certificate authentication. If the issuing CA is absent, validation fails and the FortiGate falls back to prompting for credentials, explaining the repeated prompts users report despite correct certificate configuration.
The FortiClient EMS server is not reachable from the client.
In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?
FortiClient agent
FortiAnalyzer
FortiGate ZTNA gateway
The FortiGate ZTNA gateway terminates the client tunnel and enforces access policy per session, granting or denying each request to internal applications. It is the enforcement point, while the EMS or fabric connector supplies identity and posture context used in those decisions.
FortiClient EMS
During a ZTNA implementation, the administrator configures a ZTNA rule for an internal application but users cannot connect. The FortiGate policy is correct and the application is reachable from the FortiGate. What is the most likely misconfiguration?
The firewall policy is set to deny traffic from the ZTNA gateway.
The client does not have a route to the internal application.
The client's FortiClient agent is not authenticated.
The ZTNA rule's proxy destination IP or port is wrong.
ZTNA access proxy rules forward traffic to the real application using the configured destination IP and port. If these are wrong, the FortiGate cannot reach the backend service, so users fail to connect even though the policy matches and the application is otherwise reachable.
Which TWO of the following are required components for a Fortinet ZTNA solution? (Select two.)
FortiAuthenticator
FortiWeb
FortiAnalyzer
FortiGate
FortiGate is the ZTNA gateway.
FortiClient EMS
EMS is required for endpoint compliance and tagging.
Want more Advanced VPN and Zero Trust practice?
Practice this domainThe NSE7 exam has 30 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 5 domains: Troubleshooting and Diagnostics, Enterprise Firewall and VDOMs, Advanced Threat Protection, Advanced Networking and SD-WAN, Advanced VPN and Zero Trust. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Fortinet NSE7 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.