Courseiva

CCNA Nse 3 Fortigate Operational Fundamentals Questions

75 of 103 questions · Page 1/2 · Nse 3 Fortigate Operational Fundamentals topic · Answers revealed

1
MCQmedium

A junior administrator accidentally locked themselves out of the FortiGate CLI after multiple incorrect password attempts. What is the standard administrative method to recover access without losing the configuration?

A.Perform a hardware factory reset using the pinhole reset button.
B.Use the default factory IP address 192.168.1.99 via HTTPS.
C.Wait for the lockout timer to expire, which defaults to 24 hours.
D.Log in via the physical console port using the 'maintainer' login procedure during a device reboot.
AnswerD

The maintainer account allows password resetting during a reboot via the console connection.

Why this answer

Console cable access using the physical serial/console port bypasses authentication locks if accessed via physical maintenance, or using the special 'maintainer' account procedure during a reboot.

2
Multi-Selectmedium

An administrator needs to configure local administrator accounts with specific operational privileges. Which TWO elements are required or configurable when creating a new local administrator account? (Choose two)

Select 2 answers
A.Administrator username
B.Firewall policy source IP object
C.Administrator access profile (defining permissions and privileges)
D.DHCP lease pool range
E.SSL VPN portal bookmark
AnswersA, C

Correct. A unique username is required for login.

Why this answer

Creating a local admin account requires specifying an account name, an authentication type (password or certificate), and assigning an administrator access profile.

3
MCQmedium

An administrator is troubleshooting intermittent latency on a specific interface. They need to capture live packet data passing through that interface directly from the FortiGate CLI. Which command is used for packet capture?

A.execute ping-packet
B.execute trace-route
C.get system interface traffic
D.diagnose sniffer packet
AnswerD

Correct. The packet sniffer utility allows real-time packet inspection on specified interfaces.

Why this answer

The diagnose sniffer packet command is the standard tool for capturing and displaying packets on a FortiGate CLI.

4
MCQeasy

An administrator needs to verify the current firmware version running on the FortiGate. Where can this information be found immediately upon logging into the dashboard?

A.Dashboard > System Information widget
B.Log & Report > System Events
C.Policy & Objects > Addresses
D.Network > Interfaces
AnswerA

Correct. The System Information widget shows the running firmware version prominently.

Why this answer

The System Information widget on the dashboard displays the firmware version, hostname, serial number, and uptime.

5
MCQeasy

Where can an administrator view a summary of detected security threats, such as blocked malware and intrusion prevention events, in the FortiGate web-based manager?

A.Log & Report > Security Logs
B.System > FortiGuard
C.Dashboard > Threat Map
D.Policy & Objects > Security Profiles
AnswerA

Correct. Security logs record specific security events like antivirus, web filtering, and IPS detections.

Why this answer

Security event logs and summaries are found under Log & Report > Security Logs.

6
MCQmedium

An administrator needs to check the status of FortiCare registration and feature licenses. Where in the web-based manager is this license summary displayed?

A.Policy & Objects > Licenses
B.Security Fabric > Registration
C.System > FortiGuard
D.Log & Report > License Audit
AnswerC

Correct. System > FortiGuard displays license status, contract expiration dates, and rating server connectivity.

Why this answer

License and registration status can be viewed under System > FortiGuard or the Dashboard License Information widget.

7
MCQmedium

An administrator needs to verify whether the FortiGate unit can successfully communicate with the FortiGuard distribution servers for license and signature updates. Which command should be run in the CLI to test this specific connectivity?

A.diagnose sys top
B.ping 8.8.8.8
C.execute update-now
D.execute FortiGuard-test
AnswerC

Correct. execute update-now forces an immediate check and update with FortiGuard servers, verifying connectivity.

Why this answer

The update status and connectivity to FortiGuard can be tested using the execute update-now or diagnostic commands for FortiGuard override/servers.

8
Multi-Selecteasy

Which TWO dashboard widgets are commonly used to monitor system performance and health on a FortiGate?

Select 2 answers
A.FortiView Source IPv4
B.System Information
C.System Resources
D.IPsec Monitor
E.DHCP Leases
AnswersB, C

Displays uptime, serial number, firmware version, and hostname.

Why this answer

System Resources and System Information are standard dashboard widgets for tracking hardware performance and general device status.

9
MCQeasy

An administrator wants to search for a specific user's web browsing logs from earlier in the day. Which menu should they open in the web-based manager?

A.Monitor > Web Activity
B.Log & Report > Web Filter
C.Policy & Objects > URL Filter
D.FortiView > Websites
AnswerB

Correct. Web filter logs record website access attempts and URL filtering actions.

Why this answer

Web filtering and web access logs are found under Log & Report > Web Filter.

10
MCQeasy

An administrator needs to quickly check the CPU and memory utilization of a FortiGate device directly from the web-based manager. Which dashboard widget provides this real-time system performance information by default?

A.FortiView Sessions
B.System Resources
C.License Information
D.Network Interfaces
AnswerB

Correct. The System Resources widget displays live CPU and memory utilization.

Why this answer

The System Resources widget displays real-time CPU and memory usage, allowing administrators to monitor resource consumption.

11
MCQhard

An administrator needs to verify the hardware sensor status (fans, power supplies, temperatures) of a high-end FortiGate unit. Which command provides this hardware health status?

A.execute hardware-test
B.diagnose hardware device info
C.show system sensor
D.get system hardware status
AnswerD

Correct. This command lists hardware sensor information including temperature and power supplies.

Why this answer

The get system hardware status command displays sensor readings such as fan speed and temperature.

12
MCQhard

An administrator suspects that a session is stuck in the FortiGate session table, preventing new connections. Which command allows viewing active sessions matching a specific source IP?

A.show firewall session [IP]
B.diagnose sys session filter src [IP] followed by diagnose sys session list
C.execute session clear [IP]
D.get system session list
AnswerB

Correct. Filtering and listing sessions allows pinpointing traffic for a specific source IP.

Why this answer

The diagnose sys session filter command combined with list allows filtering and viewing active sessions.

13
MCQhard

An administrator is troubleshooting a policy match issue and needs to inspect a specific security policy's hit count and ID directly from the CLI. Which CLI command should the administrator use to list all firewall policies with their internal IDs and rule details?

A.get system performance
B.diagnose sys session list
C.get system status
D.show firewall policy
AnswerD

Correct. Entering config firewall policy followed by show displays the configured policies and their IDs.

Why this answer

To view firewall policies via CLI, the command show firewall policy is used inside the configuration context.

14
Multi-Selectmedium

When setting up a new FortiGate device, an administrator needs to configure basic network parameters before deploying it in production. Which THREE parameters must be configured for basic network connectivity?

Select 3 answers
A.Interface IP address and subnet mask
B.DNS server IP addresses
C.BGP routing peer AS number
D.Default static route
E.SSL VPN portal customization
AnswersA, B, D

Interfaces require IP addressing to communicate on networks.

Why this answer

Basic network setup requires configuring physical interface IP addresses, default static routes to reach external networks, and DNS servers for name resolution.

15
MCQeasy

An administrator wants to verify the amount of free space available on the system log disk. Which dashboard widget displays this metric?

A.Storage Usage widget
B.System Resources
C.Hard Drive Status
D.Log Disk widget
AnswerD

Correct. The Log Disk widget shows total storage and used/free space for logging.

Why this answer

The Log Disk widget displays log disk usage and free space percentage.

16
MCQmedium

An administrator wants to verify the administrator access profile privileges assigned to a specific admin account. Where can access profiles be defined and edited?

A.Security Fabric > Profiles
B.System > Admin Profiles
C.System > Administrators > Profiles
D.Policy & Objects > Admin Profiles
AnswerB

Correct. Admin Profiles define read/write permissions for different administrative menus and features.

Why this answer

Administrator access profiles are managed under System > Admin Profiles.

17
Multi-Selectmedium

An administrator wants to verify high availability (HA) cluster status and member synchronization. Which TWO commands or dashboard widgets provide this HA status? (Choose two)

Select 2 answers
A.get system ha status
B.get system interface physical
C.FortiView > HA Traffic
D.High Availability dashboard widget
E.Policy & Objects > HA Rules
AnswersA, D

Correct. This CLI command outputs cluster member health, heartbeats, and synchronization status.

Why this answer

HA status can be monitored using the High Availability dashboard widget and the CLI command get system ha status.

18
MCQeasy

Where can an administrator view a summary of system alerts and warning messages directly in the web-based manager without navigating to full log reports?

A.Dashboard > System Events widget (or Event Log summary)
B.System > Monitoring
C.Network > Alerts
D.Policy & Objects > Event Monitoring
AnswerA

Correct. Dashboard widgets summarize recent system events and alerts.

Why this answer

The Event Log or System Events dashboard widgets provide quick summaries of recent system notices.

19
MCQmedium

An administrator needs to configure an idle timeout for administrative web GUI sessions to enhance security. Where is this setting located?

A.System > Administrators > Timeout
B.Policy & Objects > Global Settings
C.System > Settings > Administrator Idle Timeout
D.Log & Report > Admin Settings
AnswerC

Correct. System Settings contains the global configurable idle timeout for GUI admins.

Why this answer

Administrator session idle timeout is configured under System > Settings.

20
MCQmedium

An administrator notices that the FortiGate configuration changes made during troubleshooting were lost after an unexpected power outage. Where should the administrator check to ensure that the current running configuration is permanently saved?

A.System > Admin > Settings
B.FortiGate automatically saves running configurations to non-volatile memory immediately upon successful CLI or GUI commit actions.
C.System > Configuration > Backup
D.The CLI command execute backup config
AnswerB

Correct. FortiGate commits changes to running memory and non-volatile flash storage automatically upon a successful save action in the GUI or CLI.

Why this answer

Configuration changes in the CLI or GUI must be saved to flash storage. The active running configuration can be backed up or saved, but changes made via certain methods or scripts require explicit saves.

21
Multi-Selectmedium

An administrator wants to view historical web filtering and traffic logs on the FortiGate. Which TWO methods can be used to search and analyze stored logs? (Choose two)

Select 2 answers
A.Log & Report menu in the web-based manager with filter and search options
B.Restarting the routing daemon (gated)
C.Editing the FortiOS kernel source code directly
D.FortiAnalyzer integration or local log viewer filters
E.Running execute factory-reset
AnswersA, D

Correct. The Log & Report graphical log viewer provides robust search and filter capabilities.

Why this answer

Logs can be searched and filtered using the Log & Report menu in the GUI or via specialized log search CLI commands.

22
MCQeasy

Which dashboard widget displays the status of connected FortiGate security fabric devices and fabric topology?

A.FortiView Threat Map
B.Security Fabric Rating
C.System Resources
D.Security Fabric > Topology
AnswerD

Correct. The Security Fabric topology view visually maps out the interconnected devices.

Why this answer

The Security Fabric widget or Security Fabric topology view provides visibility into connected fabric devices.

23
MCQhard

An administrator is troubleshooting a certificate validation error when users connect to an SSL VPN portal. Where can the active SSL VPN server certificate be verified or changed in the web-based manager?

A.VPN > SSL-VPN Settings (Server Certificate field)
B.Policy & Objects > SSL Settings
C.System > Certificates > SSL-VPN
D.Security Fabric > VPN Settings
AnswerA

Correct. The SSL-VPN settings menu specifies the server certificate presented to remote VPN clients.

Why this answer

SSL VPN settings, including the server certificate selection, are configured under VPN > SSL-VPN Settings.

24
MCQmedium

An administrator needs to export the current configuration of a FortiGate to a secure local file for backup purposes. Which menu path should the administrator navigate in the web-based manager?

A.System > Settings > Maintenance
B.Click the administrator profile name at the top right of the GUI > Configuration > Backup
C.Security Fabric > Settings > Export
D.Log & Report > Backup Settings
AnswerB

Correct. On modern FortiOS versions, configuration backup and restore are accessed via the administrator profile dropdown menu at the top right of the GUI.

Why this answer

Configuration backup and restore functions are typically located under System > Configuration or via the administrator profile dropdown menu.

25
MCQeasy

An administrator wants to check the connection status of Security Fabric telemetry between the root FortiGate and downstream devices. Where is the Security Fabric status viewed?

A.System > Security Fabric Settings
B.Monitor > Fabric Monitor
C.Security Fabric > Topology
D.Dashboard > Fabric Health
AnswerC

Correct. The Security Fabric topology view displays connection status and health between fabric members.

Why this answer

Security Fabric status and topology are viewed under Security Fabric > Topology or Security Fabric Setup.

26
MCQhard

An administrator notices that configuration changes made via the CLI are not persisting after a device reboot. What is the most likely reason for this behavior?

A.The administrator exited the configuration block using 'abort' instead of 'end'.
B.The administrator forgot to issue the 'write memory' command.
C.The administrator did not issue a 'execute factory-reset' to commit.
D.The administrator failed to enable manual commit mode in system settings.
AnswerA

Using 'abort' discards all uncommitted changes made within the current configuration session.

Why this answer

FortiGate saves configuration changes to running memory immediately, but they are only written to permanent flash storage when the command completes successfully. If an invalid command or virtual domain (VDOM) context was left incomplete, or if the write failed, changes may be lost. However, standard config changes auto-save.

If flash is full or in read-only mode, it fails. Alternatively, failing to enter 'end' properly or making changes in a temporary session can cause loss. Let's look at options regarding manual commit vs auto-save.

FortiGate auto-saves upon 'end'.

27
MCQeasy

Where can an administrator view real-time bandwidth consumption per interface on the FortiGate dashboard?

A.Network Interfaces widget on the Dashboard
B.FortiView > Interfaces
C.System > Network > Performance
D.Log & Report > Bandwidth Monitor
AnswerA

Correct. The Network Interfaces widget provides live throughput and status for all interfaces.

Why this answer

The Network Interfaces widget displays real-time bandwidth and traffic rates per interface.

28
MCQmedium

An administrator needs to configure SNMP v3 monitoring on the FortiGate for integration with a network management system (NMS). Where is SNMP configured in the web-based manager?

A.Network > SNMP Agent
B.Log & Report > SNMP Settings
C.Security Fabric > SNMP
D.System > SNMP
AnswerD

Correct. SNMP v1/v2c/v3 communities, users, and trap receivers are configured under System > SNMP.

Why this answer

SNMP settings are configured under System > SNMP.

29
Multi-Selecthard

An administrator is reviewing log storage and management settings on the FortiGate. Which THREE storage options or destinations are supported for logging on a FortiGate? (Choose three)

Select 3 answers
A.Local disk (internal hard drive or flash storage)
B.FortiAnalyzer
C.Bluetooth pairing with a mobile phone
D.Local printer connected via USB
E.Syslog server
AnswersA, B, E

Correct. FortiGate can store logs locally on internal flash storage or hard drives.

Why this answer

FortiGate supports logging locally to internal storage/hard drive, forwarding to FortiAnalyzer, and forwarding to Syslog servers.

30
MCQeasy

Where in the FortiGate GUI can an administrator view a summary of detected security incidents, top applications, and top bandwidth users across the network?

A.Security Fabric > Topology
B.FortiView > Sources
C.Dashboard > Status
D.FortiView > All Sessions / Dashboards
AnswerD

FortiView provides visual dashboards for top applications, sources, destinations, and threats.

Why this answer

FortiView is the primary monitoring tool in the FortiGate GUI used to analyze traffic, threats, top applications, and users.

31
MCQeasy

Where can an administrator view a real-time list of top destination IP addresses accessed by internal users?

A.Log & Report > Destination Summary
B.Policy & Objects > Destinations
C.Monitor > Routing Table
D.FortiView > Destinations
AnswerD

Correct. FortiView Destinations shows top destination addresses receiving traffic from the network.

Why this answer

FortiView Destinations provides real-time visibility into top destination IP addresses and domains.

32
Multi-Selectmedium

An administrator is preparing to deploy a new FortiGate and needs to configure basic network parameters. Which TWO basic network settings must typically be configured on physical interfaces before deploying firewall policies? (Choose two)

Select 2 answers
A.Explicit proxy authentication realms
B.Administrative access settings (e.g., enabling HTTPS and ping for management)
C.BGP AS number and neighbor peer groups
D.IP address and subnet mask
E.SSL VPN client certificate revocation lists
AnswersB, D

Correct. Administrative access protocols must be explicitly enabled on interfaces to allow GUI/CLI management.

Why this answer

Interfaces require addressing mode (static or DHCP) and proper IP/netmask configuration, along with administrative access permissions (HTTPS, ping, etc.).

33
MCQmedium

An administrator wants to verify which administrator is currently logged into the FortiGate and from which IP address. Which CLI command should be used?

A.diagnose sys admin list
B.get system admin status
C.get system user active
D.show system admin session
AnswerB

Correct. This command lists currently logged-in administrators and their connection source IPs.

Why this answer

Active administrative sessions can be viewed using the get system admin status or system session list commands.

34
MCQeasy

An administrator wants to check the operational status and firmware version of all connected FortiExtender devices managed by the FortiGate. Which menu path should they follow?

A.System > FortiExtender
B.Security Fabric > Managed Devices
C.Policy & Objects > Device Inventory
D.Network > FortiExtender
AnswerB

Managed FortiExtender units, switches, and APs appear under Security Fabric > Managed Devices.

Why this answer

Managed FortiExtender devices are monitored and configured under the Managed Devices menu in the FortiGate GUI.

35
MCQeasy

An administrator wants to view top talkers by bandwidth usage over the past hour. Which FortiView view should be accessed?

A.FortiView > Sources
B.Policy & Objects > Sources
C.Monitor > Top Talkers
D.Log & Report > Traffic Sources
AnswerA

Correct. FortiView Sources displays top source IP addresses generating network traffic.

Why this answer

FortiView Sources displays top talkers (source IP addresses) ranked by bandwidth consumption.

36
MCQhard

An administrator needs to restore a saved configuration file to the FortiGate via the CLI. Which command is used to restore configuration settings from a backup file stored on a TFTP server?

A.execute restore config tftp [filename] [server-IP]
B.config restore tftp [server-IP] [filename]
C.system restore backup [filename]
D.upload config tftp [server-IP]
AnswerA

Correct. This command downloads and restores a configuration backup from a TFTP server.

Why this answer

The execute restore config command is used to restore configuration backups.

37
MCQeasy

An administrator wants to customize the dashboard view by adding a new widget. What is the standard method to add widgets in the FortiGate GUI?

A.Click 'Add Widget' in the top-left corner of the Dashboard view
B.Right-click any empty space in the GUI background
C.Go to Log & Report > Dashboard Options
D.Go to System > Dashboard > Settings
AnswerA

Correct. The Dashboard interface includes an 'Add Widget' button to customize displayed panels.

Why this answer

Widgets can be added by clicking the 'Add Widget' button on the Dashboard.

38
MCQeasy

An administrator needs to view active hardware temperature and power supply statuses on the dashboard. Which widget should be added?

A.Device Inventory
B.Power Monitor
C.Hardware Status widget
D.System Resources
AnswerC

Correct. The Hardware Status widget displays physical sensor health readings.

Why this answer

The Hardware Status widget displays temperature sensors, fan speeds, and power supply statuses.

39
Multi-Selecthard

An administrator is troubleshooting log delivery failures to a remote syslog server. Which TWO troubleshooting commands or tools can be used from the FortiGate CLI to verify connectivity and log transmission?

Select 2 answers
A.diagnose debug flow filter
B.execute factory-reset
C.get system arps
D.execute ping <syslog-server-ip>
E.diagnose sniffer packet any 'port 514' 4
AnswersD, E

Verifies basic IP reachability to the remote log server.

Why this answer

To troubleshoot syslog/remote logging, administrators can use packet sniffing ('diagnose sniffer packet') and test connectivity ('execute ping' or 'execute telnet').

40
MCQmedium

An administrator needs to verify the current date and time settings on the FortiGate to ensure log timestamps are accurate. Which menu path in the web-based manager is used to configure system time and NTP settings?

A.System > Settings
B.System > FortiGuard
C.Monitor > System Time
D.Log & Report > Log Settings
AnswerA

Correct. System time, timezone, and NTP server settings are configured under System > Settings.

Why this answer

System time and NTP servers are configured under System > Settings.

41
MCQhard

An administrator is troubleshooting a configuration synchronization failure in an HA cluster. Which CLI command forces an immediate configuration synchronization from the primary unit to the secondary unit?

A.execute ha synchronize config
B.diagnose ha sync-now
C.execute ha synchronize
D.config system ha force-sync
AnswerC

Correct. This command forces the primary unit to push its configuration to secondary cluster members.

Why this answer

The execute ha synchronize command forces manual synchronization of configuration or sessions in an HA cluster.

42
Multi-Selectmedium

An administrator needs to back up the FortiGate configuration and ensure that sensitive passwords are protected. Which TWO statements regarding FortiGate configuration backups are correct? (Choose two)

Select 2 answers
A.Configuration files are saved in plain text XML format that cannot be encrypted.
B.Configuration backups can only be performed by connecting a console cable.
C.Backups can be encrypted with a password to protect sensitive information such as VPN pre-shared keys and user passwords.
D.Configuration backups can be exported via the web-based manager or CLI.
E.Backups automatically include historical log databases by default.
AnswersC, D

Correct. Encrypting configuration backups protects sensitive keys and credentials.

Why this answer

Configuration backups can be performed via the GUI or CLI, and administrators are prompted for an encryption password to secure sensitive data like pre-shared keys.

43
Multi-Selecthard

An administrator is investigating a network performance degradation issue and needs to check hardware sensor health on a high-end FortiGate unit. Which THREE hardware parameters or components can be monitored via FortiGate hardware status commands or widgets? (Choose three)

Select 3 answers
A.Power supply unit (PSU) status
B.Internal chassis or CPU temperature sensors
C.Active BGP peer uptime metrics
D.Fan operational status and speeds
E.SSL VPN tunnel encryption keys
AnswersA, B, D

Correct. Power supply operational states are tracked by hardware sensors.

Why this answer

Hardware health monitoring includes fan speeds, power supply status, and internal temperature sensors.

44
MCQhard

An administrator needs to reboot the FortiGate device remotely during a maintenance window without causing data corruption. Which CLI command should be executed?

A.execute factory-reset
B.system restart
C.execute reboot
D.config system global set reboot
AnswerC

Correct. execute reboot initiates a graceful system restart.

Why this answer

The execute reboot command safely restarts the FortiGate device.

45
MCQhard

An administrator wants to verify which configuration revision history is currently active and wants to roll back to a previous revision. Where can configuration revisions be managed in the web-based manager?

A.Log & Report > Revision Logs
B.System > Maintenance > Rollback
C.Security Fabric > Backups
D.Administrator profile dropdown menu > Configuration > Revision History
AnswerD

Correct. Revision history allows administrators to view and roll back previous configuration versions.

Why this answer

Configuration revisions are managed under System > Configuration or via the administrator profile dropdown menu revision history.

46
MCQhard

An administrator is troubleshooting a DHCP server issue on the FortiGate and needs to see active IP address leases assigned by the built-in DHCP server. Which CLI command provides this information?

A.execute dhcp lease-list
B.diagnose system dhcp list
C.get router info dhcp
D.get system dhcp-server lease
AnswerA

Correct. This command outputs all active IP leases assigned by the FortiGate DHCP server.

Why this answer

The execute dhcp lease-list command displays active DHCP leases assigned by the FortiGate interface.

47
Multi-Selecthard

An administrator is examining the FortiGate routing table via the CLI. Which THREE types of routes can appear in the active routing table? (Choose three)

Select 3 answers
A.Dynamic routes (learned via protocols such as OSPF, BGP, or RIP)
B.Firewall policy object routes
C.Security Fabric telemetry routes
D.Connected routes (directly attached subnets)
E.Static routes (manually configured routes)
AnswersA, D, E

Correct. Dynamic routing protocols populate routes automatically.

Why this answer

Active routing tables can contain static routes, connected (directly attached) routes, and dynamic routes learned via protocols like OSPF or BGP.

48
MCQmedium

An administrator needs to verify whether FortiGuard web filtering rating lookups are succeeding for specific categories. Which CLI command tests web filter rating lookups for a specific URL?

A.get webfilter status [URL]
B.diagnose webfilter FortiGuard lookup [URL]
C.execute webfilter-test [URL]
D.ping fortiguard-rating [URL]
AnswerB

Correct. This diagnostic command queries FortiGuard to return the rating category for a given URL.

Why this answer

The diagnose webfilter FortiGuard lookup command tests URL categorization.

49
MCQhard

An administrator is reviewing firewall policies and notices that traffic matching a specific policy is being logged, but no traffic logs are appearing in Log & Report > Forward Traffic. FortiGate is configured to send logs to FortiAnalyzer. Where are the traffic logs being stored?

A.They are stored in the FortiGate system memory ring buffer.
B.They are buffered in RAM and will only flush when the FortiGate reboots.
C.They are discarded because local logging is automatically disabled when remote logging is active.
D.They are stored exclusively on the remote FortiAnalyzer and not on the local FortiGate storage.
AnswerD

When FortiAnalyzer is connected, traffic logs are sent off-box to the analyzer.

Why this answer

When a remote logging server like FortiAnalyzer or FortiGate Cloud is enabled and configured successfully, traffic logs are offloaded and stored on that remote device rather than locally on the FortiGate flash memory.

50
MCQhard

An administrator is troubleshooting a packet loss issue and needs to inspect the kernel buffer drops and interface error counters. Which CLI command provides a summary of interface drop statistics?

A.execute interface-test drops
B.diagnose hardware deviceinfo nic [interface]
C.show interface drops
D.get system drop-stats
AnswerB

Correct. This diagnostic command outputs driver-level statistics, including buffer drops and errors.

Why this answer

The get system interface physical or diagnose hardware deviceinfo nic commands provide drop counters and error statistics.

51
MCQmedium

An administrator wants to verify whether the FortiGate device is operating in NAT mode or Transparent mode. Where can this operational mode be checked in the web-based manager?

A.System > Feature Visibility > NAT Mode
B.Network > Operation Mode
C.Policy & Objects > Mode Settings
D.Dashboard > System Information widget (System Mode field)
AnswerD

Correct. The System Information widget displays the operating mode (NAT or Transparent).

Why this answer

System mode (NAT or Transparent) is displayed in the System Information dashboard widget.

52
MCQmedium

An administrator needs to modify the hostname of the FortiGate via the CLI. Which configuration context and command are used?

A.config system settings > set name [name] > end
B.set hostname [name]
C.config system global > set hostname [name] > end
D.execute hostname [name]
AnswerC

Correct. Global system settings like hostname are modified within the config system global context.

Why this answer

The hostname is configured under config system global using the set hostname command.

53
MCQmedium

An administrator wants to check the operational status of all physical and logical interfaces in a summary table view. Which menu path in the web-based manager should be opened?

A.Policy & Objects > Interfaces
B.Monitor > Interface Summary
C.Network > Interfaces
D.System > Interfaces
AnswerC

Correct. Network > Interfaces displays all physical ports, VLANs, and software interfaces with status and IP details.

Why this answer

Interface configurations and status summaries are viewed under Network > Interfaces.

54
MCQmedium

An administrator needs to modify the TCP session timeout for specific services. Where are global system timeout values configured in the CLI?

A.config firewall settings > set timeout [seconds] > end
B.config router global > set tcp-timeout [seconds] > end
C.config system global > set tcp-idle-timer [seconds] > end
D.execute set-timeout [seconds]
AnswerC

Correct. Global timer settings like TCP idle timeouts are configured under config system global.

Why this answer

Timeouts are configured under config system global using parameters like set tcp-idle-timer.

55
MCQeasy

How can an administrator quickly verify whether the FortiGate unit has a valid and active FortiCare support contract from the GUI?

A.Network > Interfaces
B.Policy & Objects > Objects
C.Log & Report > Event Log
D.System > FortiGuard
AnswerD

The FortiGuard menu and License Information widget display contract statuses and renewal options.

Why this answer

License and support contract status can be verified directly from the System > FortiGuard or Dashboard > License Information widget.

56
Multi-Selecthard

An administrator is troubleshooting a routing and connectivity issue on the FortiGate. Which THREE CLI commands can be used to test network reachability and path characteristics? (Choose three)

Select 3 answers
A.execute dns-lookup [hostname]
B.show router routing-table
C.execute ping [IP-address]
D.get system performance status
E.execute traceroute [IP-address]
AnswersA, C, E

Correct. execute dns-lookup tests DNS resolution against configured DNS servers.

Why this answer

Network connectivity can be tested using execute ping, execute traceroute, and execute dns-lookup.

57
MCQmedium

An administrator needs to test DNS resolution directly from the FortiGate command line interface to troubleshoot a FortiGuard connectivity issue. Which command should be used?

A.execute dns-lookup [hostname]
B.ping [hostname]
C.get system dns
D.diagnose test resolv [hostname]
AnswerA

Correct. execute dns-lookup tests DNS resolution using the configured DNS servers.

Why this answer

The execute ping or execute dns-lookup commands are used to test name resolution in FortiOS.

58
MCQmedium

An administrator needs to check the status of static routes configured on the FortiGate. Which CLI command lists all static routes?

A.config router static show
B.show firewall static-route
C.get router info routing-table static
D.diagnose ip route list static
AnswerC

Correct. This command filters the routing table to show static routes.

Why this answer

The get router info routing-table static command displays configured static routes.

59
MCQhard

An administrator is troubleshooting high memory utilization on a FortiGate. They run 'get system performance status' and see that memory usage is in conserve mode. What immediate action does FortiOS take when entering conserve mode?

A.It stops allocating memory for certain cache operations and may block new non-administrative connection attempts.
B.It immediately reboots the device to clear RAM.
C.It wipes all historical log files from local disk storage.
D.It automatically initiates a firmware rollback to the previous stable version.
AnswerA

Conserve mode restricts memory allocation, stops daemon memory growth, and can drop new sessions to prevent kernel panic.

Why this answer

When FortiOS enters memory conserve mode, it stops allocating new memory for non-critical tasks, drops new sessions or drops new connection setups depending on configuration, and prevents configuration changes to protect stability.

60
MCQeasy

An administrator wants to inspect historical logs stored locally on the FortiGate hard drive. Which menu should they open?

A.Dashboard > Log Summary
B.Log & Report > Forward Traffic
C.System > Log Config
D.Monitor > Log Viewer
AnswerB

Correct. Log & Report provides access to traffic, security, and event logs stored on the device.

Why this answer

Local logs are viewed under Log & Report.

61
Multi-Selecthard

An administrator needs to check system performance and resource bottlenecks on a FortiGate device using the CLI. Which TWO commands can be used to display CPU, memory, and process-level utilization? (Choose two)

Select 2 answers
A.diagnose sys top
B.get system interface physical
C.get system performance status
D.show system resources
E.execute system status
AnswersA, C

Correct. This command displays live CPU and memory consumption per running daemon process.

Why this answer

The get system performance status and diagnose sys top commands provide real-time CPU, memory, and process statistics.

62
MCQeasy

Where in the FortiGate web-based manager can an administrator view current system alerts, warning logs, and administrative event logs?

A.Log & Report > System Events
B.Security Fabric > Audit
C.System > Advanced
D.Monitor > Routing Monitor
AnswerA

Correct. System Events logs administrative actions, system warnings, and high-level notifications.

Why this answer

Log & Report is the centralized location for viewing traffic, event, and security logs on the FortiGate.

63
MCQeasy

An administrator wants to view active VPN tunnels and connected remote users on the dashboard. Which widget is designed for this purpose?

A.IPsec & SSL VPN widget
B.Remote Access Monitor
C.User Monitor
D.Network Interfaces
AnswerA

Correct. This dashboard widget provides summary status and tunnel counts for VPN connections.

Why this answer

The IPsec & SSL VPN widget displays active tunnel statuses and connected remote users.

64
MCQmedium

An administrator is configuring a new firewall policy to allow internal users to access the internet. Which parameter is mandatory when defining a IPv4 firewall policy in FortiOS?

A.Schedule
B.NAT (Network Address Translation)
C.Action (Accept, Deny, or IPsec)
D.Destination Address
AnswerC

The action parameter (accept/deny) is a mandatory field in every firewall policy.

Why this answer

Every firewall policy must define source interfaces, source addresses, destination interfaces, destination addresses, service, and action.

65
MCQhard

An administrator suspects memory fragmentation or a memory leak in a specific daemon (e.g., wad). Which CLI command provides detailed memory allocation statistics per daemon?

A.get system memory detail
B.show memory daemon
C.diagnose sys top or diagnose memory sysusage
D.diagnose hardware memory usage
AnswerC

Correct. Diagnostic commands display per-process memory consumption and system memory statistics.

Why this answer

The diagnose sys ps or diagnose memory detail commands show memory usage per process.

66
MCQhard

An administrator needs to troubleshoot a routing issue and verify which route will be selected by the FortiGate for a specific destination IP. Which CLI command allows routing lookup simulation?

A.diagnose ip route lookup [dest-IP]
B.show routing-table match [dest-IP]
C.get router route-check [dest-IP]
D.execute route-test [dest-IP]
AnswerA

Correct. This diagnostic command simulates routing table lookup to show which gateway and interface will be used.

Why this answer

The get router info routing-table details or diagnose ip route lookup commands allow testing route selection for specific IPs.

67
MCQeasy

An administrator wants to see a real-time list of top applications generating traffic on the network. Which FortiView tab should be opened?

A.Monitor > Application Control
B.FortiView > Applications
C.Log & Report > Application Logs
D.Policy & Objects > Applications
AnswerB

Correct. FortiView Applications provides real-time visibility into application bandwidth usage.

Why this answer

FortiView Applications displays real-time top applications passing through the FortiGate.

68
MCQhard

An administrator suspects a routing loop or gateway failure and needs to test basic IP connectivity to the default gateway with a specified source IP. Which CLI command allows specifying the source IP for a ping test?

A.diagnose ping src [source-IP] [dest-IP]
B.set ping source [source-IP]
C.ping-source [source-IP] [dest-IP]
D.execute ping-options source [source-IP] followed by execute ping [dest-IP]
AnswerD

Correct. Setting ping options allows customizing source IP, packet size, and repeat count before executing the ping.

Why this answer

The execute ping-options command allows setting parameters like source IP before running an execute ping.

69
MCQhard

An administrator needs to test reachability and path MTU to a destination IP using ICMP packets with the Don't Fragment (DF) bit set. Which CLI command allows this?

A.set ping df-bit enable
B.execute ping-options df-bit yes followed by execute ping [dest-IP]
C.ping -M do [dest-IP]
D.diagnose ping df [dest-IP]
AnswerB

Correct. Setting ping options allows enabling the DF bit for path MTU discovery testing.

Why this answer

The execute ping command supports options like setting the DF bit when combined with ping options.

70
MCQmedium

An administrator needs to set up log forwarding from the FortiGate to a remote Syslog server. Which menu path in the web-based manager is used to configure remote logging?

A.Log & Report > Log Settings
B.System > Syslog Server
C.Policy & Objects > Logging
D.Security Fabric > Log Forwarding
AnswerA

Correct. Log settings configure forwarding to FortiAnalyzer, Syslog servers, and FortiCloud.

Why this answer

Remote logging destinations (Syslog, FortiAnalyzer, etc.) are configured under Log & Report > Log Settings.

71
MCQeasy

An administrator wants to check the operational status of FortiGate HA clustering. Which dashboard widget provides an overview of HA member health and role status?

A.Security Fabric Status
B.System Topology
C.Cluster Monitor
D.High Availability widget
AnswerD

Correct. The High Availability dashboard widget shows cluster health and member roles.

Why this answer

The High Availability widget displays cluster member status, sync state, and master/slave roles.

72
Multi-Selecthard

An administrator wants to secure administrative access to the FortiGate. Which THREE best practices should be implemented?

Select 3 answers
A.Set the administrative idle timeout to unlimited for convenience.
B.Use default admin credentials across all deployed firewalls.
C.Configure trusted hosts for administrator accounts to limit access to specific IP ranges.
D.Disable HTTP administrative access and enforce HTTPS only.
E.Disable Telnet access and use SSH for secure CLI management.
AnswersC, D, E

Trusted hosts restrict management login to approved source IPs.

Why this answer

Securing management access involves restricting access via trusted hosts, enforcing strong administrator passwords, and disabling insecure protocols like HTTP and telnet.

73
Multi-Selectmedium

An administrator wants to customize the dashboard view on the FortiGate web-based manager. Which TWO actions can the administrator perform to personalize the dashboard? (Choose two)

Select 2 answers
A.Rearrange existing widgets by dragging and dropping them into preferred positions.
B.Convert the dashboard into a command-line terminal emulator.
C.Delete physical firewall ports from the dashboard interface view.
D.Modify core FortiOS kernel code directly from the dashboard widget settings.
E.Add new widgets using the 'Add Widget' option.
AnswersA, E

Correct. Dashboard widgets support drag-and-drop rearrangement.

Why this answer

Administrators can add/remove default widgets and rearrange dashboard panels.

74
MCQhard

An administrator needs to verify the status of certificate inspection and CA certificates installed on the FortiGate. Where are SSL/SSH inspection profiles and local certificates managed in the web-based manager?

A.Log & Report > Certificate Logs
B.Policy & Objects > SSL/SSH Inspection and System > Certificates
C.VPN > Certificate Manager
D.Security Fabric > Inspection Settings
AnswerB

Correct. SSL/SSH inspection profiles are under Policy & Objects, while certificates are managed under System > Certificates.

Why this answer

SSL/SSH inspection profiles are managed under Policy & Objects > SSL/SSH Inspection, and certificates are under System > Certificate.

75
MCQmedium

An administrator needs to back up the current FortiGate configuration securely to a local PC via the GUI. Which option should the administrator select?

A.System > Firmware > Backup
B.Log & Report > Log Settings > Backup
C.System > Settings > Backup Configuration
D.Security Fabric > Settings > Export
AnswerC

The configuration backup option is located under System settings or admin dropdown depending on firmware version, allowing local encryption with a password.

Why this answer

To back up the configuration from the GUI, the administrator navigates to System > Settings or clicks the admin profile name in the top right corner and selects Configuration > Backup.

Page 1 of 2 · 103 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Nse 3 Fortigate Operational Fundamentals questions.