Courseiva

Fortinet NSE 1-3 (Network Security Associate track: Foundational, Technical Introduction, Associate) (FORTINET-NSE123) (FORTINET-NSE123) — Questions 175

296 questions total · 4pages · All types, answers revealed

Page 1 of 4

Page 2
1
MCQeasy

What is the primary purpose of the FortiGuard distribution network in the Fortinet Security Fabric?

A.To deliver real-time threat intelligence updates and security signatures to Fortinet devices
B.To synchronize endpoint compliance policies with FortiClient EMS
C.To manage administrative user accounts across multiple tenants
D.To store archival system audit logs for regulatory compliance
AnswerA

FortiGuard provides continuous threat updates and signature feeds.

Why this answer

The FortiGuard distribution network provides real-time threat intelligence updates, including antivirus signatures, IPS definitions, and web filtering categories to Fortinet devices.

2
MCQmedium

A junior administrator accidentally locked themselves out of the FortiGate CLI after multiple incorrect password attempts. What is the standard administrative method to recover access without losing the configuration?

A.Perform a hardware factory reset using the pinhole reset button.
B.Use the default factory IP address 192.168.1.99 via HTTPS.
C.Wait for the lockout timer to expire, which defaults to 24 hours.
D.Log in via the physical console port using the 'maintainer' login procedure during a device reboot.
AnswerD

The maintainer account allows password resetting during a reboot via the console connection.

Why this answer

Console cable access using the physical serial/console port bypasses authentication locks if accessed via physical maintenance, or using the special 'maintainer' account procedure during a reboot.

3
MCQhard

A cybersecurity analyst is investigating a security breach where an attacker bypassed perimeter defenses by sending a weaponized PDF attachment directly to a high-ranking executive's personal email account used on a corporate laptop. What specific type of targeted attack does this represent?

A.Mass spam campaign
B.Whaling attack
C.MAC spoofing attack
D.Structured query language injection
AnswerB

Targeting executives with specialized phishing is known as whaling.

Why this answer

Whaling is a form of spear phishing specifically directed at high-profile targets like executives or senior management.

4
Multi-Selectmedium

An administrator needs to configure local administrator accounts with specific operational privileges. Which TWO elements are required or configurable when creating a new local administrator account? (Choose two)

Select 2 answers
A.Administrator username
B.Firewall policy source IP object
C.Administrator access profile (defining permissions and privileges)
D.DHCP lease pool range
E.SSL VPN portal bookmark
AnswersA, C

Correct. A unique username is required for login.

Why this answer

Creating a local admin account requires specifying an account name, an authentication type (password or certificate), and assigning an administrator access profile.

5
MCQmedium

An administrator is troubleshooting intermittent latency on a specific interface. They need to capture live packet data passing through that interface directly from the FortiGate CLI. Which command is used for packet capture?

A.execute ping-packet
B.execute trace-route
C.get system interface traffic
D.diagnose sniffer packet
AnswerD

Correct. The packet sniffer utility allows real-time packet inspection on specified interfaces.

Why this answer

The diagnose sniffer packet command is the standard tool for capturing and displaying packets on a FortiGate CLI.

6
MCQmedium

A remote employee connects to an unsecured public Wi-Fi network at a coffee shop and accesses internal corporate resources without utilizing a VPN. Which foundational security principle is primarily compromised in this scenario?

A.Availability, because public networks are prone to high latency and packet loss.
B.Non-repudiation, because transactions cannot be cryptographically verified.
C.Confidentiality, because data in transit can be intercepted by third parties.
D.Integrity, because unauthorized users can modify corporate files in transit.
AnswerC

Without a VPN, traffic can be read by anyone monitoring the local wireless medium, violating confidentiality.

Why this answer

Confidentiality is compromised because data transmitted over an unsecured network in plaintext can be intercepted via packet sniffing.

7
MCQhard

An organization wants to enforce the Principle of Least Privilege for a new database containing sensitive customer records. Which user access configuration correctly implements this principle?

A.Share a single high-privileged service account credential among the entire team.
B.Grant read-only access to specific tables only for employees whose roles explicitly require that data.
C.Assign all department members permanent administrative rights to ensure uninterrupted workflow.
D.Provide full database access to all employees during onboarding, revoking it after one year.
AnswerB

Restricting access to only necessary data and roles aligns directly with least privilege.

Why this answer

Least privilege dictates granting users only the minimum necessary access required to perform their job duties.

8
MCQhard

When configuring an IPsec VPN tunnel in FortiOS, what is the purpose of Phase 2 negotiation?

A.To assign dynamic IP addresses to remote dial-up users via DHCP relay
B.To verify the administrator credentials attempting to log into the FortiGate GUI
C.To negotiate the security parameters and encryption algorithms used to protect user data packets (IPsec SAs)
D.To establish the initial IKE handshake and peer authentication identity
AnswerC

Phase 2 establishes the IPsec SAs that secure the actual data stream.

Why this answer

Phase 2 establishes the actual IPsec Security Associations (SAs) that protect user data traffic, negotiating encapsulation protocols (ESP/AH), encryption algorithms, and lifetime parameters.

9
MCQeasy

An administrator needs to verify the current firmware version running on the FortiGate. Where can this information be found immediately upon logging into the dashboard?

A.Dashboard > System Information widget
B.Log & Report > System Events
C.Policy & Objects > Addresses
D.Network > Interfaces
AnswerA

Correct. The System Information widget shows the running firmware version prominently.

Why this answer

The System Information widget on the dashboard displays the firmware version, hostname, serial number, and uptime.

10
MCQeasy

Where can an administrator view a summary of detected security threats, such as blocked malware and intrusion prevention events, in the FortiGate web-based manager?

A.Log & Report > Security Logs
B.System > FortiGuard
C.Dashboard > Threat Map
D.Policy & Objects > Security Profiles
AnswerA

Correct. Security logs record specific security events like antivirus, web filtering, and IPS detections.

Why this answer

Security event logs and summaries are found under Log & Report > Security Logs.

11
Multi-Selectmedium

Which TWO of the following actions should an end user take if they suspect their corporate credentials have been compromised? (Choose two)

Select 2 answers
A.Immediately notify the internal IT security or helpdesk team
B.Delete all files on the computer to erase evidence of the compromise
C.Post about the incident on public social media channels to warn friends
D.Change the password immediately from a secure, uncompromised device
E.Keep the incident secret to avoid getting in trouble with management
AnswersA, D

Reporting the potential compromise allows security teams to monitor sessions and revoke access.

Why this answer

Promptly reporting the incident to IT security and changing the password immediately are critical steps to mitigate unauthorized access.

12
MCQeasy

An employee notices their computer screen locked with a message demanding cryptocurrency payment to restore encrypted files. What type of malware has infected the workstation?

A.A rootkit that grants administrative privileges to remote attackers.
B.Ransomware that encrypts critical files and demands payment for access.
C.Adware that automatically displays unwanted promotional banners.
D.Spyware that covertly records keystrokes and captures screenshots.
AnswerB

The symptom of demanding payment for file decryption is characteristic of ransomware.

Why this answer

Ransomware encrypts user files and demands a ransom payment in exchange for the decryption key.

13
MCQmedium

An employee is designing a password for a new privileged system account. Which of the following practices represents the strongest password creation standard?

A.A sequence of consecutive keyboard keys like 'qwertyuiop123!' for ease of typing
B.A password reused from personal social media accounts to ensure easy recall
C.A long passphrase consisting of random unrelated words and special characters
D.A short word combined with the current year, such as 'Summer2026!'
AnswerC

Length and complexity combined create robust entropy, defending against modern cracking tools.

Why this answer

Using a long passphrase with a combination of character types provides high entropy, making it extremely difficult to crack via brute-force or dictionary methods.

14
MCQhard

An enterprise branch office needs to establish a secure, encrypted site-to-site tunnel back to the headquarters FortiGate over the public internet. Which VPN technology provides a standard IPsec framework combined with Fortinet Security Fabric integration features?

A.IPsec VPN tunnel in route-based mode
B.FortiClient EMS telemetry connection
C.SSL VPN web portal mode
D.RADIUS single sign-on agent
AnswerA

Route-based IPsec VPNs provide standard encryption and virtual interface routing ideal for site-to-site connections.

Why this answer

IPsec VPN with aggressive or main mode supports secure site-to-site connectivity. In FortiOS, IPsec tunnels can be configured in policy-based or route-based modes.

15
MCQmedium

A remote worker is using a public Wi-Fi hotspot to access company resources. Which configuration provides the best protection for their traffic?

A.Utilize a secure VPN tunnel to the corporate network.
B.Enable browser-based spell check.
C.Ensure the laptop firewall is turned off to allow easier connectivity.
D.Use an unencrypted FTP connection for file transfers.
AnswerA

VPNs provide an encrypted tunnel that secures data transit across untrusted networks.

Why this answer

A VPN encrypts the traffic between the client and the corporate gateway, protecting data from interception on public networks.

16
MCQmedium

An administrator needs to check the status of FortiCare registration and feature licenses. Where in the web-based manager is this license summary displayed?

A.Policy & Objects > Licenses
B.Security Fabric > Registration
C.System > FortiGuard
D.Log & Report > License Audit
AnswerC

Correct. System > FortiGuard displays license status, contract expiration dates, and rating server connectivity.

Why this answer

License and registration status can be viewed under System > FortiGuard or the Dashboard License Information widget.

17
MCQhard

An attacker intercepts corporate communications by placing themselves between two communicating hosts, relaying messages and modifying them while both parties believe they are talking directly to each other. What is this attack called?

A.MAC flooding attack
B.Distributed denial of service
C.Man-in-the-Middle attack
D.SQL injection exploit
AnswerC

Interception and relay of traffic between two parties is a classic MitM attack.

Why this answer

A Man-in-the-Middle (MitM) attack involves an attacker secretly relaying and potentially altering communications between two parties who believe they are directly communicating.

18
MCQeasy

An end user receives an email from a display name matching their company executive, urging them to immediately click a link and purchase gift cards for a client meeting. Which foundational security concept and immediate action should the user apply?

A.Forward the email to all colleagues as a warning, including the live clickable link.
B.Reply to the sender asking for clarification using the reply button.
C.Recognize the social engineering attempt and use the organization's phishing reporting tool.
D.Treat it as an urgent executive request and fulfill the purchase immediately.
AnswerC

Reporting suspicious emails helps security teams isolate the threat across the network.

Why this answer

This is a classic Business Email Compromise (BEC) and phishing attack. The user should report the email using the organization's Phishing Incident Response tool rather than clicking or replying.

19
Multi-Selecteasy

Which TWO of the following practices represent essential foundational habits for maintaining strong personal and corporate password security? (Choose two)

Select 2 answers
A.Writing passwords on a physical notepad kept inside a locked desk drawer
B.Reusing the same strong master password across all banking and work systems for ease of recall
C.Storing passwords in an encrypted password manager application
D.Changing passwords every single week regardless of whether a compromise is suspected
E.Using a unique, complex password for every individual account
AnswersC, E

Password managers securely generate and store complex credentials.

Why this answer

Using unique passwords for every account prevents credential stuffing attacks from cascading, and utilizing password managers ensures complex, unguessable strings are stored securely.

20
Multi-Selectmedium

Which TWO of the following characteristics differentiate SSL VPN from IPsec VPN when deploying remote access solutions on a FortiGate? (Choose two.)

Select 2 answers
A.IPsec VPN operates exclusively at Layer 7 of the OSI model using HTTP/HTTPS protocols.
B.SSL VPN requires Internet Key Exchange (IKE) phase 1 and phase 2 negotiation parameters.
C.IPsec VPN cannot be terminated on a FortiGate device without an active FortiClient EMS license.
D.SSL VPN commonly utilizes TCP port 443, making it easier to traverse restrictive outbound firewalls.
E.SSL VPN can provide clientless web-portal access without requiring a pre-installed VPN client application.
AnswersD, E

Using standard HTTPS ports allows SSL VPN to bypass strict outbound filtering rules that often block UDP ports used by IPsec.

Why this answer

SSL VPN can operate in web mode (browser-based) or tunnel mode, whereas IPsec VPN requires dedicated client software or OS-level configurations. SSL VPN typically uses standard ports like TCP 443, whereas IPsec VPN uses UDP 500/4500.

21
Multi-Selecteasy

Which TWO protocols can be enabled on a FortiGate interface for secure administrative access? (Choose two.)

Select 2 answers
A.POP3
B.Telnet
C.HTTP
D.HTTPS
E.SSH
AnswersD, E

HTTPS provides encrypted web-based GUI administrative access.

Why this answer

HTTPS and SSH are secure protocols used for web-based GUI and command-line administrative access.

22
Multi-Selectmedium

Which TWO inspection modes are available on a FortiGate firewall for processing UTM security profiles? (Choose two.)

Select 2 answers
A.NAT routing inspection
B.Transparent bridging inspection
C.Flow-based inspection
D.Proxy-based inspection
E.Static gateway inspection
AnswersC, D

Flow-based inspection inspects traffic efficiently using flow engines.

Why this answer

FortiOS supports Flow-based inspection and Proxy-based inspection modes for UTM security profiles.

23
MCQeasy

What is the primary function of a FortiGate hardware acceleration processor (FortiASIC)?

A.To offload firewall session processing and cryptographic operations, accelerating performance
B.To manage user identities and generate FortiToken push notifications
C.To provide wireless access point controller management via CAPWAP
D.To act as an external database for storing FortiAnalyzer log archives
AnswerA

FortiASIC processors accelerate packet forwarding and crypto processing in hardware.

Why this answer

FortiASIC chips offload compute-intensive tasks like packet forwarding, cryptographic operations, and content inspection from the main CPU, accelerating firewall performance.

24
MCQmedium

An administrator needs to restrict administrative access to the FortiGate CLI and GUI so that management connections are only accepted from a specific trusted internal management workstation subnet. Where is this source IP restriction configured?

A.Within the FortiGuard subscription server list
B.Inside the DHCP server IP pool range
C.On the administrator user account configuration (Trusted Hosts)
D.Inside the global DNS server settings
AnswerC

Trusted host settings on admin accounts restrict login access to specified IP ranges.

Why this answer

Trusted hosts can be defined on administrator user accounts to ensure management access is only permitted from specified source IP addresses.

25
MCQmedium

An administrator notices that the FortiGate system disk is filling up rapidly with log files. Which action should be taken to ensure local storage does not run out of space while retaining historical logs?

A.Disable all firewall policy rule logging permanently
B.Lower the physical interface MTU size across all WAN ports
C.Switch the FortiGate from NAT mode to Transparent mode
D.Configure remote logging to FortiAnalyzer or Syslog server and enable log overwriting
AnswerD

Offloading logs to FortiAnalyzer prevents local storage fill-up while retaining data.

Why this answer

Configuring centralized logging to FortiAnalyzer or setting up log retention/overwrite policies ensures local storage exhaustion is prevented.

26
MCQmedium

An administrator needs to verify whether the FortiGate unit can successfully communicate with the FortiGuard distribution servers for license and signature updates. Which command should be run in the CLI to test this specific connectivity?

A.diagnose sys top
B.ping 8.8.8.8
C.execute update-now
D.execute FortiGuard-test
AnswerC

Correct. execute update-now forces an immediate check and update with FortiGuard servers, verifying connectivity.

Why this answer

The update status and connectivity to FortiGuard can be tested using the execute update-now or diagnostic commands for FortiGuard override/servers.

27
Multi-Selecteasy

Which TWO dashboard widgets are commonly used to monitor system performance and health on a FortiGate?

Select 2 answers
A.FortiView Source IPv4
B.System Information
C.System Resources
D.IPsec Monitor
E.DHCP Leases
AnswersB, C

Displays uptime, serial number, firmware version, and hostname.

Why this answer

System Resources and System Information are standard dashboard widgets for tracking hardware performance and general device status.

28
MCQeasy

An administrator wants to search for a specific user's web browsing logs from earlier in the day. Which menu should they open in the web-based manager?

A.Monitor > Web Activity
B.Log & Report > Web Filter
C.Policy & Objects > URL Filter
D.FortiView > Websites
AnswerB

Correct. Web filter logs record website access attempts and URL filtering actions.

Why this answer

Web filtering and web access logs are found under Log & Report > Web Filter.

29
MCQeasy

Which of the following scenarios describes a 'pretexting' social engineering attack?

A.An attacker leaves a malicious USB drive in the lobby.
B.An attacker uses automated software to guess passwords.
C.An attacker shoulder-surfs to capture a password.
D.An attacker poses as an auditor to convince an employee to disclose sensitive internal procedures.
AnswerD

Posing as an authority figure to gather information is a classic pretext.

Why this answer

Pretexting involves creating a fabricated scenario to manipulate a victim into providing information.

30
Multi-Selectmedium

Which TWO of the following are considered 'social engineering' techniques?

Select 2 answers
A.Using a rainbow table to crack hashed passwords.
B.Baiting a victim with a 'free' USB drive that contains malware.
C.Tailgating into a secure office area by following an authorized employee.
D.Performing a denial of service attack on a web server.
E.Using a vulnerability scanner to find open ports.
AnswersB, C

This exploits curiosity to deliver a payload.

Why this answer

Baiting and tailgating are both social engineering methods used to exploit human behavior.

31
MCQeasy

An administrator needs to quickly check the CPU and memory utilization of a FortiGate device directly from the web-based manager. Which dashboard widget provides this real-time system performance information by default?

A.FortiView Sessions
B.System Resources
C.License Information
D.Network Interfaces
AnswerB

Correct. The System Resources widget displays live CPU and memory utilization.

Why this answer

The System Resources widget displays real-time CPU and memory usage, allowing administrators to monitor resource consumption.

32
MCQhard

An administrator needs to verify the hardware sensor status (fans, power supplies, temperatures) of a high-end FortiGate unit. Which command provides this hardware health status?

A.execute hardware-test
B.diagnose hardware device info
C.show system sensor
D.get system hardware status
AnswerD

Correct. This command lists hardware sensor information including temperature and power supplies.

Why this answer

The get system hardware status command displays sensor readings such as fan speed and temperature.

33
MCQhard

An enterprise security team implements Multi-Factor Authentication (MFA) across all employee accounts. Which combination of authentication factors represents the strongest implementation of MFA?

A.A password, a push notification sent to a physical mobile device, and a biometric thumbprint scan.
B.A smart card and a hardware security token.
C.A biometric fingerprint scan and a facial recognition scan.
D.A password and a PIN memorized by the user.
AnswerA

This combines knowledge (password), possession (phone), and inherence (biometric), utilizing three separate categories.

Why this answer

Strong MFA combines three distinct authentication factors: something you know, something you have, and something you are.

34
MCQhard

An administrator suspects that a session is stuck in the FortiGate session table, preventing new connections. Which command allows viewing active sessions matching a specific source IP?

A.show firewall session [IP]
B.diagnose sys session filter src [IP] followed by diagnose sys session list
C.execute session clear [IP]
D.get system session list
AnswerB

Correct. Filtering and listing sessions allows pinpointing traffic for a specific source IP.

Why this answer

The diagnose sys session filter command combined with list allows filtering and viewing active sessions.

35
MCQmedium

An administrator wants to configure a firewall policy so that specific internal users can only access the internet during non-work hours. Which object type should be added to the firewall policy to enforce this time restriction?

A.Firewall Schedule object
B.Virtual IP (VIP) object
C.Application Control signature
D.Traffic Shaper object
AnswerA

Schedule objects allow administrators to enforce time-based firewall rules.

Why this answer

Schedule objects define specific time periods and days of the week, which can be added to firewall policies to enforce time-based access control.

36
MCQmedium

An administrator needs to ensure that administrative sessions to the FortiGate GUI automatically terminate after 15 minutes of inactivity. Where is this idle timeout setting configured?

A.Inside the individual firewall policy rule settings
B.Inside the DHCP server IP lease settings
C.Under System Global settings (Administrator Idle Timeout)
D.Within the static routing table configuration
AnswerC

Global settings control system-wide administrative idle timeout thresholds.

Why this answer

System idle timeout for administrators is configured under system global settings.

37
MCQhard

An administrator is troubleshooting a policy match issue and needs to inspect a specific security policy's hit count and ID directly from the CLI. Which CLI command should the administrator use to list all firewall policies with their internal IDs and rule details?

A.get system performance
B.diagnose sys session list
C.get system status
D.show firewall policy
AnswerD

Correct. Entering config firewall policy followed by show displays the configured policies and their IDs.

Why this answer

To view firewall policies via CLI, the command show firewall policy is used inside the configuration context.

38
Multi-Selectmedium

When setting up a new FortiGate device, an administrator needs to configure basic network parameters before deploying it in production. Which THREE parameters must be configured for basic network connectivity?

Select 3 answers
A.Interface IP address and subnet mask
B.DNS server IP addresses
C.BGP routing peer AS number
D.Default static route
E.SSL VPN portal customization
AnswersA, B, D

Interfaces require IP addressing to communicate on networks.

Why this answer

Basic network setup requires configuring physical interface IP addresses, default static routes to reach external networks, and DNS servers for name resolution.

39
MCQeasy

An administrator wants to verify the amount of free space available on the system log disk. Which dashboard widget displays this metric?

A.Storage Usage widget
B.System Resources
C.Hard Drive Status
D.Log Disk widget
AnswerD

Correct. The Log Disk widget shows total storage and used/free space for logging.

Why this answer

The Log Disk widget displays log disk usage and free space percentage.

40
MCQeasy

What is the primary function of a FortiGate static route?

A.To manually specify the next-hop gateway for routing traffic to specific destination networks
B.To translate private internal IP addresses to public WAN IP addresses
C.To inspect HTTP web traffic for malicious scripts
D.To authenticate remote VPN users against Active Directory
AnswerA

Static routes define explicit paths for traffic destined for remote subnets.

Why this answer

A static route manually defines the next-hop IP gateway for specific destination subnets when packets cannot be resolved by directly connected interfaces.

41
MCQmedium

An administrator wants to ensure that all configuration changes made on a FortiGate are tracked with specific user accountability and revision history. Which Fortinet management tool provides centralized configuration revision control and rollback capabilities?

A.FortiAnalyzer
B.FortiClient EMS
C.FortiAuthenticator
D.FortiManager
AnswerD

FortiManager provides revision control, audit trails, and configuration rollbacks.

Why this answer

FortiManager maintains centralized configuration revisions, audit trails, and allows administrators to roll back changes to previous known-good states.

42
Multi-Selecteasy

Which THREE of the following actions are examples of good physical security practices in an office environment? (Choose three)

Select 3 answers
A.Locking your workstation screen every time you step away from your desk
B.Wearing your employee identification badge visibly at all times while on premises
C.Challenging or reporting unbadged individuals wandering through secure office areas
D.Leaving visitor logs and visitor badges unattended on the front reception desk for anyone to take
E.Propping open secure exterior fire doors to let fresh air into the building
AnswersA, B, C

Screen locking prevents unauthorized physical access to active user sessions.

Why this answer

Locking unattended screens, wearing ID badges, and challenging unescorted visitors are all fundamental physical security controls.

43
MCQhard

When configuring FortiGate High Availability (HA) in active-passive mode, what is the role of the heartbeat interfaces?

A.To connect FortiClient EMS endpoints to the root FortiGate
B.To exchange keepalive health packets and synchronize session states and configurations between cluster members
C.To download daily antivirus signature updates from FortiGuard servers
D.To route user internet traffic across public WAN connections to the ISP
AnswerB

Heartbeat links maintain cluster synchronization and failover detection.

Why this answer

Heartbeat interfaces are dedicated connections between HA cluster members used to transmit keepalive signals, synchronize configuration states, and maintain session synchronization.

44
MCQmedium

An administrator wants to verify the administrator access profile privileges assigned to a specific admin account. Where can access profiles be defined and edited?

A.Security Fabric > Profiles
B.System > Admin Profiles
C.System > Administrators > Profiles
D.Policy & Objects > Admin Profiles
AnswerB

Correct. Admin Profiles define read/write permissions for different administrative menus and features.

Why this answer

Administrator access profiles are managed under System > Admin Profiles.

45
Multi-Selectmedium

An administrator wants to verify high availability (HA) cluster status and member synchronization. Which TWO commands or dashboard widgets provide this HA status? (Choose two)

Select 2 answers
A.get system ha status
B.get system interface physical
C.FortiView > HA Traffic
D.High Availability dashboard widget
E.Policy & Objects > HA Rules
AnswersA, D

Correct. This CLI command outputs cluster member health, heartbeats, and synchronization status.

Why this answer

HA status can be monitored using the High Availability dashboard widget and the CLI command get system ha status.

46
MCQhard

An administrator is troubleshooting a scenario where internal users can browse safe websites, but HTTPS inspection using certificates is throwing browser security warnings for certain internal web applications. What is the most likely cause of this behavior when using Deep Packet Inspection (DPI) on FortiGate?

A.The Web Filtering license on the FortiGate has expired, causing HTTPS inspection to fail open.
B.The firewall policy is configured with proxy-based inspection instead of flow-based inspection.
C.The Antivirus database update failed, preventing the FortiGate from decrypting TLS 1.3 handshakes.
D.The FortiGate CA certificate has not been installed in the trusted root certificate store of the client endpoints.
AnswerD

Browsers flag DPI-intercepted HTTPS traffic as untrusted unless the inspecting FortiGate's CA certificate is installed on the client.

Why this answer

During Deep Packet Inspection (DPI), FortiGate acts as a man-in-the-middle, re-signing SSL/TLS traffic with its internal CA certificate. If the FortiGate CA certificate is not installed in the client browser's trusted root store, the browser displays untrusted certificate warnings.

47
MCQeasy

Where can an administrator view a summary of system alerts and warning messages directly in the web-based manager without navigating to full log reports?

A.Dashboard > System Events widget (or Event Log summary)
B.System > Monitoring
C.Network > Alerts
D.Policy & Objects > Event Monitoring
AnswerA

Correct. Dashboard widgets summarize recent system events and alerts.

Why this answer

The Event Log or System Events dashboard widgets provide quick summaries of recent system notices.

48
Multi-Selecthard

Which TWO strategies are recognized as effective defenses against social engineering attacks like phishing and pretexting? (Choose two.)

Select 2 answers
A.Conducting regular security awareness training and simulated phishing tests for all staff.
B.Implementing multi-factor authentication (MFA) to protect user accounts even if credentials are exposed.
C.Permitting unrestricted personal USB drive usage on all corporate endpoints without scanning.
D.Instructing employees to comply immediately with any urgent executive request received via personal email.
E.Disabling all spam and email filtering to ensure zero legitimate messages are ever delayed.
AnswersA, B

Training helps employees recognize suspicious cues and builds an organizational culture of security.

Why this answer

Effective defense against social engineering combines human security awareness training with robust technical email filtering controls.

49
MCQhard

An internal auditor reviews network security logs and discovers that clear-text protocols such as Telnet and HTTP are actively used for managing core network devices. Which security principle is directly violated, and what is the recommended remediation?

A.Integrity is violated; remediation involves enabling packet checksum validation on all switches.
B.Non-repudiation is violated; remediation involves implementing digital signatures on email traffic.
C.Availability is violated; remediation involves upgrading uplink port speeds to 10Gbps.
D.Confidentiality is violated; remediation involves migrating to encrypted management protocols like SSH and HTTPS.
AnswerD

Unencrypted management traffic exposes passwords to sniffing, violating confidentiality, which is resolved by using SSH and HTTPS.

Why this answer

Telnet and HTTP transmit credentials and management data in clear text, violating confidentiality, and should be replaced with SSH and HTTPS.

50
MCQhard

An organization wants to prevent users from visiting malicious websites identified in real-time by a threat intelligence database. Which feature is most effective for this?

A.MAC address filtering on the local switch.
B.Local static IP filtering.
C.Dynamic URL filtering with reputation-based feeds.
D.Disabling cookies in the browser.
AnswerC

Reputation-based filtering uses real-time intelligence to identify and block malicious sites.

Why this answer

URL filtering integrated with threat intelligence feeds allows the gateway to block access to known malicious domains before the connection is established.

51
MCQeasy

An employee receives a phone call from an individual claiming to be from the IT department, asking for their network password to resolve an urgent system ticket. The caller sounds professional and urgent. What best describes this type of attack?

A.Drive-by download
B.Denial of service
C.Phishing via email
D.Vishing (Voice Phishing)
AnswerD

Using telephone calls to impersonate trusted personnel for data theft is vishing.

Why this answer

Vishing (voice phishing) uses telephone communication to manipulate individuals into divulging confidential information.

52
MCQmedium

An administrator configures a firewall policy with Web Filtering. When a user tries to access a newly created website whose category is unknown by the FortiGate, how does FortiGate handle the rating request?

A.It sends a real-time rating query to the FortiGuard servers to classify the URL
B.It forwards the page to FortiSandbox for zero-day file execution
C.It automatically blocks the website as a high-risk security threat
D.It quarantines the user's workstation inside FortiClient EMS
AnswerA

FortiGate queries FortiGuard servers dynamically for uncached web categories.

Why this answer

When a URL is uncached or uncategorized locally, the FortiGate queries the FortiGuard Web Filtering rating servers in real-time to determine the category.

53
MCQeasy

An attacker intercepts legitimate communication between two parties and alters the message content while impersonating each party to the other. What type of cyber attack has occurred?

A.A man-in-the-middle attack intercepting and modifying transit data.
B.A distributed denial-of-service attack flooding servers.
C.A zero-day exploit leveraging unpatched software code.
D.A brute-force attack guessing login credentials.
AnswerA

MitM attacks involve secretly relaying and potentially altering communications between two parties who believe they are directly communicating.

Why this answer

An attack where an adversary positions themselves between two endpoints to monitor or alter traffic is a Man-in-the-Middle (MitM) attack.

54
MCQmedium

During a security awareness training session, an administrator explains how attackers use pretexting. Which scenario best exemplifies a pretexting attack?

A.An attacker installs a keylogger on an unattended physical workstation in an office.
B.An attacker floods a web server with synthetic traffic to crash the service.
C.An attacker calls the helpdesk posing as a new executive claiming to have lost their password, requesting a reset.
D.An attacker sends mass emails containing a malicious macro-enabled attachment.
AnswerC

Posing as an executive with an urgent fictitious backstory is a classic pretexting scenario.

Why this answer

Pretexting involves an attacker fabricating a scenario or identity to trick a victim into releasing information.

55
Multi-Selecthard

Which TWO mechanisms are commonly utilized by attackers to establish persistence on a compromised workstation so they can retain access after a system reboot? (Choose two.)

Select 2 answers
A.Running a temporary calculation script inside an isolated browser incognito tab.
B.Running an optional software update diagnostic tool provided by the hardware manufacturer.
C.Installing a kernel-level rootkit that hooks into core operating system processes.
D.Clearing the system browser cache and emptying the local operating system recycle bin.
E.Modifying operating system startup registry keys or creating automated scheduled tasks.
AnswersC, E

Rootkits embed themselves deeply into the OS kernel to hide malicious activity and survive reboots.

Why this answer

Attackers maintain persistence through mechanisms such as scheduled tasks, startup registry keys, or installed rootkits.

56
Multi-Selectmedium

Which TWO methods are effective ways to protect user accounts against credential-based attacks like credential stuffing and brute-forcing? (Choose two)

Select 2 answers
A.Permitting HTTP plaintext transmission for login forms to speed up authentication.
B.Allowing users to share identical passwords to reduce password fatigue.
C.Implementing account lockout policies after a threshold of failed login attempts.
D.Enforcing Multi-Factor Authentication (MFA) across all authentication portals.
E.Disabling logging mechanisms to prevent server storage bloat.
AnswersC, D

Lockout policies stop automated brute-force guessing tools.

Why this answer

Multi-factor authentication and account lockout policies effectively mitigate credential stuffing and brute-forcing.

57
MCQmedium

An administrator needs to configure an idle timeout for administrative web GUI sessions to enhance security. Where is this setting located?

A.System > Administrators > Timeout
B.Policy & Objects > Global Settings
C.System > Settings > Administrator Idle Timeout
D.Log & Report > Admin Settings
AnswerC

Correct. System Settings contains the global configurable idle timeout for GUI admins.

Why this answer

Administrator session idle timeout is configured under System > Settings.

58
MCQmedium

An administrator notices that the FortiGate configuration changes made during troubleshooting were lost after an unexpected power outage. Where should the administrator check to ensure that the current running configuration is permanently saved?

A.System > Admin > Settings
B.FortiGate automatically saves running configurations to non-volatile memory immediately upon successful CLI or GUI commit actions.
C.System > Configuration > Backup
D.The CLI command execute backup config
AnswerB

Correct. FortiGate commits changes to running memory and non-volatile flash storage automatically upon a successful save action in the GUI or CLI.

Why this answer

Configuration changes in the CLI or GUI must be saved to flash storage. The active running configuration can be backed up or saved, but changes made via certain methods or scripts require explicit saves.

59
MCQeasy

An administrator needs to ensure that internal network users cannot bypass corporate security policies by using unauthorized peer-to-peer file sharing or gaming applications. Which FortiGate security feature is specifically designed to identify and take action against these types of network protocols?

A.Application Control
B.Antivirus Profile
C.NAT IP Pool
D.Static Route Table
AnswerA

Application Control detects and manages non-standard applications and protocols running across standard or random ports.

Why this answer

Application Control identifies and controls applications (like P2P, gaming, social media) regardless of port or protocol by analyzing traffic heuristics and signatures.

60
MCQeasy

An IT administrator creates complex password policies requiring a mix of uppercase, lowercase, numbers, and special characters. Which security objective does this practice primarily support?

A.Preventing structured SQL injection attacks against web databases.
B.Mitigating brute-force and credential-guessing attacks.
C.Preventing physical theft of laptop hardware.
D.Ensuring high network bandwidth availability for video conferencing.
AnswerB

Complex passwords expand the keyspace, directly hindering automated guessing tools.

Why this answer

Complex passwords increase entropy, making brute-force and dictionary attacks significantly harder to execute successfully.

61
Multi-Selecthard

Which THREE components or protocols are involved in establishing and maintaining a FortiGate High Availability (HA) cluster using FGCP? (Choose three.)

Select 3 answers
A.Session synchronization and session pickup settings
B.BGP exterior routing protocol peer autonomous systems
C.RADIUS authentication server token polling
D.FGCP heartbeat keepalive packets and hello messages
E.Dedicated HA heartbeat interfaces
AnswersA, D, E

Session synchronization ensures active sessions fail over seamlessly without dropping connections.

Why this answer

FGCP clustering relies on dedicated heartbeat interfaces, cluster hello/keepalive packets, and session synchronization/pickup configurations.

62
Multi-Selectmedium

An administrator wants to view historical web filtering and traffic logs on the FortiGate. Which TWO methods can be used to search and analyze stored logs? (Choose two)

Select 2 answers
A.Log & Report menu in the web-based manager with filter and search options
B.Restarting the routing daemon (gated)
C.Editing the FortiOS kernel source code directly
D.FortiAnalyzer integration or local log viewer filters
E.Running execute factory-reset
AnswersA, D

Correct. The Log & Report graphical log viewer provides robust search and filter capabilities.

Why this answer

Logs can be searched and filtered using the Log & Report menu in the GUI or via specialized log search CLI commands.

63
MCQeasy

Which dashboard widget displays the status of connected FortiGate security fabric devices and fabric topology?

A.FortiView Threat Map
B.Security Fabric Rating
C.System Resources
D.Security Fabric > Topology
AnswerD

Correct. The Security Fabric topology view visually maps out the interconnected devices.

Why this answer

The Security Fabric widget or Security Fabric topology view provides visibility into connected fabric devices.

64
MCQhard

An administrator is troubleshooting a certificate validation error when users connect to an SSL VPN portal. Where can the active SSL VPN server certificate be verified or changed in the web-based manager?

A.VPN > SSL-VPN Settings (Server Certificate field)
B.Policy & Objects > SSL Settings
C.System > Certificates > SSL-VPN
D.Security Fabric > VPN Settings
AnswerA

Correct. The SSL-VPN settings menu specifies the server certificate presented to remote VPN clients.

Why this answer

SSL VPN settings, including the server certificate selection, are configured under VPN > SSL-VPN Settings.

65
MCQmedium

An administrator needs to export the current configuration of a FortiGate to a secure local file for backup purposes. Which menu path should the administrator navigate in the web-based manager?

A.System > Settings > Maintenance
B.Click the administrator profile name at the top right of the GUI > Configuration > Backup
C.Security Fabric > Settings > Export
D.Log & Report > Backup Settings
AnswerB

Correct. On modern FortiOS versions, configuration backup and restore are accessed via the administrator profile dropdown menu at the top right of the GUI.

Why this answer

Configuration backup and restore functions are typically located under System > Configuration or via the administrator profile dropdown menu.

66
MCQhard

An enterprise is deploying FortiGate High Availability (HA) in active-active mode. How does active-active mode differ from active-passive mode regarding session handling?

A.Active-active requires manual administrator failover, while active-passive is fully automated
B.Active-active disables all firewall security profiles to maximize raw throughput
C.Active-active distributes session processing across multiple cluster units, whereas active-passive processes all traffic on a single primary unit
D.Active-active eliminates the need for heartbeat cables between cluster units
AnswerC

Active-active mode shares session processing across multiple active cluster members.

Why this answer

In active-active mode, session load is distributed across multiple cluster members using session-pickup/load-balancing mechanisms, whereas active-passive runs all traffic through the primary unit until a failover occurs.

67
MCQeasy

An organization is deploying FortiGate firewalls to segment internal network zones. What is the default action of a newly created firewall policy when traffic matches neither this policy nor any other rule?

A.Drop and send ICMP destination unreachable
B.Redirect to Captive Portal
C.Implicit Deny
D.Implicit Accept
AnswerC

Any traffic not matched by explicit policies is blocked by the implicit deny rule at the bottom of the policy table.

Why this answer

Implicit Deny is the default security behavior of FortiGate firewalls, ensuring any traffic not explicitly permitted by a firewall policy is dropped.

68
Multi-Selecteasy

Which TWO firewall operational modes can be configured on a FortiGate device? (Choose two.)

Select 2 answers
A.Sandbox isolation mode
B.Promiscuous sniffing mode
C.Transparent mode
D.Endpoint agent mode
E.NAT mode
AnswersC, E

Transparent mode bridges Ethernet frames at Layer 2 without routing or IP modification.

Why this answer

FortiGate firewalls operate in either NAT mode or Transparent mode.

69
Multi-Selecteasy

Which TWO of the following behaviors are recommended when handling unexpected or suspicious email attachments? (Choose two)

Select 2 answers
A.Forward suspicious attachments to all coworkers to see if anyone recognizes them
B.Immediately open executable attachments (.exe) to check what program they run
C.Refrain from opening files with double extensions like .pdf.exe or unexpected script formats
D.Verify the legitimacy of the attachment by contacting the sender through an independent, trusted communication channel
E.Disable your antivirus software temporarily so it does not block the file download
AnswersC, D

Double extensions and script formats are common techniques used to disguise malware.

Why this answer

Users should verify files with senders through independent channels and avoid opening unknown executable or script attachments.

70
MCQeasy

An administrator wants to check the connection status of Security Fabric telemetry between the root FortiGate and downstream devices. Where is the Security Fabric status viewed?

A.System > Security Fabric Settings
B.Monitor > Fabric Monitor
C.Security Fabric > Topology
D.Dashboard > Fabric Health
AnswerC

Correct. The Security Fabric topology view displays connection status and health between fabric members.

Why this answer

Security Fabric status and topology are viewed under Security Fabric > Topology or Security Fabric Setup.

71
MCQhard

A user reports that their workstation is running unusually slow and sending out large amounts of encrypted traffic to an unknown external IP. What is the most likely issue?

A.The user installed a legitimate browser extension.
B.The user's local firewall is performing a full system scan.
C.The system is performing a routine background update.
D.The host is infected with malware and participating in a botnet.
AnswerD

Malware communicating with a C2 server often exhibits these traffic patterns.

Why this answer

These symptoms are consistent with a botnet infection where the host is part of a command-and-control network.

72
MCQeasy

What is the primary function of a FortiGate firewall policy action set to 'Accept'?

A.To redirect the user browser to a captive portal authentication page
B.To permit matching traffic to traverse the FortiGate
C.To encapsulate the packet inside an IPsec VPN tunnel
D.To drop the matching packet silently without logging
AnswerB

An 'Accept' action allows matched traffic to pass through the firewall.

Why this answer

When a packet matches a firewall policy with an action of 'Accept', the FortiGate permits the traffic to pass through the device toward its destination.

73
Multi-Selecteasy

Which THREE of the following actions represent safe habits when using public Wi-Fi hotspots? (Choose three)

Select 3 answers
A.Conducting personal online banking without checking for HTTPS or using a VPN
B.Disabling automatic connection to open Wi-Fi networks on your mobile device
C.Accepting all unknown certificate warnings when browsing on public hotspots
D.Using a trusted corporate Virtual Private Network (VPN) for all internet traffic
E.Avoiding access to highly sensitive corporate accounts unless an encrypted tunnel is active
AnswersB, D, E

This prevents devices from connecting to rogue access points automatically.

Why this answer

Using a VPN, avoiding sensitive transactions on unencrypted networks, and disabling automatic network connection features protect users on public Wi-Fi.

74
Multi-Selecteasy

Which TWO of the following are core components of the Fortinet Security Fabric architecture? (Choose two.)

Select 2 answers
A.VMware ESXi hypervisor
B.Microsoft Active Directory
C.FortiAnalyzer
D.Cisco Catalyst Switch
E.FortiGate
AnswersC, E

FortiAnalyzer provides centralized analytics and log management for the Security Fabric.

Why this answer

FortiGate (firewall) and FortiAnalyzer (logging/analytics) are core foundational pillars of the Fortinet Security Fabric.

75
MCQeasy

Which Fortinet product acts as the centralized log management and reporting server that aggregates log data from multiple FortiGate devices across an enterprise network?

A.FortiSandbox
B.FortiAuthenticator
C.FortiAnalyzer
D.FortiWeb
AnswerC

FortiAnalyzer provides centralized logging, analysis, and auditing capabilities.

Why this answer

FortiAnalyzer collects, analyzes, and correlates log data from FortiGate and other Security Fabric devices, generating comprehensive reports.

Page 1 of 4

Page 2

All pages