Courseiva

Fortinet NSE 1-3 (Network Security Associate track: Foundational, Technical Introduction, Associate) (FORTINET-NSE123) (FORTINET-NSE123) — Questions 76150

296 questions total · 4pages · All types, answers revealed

Page 1

Page 2 of 4

Page 3
76
MCQmedium

A network engineer wants to inspect web traffic for malicious downloads and web-based threats passing through a FortiGate device. Where must this inspection profile be applied to take effect?

A.Directly under the physical interface configuration
B.Inside an IPv4 firewall policy matching the traffic
C.Inside the static routing table configuration
D.Under the Global System Settings menu
AnswerB

Security profiles must be attached to firewall policies to process traffic.

Why this answer

Security profiles, such as Antivirus, Web Filtering, and IPS, must be bound to an active IPv4 or IPv6 firewall policy to inspect traffic traversing the FortiGate.

77
MCQhard

An administrator notices that configuration changes made via the CLI are not persisting after a device reboot. What is the most likely reason for this behavior?

A.The administrator exited the configuration block using 'abort' instead of 'end'.
B.The administrator forgot to issue the 'write memory' command.
C.The administrator did not issue a 'execute factory-reset' to commit.
D.The administrator failed to enable manual commit mode in system settings.
AnswerA

Using 'abort' discards all uncommitted changes made within the current configuration session.

Why this answer

FortiGate saves configuration changes to running memory immediately, but they are only written to permanent flash storage when the command completes successfully. If an invalid command or virtual domain (VDOM) context was left incomplete, or if the write failed, changes may be lost. However, standard config changes auto-save.

If flash is full or in read-only mode, it fails. Alternatively, failing to enter 'end' properly or making changes in a temporary session can cause loss. Let's look at options regarding manual commit vs auto-save.

FortiGate auto-saves upon 'end'.

78
MCQhard

An administrator is configuring a FortiGate firewall and needs to ensure that packets matching an explicit allow policy are also logged. Where should the administrator enable logging for this specific policy?

A.Inside the static route next-hop configuration
B.Within the physical interface administrative access profile
C.Inside the specific firewall policy rule settings under Log Allowed Traffic
D.Under the global system time zone and NTP settings
AnswerC

Firewall policy logging is enabled per policy rule to track allowed or denied traffic.

Why this answer

Log settings for a firewall policy (such as logging all sessions or security events) are configured directly inside the individual firewall policy rule parameters.

79
MCQeasy

Where can an administrator view real-time bandwidth consumption per interface on the FortiGate dashboard?

A.Network Interfaces widget on the Dashboard
B.FortiView > Interfaces
C.System > Network > Performance
D.Log & Report > Bandwidth Monitor
AnswerA

Correct. The Network Interfaces widget provides live throughput and status for all interfaces.

Why this answer

The Network Interfaces widget displays real-time bandwidth and traffic rates per interface.

80
MCQmedium

An administrator needs to configure SNMP v3 monitoring on the FortiGate for integration with a network management system (NMS). Where is SNMP configured in the web-based manager?

A.Network > SNMP Agent
B.Log & Report > SNMP Settings
C.Security Fabric > SNMP
D.System > SNMP
AnswerD

Correct. SNMP v1/v2c/v3 communities, users, and trap receivers are configured under System > SNMP.

Why this answer

SNMP settings are configured under System > SNMP.

81
Multi-Selectmedium

Which TWO actions should an end-user take to protect their physical workstation security?

Select 2 answers
A.Disable the screensaver to ensure the system is always visible.
B.Store sensitive documents in a locked drawer when not in use.
C.Leave the workstation unlocked during lunch breaks to save time.
D.Write the BIOS password on a post-it note attached to the monitor.
E.Lock the computer screen before walking away from the desk.
AnswersB, E

Physical document protection is as important as digital security.

Why this answer

Locking the screen and keeping sensitive documents stored securely are fundamental physical security controls.

82
MCQmedium

An enterprise network architect is designing a site-to-site VPN architecture to connect a branch office to headquarters using FortiGate devices. The branch office relies on a dynamic broadband connection with a frequently changing public IP address. Which VPN configuration approach should be implemented?

A.Implement Virtual Domain (VDOM) links to bridge the branch office directly to headquarters across Layer 2.
B.Configure static IPsec phase 1 parameters specifying the exact public IP address of the branch office on the headquarters FortiGate.
C.Configure an SSL VPN web portal on the branch office FortiGate.
D.Configure a site-to-site IPsec VPN with the headquarters acting as the dial-up server and the branch acting as the dial-up client.
AnswerD

A dial-up IPsec VPN setup accommodates branch offices with dynamic public IPs by having the static headquarters listen for incoming connections from dynamic peers.

Why this answer

When one peer has a dynamic IP address, Main Mode IPsec VPNs with dynamic dial-up user settings or Aggressive Mode with dynamic ID peer IDs are typically used. In modern FortiOS, dial-up IPsec VPN configurations allow the dynamically addressed branch to initiate the tunnel to the static headquarters.

83
Multi-Selecthard

An administrator is reviewing log storage and management settings on the FortiGate. Which THREE storage options or destinations are supported for logging on a FortiGate? (Choose three)

Select 3 answers
A.Local disk (internal hard drive or flash storage)
B.FortiAnalyzer
C.Bluetooth pairing with a mobile phone
D.Local printer connected via USB
E.Syslog server
AnswersA, B, E

Correct. FortiGate can store logs locally on internal flash storage or hard drives.

Why this answer

FortiGate supports logging locally to internal storage/hard drive, forwarding to FortiAnalyzer, and forwarding to Syslog servers.

84
MCQeasy

Where in the FortiGate GUI can an administrator view a summary of detected security incidents, top applications, and top bandwidth users across the network?

A.Security Fabric > Topology
B.FortiView > Sources
C.Dashboard > Status
D.FortiView > All Sessions / Dashboards
AnswerD

FortiView provides visual dashboards for top applications, sources, destinations, and threats.

Why this answer

FortiView is the primary monitoring tool in the FortiGate GUI used to analyze traffic, threats, top applications, and users.

85
Multi-Selecthard

Which THREE practices represent fundamental cybersecurity hygiene for end users to protect corporate endpoints? (Choose three)

Select 3 answers
A.Storing master credentials in a plain-text document on the desktop for quick reference.
B.Promptly installing operating system and application security patches.
C.Disabling endpoint antivirus agents to maximize system performance during video calls.
D.Verifying software legitimacy before downloading and installing third-party applications.
E.Locking the workstation screen whenever stepping away from the desk.
AnswersB, D, E

Patching closes known vulnerabilities exploited by malware.

Why this answer

Keeping software updated, avoiding unverified downloads, and locking screens are foundational hygiene steps.

86
MCQeasy

Where can an administrator view a real-time list of top destination IP addresses accessed by internal users?

A.Log & Report > Destination Summary
B.Policy & Objects > Destinations
C.Monitor > Routing Table
D.FortiView > Destinations
AnswerD

Correct. FortiView Destinations shows top destination addresses receiving traffic from the network.

Why this answer

FortiView Destinations provides real-time visibility into top destination IP addresses and domains.

87
Multi-Selectmedium

An administrator is preparing to deploy a new FortiGate and needs to configure basic network parameters. Which TWO basic network settings must typically be configured on physical interfaces before deploying firewall policies? (Choose two)

Select 2 answers
A.Explicit proxy authentication realms
B.Administrative access settings (e.g., enabling HTTPS and ping for management)
C.BGP AS number and neighbor peer groups
D.IP address and subnet mask
E.SSL VPN client certificate revocation lists
AnswersB, D

Correct. Administrative access protocols must be explicitly enabled on interfaces to allow GUI/CLI management.

Why this answer

Interfaces require addressing mode (static or DHCP) and proper IP/netmask configuration, along with administrative access permissions (HTTPS, ping, etc.).

88
MCQmedium

An administrator wants to verify which administrator is currently logged into the FortiGate and from which IP address. Which CLI command should be used?

A.diagnose sys admin list
B.get system admin status
C.get system user active
D.show system admin session
AnswerB

Correct. This command lists currently logged-in administrators and their connection source IPs.

Why this answer

Active administrative sessions can be viewed using the get system admin status or system session list commands.

89
MCQeasy

An administrator wants to check the operational status and firmware version of all connected FortiExtender devices managed by the FortiGate. Which menu path should they follow?

A.System > FortiExtender
B.Security Fabric > Managed Devices
C.Policy & Objects > Device Inventory
D.Network > FortiExtender
AnswerB

Managed FortiExtender units, switches, and APs appear under Security Fabric > Managed Devices.

Why this answer

Managed FortiExtender devices are monitored and configured under the Managed Devices menu in the FortiGate GUI.

90
MCQeasy

An administrator wants to view top talkers by bandwidth usage over the past hour. Which FortiView view should be accessed?

A.FortiView > Sources
B.Policy & Objects > Sources
C.Monitor > Top Talkers
D.Log & Report > Traffic Sources
AnswerA

Correct. FortiView Sources displays top source IP addresses generating network traffic.

Why this answer

FortiView Sources displays top talkers (source IP addresses) ranked by bandwidth consumption.

91
MCQmedium

An organization wants to educate its employees on how to recognize sophisticated spear-phishing emails that use personalized details gathered from public professional networks. Which training approach is most effective for building practical resilience?

A.Blocking all external incoming emails entirely
B.Conducting regular simulated phishing tests with immediate feedback
C.Restricting employees from having LinkedIn or social media accounts
D.Requiring employees to read a 100-page security policy manual annually
AnswerB

Practical simulations reinforce awareness and test behavioral readiness effectively.

Why this answer

Simulated phishing campaigns combined with immediate, contextual training help users recognize real-world tactics safely.

92
MCQhard

An administrator needs to restore a saved configuration file to the FortiGate via the CLI. Which command is used to restore configuration settings from a backup file stored on a TFTP server?

A.execute restore config tftp [filename] [server-IP]
B.config restore tftp [server-IP] [filename]
C.system restore backup [filename]
D.upload config tftp [server-IP]
AnswerA

Correct. This command downloads and restores a configuration backup from a TFTP server.

Why this answer

The execute restore config command is used to restore configuration backups.

93
MCQeasy

An administrator wants to customize the dashboard view by adding a new widget. What is the standard method to add widgets in the FortiGate GUI?

A.Click 'Add Widget' in the top-left corner of the Dashboard view
B.Right-click any empty space in the GUI background
C.Go to Log & Report > Dashboard Options
D.Go to System > Dashboard > Settings
AnswerA

Correct. The Dashboard interface includes an 'Add Widget' button to customize displayed panels.

Why this answer

Widgets can be added by clicking the 'Add Widget' button on the Dashboard.

94
MCQhard

When configuring an IPsec VPN tunnel between two FortiGate units, what is the function of Dead Peer Detection (DPD)?

A.To authenticate administrators logging into the FortiGate GUI via RADIUS
B.To balance outbound traffic across multiple WAN interfaces using SD-WAN
C.To detect unresponsive VPN peers and tear down dead security associations
D.To encrypt user data payloads using AES-256 algorithms
AnswerC

DPD checks peer liveness to ensure fast detection of broken tunnel connections.

Why this answer

DPD detects dead or unresponsive VPN peers by periodically sending hello/acknowledgment probes, allowing the FortiGate to tear down stale security associations and re-establish the tunnel.

95
Multi-Selecthard

Which THREE of the following statements accurately describe foundational security principles in enterprise environments? (Choose three)

Select 3 answers
A.System administrators should always share a single root account password to ensure accountability
B.The principle of least privilege ensures users and accounts are granted only the minimum access needed
C.Separation of duties ensures that critical, high-risk tasks require involvement from multiple people
D.Security through obscurity should be used as the primary defense mechanism for databases
E.Defense in depth relies on deploying multiple overlapping security layers rather than a single defense
AnswersB, C, E

Least privilege limits access scope to reduce potential damage from compromised accounts.

Why this answer

Least privilege, defense in depth, and separation of duties are core foundational security principles.

96
MCQmedium

An administrator wants to ensure that administrative access to the FortiGate GUI is restricted to secure HTTPS connections only, while disabling insecure HTTP access. Where is this administrative access protocol configured on the FortiGate?

A.Inside the firewall policy table rules
B.Inside the static routing table configuration
C.Under the physical or logical interface settings (Administrative Access)
D.Within the FortiGuard update subscription settings
AnswerC

Admin access methods like HTTPS and SSH are configured per interface.

Why this answer

Administrative access protocols (HTTPS, SSH, PING) are enabled or disabled on individual physical or logical interface configurations under Network > Interfaces.

97
MCQeasy

An administrator needs to view active hardware temperature and power supply statuses on the dashboard. Which widget should be added?

A.Device Inventory
B.Power Monitor
C.Hardware Status widget
D.System Resources
AnswerC

Correct. The Hardware Status widget displays physical sensor health readings.

Why this answer

The Hardware Status widget displays temperature sensors, fan speeds, and power supply statuses.

98
Multi-Selecthard

An administrator is troubleshooting log delivery failures to a remote syslog server. Which TWO troubleshooting commands or tools can be used from the FortiGate CLI to verify connectivity and log transmission?

Select 2 answers
A.diagnose debug flow filter
B.execute factory-reset
C.get system arps
D.execute ping <syslog-server-ip>
E.diagnose sniffer packet any 'port 514' 4
AnswersD, E

Verifies basic IP reachability to the remote log server.

Why this answer

To troubleshoot syslog/remote logging, administrators can use packet sniffing ('diagnose sniffer packet') and test connectivity ('execute ping' or 'execute telnet').

99
MCQmedium

An administrator needs to verify the current date and time settings on the FortiGate to ensure log timestamps are accurate. Which menu path in the web-based manager is used to configure system time and NTP settings?

A.System > Settings
B.System > FortiGuard
C.Monitor > System Time
D.Log & Report > Log Settings
AnswerA

Correct. System time, timezone, and NTP server settings are configured under System > Settings.

Why this answer

System time and NTP servers are configured under System > Settings.

100
MCQmedium

An administrator wants to inspect incoming files for unknown zero-day malware using advanced behavior analysis in a secure virtual environment before allowing them onto endpoints. Which Fortinet security component fulfills this requirement?

A.FortiSandbox integration
B.Intrusion Prevention System signature matching
C.FortiGuard Antivirus signature lookup
D.Web filtering URL categorization
AnswerA

FortiSandbox analyzes files in a controlled environment to catch unknown malware.

Why this answer

FortiSandbox executes suspicious files in an isolated virtual sandbox environment to observe behavior and detect zero-day threats.

101
MCQhard

An administrator is troubleshooting a configuration synchronization failure in an HA cluster. Which CLI command forces an immediate configuration synchronization from the primary unit to the secondary unit?

A.execute ha synchronize config
B.diagnose ha sync-now
C.execute ha synchronize
D.config system ha force-sync
AnswerC

Correct. This command forces the primary unit to push its configuration to secondary cluster members.

Why this answer

The execute ha synchronize command forces manual synchronization of configuration or sessions in an HA cluster.

102
Multi-Selectmedium

An administrator needs to back up the FortiGate configuration and ensure that sensitive passwords are protected. Which TWO statements regarding FortiGate configuration backups are correct? (Choose two)

Select 2 answers
A.Configuration files are saved in plain text XML format that cannot be encrypted.
B.Configuration backups can only be performed by connecting a console cable.
C.Backups can be encrypted with a password to protect sensitive information such as VPN pre-shared keys and user passwords.
D.Configuration backups can be exported via the web-based manager or CLI.
E.Backups automatically include historical log databases by default.
AnswersC, D

Correct. Encrypting configuration backups protects sensitive keys and credentials.

Why this answer

Configuration backups can be performed via the GUI or CLI, and administrators are prompted for an encryption password to secure sensitive data like pre-shared keys.

103
MCQhard

An organization is deploying FortiClient Endpoint Management Server (EMS) alongside FortiGate to enforce Zero Trust Network Access (ZTNA). A remote user's laptop connects to an unsecured public Wi-Fi hotspot. How does the Fortinet ZTNA solution ensure secure application access for this user without establishing a traditional full-tunnel VPN?

A.By dynamically checking endpoint posture tags supplied by FortiClient EMS and applying proxy-based access control per application.
B.By forcing all local Wi-Fi traffic through a hardware-based Layer 2 bridge established via FortiExtender.
C.By translating all internal server IP addresses into public routable IPs via Static NAT on the endpoint.
D.By establishing a permanent IPsec tunnel that encapsulates all endpoint traffic regardless of destination.
AnswerA

ZTNA leverages FortiClient EMS posture tags to authenticate and authorize access to specific enterprise applications via a proxy policy.

Why this answer

FortiClient ZTNA evaluates device posture (OS patches, antivirus status, registry checks) via EMS tags, and FortiGate acts as a ZTNA proxy, granting application-level access through explicit proxy rules only if posture tags match.

104
MCQeasy

Within the Fortinet Security Fabric architecture, what is the primary role of an upstream FortiGate device acting as the root node compared to downstream internal segmentation firewalls?

A.To replace the need for FortiClient endpoints by directly installing VPN clients on user laptops.
B.To coordinate fabric topology, aggregate fabric information, and distribute top-level security configurations.
C.To act exclusively as an offline logging collector without participating in traffic forwarding.
D.To handle local domain name resolution (DNS) and DHCP services for the entire enterprise network.
AnswerB

The root FortiGate coordinates the Security Fabric, provides visibility across connected devices, and pushes synchronized configurations.

Why this answer

The root FortiGate in a Security Fabric orchestrates overall fabric topology, aggregates threat intelligence, and synchronizes settings downward to internal segmentation firewalls (ISF).

105
MCQhard

An IT auditor is reviewing network access controls and discovers that guest Wi-Fi users are placed on the same subnet as internal corporate workstations without any traffic isolation. Which security principle has been violated?

A.Cryptographic salting
B.Symmetric encryption
C.Network segmentation
D.Non-repudiation verification
AnswerC

Placing guests on the corporate subnet without isolation violates network segmentation best practices.

Why this answer

Network segmentation isolates untrusted zones (like guest networks) from sensitive internal assets to limit the impact of a breach.

106
Multi-Selecthard

An administrator is hardening endpoint security using FortiClient and FortiGate integration. Which THREE core security functions can be enforced through this endpoint-to-firewall integration? (Choose three.)

Select 3 answers
A.Direct replacement of core routing protocols such as BGP and OSPF on upstream carrier routers.
B.Enforcement of compliance posture tags for Zero Trust Network Access (ZTNA).
C.Vulnerability scanning and reporting of missing OS patches or software updates.
D.Hardware-level replacement of physical switch port VLAN configurations from the endpoint GUI.
E.Automated network quarantine of infected endpoints via Security Fabric integration.
AnswersB, C, E

FortiClient EMS evaluates security posture and applies tags that FortiGate uses to grant or deny application access.

Why this answer

FortiClient and FortiGate integration supports vulnerability scanning, compliance/posture checks via EMS tags, dynamic ZTNA access control, and automated quarantine of compromised endpoints.

107
Multi-Selecthard

An administrator is investigating a network performance degradation issue and needs to check hardware sensor health on a high-end FortiGate unit. Which THREE hardware parameters or components can be monitored via FortiGate hardware status commands or widgets? (Choose three)

Select 3 answers
A.Power supply unit (PSU) status
B.Internal chassis or CPU temperature sensors
C.Active BGP peer uptime metrics
D.Fan operational status and speeds
E.SSL VPN tunnel encryption keys
AnswersA, B, D

Correct. Power supply operational states are tracked by hardware sensors.

Why this answer

Hardware health monitoring includes fan speeds, power supply status, and internal temperature sensors.

108
Multi-Selecteasy

Which TWO characteristics describe effective password management principles? (Choose two.)

Select 2 answers
A.Changing passwords every single week regardless of whether any compromise indicators exist.
B.Writing down primary administrator passwords on sticky notes attached to computer monitors.
C.Using a password manager to generate and store complex, unique passwords securely.
D.Reusing the same strong password across all personal and professional accounts for convenience.
E.Employing long passphrases that combine multiple random words for high entropy and memorability.
AnswersC, E

Password managers eliminate the need to memorize complex passwords and prevent reuse.

Why this answer

Effective password management relies on using password managers to generate long, unique passphrases or passwords for every account.

109
MCQhard

An administrator needs to reboot the FortiGate device remotely during a maintenance window without causing data corruption. Which CLI command should be executed?

A.execute factory-reset
B.system restart
C.execute reboot
D.config system global set reboot
AnswerC

Correct. execute reboot initiates a graceful system restart.

Why this answer

The execute reboot command safely restarts the FortiGate device.

110
Multi-Selecthard

Which THREE actions can a FortiGate Web Filtering profile take when a user attempts to access a website belonging to a blocked category? (Choose three.)

Select 3 answers
A.Automatically quarantine the user workstation inside FortiClient EMS
B.Block the request and display a customizable replacement message page
C.Encapsulate all HTTP packets inside an IPsec VPN tunnel
D.Monitor and log the access event without blocking the connection
E.Allow the request but require the user to click past a warning page
AnswersB, D, E

Blocking presents a replacement message explaining why access was denied.

Why this answer

When a web filter category is blocked, the FortiGate can block the page and show a replacement message, allow with a warning prompt, or monitor/log the event.

111
Multi-Selectmedium

Which TWO authentication methods or servers can be integrated with a FortiGate for user identity verification? (Choose two.)

Select 2 answers
A.Simple Network Management Protocol (SNMP) agent
B.LDAP / Active Directory server
C.RADIUS authentication server
D.Syslog UDP collector
E.Network Time Protocol (NTP) server
AnswersB, C

FortiGate integrates with LDAP and Active Directory for enterprise user authentication.

Why this answer

FortiGate supports integration with external authentication servers such as LDAP/Active Directory and RADIUS.

112
MCQhard

An administrator wants to verify which configuration revision history is currently active and wants to roll back to a previous revision. Where can configuration revisions be managed in the web-based manager?

A.Log & Report > Revision Logs
B.System > Maintenance > Rollback
C.Security Fabric > Backups
D.Administrator profile dropdown menu > Configuration > Revision History
AnswerD

Correct. Revision history allows administrators to view and roll back previous configuration versions.

Why this answer

Configuration revisions are managed under System > Configuration or via the administrator profile dropdown menu revision history.

113
MCQmedium

An administrator notices that a specific software application is being blocked by Application Control. Upon checking the logs, the administrator wants to create an exception to allow this specific application while keeping the rest of the application control category blocked. How can this be achieved?

A.By adding an Application Override rule inside the Application Control profile
B.By disabling the entire Antivirus scanning engine globally
C.By changing the static routing table administrative distance
D.By switching the FortiGate firewall from NAT mode to Transparent mode
AnswerA

Application overrides allow granular allow/block exceptions for individual applications.

Why this answer

Application Control profiles support application overrides, allowing administrators to add specific allow or block exceptions for individual applications within a category.

114
MCQhard

When configuring an SSL VPN tunnel mode connection for mobile workers, what does the FortiGate assign to the client machine to enable communication with internal subnets?

A.A virtual IP address from a configured SSL VPN IP pool
B.A static public IP address belonging to the ISP WAN interface
C.A physical MAC address mapped to the switch port
D.A dynamic DNS hostname managed by FortiGuard
AnswerA

Tunnel mode assigns a virtual IP address so clients can route traffic securely.

Why this answer

In SSL VPN tunnel mode, the FortiGate assigns a virtual IP address from a dedicated IP pool to the client virtual adapter.

115
Multi-Selectmedium

Which TWO behaviors are recognized indicators that an incoming email may be a phishing attempt? (Choose two)

Select 2 answers
A.The message conveys extreme urgency and threatens negative consequences if action is not taken immediately.
B.The message includes a link to the corporate intranet home page via the internal DNS domain.
C.The sender email address domain subtly differs from the legitimate organization's domain name.
D.The email is addressed specifically to your correct full corporate title and department.
E.The email contains standard company newsletter updates sent through an official mailing platform.
AnswersA, C

Attackers manufacture urgency to bypass critical thinking.

Why this answer

Urgency, mismatched sender domains, and unexpected attachments are key indicators of phishing.

116
MCQmedium

An enterprise network team notices that internal workstations are periodically querying known malicious command-and-control (C2) domains. However, direct external DNS queries are blocked. How might an advanced malware strain attempt to resolve these domains?

A.By relying exclusively on local ARP tables
B.By broadcasting requests via local Bluetooth signals
C.By converting domain names into physical print jobs
D.By leveraging alternative public DNS resolvers or DNS-over-HTTPS (DoH)
AnswerD

Malware can bypass local DNS blocks by using external public resolvers or encrypted DNS protocols.

Why this answer

Advanced malware often uses alternative lookup methods, such as utilizing hardcoded public DNS resolvers or tunneling protocols, to bypass internal DNS restrictions.

117
Multi-Selecthard

Which THREE methods can be used to back up or restore a FortiGate configuration? (Choose three.)

Select 3 answers
A.FortiManager centralized configuration management and revision templates
B.FortiGate Command Line Interface (CLI) configuration commands
C.FortiGate Web-based Manager (GUI) backup and restore utility
D.FortiAnalyzer log archive export utilities
E.FortiClient EMS endpoint profile synchronization
AnswersA, B, C

FortiManager manages device backups, revisions, and automated deployments.

Why this answer

FortiGate configurations can be backed up or restored via the Web GUI, CLI (console/SSH/TFTP), and centralized management platforms like FortiManager.

118
MCQmedium

A network administrator is setting up a corporate policy to prevent unauthorized internal users from sniffing traffic passing through a shared network segment. Which fundamental security principle is being addressed by implementing encrypted communication protocols like HTTPS and SSH?

A.Integrity
B.Confidentiality
C.Availability
D.Non-repudiation
AnswerB

Confidentiality protects sensitive data from unauthorized interception and eavesdropping.

Why this answer

Confidentiality ensures that data is readable only by intended parties, which is achieved through encryption, preventing casual sniffing on shared segments.

119
Multi-Selecthard

Which THREE of the following practices help protect end-user devices (endpoints) from malware and compromise? (Choose three)

Select 3 answers
A.Exercising caution when clicking links or downloading files from untrusted sources
B.Running reputable, centralized endpoint security software (antivirus/EDR)
C.Downloading cracked software and keygens from peer-to-peer file-sharing networks
D.Disabling all firewall rules and network logging to maximize system performance
E.Keeping operating systems and application software patched and up to date
AnswersA, B, E

Mindful browsing prevents the accidental introduction of malware onto the device.

Why this answer

Endpoint protection, keeping software updated, and avoiding unverified links or downloads are vital practices for endpoint security.

120
MCQeasy

What is the primary function of FortiMail in an enterprise security architecture?

A.To protect the organization against email-borne threats such as spam, malware, and phishing
B.To act as a centralized log analysis and reporting appliance
C.To manage wireless access points and guest Wi-Fi authentication portals
D.To provide SSL VPN client tunnels for remote workers
AnswerA

FortiMail provides dedicated email security and threat prevention.

Why this answer

FortiMail is a secure email gateway designed to protect organizations from spam, malware, phishing, and data loss via email.

121
MCQeasy

What is the primary purpose of a firewall address group in FortiOS?

A.To assign dynamic VLAN tags to switch ports
B.To configure VPN Phase 1 encryption transforms
C.To group multiple address objects together for simplified firewall policy configuration
D.To schedule automated system backup intervals
AnswerC

Address groups allow multiple subnets/IPs to be referenced in a single policy rule.

Why this answer

Firewall address groups combine multiple individual address objects into a single group, simplifying policy management when rules apply to multiple hosts or subnets.

122
MCQhard

An administrator is troubleshooting a DHCP server issue on the FortiGate and needs to see active IP address leases assigned by the built-in DHCP server. Which CLI command provides this information?

A.execute dhcp lease-list
B.diagnose system dhcp list
C.get router info dhcp
D.get system dhcp-server lease
AnswerA

Correct. This command outputs all active IP leases assigned by the FortiGate DHCP server.

Why this answer

The execute dhcp lease-list command displays active DHCP leases assigned by the FortiGate interface.

123
MCQmedium

A network security administrator needs to block peer-to-peer (P2P) file sharing applications across the corporate network. Which FortiOS security feature should be added to the firewall policy to identify and block these specific applications regardless of the ports they use?

A.Static port-blocking firewall rules
B.SSL certificate inspection profile
C.Application Control profile
D.Antivirus signature database
AnswerC

Application Control detects and blocks applications by signature inspection across any port.

Why this answer

Application Control identifies applications based on signature analysis and behavioral characteristics rather than TCP/UDP port numbers.

124
MCQhard

An organization is deploying FortiGate in Transparent mode instead of NAT mode. How does a Transparent mode FortiGate handle incoming packets at Layer 2?

A.It performs full NAT on all source and destination IP addresses for every packet
B.It terminates all Ethernet frames and encapsulates them into PPPoE tunnels
C.It acts as a dynamic routing peer running BGP and OSPF across all interfaces
D.It operates as a Layer 2 bridge, inspecting traffic without altering IP addresses or performing routing
AnswerD

Transparent mode bridges traffic at Layer 2 without routing or altering IP headers.

Why this answer

In Transparent mode, the FortiGate operates as a bridge (Layer 2 device) without modifying IP addresses, inspecting traffic as it passes between interfaces on the same subnet.

125
MCQeasy

What is the primary function of a firewall policy ID on a FortiGate?

A.To assign an IP address to the DHCP client
B.To uniquely identify and reference the firewall policy rule
C.To determine the cryptographic key used for IPsec VPN encryption
D.To define the physical switch port VLAN assignment
AnswerB

Policy IDs uniquely identify each rule in the firewall policy table.

Why this answer

Every firewall policy is assigned a unique policy ID number by FortiOS to identify, reference, and reorder rules in the policy list.

126
MCQeasy

What is the primary function of FortiSandbox in an enterprise security architecture?

A.To filter web browsing categories and block malicious URLs
B.To centralize log storage and generate graphical compliance reports
C.To authenticate remote SSL VPN users against Active Directory
D.To analyze unknown files and zero-day malware in an isolated virtual environment
AnswerD

FortiSandbox executes files safely to detect advanced zero-day threats.

Why this answer

FortiSandbox runs suspicious, unknown files in an isolated virtual environment to observe their behavior and detect zero-day malware.

127
MCQhard

An organization is deploying a FortiGate firewall in NAT mode. By default, how does the FortiGate handle outbound traffic leaving the internal network for the internet in terms of source IP addressing?

A.It encapsulates all outbound packets inside GRE tunnels without IP header alteration
B.It forwards the original private IP address without modification across public routers
C.It drops outbound packets unless explicit static destination NAT rules are created
D.It translates the private source IP address to the outgoing interface IP address using Network Address Translation (SNAT)
AnswerD

SNAT replaces private internal source IPs with the public IP of the WAN interface.

Why this answer

In NAT mode, outbound traffic passing through a firewall policy with NAT enabled is translated (SNAT) to the outgoing interface's IP address.

128
MCQeasy

An end user receives an alert that their browser has blocked a potentially malicious website that tried to automatically download an executable file without user interaction. What term describes this type of silent threat?

A.Drive-by download
B.Physical shoulder surfing
C.Social engineering phone call
D.Email phishing scam
AnswerA

Automatic background downloads of malicious files while browsing represent drive-by downloads.

Why this answer

A drive-by download occurs when malware is downloaded automatically without the user's explicit consent or knowledge when visiting a compromised website.

129
Multi-Selecthard

An administrator is examining the FortiGate routing table via the CLI. Which THREE types of routes can appear in the active routing table? (Choose three)

Select 3 answers
A.Dynamic routes (learned via protocols such as OSPF, BGP, or RIP)
B.Firewall policy object routes
C.Security Fabric telemetry routes
D.Connected routes (directly attached subnets)
E.Static routes (manually configured routes)
AnswersA, D, E

Correct. Dynamic routing protocols populate routes automatically.

Why this answer

Active routing tables can contain static routes, connected (directly attached) routes, and dynamic routes learned via protocols like OSPF or BGP.

130
Multi-Selecteasy

Which TWO practices represent fundamental cybersecurity hygiene guidelines for everyday end users? (Choose two.)

Select 2 answers
A.Clicking on unexpected email attachments immediately to verify their safety.
B.Sharing corporate passwords with trusted team members to ensure project continuity.
C.Disabling all endpoint antivirus software to speed up system performance.
D.Locking the workstation screen whenever walking away from the desk.
E.Using complex, unique passwords for every separate work account.
AnswersD, E

Locking unattended screens prevents physical unauthorized access by opportunistic visitors.

Why this answer

End users should maintain strong, unique passwords and lock their screens when leaving workstations unattended.

131
MCQmedium

An administrator needs to verify whether FortiGuard web filtering rating lookups are succeeding for specific categories. Which CLI command tests web filter rating lookups for a specific URL?

A.get webfilter status [URL]
B.diagnose webfilter FortiGuard lookup [URL]
C.execute webfilter-test [URL]
D.ping fortiguard-rating [URL]
AnswerB

Correct. This diagnostic command queries FortiGuard to return the rating category for a given URL.

Why this answer

The diagnose webfilter FortiGuard lookup command tests URL categorization.

132
MCQhard

An administrator is reviewing firewall policies and notices that traffic matching a specific policy is being logged, but no traffic logs are appearing in Log & Report > Forward Traffic. FortiGate is configured to send logs to FortiAnalyzer. Where are the traffic logs being stored?

A.They are stored in the FortiGate system memory ring buffer.
B.They are buffered in RAM and will only flush when the FortiGate reboots.
C.They are discarded because local logging is automatically disabled when remote logging is active.
D.They are stored exclusively on the remote FortiAnalyzer and not on the local FortiGate storage.
AnswerD

When FortiAnalyzer is connected, traffic logs are sent off-box to the analyzer.

Why this answer

When a remote logging server like FortiAnalyzer or FortiGate Cloud is enabled and configured successfully, traffic logs are offloaded and stored on that remote device rather than locally on the FortiGate flash memory.

133
MCQhard

An enterprise branch office has two distinct internet connections (Fiber and Cable). The administrator wants traffic to preferentially use the Fiber link, but automatically fail over to the Cable link if the Fiber link experiences packet loss exceeding 5%. Which FortiOS feature accomplishes this?

A.SD-WAN Performance SLA and SD-WAN rules
B.RIPv2 dynamic routing protocol updates
C.Static routes with equal administrative distance and metric
D.High availability active-active clustering heartbeat rules
AnswerA

SD-WAN rules dynamically steer traffic based on real-time SLA metrics like packet loss.

Why this answer

SD-WAN performance SLAs monitor latency, jitter, and packet loss, allowing administrators to configure rule-based path selection and automatic failover.

134
MCQmedium

A network administrator notices that a web filtering profile configured on a FortiGate is blocking a specific educational video streaming category, but the exception list needs to allow a single permitted URL within that category. Where in FortiOS should the administrator add this specific URL override?

A.Inside the Application Control sensor blacklist configuration.
B.Under Firewall Policy Destination Addresses.
C.Inside the Web Filter Security Profile under URL Filter table overrides.
D.Within the Intrusion Prevention System (IPS) sensor signature exception list.
AnswerC

URL filter table entries inside the Web Filter profile permit specific wildcard or exact URLs to bypass category blocks.

Why this answer

FortiOS Web Filtering profiles allow administrators to configure URL Filters with action types such as Exempt, Block, Allow, or Monitor to override category-based decisions.

135
MCQhard

An administrator is troubleshooting a packet loss issue and needs to inspect the kernel buffer drops and interface error counters. Which CLI command provides a summary of interface drop statistics?

A.execute interface-test drops
B.diagnose hardware deviceinfo nic [interface]
C.show interface drops
D.get system drop-stats
AnswerB

Correct. This diagnostic command outputs driver-level statistics, including buffer drops and errors.

Why this answer

The get system interface physical or diagnose hardware deviceinfo nic commands provide drop counters and error statistics.

136
MCQmedium

Which action is a best practice for managing passwords to prevent credential stuffing attacks?

A.Change passwords only when forced by the system administrator.
B.Write passwords on a physical sticky note hidden under the keyboard.
C.Use a password manager to generate and store unique, strong passwords for each site.
D.Use the same password for all work-related accounts to ensure memory efficiency.
AnswerC

This approach eliminates the risk associated with password reuse.

Why this answer

Using a unique, complex password for every service ensures that one breach does not lead to the compromise of other accounts.

137
MCQeasy

When setting up a new online account for a business service, an employee is prompted to save a set of 10 backup recovery codes in case they lose access to their authenticator app. What is the best practice for handling these recovery codes?

A.Write them on a sticky note attached to the computer monitor for convenience
B.Discard them immediately as they are unnecessary if an app is installed
C.Store them in an encrypted password manager or secure offline location
D.Share them in a public corporate chat channel so teammates can assist if needed
AnswerC

Secure storage ensures availability for emergency recovery without exposing them to unauthorized access.

Why this answer

Recovery codes should be stored securely and privately, such as in an encrypted password manager, rather than on sticky notes or unsecured text files.

138
MCQmedium

An administrator wants to verify whether the FortiGate device is operating in NAT mode or Transparent mode. Where can this operational mode be checked in the web-based manager?

A.System > Feature Visibility > NAT Mode
B.Network > Operation Mode
C.Policy & Objects > Mode Settings
D.Dashboard > System Information widget (System Mode field)
AnswerD

Correct. The System Information widget displays the operating mode (NAT or Transparent).

Why this answer

System mode (NAT or Transparent) is displayed in the System Information dashboard widget.

139
MCQmedium

Which cybersecurity practice is most effective in mitigating the impact of a catastrophic ransomware infection on critical enterprise databases?

A.Deploying standard HTTP web proxies without inspection.
B.Increasing the corporate internet bandwidth capacity.
C.Enabling automatic operating system wallpaper updates.
D.Maintaining secure, immutable, and offline backups of critical data.
AnswerD

Offsite or immutable backups allow organizations to recover encrypted files without negotiating with attackers.

Why this answer

Maintaining regular, immutable backups stored offline or in a segmented cloud repository ensures data can be restored without paying a ransom.

140
MCQhard

When configuring an IPsec VPN tunnel between two FortiGate units, what is the purpose of establishing a local ID (Peer ID) in Phase 1?

A.To assign virtual IP addresses to SSL VPN client workstations
B.To encrypt user data payloads using AES-GCM encryption
C.To provide a distinct peer identifier during Phase 1 authentication, particularly useful with dynamic IPs
D.To define the static routing administrative distance metric for the VPN tunnel
AnswerC

Peer ID ensures correct tunnel identification when authenticating devices with dynamic addresses.

Why this answer

Local ID allows peers to identify themselves during Phase 1 negotiation, which is especially useful when one or both peers use dynamic IP addresses and need a distinct identifier for authentication matching.

141
MCQmedium

An administrator configures a firewall policy with Antivirus enabled in flow-based inspection mode. When a user attempts to download an infected file, how does the FortiGate handle the transfer?

A.It drops the packet silently without notifying the user or generating a log
B.It aborts the connection immediately and displays a replacement message to the user
C.It buffers the entire file to disk, cleans the file, and then emails the cleaned file to the user
D.It allows the download to complete and then quarantines the file locally on the client endpoint
AnswerB

Flow-based antivirus drops the malicious stream instantly upon detection.

Why this answer

In flow-based inspection, when malware is detected, the FortiGate interrupts and drops the connection stream immediately, replacing the file with a replacement message.

142
MCQmedium

An administrator needs to modify the hostname of the FortiGate via the CLI. Which configuration context and command are used?

A.config system settings > set name [name] > end
B.set hostname [name]
C.config system global > set hostname [name] > end
D.execute hostname [name]
AnswerC

Correct. Global system settings like hostname are modified within the config system global context.

Why this answer

The hostname is configured under config system global using the set hostname command.

143
Multi-Selecteasy

Which TWO types of objects can be created to group network resources for firewall policies on a FortiGate? (Choose two.)

Select 2 answers
A.SD-WAN performance SLA group
B.High availability heartbeat group
C.Firewall address group
D.Firewall service group
E.Antivirus signature group
AnswersC, D

Address groups combine multiple IP address objects into a single group for policies.

Why this answer

Administrators can create firewall address objects/groups and service objects/groups to organize policies.

144
Multi-Selectmedium

Which TWO of the following indicators are commonly associated with a potential phishing email? (Choose two)

Select 2 answers
A.Generic greetings like 'Dear Customer' instead of the recipient's actual name
B.A standard newsletter sent via an officially approved corporate marketing platform with working unsubscribe links
C.A sender domain address that slightly misspells a trusted organization's name
D.Content written with perfect grammar, standard company formatting, and no sense of urgency
E.An email digitally signed with a valid corporate PKI certificate issued by the internal IT department
AnswersA, C

Mass phishing campaigns often use generic salutations because they target many recipients.

Why this answer

Phishing emails frequently employ artificial urgency to prompt rash actions and often feature sender addresses with subtle domain spoofing or misspellings.

145
MCQhard

An organization wants to ensure that no single administrator has the unchecked authority to approve and deploy high-risk firewall rule changes into production. Which security governance mechanism should be implemented?

A.Separation of duties
B.Mandatory access control labeling
C.Single sign-on federation
D.Role-based access auditing
AnswerA

Requiring one admin to create a rule and a different admin to approve/deploy it enforces separation of duties.

Why this answer

Separation of duties ensures that critical tasks require authorization from multiple distinct individuals to prevent misuse or error.

146
MCQhard

When configuring dynamic routing on a FortiGate using OSPF, what is the function of a designated router (DR) in a multi-access broadcast network?

A.To translate private internal IP addresses to public IPs for internet browsing
B.To encrypt user data traffic traversing IPsec VPN tunnels between headquarters and branches
C.To distribute antivirus signature updates to isolated FortiGate appliances
D.To centralize LSA exchanges and minimize routing protocol traffic on multi-access broadcast networks
AnswerD

The DR optimizes OSPF traffic by reducing full-mesh adjacencies on broadcast segments.

Why this answer

In OSPF broadcast networks, a Designated Router (DR) minimizes routing protocol traffic by acting as a central collection and distribution point for link-state advertisements (LSAs) among all routers on that segment.

147
MCQmedium

An administrator wants to check the operational status of all physical and logical interfaces in a summary table view. Which menu path in the web-based manager should be opened?

A.Policy & Objects > Interfaces
B.Monitor > Interface Summary
C.Network > Interfaces
D.System > Interfaces
AnswerC

Correct. Network > Interfaces displays all physical ports, VLANs, and software interfaces with status and IP details.

Why this answer

Interface configurations and status summaries are viewed under Network > Interfaces.

148
MCQmedium

An administrator needs to modify the TCP session timeout for specific services. Where are global system timeout values configured in the CLI?

A.config firewall settings > set timeout [seconds] > end
B.config router global > set tcp-timeout [seconds] > end
C.config system global > set tcp-idle-timer [seconds] > end
D.execute set-timeout [seconds]
AnswerC

Correct. Global timer settings like TCP idle timeouts are configured under config system global.

Why this answer

Timeouts are configured under config system global using parameters like set tcp-idle-timer.

149
MCQhard

An organization requires high availability (HA) for two FortiGate devices to ensure continuous network uptime during hardware failures. Which operating mode synchronizes sessions, configuration, and routing state between the primary and secondary units in an active-passive cluster?

A.Dynamic Multicast Routing Protocol (PIM-SM)
B.FortiGate Clustering Protocol (FGCP) Active-Passive mode
C.Virtual Router Redundancy Protocol (VRRP) active-active balancing
D.Border Gateway Protocol (BGP) Multipath clustering
AnswerB

FGCP active-passive synchronization ensures session failover and seamless high availability.

Why this answer

FGCP (FortiGate Clustering Protocol) in an active-passive high availability configuration synchronizes session tables and configurations so the secondary unit can seamlessly take over if the primary fails.

150
Multi-Selectmedium

Which TWO criteria can be used in a FortiGate firewall policy to match and control traffic? (Choose two.)

Select 2 answers
A.Service objects (ports and protocols like HTTP or SSH)
B.FortiGuard signature version number
C.Source and destination IP addresses / address objects
D.CPU utilization percentage of FortiASIC chips
E.Administrator GUI idle timeout threshold
AnswersA, C

Service objects define the specific network ports and protocols permitted by the policy.

Why this answer

Firewall policies match traffic based on source/destination interfaces, source/destination addresses, services, schedules, and user identities.

Page 1

Page 2 of 4

Page 3

All pages