FORTINET-NSE123 · domain
Nse 2 Technical Introduction TO Fortinet Security
Practise Fortinet NSE 1-3 (Network Security Associate track: Foundational, Technical Introduction, Associate) (FORTINET-NSE123) Nse 2 Technical Introduction TO Fortinet Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Nse 2 Technical Introduction TO Fortinet Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Nse 2 Technical Introduction TO Fortinet Security
Nse 2 Technical Introduction TO Fortinet Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Nse 2 Technical Introduction TO Fortinet Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Nse 2 Technical Introduction TO Fortinet Security questions (105)
Click any question to see the full explanation, or start a practice session above.
What is the primary purpose of the FortiGuard distribution network in the Fortinet Security Fabric?
Easy2When configuring an IPsec VPN tunnel in FortiOS, what is the purpose of Phase 2 negotiation?
Hard3An enterprise branch office needs to establish a secure, encrypted site-to-site tunnel back to the headquarters FortiGate over the public internet. Which VPN technology provides a standard IPsec framework combined with Fortinet Security Fabric integration features?
Hard4Which TWO of the following characteristics differentiate SSL VPN from IPsec VPN when deploying remote access solutions on a FortiGate? (Choose two.)
Medium5Which TWO protocols can be enabled on a FortiGate interface for secure administrative access? (Choose two.)
Easy6Which TWO inspection modes are available on a FortiGate firewall for processing UTM security profiles? (Choose two.)
Medium7What is the primary function of a FortiGate hardware acceleration processor (FortiASIC)?
Easy8An administrator needs to restrict administrative access to the FortiGate CLI and GUI so that management connections are only accepted from a specific trusted internal management workstation subnet. Where is this source IP restriction configured?
Medium9An administrator notices that the FortiGate system disk is filling up rapidly with log files. Which action should be taken to ensure local storage does not run out of space while retaining historical logs?
Medium10An administrator wants to configure a firewall policy so that specific internal users can only access the internet during non-work hours. Which object type should be added to the firewall policy to enforce this time restriction?
Medium11An administrator needs to ensure that administrative sessions to the FortiGate GUI automatically terminate after 15 minutes of inactivity. Where is this idle timeout setting configured?
Medium12What is the primary function of a FortiGate static route?
Easy13An administrator wants to ensure that all configuration changes made on a FortiGate are tracked with specific user accountability and revision history. Which Fortinet management tool provides centralized configuration revision control and rollback capabilities?
Medium14When configuring FortiGate High Availability (HA) in active-passive mode, what is the role of the heartbeat interfaces?
Hard15An administrator is troubleshooting a scenario where internal users can browse safe websites, but HTTPS inspection using certificates is throwing browser security warnings for certain internal web applications. What is the most likely cause of this behavior when using Deep Packet Inspection (DPI) on FortiGate?
Hard16An administrator configures a firewall policy with Web Filtering. When a user tries to access a newly created website whose category is unknown by the FortiGate, how does FortiGate handle the rating request?
Medium17An administrator needs to ensure that internal network users cannot bypass corporate security policies by using unauthorized peer-to-peer file sharing or gaming applications. Which FortiGate security feature is specifically designed to identify and take action against these types of network protocols?
Easy18Which THREE components or protocols are involved in establishing and maintaining a FortiGate High Availability (HA) cluster using FGCP? (Choose three.)
Hard19An enterprise is deploying FortiGate High Availability (HA) in active-active mode. How does active-active mode differ from active-passive mode regarding session handling?
Hard20An organization is deploying FortiGate firewalls to segment internal network zones. What is the default action of a newly created firewall policy when traffic matches neither this policy nor any other rule?
Easy21Which TWO firewall operational modes can be configured on a FortiGate device? (Choose two.)
Easy22What is the primary function of a FortiGate firewall policy action set to 'Accept'?
Easy23Which TWO of the following are core components of the Fortinet Security Fabric architecture? (Choose two.)
Easy24Which Fortinet product acts as the centralized log management and reporting server that aggregates log data from multiple FortiGate devices across an enterprise network?
Easy25A network engineer wants to inspect web traffic for malicious downloads and web-based threats passing through a FortiGate device. Where must this inspection profile be applied to take effect?
Medium26An administrator is configuring a FortiGate firewall and needs to ensure that packets matching an explicit allow policy are also logged. Where should the administrator enable logging for this specific policy?
Hard27An enterprise network architect is designing a site-to-site VPN architecture to connect a branch office to headquarters using FortiGate devices. The branch office relies on a dynamic broadband connection with a frequently changing public IP address. Which VPN configuration approach should be implemented?
Medium28When configuring an IPsec VPN tunnel between two FortiGate units, what is the function of Dead Peer Detection (DPD)?
Hard29An administrator wants to ensure that administrative access to the FortiGate GUI is restricted to secure HTTPS connections only, while disabling insecure HTTP access. Where is this administrative access protocol configured on the FortiGate?
Medium30An administrator wants to inspect incoming files for unknown zero-day malware using advanced behavior analysis in a secure virtual environment before allowing them onto endpoints. Which Fortinet security component fulfills this requirement?
Medium31An organization is deploying FortiClient Endpoint Management Server (EMS) alongside FortiGate to enforce Zero Trust Network Access (ZTNA). A remote user's laptop connects to an unsecured public Wi-Fi hotspot. How does the Fortinet ZTNA solution ensure secure application access for this user without establishing a traditional full-tunnel VPN?
Hard32Within the Fortinet Security Fabric architecture, what is the primary role of an upstream FortiGate device acting as the root node compared to downstream internal segmentation firewalls?
Easy33An administrator is hardening endpoint security using FortiClient and FortiGate integration. Which THREE core security functions can be enforced through this endpoint-to-firewall integration? (Choose three.)
Hard34Which THREE actions can a FortiGate Web Filtering profile take when a user attempts to access a website belonging to a blocked category? (Choose three.)
Hard35Which TWO authentication methods or servers can be integrated with a FortiGate for user identity verification? (Choose two.)
Medium36An administrator notices that a specific software application is being blocked by Application Control. Upon checking the logs, the administrator wants to create an exception to allow this specific application while keeping the rest of the application control category blocked. How can this be achieved?
Medium37When configuring an SSL VPN tunnel mode connection for mobile workers, what does the FortiGate assign to the client machine to enable communication with internal subnets?
Hard38Which THREE methods can be used to back up or restore a FortiGate configuration? (Choose three.)
Hard39What is the primary function of FortiMail in an enterprise security architecture?
Easy40What is the primary purpose of a firewall address group in FortiOS?
Easy41A network security administrator needs to block peer-to-peer (P2P) file sharing applications across the corporate network. Which FortiOS security feature should be added to the firewall policy to identify and block these specific applications regardless of the ports they use?
Medium42An organization is deploying FortiGate in Transparent mode instead of NAT mode. How does a Transparent mode FortiGate handle incoming packets at Layer 2?
Hard43What is the primary function of a firewall policy ID on a FortiGate?
Easy44What is the primary function of FortiSandbox in an enterprise security architecture?
Easy45An organization is deploying a FortiGate firewall in NAT mode. By default, how does the FortiGate handle outbound traffic leaving the internal network for the internet in terms of source IP addressing?
Hard46An enterprise branch office has two distinct internet connections (Fiber and Cable). The administrator wants traffic to preferentially use the Fiber link, but automatically fail over to the Cable link if the Fiber link experiences packet loss exceeding 5%. Which FortiOS feature accomplishes this?
Hard47A network administrator notices that a web filtering profile configured on a FortiGate is blocking a specific educational video streaming category, but the exception list needs to allow a single permitted URL within that category. Where in FortiOS should the administrator add this specific URL override?
Medium48When configuring an IPsec VPN tunnel between two FortiGate units, what is the purpose of establishing a local ID (Peer ID) in Phase 1?
Hard49An administrator configures a firewall policy with Antivirus enabled in flow-based inspection mode. When a user attempts to download an infected file, how does the FortiGate handle the transfer?
Medium50Which TWO types of objects can be created to group network resources for firewall policies on a FortiGate? (Choose two.)
Easy51When configuring dynamic routing on a FortiGate using OSPF, what is the function of a designated router (DR) in a multi-access broadcast network?
Hard52An organization requires high availability (HA) for two FortiGate devices to ensure continuous network uptime during hardware failures. Which operating mode synchronizes sessions, configuration, and routing state between the primary and secondary units in an active-passive cluster?
Hard53Which TWO criteria can be used in a FortiGate firewall policy to match and control traffic? (Choose two.)
Medium54What is the primary function of a FortiGate Virtual IP (VIP) object?
Easy55An administrator wants to view a chronological log of security threats and blocked virus events in real-time directly on the FortiGate GUI. Which FortiOS feature provides this live graphical and tabular logging interface?
Medium56An administrator is setting up a new FortiGate firewall and needs to configure basic access control between the internal corporate network and the external public network. Which object type should the administrator create first to group internal IP addresses for policy creation?
Easy57When a FortiGate device inspects HTTPS traffic using deep inspection, how does the security engine handle the TLS/SSL encryption handshake between the client and the destination server?
Hard58When configuring an IPsec VPN tunnel between two FortiGate units using pre-shared keys (PSK), what is required for successful Phase 1 authentication?
Hard59A security analyst is investigating a security alert generated by FortiGate Intrusion Prevention System (IPS). The log indicates that a known exploit signature was detected and dropped. How does FortiGate IPS inspect network traffic to identify such patterns?
Medium60Which Fortinet security product is specifically designed to protect web applications (such as public-facing e-commerce portals) against OWASP Top 10 vulnerabilities like SQL injection and cross-site scripting?
Easy61Which TWO security profiles can be attached to a FortiGate firewall policy to protect against malware and threats? (Choose two.)
Easy62An administrator needs to protect internal servers against known vulnerability exploits and attack signatures traversing the network. Which security feature should be enabled in the firewall policy?
Medium63An administrator wants to prevent users from uploading confidential company documents to external cloud storage websites. Which Fortinet security profile feature inspects outbound traffic for specific file types or sensitive keywords?
Medium64Which TWO settings are required when configuring a basic static route on a FortiGate? (Choose two.)
Medium65Which TWO logging destinations can receive log data from a FortiGate firewall? (Choose two.)
Easy66What is the primary function of a FortiGate firewall policy destination setting?
Easy67An administrator needs to monitor bandwidth consumption across different applications on the FortiGate. Which feature allows the administrator to view real-time traffic bandwidth by application and enforce traffic shaping guarantees?
Medium68What is the primary purpose of defining zones (interface zones) in FortiOS firewall configurations?
Easy69When configuring firewall policies on a FortiGate device, an administrator must define matching criteria and actions. Which THREE elements are mandatory components of a standard IPv4 firewall policy in FortiOS? (Choose three.)
Hard70When configuring a FortiGate interface to connect to an external ISP network that utilizes dynamic IP assignment via DHCP, which setting must be enabled on the interface parameters?
Hard71When configuring an SSL VPN portal on a FortiGate, what is the primary operational difference between SSL VPN Web Mode and Tunnel Mode?
Hard72What is the primary function of a FortiSwitch unit when integrated into the Fortinet Security Fabric?
Easy73What is the primary function of a FortiAuthenticator device?
Easy74An administrator notices that a FortiGate high availability (HA) cluster has experienced a failover. Which log category on the FortiGate or FortiAnalyzer should the administrator check to investigate the cause of the HA state transition?
Medium75When configuring dynamic routing on a FortiGate using OSPF, what is the purpose of defining OSPF areas?
Hard76A system administrator needs to update the signature databases for Antivirus and IPS on an isolated FortiGate that lacks direct internet connectivity. Which Fortinet product can be deployed locally on the network to act as an offline update distributor?
Medium77An administrator needs to back up the FortiGate configuration regularly and securely. Which method allows the administrator to encrypt the configuration file with a password before downloading it from the GUI?
Medium78When configuring an IPsec VPN tunnel in FortiOS, what is the role of NAT Traversal (NAT-T)?
Hard79An administrator wants to block specific types of USB or removable storage devices from connecting to corporate laptops. Which Fortinet component manages endpoint device control policies?
Medium80An administrator wants to allow remote workers to securely connect to the internal network using an SSL VPN web portal that presents a customized login page and bookmarks to internal resources. Which SSL VPN mode provides this browser-based access without requiring a pre-installed desktop client?
Medium81An administrator wants to ensure that internal users attempting to visit known phishing or malware-hosting domains are blocked automatically before establishing a connection. Which security profile should be added to the firewall policy?
Medium82Which Fortinet tool provides a centralized management pane of glass for provisioning, updating, and monitoring multiple FortiGate firewall policies and device configurations across an enterprise?
Easy83An enterprise is configuring a redundant multi-WAN architecture on a FortiGate. Which feature allows the FortiGate to automatically measure latency, jitter, and packet loss on multiple internet connections and dynamically steer traffic over the best performing path?
Hard84When logging into the FortiGate Web-based Manager (GUI) for the first time, what is the default administrator username?
Easy85What is the primary function of a FortiSwitch port configured with FortiLink?
Easy86What is the primary function of a firewall inspection mode that processes packets at Layer 3 and Layer 4 using packet headers without reassembling application streams?
Easy87Which TWO threat intelligence services or features are delivered dynamically by the FortiGuard network? (Choose two.)
Medium88An organization is deploying an SD-WAN architecture on a FortiGate. When multiple WAN interfaces are combined into an SD-WAN zone, how do firewall policies reference the destination or source of the traffic?
Hard89What is the primary function of a FortiGate firewall policy source interface setting?
Easy90Which TWO features or protocols are used in Fortinet SD-WAN deployments to optimize multi-path traffic routing? (Choose two.)
Medium91A security analyst needs to ensure that endpoints connected to the corporate network have an active, up-to-date FortiClient security agent installed before granting network access. Which Fortinet component manages endpoint compliance and synchronization with the Fortinet Security Fabric?
Medium92What is the primary purpose of FortiToken in a Fortinet security solution?
Easy93An organization wants to implement the Fortinet Security Fabric to gain centralized visibility across multiple distributed security devices. Which core protocol is utilized by Security Fabric devices to discover, authenticate, and securely communicate with the root FortiGate?
Hard94An administrator notices that users are accessing unauthorized social media websites during work hours. Which security profile feature should be configured on the FortiGate to block access to these specific categories of websites?
Easy95An administrator wants to deploy a wireless network across a corporate campus managed directly by the FortiGate firewall. Which Fortinet technology enables the FortiGate to control and provision FortiAPs directly?
Hard96Which TWO of the following statements correctly describe core concepts of the Fortinet Security Fabric? (Choose two.)
Medium97Which THREE protocols or technologies are commonly used to establish secure remote access VPNs on a FortiGate? (Choose three.)
Hard98When configuring an IPsec VPN tunnel between two FortiGate devices, what is the specific role of Phase 1 negotiation?
Hard99Which THREE parameters must be configured identically on both peers to successfully establish an IPsec Phase 1 tunnel? (Choose three.)
Hard100What is the primary function of a FortiGate interface configured in NAT mode?
Easy101An administrator needs to ensure that critical administrative login events and firewall configuration changes generate an immediate real-time alert email. Where are email alert settings configured on the FortiGate?
Medium102Which THREE features are provided by FortiClient EMS when integrated into the Fortinet Security Fabric? (Choose three.)
Hard103An administrator is setting up a FortiGate firewall and needs to define the security posture for traffic flowing from the internal network to the external Internet. Which object type should the administrator configure to enforce unified threat management features such as Antivirus, Web Filtering, and Intrusion Prevention on that traffic?
Easy104An administrator wants to ensure that specific internal users can access the internet while others cannot, based on their Active Directory group membership. How can this access control be implemented on a FortiGate?
Medium105An enterprise requires authentication of remote users connecting via SSL VPN against a Microsoft Active Directory server. Which Fortinet component can be deployed to synchronize user credentials and provide single sign-on (SSO) services?
HardOther domains
All FORTINET-NSE123 exam domains
Frequently asked questions
- What does the Nse 2 Technical Introduction TO Fortinet Security domain cover on the FORTINET-NSE123 exam?
- Nse 2 Technical Introduction TO Fortinet Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 105 Nse 2 Technical Introduction TO Fortinet Security questions in the FORTINET-NSE123 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Nse 2 Technical Introduction TO Fortinet Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.