Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 1–75

773 questions total · 11pages · All types, answers revealed

Page 1 of 11

Page 2
1
MCQmedium

A FortiGate with multiple VDOMs is configured for FSSO with Active Directory polling. Users in VDOM1 are authenticated correctly, but users in VDOM2 are not. What should be checked FIRST?

A.The DNS resolution for the domain controller in VDOM2
B.The firewall policy ordering in VDOM2
C.The FSSO collector agent settings for VDOM2
D.The LDAP server configuration in VDOM2
AnswerC

In a multi-VDOM architecture, each VDOM is a separate security context, so FSSO collector agent settings must be defined individually for every VDOM that requires single sign-on. If VDOM2 lacks its own collector agent configuration, or if the configured agent's IP, port, shared secret, or AD polling credentials are incorrect, the FortiGate will not receive login events for users in that VDOM. Without these events, FSSO cannot map users to IP addresses, breaking user-aware policies. This is the root cause and the correct answer.

Why this answer

In a multi-VDOM FSSO setup with Active Directory polling, each VDOM requires its own FSSO collector agent configuration to map domain users to the correct VDOM. Since VDOM1 works but VDOM2 does not, the most likely cause is that the FSSO collector agent settings for VDOM2 are missing or misconfigured, such as the collector agent IP, port, or shared secret. This is the first item to verify because FSSO polling relies on per-VDOM agent communication to deliver user-to-IP mappings.

Exam trap

The trap here is that candidates often assume LDAP server configuration is the root cause for any authentication failure, but FSSO polling relies on the collector agent, not LDAP binds, making Option D a common distractor.

How to eliminate wrong answers

Option A is wrong because DNS resolution for the domain controller is a prerequisite for LDAP or FSSO polling to function at all; if it were broken, VDOM1 would also fail, and DNS issues typically affect all VDOMs equally. Option B is wrong because firewall policy ordering affects traffic matching and access control, not the authentication mechanism itself; FSSO user groups can be used in policies, but the failure to authenticate users in VDOM2 is not caused by policy order. Option D is wrong because LDAP server configuration is used for direct LDAP authentication, not for FSSO polling; FSSO with Active Directory polling uses the collector agent to obtain user logon events from domain controllers, not an LDAP bind.

2
MCQeasy

What is the function of Zero Trust Network Access (ZTNA) on a FortiGate?

A.It allows users to securely access internal applications without a VPN, based on identity and device posture
B.It replaces the firewall policy for all traffic
C.It encrypts all traffic between the FortiGate and the internet
D.It is a cloud-based subscription for antivirus updates
AnswerA

ZTNA enables per-application, identity-based access control: the FortiGate acts as an access proxy, authenticating the user (via SAML, LDAP, or local login) and verifying device posture (using FortiClient or other telemetry) before allowing a short-lived, encrypted session to a specific internal application. This eliminates the need for a full VPN tunnel, enforcing least-privilege access while keeping the user unaware of the complete internal network.

Why this answer

ZTNA on FortiGate provides secure, identity-based access to internal applications without requiring a traditional VPN tunnel. It evaluates user identity and device posture before granting access, ensuring that only authorized users and compliant devices can reach specific applications. This aligns with the Zero Trust principle of 'never trust, always verify' and is implemented via FortiGate's ZTNA features, often integrated with FortiClient and FortiAuthenticator.

Exam trap

NSE4 often tests the misconception that ZTNA is a replacement for VPNs or firewalls, when it is actually a complementary access control mechanism that requires identity and posture checks.

How to eliminate wrong answers

Option B is wrong because ZTNA does not replace firewall policies; it works alongside them to provide granular, application-level access control, and firewall policies still govern other traffic. Option C is wrong because ZTNA does not encrypt all traffic between the FortiGate and the internet; encryption is typically handled by IPsec or TLS VPNs, and ZTNA focuses on access control, not bulk encryption. Option D is wrong because ZTNA is not a cloud-based subscription for antivirus updates; that describes FortiGuard services, while ZTNA is a network access security feature.

3
MCQhard

A FortiGate has two firewall policies: Policy ID 1 (source: 10.0.1.0/24, destination: 203.0.113.0/24, action: allow, NAT: enabled) and Policy ID 2 (source: 10.0.1.0/24, destination: all, action: allow, NAT: enabled, IP pool: pool1). A user from 10.0.1.10 sends traffic to 203.0.113.5. Which policy will the traffic match and why?

A.Both policies will be applied because the traffic matches both
B.Policy ID 2 because it has a broader destination and is more inclusive
C.Policy ID 1 because it is the first matching policy in the list
D.Neither policy; implicit deny will block the traffic
AnswerC

FortiGate performs a sequential lookup from the top of the policy list, and the first policy whose source, destination, service, user, and other attributes match the packet becomes the winner. Here, Policy ID 1 meets the session's source and destination, so the lookup terminates immediately. Consequently, Policy ID 1 is the only rule applied, even if later rules are equally or more general.

Why this answer

Policy ID 1 is correct because FortiGate uses a sequential, first-match policy evaluation model. Traffic from 10.0.1.10 to 203.0.113.5 matches the source and destination of Policy ID 1 exactly, and since it appears first in the policy list, it is applied immediately. Once a match is found, no further policies are evaluated, even if a later policy (like Policy ID 2) also matches.

Exam trap

The trap here is that candidates often assume a broader or more inclusive policy (like 'destination all') will override a more specific one, but FortiGate's first-match logic means policy order, not specificity, determines which policy is applied.

How to eliminate wrong answers

Option A is wrong because FortiGate does not apply multiple policies to the same traffic; it stops at the first match. Option B is wrong because FortiGate does not select policies based on inclusivity or broader destination; it strictly follows the order in the policy list. Option D is wrong because the traffic explicitly matches Policy ID 1, which has an allow action, so the implicit deny is never reached.

4
MCQhard

An administrator is configuring ZTNA (Zero Trust Network Access) on a FortiGate. The administrator needs to ensure that only clients with a valid posture assessment can access an internal application. Which access proxy setting must be configured to enforce this requirement?

A.Enable SSL deep inspection on the access proxy
B.Configure a ZTNA rule with a ZTNA tag requirement
C.Set the access proxy to use certificate-based authentication
D.Enable multi-factor authentication on the access proxy
AnswerB

Configuring a ZTNA rule with a ZTNA tag requirement is the only option that directly enforces security posture. The FortiGate requires that the connecting client present a specific tag that is only issued after the endpoint passes posture checks such as patching and host firewall status. If the tag is absent or does not match the required value, the rule blocks access. This tag-based enforcement is the core mechanism for zero-trust posture verification in Fortinet's ZTNA.

Why this answer

ZTNA on FortiGate enforces zero trust by requiring clients to present a valid ZTNA tag, which is issued only after a successful posture assessment by FortiClient EMS. Configuring a ZTNA rule with a tag requirement ensures that only endpoints meeting the posture policy can reach the protected application through the access proxy. This is the mechanism that ties posture validation to access enforcement.

Exam trap

The trap is conflating authentication mechanisms (certificates, MFA) with posture assessment; candidates pick certificate or MFA options thinking they enforce device health when only ZTNA tags reflect posture.

How to eliminate wrong answers

Option A is wrong because SSL deep inspection decrypts and inspects traffic content; it does not perform endpoint posture assessment or enforce tag-based access. Option C is wrong because certificate-based authentication verifies client identity, not device posture; a compliant certificate does not prove the endpoint meets security requirements like antivirus or patch level. Option D is wrong because MFA strengthens user authentication but does not evaluate device health or posture, so it cannot enforce the posture requirement alone.

5
MCQhard

An administrator configures a VIP for port forwarding: public IP 203.0.113.10 port 8080 to internal server 10.0.1.10 port 80. External users can connect to http://203.0.113.10:8080 but receive a timeout. The firewall policy allows traffic from any to the VIP on destination port 8080. The internal server is reachable from internal hosts. What is the most likely problem?

A.The internal server is not running a web server
B.The VIP is not associated with the policy
C.The policy destination service is set to HTTP (port 80) instead of port 8080
D.The source NAT is not configured
AnswerC

The policy's destination service is incorrectly set to HTTP (port 80) instead of the pre-NAT destination port 8080. FortiGate evaluates firewall policies against the packet's original destination port before any NAT translation occurs, so the policy must match the port the client connects to (i.e., the external port on the VIP, 8080). Using service HTTP (port 80) will cause the implicit deny rule to drop the packets because the session's destination port does not match the policy's service. The correct fix is to change the service to the pre-NAT port (e.g., a custom TCP/8080 service) or adjust the VIP to listen on port 80.

Why this answer

The firewall policy must match the destination port of the incoming traffic. External users connect to port 8080 on the VIP, but if the policy's destination service is set to HTTP (port 80), the policy will not match traffic destined for port 8080. Even though the VIP translates the destination to port 80 on the internal server, the firewall policy evaluation occurs before NAT translation, so the policy must match the original destination port (8080).

Exam trap

The trap here is that candidates mistakenly think the policy should match the internal server's port (80) because the VIP translates to that port, but FortiOS policy evaluation occurs before NAT, so the policy must match the original destination port (8080).

How to eliminate wrong answers

Option A is wrong because the internal server is reachable from internal hosts, confirming the web server is running and functional. Option B is wrong because VIPs in FortiOS are automatically associated with firewall policies that reference them; the VIP does not need a separate association step. Option D is wrong because source NAT (SNAT) is not required for inbound port forwarding; the VIP handles destination NAT, and return traffic is automatically handled by the session table without explicit SNAT configuration.

6
MCQmedium

An administrator configures a policy route to force traffic from a specific source subnet to use a particular WAN interface. After applying the configuration, the traffic still uses the default route. What is the most likely cause?

A.The static default route has a lower administrative distance than the policy route
B.The FortiGate's VDOM is enabled and the policy route is in the wrong VDOM
C.The policy route's incoming interface is incorrectly configured
D.The policy route has a lower priority than the static default route
AnswerC

Policy routes are matched based on the incoming interface alongside source and destination criteria. If the configured incoming interface does not match the physical or logical interface on which the traffic actually enters, the FortiGate will skip the policy route and fall back to the routing table. For example, specifying port1 while traffic arrives on port2 means the policy is never evaluated, so the traffic follows the default route instead.

Why this answer

Policy routes are evaluated based on the incoming interface specified in the rule. If the incoming interface is misconfigured (e.g., set to 'any' or the wrong physical interface), the FortiGate will not match the traffic against the policy route, causing it to fall through to the routing table and use the default route. The policy route must explicitly match the interface on which the traffic enters the FortiGate.

Exam trap

The trap here is that candidates often confuse policy routes with static routes or assume that a policy route applies globally, when in fact the incoming interface is a critical matching condition that must be correctly configured for the policy to take effect.

How to eliminate wrong answers

Option A is wrong because administrative distance applies to routes in the routing table, not to policy routes; policy routes override the routing table regardless of administrative distance. Option B is wrong because while VDOM misplacement can cause policy routes to not apply, the question states the configuration was applied, and VDOM issues would typically prevent the policy from being created or visible, not silently ignore it. Option D is wrong because policy routes do not have a 'priority' value relative to static routes; they are evaluated before the routing table lookup, and if the incoming interface matches, the policy route is used unconditionally.

7
MCQeasy

A FortiGate administrator needs to allow inbound SSH access from the internet to a single internal server at IP 10.0.1.10. The public IP on the WAN interface is 203.0.113.5. Which type of object should be configured to map the public IP and port to the internal server?

A.IP Pool
B.Central NAT policy
C.Virtual IP (VIP)
D.Address object
AnswerC

A Virtual IP (VIP) is the FortiOS object that enables destination NAT and port forwarding for inbound traffic, which is exactly what is needed to allow SSH from the internet to an internal server. The administrator defines a VIP entry with the public interface IP and TCP port 22, maps it to the internal server's private IP and port 22, and then uses that VIP as the destination in a firewall policy that permits tcp/22. When a packet arrives for the public IP, the FortiGate rewrites the destination address to the internal IP, allowing the session to reach the SSH daemon.

Why this answer

A Virtual IP (VIP) object is the correct choice because it specifically maps a public IP and port (203.0.113.5:22) to a private IP and port (10.0.1.10:22) for inbound destination NAT (DNAT). This allows external SSH traffic to reach the internal server by translating the destination address and port at the FortiGate WAN interface.

Exam trap

The trap here is that candidates often confuse IP Pools (used for source NAT) with Virtual IPs (used for destination NAT), leading them to select Option A when the question clearly requires inbound mapping.

How to eliminate wrong answers

Option A is wrong because an IP Pool is used for source NAT (SNAT) to translate the source IP of outbound traffic, not for inbound destination mapping. Option B is wrong because Central NAT policy is a centralized method to define NAT rules, but it still requires a VIP object to specify the destination translation; it is not the object itself. Option D is wrong because an Address object only defines a network or host IP for policy matching, but it does not provide the port mapping or translation functionality needed for inbound access.

8
MCQmedium

An administrator runs 'diagnose firewall iprope list 100000' and sees 'action=deny' entries for traffic that should be allowed. The policy list shows an allow policy with ID 1 for that traffic. What is the most likely cause of the deny?

A.The traffic is being blocked by a local-in policy
B.The implicit deny rule is being triggered because the policy is disabled
C.The firewall policy is not installed in the kernel due to an error
D.A security profile is dropping the traffic after the policy matches
AnswerC

The 'diagnose firewall iprope list' command displays the kernel's actual IPv4 firewall policy list. If a policy fails to install—due to memory constraints, commit errors, or conflicting objects—it will be absent from this output, causing traffic to fall through to the implicit deny rule. An error message in the command's output or a missing policy ID is the direct indicator of a kernel installation failure, making this the correct explanation.

Why this answer

The 'diagnose firewall iprope list 100000' command displays the kernel-level firewall policy list. If the policy list shows an allow policy (ID 1) but the kernel entries show 'action=deny', it indicates that the policy was not successfully installed into the kernel's connection tracking or firewall engine. This typically occurs due to a policy installation error, such as a configuration inconsistency or a failure during the commit process, causing the kernel to fall back to a default deny action for that traffic.

Exam trap

The trap here is that candidates assume the policy list shown in the GUI or CLI always reflects the active kernel state, but Fortinet tests the understanding that a policy may exist in the configuration yet fail to install into the kernel, causing unexpected denies despite an apparent allow rule.

How to eliminate wrong answers

Option A is wrong because local-in policies apply to traffic destined to the FortiGate itself (e.g., management traffic), not to traffic passing through the firewall, and the question describes traffic that should be allowed by a policy, implying transit traffic. Option B is wrong because if the policy were disabled, it would not appear in the policy list as an allow policy with ID 1; a disabled policy is not evaluated, and the implicit deny would only apply if no other policy matches, but here the policy exists and is enabled. Option D is wrong because security profiles (e.g., antivirus, web filter) are applied after a policy match and would not cause a 'deny' action in the kernel iprope list; they would instead log a separate action like 'block' or 'reset' at the application layer, not a kernel-level deny.

9
MCQhard

An administrator is troubleshooting an IPsec VPN that fails to establish Phase 2. The Phase 1 is up. The administrator runs 'diagnose vpn ike log' and sees the message 'no matching phase2 proposal found'. What is the MOST likely cause?

A.Pre-shared key mismatch
B.IKE version mismatch (IKEv1 vs IKEv2)
C.Phase 1 encryption algorithm mismatch
D.Phase 2 proxy ID mismatch
AnswerD

Phase 2 proxy IDs define the exact local and remote networks that the IPsec tunnel will protect. A mismatch in these traffic selectors—for example, one side sends 10.0.0.0/24 while the other expects 192.168.0.0/24—causes the Quick Mode negotiation to fail even after a successful Phase 1. FortiGate logs often show 'no matching Phase 2 proposal' or 'receive proxy ID not acceptable.' This is the classic cause of a Phase 2 failure.

Why this answer

The message 'no matching phase2 proposal found' indicates that the IPsec security associations (SAs) proposed by the remote peer do not match the local Phase 2 configuration. Phase 2 uses proxy IDs (local/remote subnets and ports) to define which traffic should be encrypted. A mismatch in these proxy IDs, such as incorrect subnet definitions or protocol/port values, prevents the IKE negotiation from completing Phase 2, even though Phase 1 (which authenticates and establishes the IKE SA) is already up.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 failures, assuming a Phase 2 error like 'no matching phase2 proposal' is caused by authentication or encryption mismatches, when it is specifically a proxy ID or traffic selector mismatch.

How to eliminate wrong answers

Option A is wrong because a pre-shared key mismatch would prevent Phase 1 from establishing, not Phase 2; Phase 1 authentication occurs before Phase 2 begins. Option B is wrong because an IKE version mismatch (IKEv1 vs IKEv2) would cause a failure during Phase 1 negotiation, not Phase 2, as the IKE version is negotiated first. Option C is wrong because a Phase 1 encryption algorithm mismatch would prevent Phase 1 from completing; Phase 2 proposals are independent of Phase 1 algorithms and are negotiated after Phase 1 is established.

10
MCQeasy

An administrator needs to block access to specific websites based on their FQDN (e.g., *.example.com). The FortiGate should match the destination domain regardless of the IP address the domain resolves to. Which type of address object should the admin use in the firewall policy destination?

A.Geography object
B.Subnet object
C.Wildcard FQDN object
D.FQDN object
AnswerC

Wildcard FQDN supports patterns with * to match multiple domains.

Why this answer

A Wildcard FQDN object allows the FortiGate to match traffic based on the destination domain name pattern (e.g., *.example.com) regardless of the IP address the domain resolves to. This object type performs DNS-based policy enforcement, where the FortiGate inspects the SNI field in the TLS handshake or the Host header in HTTP to match the FQDN pattern, not the destination IP.

Exam trap

The trap here is that candidates often confuse a standard FQDN object with a Wildcard FQDN object, assuming the FQDN object supports wildcard patterns or dynamic IP resolution, when in fact it only resolves to a static IP at policy installation time and cannot match patterns like *.example.com.

How to eliminate wrong answers

Option A is wrong because a Geography object matches traffic based on the source or destination IP address's geographic location (country), not the FQDN. Option B is wrong because a Subnet object matches traffic based on a specific IP address or range (e.g., 10.0.0.0/24), which cannot account for dynamic IP resolution of a domain. Option D is wrong because a standard FQDN object resolves the domain to a single IP address at policy installation time and does not support wildcard patterns like *.example.com; it also cannot match traffic if the domain resolves to multiple IPs or changes over time.

11
MCQhard

An administrator configures a DLP profile to detect credit card numbers in email traffic. The DLP rule uses a regular expression. However, the DLP sensor is not triggering on emails containing credit card numbers. What is a likely reason?

A.SSL deep inspection is not enabled on the policy
B.The regular expression is case-sensitive and credit card numbers are lowercase
C.The DLP sensor is configured to 'monitor' only
D.The DLP profile is applied to the inbound policy only
AnswerA

The FortiGate cannot inspect email content that is encrypted with TLS unless SSL deep inspection is enabled on the security policy. Without it, the device only sees the encrypted SMTP session, so DLP pattern matching never reads the credit card numbers in the payload. This is why the DLP profile appears to detect nothing despite being correctly configured.

Why this answer

DLP sensors inspecting email traffic require SSL deep inspection to decrypt the SMTP traffic if it is encrypted via TLS (STARTTLS). Without SSL deep inspection enabled on the firewall policy, the FortiGate cannot see the plaintext content of encrypted emails, so the DLP regular expression will never match credit card numbers. This is the most likely reason the DLP sensor is not triggering.

Exam trap

The trap here is that candidates assume DLP works on all traffic regardless of encryption, but Fortinet tests the understanding that SSL deep inspection is a prerequisite for DLP to inspect encrypted email content.

How to eliminate wrong answers

Option B is wrong because regular expressions in FortiGate DLP are case-insensitive by default, and credit card numbers are numeric, not alphabetic, so case sensitivity is irrelevant. Option C is wrong because a DLP sensor configured to 'monitor' only still triggers logging and can generate alerts; it does not prevent detection or matching. Option D is wrong because DLP profiles can be applied to both inbound and outbound policies, and even if applied only to inbound, emails containing credit card numbers would still be detected if they are inbound; the issue is encryption, not direction.

12
MCQeasy

An administrator wants to monitor real-time traffic flows on a FortiGate, specifically to see packet details for traffic matching certain criteria. Which command should the administrator use to capture live packets on an interface?

A.diagnose sniffer packet
B.diagnose debug enable and diagnose debug flow trace
C.diagnose sys session list
D.execute system grep from CLI
AnswerA

diagnose sniffer packet is the correct command for real-time packet-level monitoring. It instructs the FortiGate's kernel to capture raw packets on a specified interface (or 'any') and displays their headers and payload directly in the terminal, optionally filtered by protocol, host, or port. This is equivalent to tcpdump on Linux and is the go-to tool when you need to see the actual bytes crossing the wire, not just session summaries.

Why this answer

The 'diagnose sniffer packet' command is FortiGate's built-in packet capture tool, allowing administrators to capture live packets on a specified interface with optional filters for host, port, and protocol. It provides real-time packet-level visibility similar to tcpdump, which is exactly what is needed to inspect packet details for traffic matching specific criteria.

Exam trap

NSE4 often tests the distinction between 'diagnose sniffer packet' (raw packet capture) and 'diagnose debug flow' (session/flow tracing) — candidates confuse the two because both are used for traffic troubleshooting.

How to eliminate wrong answers

Option B is wrong because 'diagnose debug flow' traces session setup and packet processing through the kernel but does not capture raw packet contents or headers. Option C is wrong because 'diagnose sys session list' only displays the session table entries (state, NAT, timeouts) and does not show packet-level details. Option D is wrong because 'execute system grep' is not a valid FortiGate command for packet capture and cannot inspect live traffic.

13
MCQhard

A FortiGate is configured in an HA active-passive cluster. When the active unit fails, the passive unit takes over, but IPsec VPN tunnels fail to re-establish. The configuration is synchronized. What is the most likely cause?

A.The pre-shared key is different on the two units.
B.The firewall policies for VPN traffic are not synchronized.
C.The HA heartbeat interface is down.
D.The IPsec VPN is using the physical interface IP instead of a virtual IP (VIP) or floating IP.
AnswerD

In an active-passive HA pair, the physical interface IP address is owned by the active unit only, and when failover occurs the new active unit uses its own physical IP, which differs from the previous one. IPsec tunnels identify peers by IP address during IKE phase 1 and phase 2, so any change in the local endpoint breaks the existing SAs and prevents new ones from being established. Configuring a virtual IP or floating IP for the IPsec endpoint ensures the address stays constant across failover, allowing the tunnel to survive the transition.

Why this answer

In an HA active-passive cluster, IPsec VPN tunnels typically bind to the physical interface IP address. When failover occurs, the passive unit assumes the cluster's virtual MAC and IP addresses, but the IPsec tunnel endpoints remain tied to the original physical IP. Since the new active unit has a different physical interface IP, the remote peer sees a mismatched source address and drops the connection.

Using a virtual IP (VIP) or floating IP ensures the tunnel endpoint stays consistent across failover.

Exam trap

The trap here is that candidates assume configuration synchronization covers all aspects of VPN operation, overlooking that IPsec tunnels bind to physical interface IPs by default unless explicitly configured with a virtual IP or floating address.

How to eliminate wrong answers

Option A is wrong because the pre-shared key is synchronized as part of the configuration, so both units share the same key; a mismatch would prevent initial synchronization, not cause failover-specific failure. Option B is wrong because firewall policies for VPN traffic are also synchronized in the HA configuration, so they are identical on both units. Option C is wrong because the HA heartbeat interface being down would prevent failover from occurring at all, not cause VPN tunnels to fail after a successful takeover.

14
MCQmedium

You run the following command on a FortiGate: diagnose vpn ike gateway list. The output shows a gateway with state=DOWN. What is the most likely cause?

A.The remote peer is not reachable or is blocking IKE traffic
B.The pre-shared key is correct but expired
C.The IPsec Phase 2 parameters are mismatched
D.The local certificate is not trusted by the remote peer
AnswerA

The `diagnose vpn ike` output showing an IKE SA state of DOWN typically indicates that no IKE negotiation response has been received. This commonly means the remote peer is unreachable at the network layer (no route, filter, or the peer is down) or that IKE traffic on UDP ports 500/4500 is being blocked by an intermediate firewall. Before investigating authentication or configuration mismatches, you must verify basic IP connectivity and bidirectional UDP reachability to the peer's public IP address.

Why this answer

The `state=DOWN` in the `diagnose vpn ike gateway list` output indicates that the IKE Phase 1 (main mode or aggressive mode) negotiation has failed or never completed. The most common cause is that the remote peer is unreachable (e.g., due to network issues, firewall rules blocking UDP ports 500/4500, or incorrect peer IP configuration) or that the remote peer is actively blocking IKE traffic, preventing the initial exchange of IKE SA proposals.

Exam trap

Candidates often confuse Phase 1 (IKE) failures with Phase 2 (IPsec) issues, but state=DOWN indicates a Phase 1 problem. However, certificate trust errors are also Phase 1 failures; they are not excluded by state=DOWN, but the most likely cause among the options is remote peer unreachable/blocking IKE traffic.

How to eliminate wrong answers

Option B is wrong because pre-shared keys do not have an expiration attribute in IKEv1 or IKEv2; they are static credentials and cannot 'expire' — certificate expiration is a separate concept. Option C is wrong because Phase 2 (IPsec SA) parameters are negotiated only after Phase 1 (IKE) is successfully established; a Phase 1 state of DOWN means Phase 2 has not yet been attempted. Option D is wrong because certificate trust issues would only manifest during IKE authentication if certificate-based authentication is configured, but the state=DOWN indicates the IKE SA itself was never formed, which occurs before certificate validation; certificate errors typically result in a state like AUTH_FAILED or DOWN with specific error messages, not a generic DOWN state.

15
MCQmedium

A FortiGate administrator notices that after upgrading the firmware, the HA cluster fails to form. Both units show the correct HA configuration. What is the most likely cause?

A.The HA heartbeat interfaces are not connected
B.The HA mode is set to active-active on one unit and active-passive on the other
C.The firmware versions are different on the two units
D.The HA priority values are identical
AnswerC

The most common cause of an HA cluster refusing to form after a firmware upgrade is that FortiGate HA does not support mixed FortiOS versions across cluster members. When one unit runs a newer build than the other, the cluster cannot synchronize because the internal protocol/data structures differ, and the HA status will report a firmware version mismatch. Since the problem appeared right after the upgrade, verifying that both units are on the same upgraded firmware build is the correct first step.

Why this answer

FortiGate HA requires that all cluster members run the same firmware version. After an upgrade, if one unit is upgraded and the other is not, the HA cluster will not form because the HA protocol version and heartbeat packet format may differ. The units will show correct HA configuration but will not establish a heartbeat due to version mismatch.

This is a common issue during firmware upgrades in an HA cluster.

Exam trap

NSE4 often tests the misconception that HA configuration parameters like priority or mode are the primary cause of cluster formation failure, when in fact firmware version mismatch is a critical and common cause after upgrades.

How to eliminate wrong answers

Option A is wrong because if the HA heartbeat interfaces were not connected, the cluster would not form, but the question states both units show correct HA configuration, implying physical connectivity is likely fine; moreover, this is a basic check that would be noticed immediately. Option B is wrong because FortiGate HA requires both units to have the same HA mode (active-active or active-passive); if they differ, the cluster will not form, but the question says both units show the correct HA configuration, which would include matching HA mode. Option D is wrong because identical HA priority values do not prevent cluster formation; priority only determines which unit becomes the primary (master), and if priorities are equal, the unit with the higher serial number or longer uptime may become primary, but the cluster still forms.

16
MCQmedium

You run 'get system performance status' and see CPU usage at 95% with high context switch rate. The FortiGate is not passing any traffic. What is the most likely cause?

A.A routing loop is causing continuous packet processing
B.The FortiGate is under a DDoS attack
C.The antivirus engine is updating signatures
D.The FortiGate is in transparent mode
AnswerA

A routing loop occurs when packets are repeatedly forwarded between interfaces or virtual domains without reaching a final destination, causing the kernel's forwarding engine to process the same packet iteratively. This can happen with static routes pointing to each other or with dynamic routing protocol inconsistencies, and on FortiGate it often shows high CPU in the kernel's netlink or IP forwarding process. Since the loop re-injects packets into the forwarding pipeline even in the absence of external traffic (e.g., from self-originated packets or multicast), it can sustain 95% CPU utilization.

Why this answer

A routing loop causes the FortiGate to continuously process and re-process packets as they are forwarded in a cycle between routers, leading to high CPU usage and context switch rates. The loop prevents traffic from being successfully delivered, resulting in zero traffic passing through the FortiGate. This matches the observed symptoms of 95% CPU usage and high context switching.

Exam trap

The trap here is that candidates often associate high CPU usage with a DDoS attack, but the key clue is the high context switch rate combined with zero traffic passing, which points to a routing loop rather than a flood of traffic.

How to eliminate wrong answers

Option B is wrong because a DDoS attack would typically cause high CPU usage and packet drops, but the FortiGate would still pass some legitimate traffic or at least process packets; the complete inability to pass traffic is more characteristic of a routing loop. Option C is wrong because antivirus signature updates are a background process that may cause a temporary CPU spike but not sustained 95% usage with high context switching, and they do not prevent all traffic from passing. Option D is wrong because transparent mode does not inherently cause high CPU usage or context switching; it is a Layer 2 forwarding mode that should not impact performance in this way.

17
MCQhard

A company has a FortiGate at headquarters running FortiOS 7.2 and a remote office with a FortiGate 60F running FortiOS 7.0. They have an IPsec VPN tunnel between them for site-to-site connectivity. Recently, the remote office upgraded their FortiGate from 6.4 to 7.0. After the upgrade, the VPN tunnel is down. The Phase 1 status shows 'negotiating' but never completes. The administrator has verified that the pre-shared key, IKE version (IKEv2), and authentication method are the same on both sides. The Phase 1 proposal on the headquarters is: encryption: AES256, SHA256, DH group 14, lifetime 86400. The remote office uses: encryption: AES256, SHA1, DH group 14, lifetime 86400. What is the most likely cause of the failure?

A.The DH group is different; headquarters uses group 14, remote uses group 5.
B.The Phase 1 hash algorithm differs; headquarters uses SHA256, remote uses SHA1.
C.The IKE version is mismatched; headquarters uses IKEv2 and remote uses IKEv1.
D.The pre-shared key is incorrect after the upgrade.
AnswerB

The Phase 1 hash algorithm (also known as the integrity algorithm) is indeed the mismatch: the headquarters FortiGate expects SHA-256 while the remote peer is configured with SHA-1. During IKE Phase 1 negotiation, both peers exchange proposal payloads containing the hash algorithm, and if the hashes do not match, the IKE SA cannot be established. SHA-1 is outdated and not often the default in FortiOS 7, but if the remote peer still uses it, the SA negotiation fails immediately. This is the correct answer because the hash algorithm must be identical on both VPN endpoints.

Why this answer

The Phase 1 proposal mismatch on the hash algorithm (SHA256 vs. SHA1) prevents the IKEv2 peers from agreeing on a common transform set. Even though all other parameters match, the hash algorithm must be identical on both sides for the IKE SA to be established.

The 'negotiating' state that never completes is a classic symptom of a proposal mismatch.

Exam trap

The trap here is that candidates assume all Phase 1 parameters are correct because the pre-shared key, IKE version, and authentication method match, overlooking the critical requirement that the hash algorithm must also be identical for the IKE SA to be established.

How to eliminate wrong answers

Option A is wrong because the DH group is explicitly stated as group 14 on both sides, so there is no mismatch. Option C is wrong because the administrator verified that IKEv2 is used on both sides, and the question states the IKE version is the same. Option D is wrong because the administrator has verified that the pre-shared key is the same after the upgrade, and an incorrect PSK would typically result in a different Phase 1 status (e.g., 'down' with authentication failures) rather than indefinite 'negotiating'.

18
MCQeasy

Which command is used to back up the FortiGate configuration to a TFTP server?

A.save config tftp <filename> <server_ip>
B.backup tftp config <filename> <server_ip>
C.execute backup config tftp <filename> <server_ip>
D.copy config tftp <filename> <server_ip>
AnswerC

This is the exact and only valid FortiGate CLI command for backing up configuration to a TFTP server. The 'execute' verb initiates an administrative task, 'backup config' specifies the operation, and 'tftp <filename> <server_ip>' supplies the transfer protocol and destination. After entering the command, the FortiGate prompts for confirmation and then uploads the complete configuration file to the specified TFTP server.

Why this answer

The correct command to back up the FortiGate configuration to a TFTP server is 'execute backup config tftp <filename> <server_ip>'. This is because FortiGate uses the 'execute' command for operational tasks, and 'backup config tftp' specifically instructs the system to export the running configuration to a TFTP server. The other options use incorrect syntax or commands that are not recognized by the FortiGate CLI.

Exam trap

The trap here is that candidates familiar with Cisco IOS may mistakenly choose 'copy config tftp' (Option D), which is valid for Cisco but not for FortiGate, where the correct syntax requires 'execute backup config tftp'.

How to eliminate wrong answers

Option A is wrong because 'save config tftp' is not a valid FortiGate command; the correct syntax uses 'execute backup' rather than 'save'. Option B is wrong because 'backup tftp config' reverses the order of keywords and omits 'execute', which is required for operational commands in FortiGate. Option D is wrong because 'copy config tftp' is a Cisco IOS command, not a FortiGate command; FortiGate uses 'execute backup config tftp' for this purpose.

19
Multi-Selectmedium

A FortiGate administrator is configuring IPS to protect against a known exploit targeting a web server. The administrator wants to ensure that the IPS engine can decode the HTTP protocol. Which TWO actions are necessary?

Select 2 answers
A.Enable the HTTP protocol decoder in the IPS sensor
B.Configure an IP pool for the web server
C.Enable SSL deep inspection on the firewall policy
D.Set the IPS action to 'block'
E.Disable the FTP protocol decoder
AnswersA, C

The IPS engine uses protocol decoders to parse and normalize traffic into a structured format for signature matching. Without the HTTP decoder, the engine processes raw TCP segments and cannot interpret HTTP headers, URLs, or payloads, so HTTP-specific signatures won't trigger correctly. Enabling this decoder is mandatory for any meaningful HTTP inspection.

Why this answer

The HTTP protocol decoder must be enabled in the IPS sensor because the IPS engine uses protocol decoders to normalize traffic and apply signatures correctly. Without the HTTP decoder, the IPS engine cannot parse HTTP headers, methods, or URIs, making it blind to web-based exploits. This is a prerequisite for any HTTP-specific IPS inspection.

Exam trap

The trap here is that candidates often confuse the IPS action (block, monitor) with the enabling of protocol decoders, or assume SSL deep inspection alone is sufficient for HTTP inspection, when in fact both the HTTP decoder and SSL deep inspection are required for encrypted web traffic.

20
MCQhard

A FortiGate configured with IPS anomaly detection is generating false positives for the 'tcp_syn_flood' anomaly. The administrator wants to reduce the false positives without completely disabling the detection. Which action should the administrator take?

A.Disable the anomaly and use a custom IPS signature
B.Decrease the threshold value
C.Set the action to 'pass'
D.Increase the threshold value
AnswerD

Increasing the threshold value adjusts the anomaly's sensitivity so that a significantly larger rate of SYN packets per second is necessary to trigger the tcp_syn_flood anomaly. Legitimate connection bursts will now remain below the alarm level, avoiding false positives, while a genuine flood will still generate enough traffic to exceed the threshold and be blocked. This is the correct tune because it maintains an active defense while suppressing noise from normal traffic patterns.

Why this answer

Increasing the threshold value reduces false positives by requiring a higher rate of TCP SYN packets per second before the 'tcp_syn_flood' anomaly triggers an alert or action. This allows legitimate traffic bursts to pass without being flagged, while still detecting genuine SYN flood attacks. The threshold defines the sensitivity of the anomaly detection; raising it makes the detection less sensitive to low-volume spikes.

Exam trap

The trap here is that candidates often assume decreasing a threshold makes detection less sensitive (to reduce false positives), but in FortiGate anomaly detection, decreasing the threshold actually increases sensitivity, leading to more false positives.

How to eliminate wrong answers

Option A is wrong because disabling the anomaly and using a custom IPS signature would bypass the built-in anomaly detection entirely, which is not necessary and adds complexity; the goal is to reduce false positives, not replace detection. Option B is wrong because decreasing the threshold value makes the detection more sensitive, which would increase false positives, not reduce them. Option C is wrong because setting the action to 'pass' would disable all blocking or alerting for the anomaly, effectively ignoring the detection and not reducing false positives in a controlled manner.

21
MCQeasy

Which inspection mode allows FortiGate to perform virus scanning by reassembling the entire file in memory before scanning, providing better detection but potentially higher latency?

A.Fast-path inspection
B.Deep inspection
C.Proxy-based inspection
D.Flow-based inspection
AnswerC

Proxy-based inspection is the correct mode because it fully reassembles and buffers the entire file in memory before submitting it to the antivirus engine. This complete content capture enables sophisticated pattern matching and detection of threats that rely on whole-file context, at the expense of increased latency. For maximum virus detection assurance, FortiGate administrators use proxy-based inspection for antivirus profiles.

Why this answer

Proxy-based inspection is the FortiGate mode where the full file is buffered and reassembled in memory before the security profile (AV, IPS, etc.) inspects it. This allows complete-file scanning, so detection of threats that span multiple packets or require the whole file is far better, at the cost of added latency and memory usage. Flow-based inspection, by contrast, scans packets as they stream through, which is faster but can miss threats that only appear once the file is fully assembled.

Exam trap

NSE4 often tests the confusion between flow-based and proxy-based inspection, where candidates incorrectly assume flow-based mode reassembles the entire file — it does not; only proxy-based inspection buffers the full file in memory.

How to eliminate wrong answers

Option A is wrong because 'fast-path inspection' is not a FortiGate inspection mode — it refers to the accelerated path for traffic that bypasses UTM scanning, not a full-file scanning mode. Option B is wrong because 'deep inspection' is not a FortiGate proxy/flow mode; it describes the use of full SSL/TLS inspection (decrypting traffic) rather than the buffering behavior of proxy mode. Option D is wrong because flow-based inspection scans packets in-stream without reassembling the entire file in memory, so it offers lower latency but weaker detection than proxy-based inspection.

22
Multi-Selecthard

A FortiGate is configured with policy-based NAT and multiple IP pools. The administrator wants traffic from the 192.168.1.0/24 subnet to use IP pool 'POOL1' (203.0.113.1-203.0.113.10) and traffic from 192.168.2.0/24 to use IP pool 'POOL2' (203.0.113.11-203.0.113.20). Which THREE steps are necessary?

Select 3 answers
A.Create two firewall policies, one for each subnet
B.In each policy, enable NAT and select the corresponding IP pool
C.Configure a single firewall policy with both subnets in the source address group
D.Create two IP pool objects, POOL1 and POOL2
E.Enable Central NAT and define two NAT policies
AnswersA, B, D

Two firewall policies are required because policy-based NAT binds the source translation directly to the policy entry. Since each subnet must egress with a different public IP pool, a separate policy for each subnet allows the FortiGate to select the correct pool based on the source address. This creates a clean one-to-one mapping of source subnet to NAT pool, with no reliance on routing or additional match conditions.

Why this answer

Policy-based NAT requires separate firewall policies to apply different IP pools to different source subnets. Each firewall policy can have its own NAT settings, including a specific IP pool, allowing traffic from 192.168.1.0/24 to use POOL1 and traffic from 192.168.2.0/24 to use POOL2.

Exam trap

The trap here is that candidates may think a single policy with multiple source addresses can apply different NAT pools, but FortiGate policy-based NAT requires separate policies for distinct NAT configurations.

23
MCQhard

You run the following CLI command on a FortiGate: diagnose sys session filter dport 443 diagnose sys session list The output shows many sessions with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the traffic?

A.The sessions are fully established and idle
B.The sessions are for UDP traffic
C.The sessions are being inspected by SSL deep inspection
D.The sessions are in the SYN_SENT state and have not completed the three-way handshake
AnswerD

The proto_state=01 in the session table is interpreted as SYN_SENT, meaning the TCP handshake has not completed. The FortiGate has sent (or received) a SYN and is waiting for the corresponding SYN-ACK to move to ESTABLISHED (proto_state=02). Because the session remains in proto_state=01, it correctly indicates that the sessions are in the SYN_SENT state and have not completed the three-way handshake.

Why this answer

The proto=6 indicates TCP, and proto_state=01 indicates a TCP session in the SYN_SENT state (i.e., the three-way handshake is not complete). The long duration suggests these are half-open sessions, possibly indicating a SYN flood attack.

24
MCQmedium

A company uses Active Directory for user authentication. They want users to automatically authenticate to the FortiGate without entering credentials when accessing the internet. Which authentication method should the administrator configure?

A.LDAP authentication with captive portal
B.RADIUS authentication with PAP
C.Local user authentication
D.FSSO with Active Directory polling
AnswerD

FSSO with Active Directory polling is correct because it provides transparent, non-interactive authentication. A collector agent polls the Active Directory domain controllers for Windows security event logs, capturing successful user logon events and mapping them to the user's IP address. This information is sent to the FortiGate, which dynamically associates the user's traffic with their AD identity without requiring any manual credential entry. As a result, the firewall can apply user-based policies based on AD logon activity, seamlessly authenticating users as they access the network.

Why this answer

FSSO (Fortinet Single Sign-On) with Active Directory polling allows users to be automatically authenticated to the FortiGate based on their existing Windows domain login. The FortiGate polls the domain controllers for user logon events, mapping the user's IP address to their authenticated identity without requiring any additional credential entry. This meets the requirement of transparent internet access authentication.

Exam trap

The trap here is that candidates often confuse LDAP authentication (which requires credential entry) with FSSO (which provides transparent authentication), leading them to select LDAP with captive portal thinking it integrates with Active Directory for automatic login.

How to eliminate wrong answers

Option A is wrong because LDAP authentication with captive portal requires users to manually enter their credentials on a web portal, which contradicts the requirement for automatic authentication. Option B is wrong because RADIUS with PAP still requires the user to provide credentials (typically via a captive portal or VPN client) and does not provide seamless single sign-on from the Windows login. Option C is wrong because local user authentication requires users to be defined locally on the FortiGate and always demands credential entry, offering no integration with Active Directory for automatic authentication.

25
MCQhard

A FortiGate administrator is configuring FSSO with Active Directory polling. Users in the 'Sales' group are not being authenticated correctly, while users in the 'IT' group are working fine. The administrator verifies that the FSSO agent is connected and polling the domain controllers. Which action should the administrator take to troubleshoot the issue?

A.Verify that the 'Sales' group exists in Active Directory and has the correct permissions.
B.Check the FSSO group filter and ensure that the 'Sales' group is included in the FSSO configuration.
C.Increase the 'polling interval' in the FSSO configuration to reduce latency.
D.Restart the FSSO agent service on the domain controller.
AnswerB

If the 'Sales' group is not included in the FSSO group filter, the FortiGate will not recognize users from that group as authenticated. The administrator should verify that the FSSO configuration on the FortiGate includes the 'Sales' group, either by selecting it in the FSSO connector or by using a group filter that matches it. This is a common oversight when some groups work and others do not.

Why this answer

In FSSO with AD polling, the FortiGate only monitors and authenticates users from groups that are included in the FSSO configuration. If the 'Sales' group is not selected or does not match a group filter, users in that group will not be recognized as authenticated. The administrator should check the FSSO connector settings to ensure the 'Sales' group is included.

Other actions like restarting the agent or changing polling interval are unlikely to help because the 'IT' group works, indicating the agent is operational.

Exam trap

The trap here is assuming that FSSO automatically authenticates all groups, but it only does so for groups explicitly included in the FSSO configuration or matching a filter.

26
Multi-Selecthard

An administrator wants to block all traffic from the 'P2P' application category but allow traffic from 'File Sharing' applications like Dropbox. Which THREE configurations are required to achieve this?

Select 3 answers
A.Create an application control profile that sets 'P2P' category to 'block' and 'File Sharing' category to 'allow'
B.Set the firewall policy inspection mode to proxy-based
C.Enable SSL/TLS deep inspection on the firewall policy
D.Ensure that the application control signatures are up to date
E.Apply a web filter profile to override the application control
AnswersA, C, D

Creating an application control profile with 'P2P' set to 'block' and 'File Sharing' set to 'allow' is the fundamental step because FortiOS application control categorizes traffic into distinct signatures. This configuration explicitly permits file-sharing protocols like FTP or SMB while denying peer-to-peer applications such as BitTorrent or eMule. Without this profile, no other setting can differentiate between these two categories.

Why this answer

An application control profile directly manages application categories, allowing you to set 'P2P' to 'block' and 'File Sharing' to 'allow'. This profile is then applied to a firewall policy to enforce the desired traffic filtering. Without this profile, the firewall cannot differentiate between these application categories.

Exam trap

The trap here is that candidates often assume proxy-based inspection is mandatory for application control, but FortiOS supports application control in both flow-based and proxy-based modes, making Option B a distractor.

27
Multi-Selecthard

An administrator is troubleshooting a FortiGate that is not sending logs to FortiCloud. The FortiGate has internet connectivity and a valid FortiCloud subscription. Which THREE steps should the administrator take to resolve this issue? (Select three.)

Select 3 answers
A.Ensure that the log types (traffic, event, security) are enabled for FortiCloud
B.Verify the FortiCloud status in the dashboard
C.Check if the FortiGate can resolve FortiCloud's FQDN
D.Increase the log buffer size
E.Disable the antivirus profile temporarily
AnswersA, B, C

FortiCloud log forwarding is configured under Log Settings, where the administrator must explicitly select which log types (traffic, event, security) are sent to FortiCloud. If only the default or local log types are enabled, or if these categories are left unchecked, the FortiGate will not upload the corresponding logs even though local logging works. This is a common misconfiguration because enabling local logging does not automatically enable cloud forwarding for every log type; each category must be individually selected in the FortiCloud log settings.

Why this answer

Option A is correct because FortiCloud log forwarding only transmits the log categories that are explicitly enabled under Log & Report > Log Settings > FortiCloud, so traffic, event, and security logs must each be turned on for them to be uploaded. Option B is correct because the dashboard FortiCloud widget shows the registration/entitlement status and whether the FortiGate is successfully connected to FortiCloud, which is the fastest way to confirm the subscription is actually active on the device. Option C is correct because the FortiGate must resolve the FortiCloud FQDN (for example, the service endpoint such as fortigate.forticloud.com or the region-specific logging endpoint) via DNS; if name resolution fails, logs cannot be sent even with working internet and a valid subscription.

Option D is incorrect because increasing the log buffer size only affects local disk/memory log retention and does not fix FortiCloud delivery. Option E is incorrect because disabling an antivirus profile has no bearing on log transmission and would only weaken security.

Exam trap

NSE4 often tests the assumption that internet connectivity alone guarantees FortiCloud logging, ignoring the need for correct log category enablement, registration status, and DNS resolution.

28
MCQhard

An organization has a FortiGate with two internet connections (WAN1 and WAN2). They want traffic to a specific web service (203.0.113.50 port 443) to always exit via WAN2. All other internet traffic should use WAN1. Which feature should be used to achieve this?

A.Central NAT policy to force the traffic out of WAN2
B.Static route with a higher priority for WAN2 to 203.0.113.0/24
C.SD-WAN with a strategy of 'Best Quality'
D.Policy-based routing (PBR) configured with a policy matching the destination and service
AnswerD

PBR overrides the routing table lookup for matching traffic, letting you steer sessions to 203.0.113.50:443 out WAN2 while the default route sends everything else via WAN1. A plain static route cannot selectively match destination plus service, so PBR satisfies the per-service egress constraint.

Why this answer

Policy-based routing (PBR) allows you to override the routing table based on match criteria such as source/destination IP, port, or protocol. In this scenario, you create a PBR policy that matches destination 203.0.113.50 and service TCP/443, then sets the next-hop to the WAN2 gateway. This ensures that only traffic to that specific web service exits via WAN2, while all other traffic follows the default route via WAN1.

Exam trap

The trap here is that candidates confuse policy-based routing with static routing or SD-WAN strategies, assuming that a more specific static route or a quality-based SD-WAN rule can achieve the same per-service interface selection, but only PBR provides the necessary layer-4 granularity to match both destination IP and port.

How to eliminate wrong answers

Option A is wrong because Central NAT policy controls source NAT translation (e.g., which IP address traffic is masqueraded to), not the egress interface selection; it cannot force traffic out of a specific WAN link. Option B is wrong because a static route with a higher priority (lower administrative distance) for 203.0.113.0/24 would direct all traffic to that subnet (including other ports or services) via WAN2, not just port 443, and it does not provide per-service granularity. Option C is wrong because SD-WAN with 'Best Quality' strategy selects the best path based on link quality metrics (latency, jitter, packet loss) rather than forcing traffic to a specific interface; it would not guarantee that the traffic always exits via WAN2.

29
MCQeasy

Which authentication server type can be used with FortiGate to authenticate remote VPN users with two-factor authentication using FortiTokens?

A.POP3
B.LDAP
C.RADIUS
D.TACACS+
AnswerC

RADIUS (Remote Authentication Dial-In User Service) is the standard centralized authentication protocol for network access, and FortiGate supports it for VPN and firewall authentication. It can be integrated with a RADIUS server, such as FortiAuthenticator, to validate both the user password and FortiToken two-factor codes. This makes RADIUS the correct and widely used authentication server type for FortiGate with two-factor authentication.

Why this answer

RADIUS is the correct authentication server type because it supports two-factor authentication with FortiTokens, including the ability to forward token challenges (e.g., one-time passwords) between FortiGate and the RADIUS server. FortiGate acts as a RADIUS client, sending authentication requests to a RADIUS server that validates both the user's primary credentials and the FortiToken OTP, enabling secure remote VPN access.

Exam trap

The trap here is that candidates often confuse LDAP with RADIUS, assuming LDAP can handle two-factor authentication because it is commonly used for user directory lookups, but LDAP lacks the protocol mechanisms (like Access-Challenge) to support token-based OTP validation required for FortiTokens.

How to eliminate wrong answers

Option A is wrong because POP3 is an email retrieval protocol (Post Office Protocol version 3) and cannot perform authentication server functions, let alone two-factor authentication with FortiTokens. Option B is wrong because LDAP is a directory access protocol that supports only single-factor authentication (username/password) and cannot process FortiToken OTP challenges or two-factor authentication natively. Option D is wrong because TACACS+ is a Cisco-proprietary AAA protocol that separates authentication, authorization, and accounting but does not support FortiToken two-factor authentication; FortiGate does not use TACACS+ for FortiToken-based VPN authentication.

30
MCQeasy

A FortiGate administrator wants to restrict access to a sensitive server (10.0.0.100) such that only users who authenticate via LDAP can access it. Which firewall policy configuration is required?

A.Policy: source any, destination 10.0.0.100, service any, action accept
B.Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP
C.Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP, set groups "LDAP-Users"
D.Policy: source any, destination 10.0.0.100, service any, action accept, enable FSSO authentication
AnswerC

This is the correct configuration because it enables authentication, selects LDAP as the authentication type, and explicitly restricts access to members of the LDAP-Users group. In FortiOS, an identity-based policy with a specified group enforces both authentication (credentials verified against LDAP) and authorization (group membership checked). After a user authenticates successfully and is a member of LDAP-Users, the accept action permits traffic to 10.0.0.100.

Why this answer

It combines the required firewall policy elements: enabling authentication, setting the authentication type to LDAP, and restricting access to members of the LDAP group 'LDAP-Users'. This ensures that only users who successfully authenticate via LDAP and belong to the specified group can reach the sensitive server at 10.0.0.100. Without the group restriction, any authenticated LDAP user could access the server, which does not meet the requirement of restricting access to only authenticated users.

Exam trap

The trap here is that candidates often think enabling authentication alone is sufficient, but they overlook the critical need to specify a group to restrict access to only the intended subset of authenticated users.

How to eliminate wrong answers

Option A is wrong because it allows all traffic without any authentication, completely bypassing the requirement to restrict access to authenticated users. Option B is wrong because while it enables authentication and sets the auth-type to LDAP, it does not specify a group; this would allow any user who can authenticate via LDAP to access the server, which is too permissive and does not enforce the intended restriction. Option D is wrong because FSSO (Fortinet Single Sign-On) authentication is used for transparent authentication based on Windows domain logins and is not the same as requiring explicit LDAP authentication; it does not meet the requirement for users to authenticate via LDAP.

31
MCQmedium

A FortiGate administrator needs to ensure that traffic logs are sent to a FortiAnalyzer even when the FortiGate's local disk is full. What configuration is required?

A.Enable 'disk logging' with rollover policy
B.Increase the log severity to 'emergency' only
C.Enable 'remote log' under Log Settings and specify the FortiAnalyzer IP
D.Configure a log filter to send only security logs
AnswerC

Enabling remote logging under Log Settings and specifying the FortiAnalyzer IP address configures the FortiGate to stream logs directly to FortiAnalyzer over the network using its dedicated logging protocols. This is the correct method because it establishes FortiAnalyzer as a log destination, ensuring that traffic logs are continuously transferred to the central analyzer regardless of local disk capacity or local retention policies.

Why this answer

To ensure logs are sent to FortiAnalyzer even when the local disk is full, the administrator must enable remote logging under Log Settings and specify the FortiAnalyzer IP. This configures the FortiGate to send logs to the remote server independently of local disk status.

Exam trap

NSE4 often tests the confusion between local and remote logging, where candidates might think that enabling disk logging or adjusting severity will automatically send logs to FortiAnalyzer, but remote logging must be explicitly configured.

How to eliminate wrong answers

Option A is wrong because disk logging with rollover policy only manages local storage and does not guarantee remote logging when disk is full. Option B is wrong because increasing log severity to emergency only reduces the number of logs but does not ensure remote logging. Option D is wrong because a log filter only selects which logs to send, but without enabling remote logging, no logs are sent to FortiAnalyzer.

32
MCQmedium

A school district uses a FortiGate to filter web traffic for students. The administrator wants to enforce that Google searches are filtered for explicit content. Which configuration should be applied?

A.Enable 'Google Safe Search' in the web filter profile under 'FortiGuard Categories' -> 'Safe Search'.
B.Use an application control profile to block the 'Google Search' application.
C.Create a URL filter to block URLs containing 'porn' or 'adult'.
D.Block the URL category 'Search Engines' and allow only approved search engines.
AnswerA

Enabling Google Safe Search in the web filter profile forces Google to return filtered results, blocking explicit content at the search engine itself. This satisfies the requirement to enforce filtered Google searches for students without inspecting every result page.

Why this answer

FortiGate's web filter profile includes a 'Safe Search' feature that enforces safe search on popular search engines like Google, Bing, and YouTube. Enabling 'Google Safe Search' under FortiGuard Categories -> Safe Search forces Google to return filtered results by modifying the search request to include the safe search parameter (e.g., 'safe=active'). This is the correct and granular way to enforce safe search without blocking search engines entirely.

Exam trap

NSE4 often tests the misconception that application control or URL filtering can enforce safe search, when in fact only the explicit Safe Search setting in the web filter profile performs this function.

How to eliminate wrong answers

Option B is wrong because application control blocks or allows applications based on signatures; blocking 'Google Search' would prevent all Google searches, not just filter explicit content. Option C is wrong because URL filtering based on keywords like 'porn' or 'adult' is easily bypassed and does not enforce safe search on search engine result pages. Option D is wrong because blocking the entire 'Search Engines' category and allowing only approved ones is overly restrictive and does not filter explicit content within allowed search engines.

33
MCQhard

A medium-sized enterprise has a FortiGate 100F in NAT/Route mode with three interfaces: port1 (WAN, 203.0.113.1/24, gateway 203.0.113.254), port2 (internal, 192.168.1.1/24), and port3 (DMZ, 10.0.0.1/24). The internal network hosts a web server at 192.168.1.10 and a mail server at 192.168.1.20. The DMZ hosts a public web server at 10.0.0.10 and a public DNS server at 10.0.0.20. The company has a single public IP 203.0.113.1. The administrator has configured the following: - Port forwarding: external HTTP to DMZ web server (10.0.0.10:80) and external DNS to DMZ DNS server (10.0.0.20:53). - Outbound NAT (IP Pool) for internal users to 203.0.113.1. - Firewall policies allowing internal to external, DMZ to external, and external to DMZ (for forwarded services). Users report that they can access the Internet but cannot reach the internal web server (192.168.1.10) via its public IP (203.0.113.1:80). The DMZ web server is accessible from the Internet. What is the most likely cause?

A.The firewall policy from internal to DMZ is blocking traffic
B.Hairpin NAT is not enabled on the FortiGate
C.The port forwarding rule maps the public IP to the DMZ server, not the internal server
D.The IP Pool for outbound NAT is misconfigured
AnswerC

The port forwarding rule, implemented as a Virtual IP (VIP), maps the public IP and port to 10.0.0.10, which is the DMZ server. When internal users attempt to access the internal server via the public IP, the FortiGate uses this VIP and translates the destination to the DMZ server's IP address. Consequently, the traffic never reaches the intended internal server, and the internal users cannot establish a connection to it. To resolve this, the VIP's mapped IP must be changed to the internal server's address, or a separate VIP must be created for the internal server.

Why this answer

The port forwarding rule is configured to forward external HTTP requests (port 80) to the DMZ web server at 10.0.0.10. The internal web server at 192.168.1.10 is not covered by any port forwarding rule. Therefore, when internal users try to access the public IP 203.0.113.1:80, the traffic is not redirected to the internal server, and the request fails.

This is the primary cause, not a missing hairpin NAT or misconfigured outbound NAT.

Exam trap

The trap here is that candidates often assume hairpin NAT is the universal fix for internal access to public IPs, but they overlook that the port forwarding rule must first exist for the target internal server; without that rule, hairpin NAT has no effect.

How to eliminate wrong answers

Option A is wrong because the problem is about accessing the internal web server via its public IP, not about traffic between internal and DMZ zones; the firewall policy from internal to DMZ is irrelevant here. Option B is wrong because hairpin NAT (also called NAT reflection) is only needed when a device on the internal network tries to reach another internal device via the public IP, but in this scenario, the port forwarding rule does not even point to the internal server, so enabling hairpin NAT would not fix the issue. Option D is wrong because the IP Pool for outbound NAT is correctly configured to translate internal users' source IPs to 203.0.113.1 for Internet access, and users can already access the Internet, indicating outbound NAT is functioning properly.

34
MCQmedium

You have a hub-and-spoke IPsec VPN with 10 spokes. The central FortiGate (hub) has 10 phase2 selectors, one for each spoke. You need to add a new spoke. What is the MOST efficient way to configure the hub?

A.Configure a route-based VPN and use dynamic routing protocols to advertise routes
B.Add another phase2 selector for the new spoke
C.Replace all phase2 selectors with a single policy-based VPN
D.Use a single phase2 selector with 0.0.0.0/0.0.0.0 for all spokes
AnswerA

Route-based VPNs abstract the tunnel as a virtual interface, so you can run a dynamic routing protocol like BGP or OSPF across it to advertise learned routes automatically. When a new spoke is added, the hub only needs to form a routing adjacency with that spoke, and the spoke's subnets are injected into the hub's routing table without touching phase2 selectors or traffic policies. This is the only option that truly scales to 10+ spokes because routing information propagates dynamically, eliminating per-spoke manual configuration.

Why this answer

A route-based VPN with dynamic routing (e.g., BGP or OSPF) is the most efficient approach because it eliminates the need to manually add a new phase2 selector for each new spoke. The hub can automatically learn the spoke's routes via the dynamic routing protocol, and the single phase2 selector (0.0.0.0/0) covers all traffic, simplifying configuration and scaling. This design also supports redundancy and load balancing across multiple spokes without reconfiguring the hub.

Exam trap

The trap here is that candidates often think adding a new phase2 selector (Option B) is the simplest solution, but they overlook the scalability and maintenance burden, while the 0.0.0.0/0 selector (Option D) is mistakenly assumed to work in policy-based VPNs without understanding that it requires a route-based design to function correctly.

How to eliminate wrong answers

Option B is wrong because adding another phase2 selector for each new spoke is manual, does not scale well, and requires updating the hub configuration every time a spoke is added, which is inefficient for 10+ spokes. Option C is wrong because replacing all phase2 selectors with a single policy-based VPN would still require manual policy configuration for each spoke and does not leverage dynamic routing, making it less efficient and more error-prone. Option D is wrong because using a single phase2 selector with 0.0.0.0/0.0.0.0 for all spokes in a policy-based VPN would cause traffic to be sent to the wrong spoke (since the selector does not differentiate between spokes), breaking connectivity; this only works with route-based VPNs where the routing table determines the correct tunnel.

35
MCQeasy

An administrator needs to allow management access to a FortiGate from the internal network only via HTTPS and SSH. The internal interface is named internal. Which configuration should the administrator apply?

A.Create a firewall policy allowing HTTPS and SSH from the internal network to the FortiGate's internal IP address.
B.Enable HTTPS and SSH under System > Settings and set the management port to the internal interface.
C.Under Network > Interfaces, edit the internal interface and enable HTTPS and SSH in the Administrative Access section.
D.Configure an admin user with a trusthost of the internal subnet and set the admin profile to allow HTTPS and SSH.
AnswerC

Enabling HTTPS and SSH under Administrative Access on the internal interface allows management access from that network. This is the correct place to control which protocols are permitted for management on a per-interface basis. Other protocols remain disabled, meeting the requirement.

Why this answer

Management access protocols are enabled per interface under Network > Interfaces by selecting the desired protocols in the Administrative Access section. This directly controls which protocols are allowed on that interface. Firewall policies, trusthost, and global settings do not enable management protocols on an interface.

Exam trap

The trap here is confusing firewall policies with interface administrative access settings, thinking that a policy is needed to allow management traffic to the FortiGate.

36
MCQeasy

An administrator wants to block access to websites that host malware. Which FortiGate feature should be configured to achieve this goal?

A.IPS profile
B.DNS Filter profile
C.Application Control profile
D.Web Filtering profile with FortiGuard categories
AnswerD

A Web Filtering profile with FortiGuard categories is purpose-built for this task: it leverages FortiGuard's extensive web rating database to classify URLs into categories such as 'Malicious Web Sites' and applies a configurable action (block, warn, or allow) for each category. This profile evaluates the full URL at proxy level, enabling precise blocking of pages that host malware or phishing content.

Why this answer

FortiGate's Web Filtering profile with FortiGuard categories is the correct feature because it allows administrators to block access to websites based on URL categories, including those known to host malware. FortiGuard maintains a continuously updated database of malicious URLs, and applying a web filtering profile that blocks the 'Malicious Websites' category directly prevents users from accessing such sites. This is the most straightforward and effective method for blocking malware-hosting websites at the proxy or flow-based inspection level.

Exam trap

The trap here is that candidates often confuse DNS Filtering (which blocks domains at the DNS level) with Web Filtering (which blocks URLs at the HTTP/HTTPS level), but DNS Filtering cannot block specific URL paths or subdirectories, making it insufficient for blocking malware-hosting websites that may share a domain with legitimate content.

How to eliminate wrong answers

Option A is wrong because an IPS profile is designed to detect and prevent network-based attacks by inspecting traffic for exploit signatures, not to block access to specific websites or URL categories. Option B is wrong because a DNS Filter profile controls access based on domain name resolution, blocking or redirecting DNS queries to known malicious domains, but it does not inspect the full URL path or HTTP content, and it is not the primary feature for blocking malware-hosting websites. Option C is wrong because an Application Control profile identifies and controls applications (e.g., social media, file sharing) based on signatures, not URLs or web categories, so it cannot block specific websites hosting malware.

37
MCQhard

An admin notices that a firewall policy allowing inbound HTTPS to a server is not matching traffic. The policy has source set to 'all', destination to the server's IP, and service to HTTPS. The admin checks the policy list and sees that policy ID 1 matches the traffic. What is the MOST likely reason the intended policy (ID 10) is not matching?

A.Policy ID 1 has a higher priority and matches before policy ID 10
B.The firewall policy is disabled
C.The service object for HTTPS is misconfigured in policy ID 10
D.The destination address is incorrect in policy ID 10
AnswerA

FortiGate security policies are evaluated sequentially from the top of the policy table, and the first policy that matches all criteria (source, destination, service, schedule, etc.) is applied, terminating the lookup. Policy ID 1 has a lower numeric ID, which places it above policy ID 10 in the default ordering, so it is evaluated first. Because policy ID 1 already matches the inbound traffic, policy ID 10 is never reached, even if its configuration is perfectly valid. This is a classic policy shadowing issue where a broader or earlier policy overrides a more specific later one.

Why this answer

Policy ID 1 has a higher priority because FortiGate evaluates firewall policies in sequential order from top to bottom. When policy ID 1 matches the traffic (e.g., it also allows HTTPS to the same destination), the traffic is processed by policy ID 1 and never reaches policy ID 10. This is the most likely reason the intended policy is not matching.

Exam trap

The trap here is that candidates may think policy ID numbers determine priority, but FortiGate uses the sequential order in the policy list, not the ID number, and the default policy ID 1 is often an 'allow all' or 'deny all' rule that matches before any lower-ID policies.

How to eliminate wrong answers

Option B is wrong because if the firewall policy were disabled, it would simply not match traffic, but the admin would see no match for policy ID 10, not a match on policy ID 1. Option C is wrong because a misconfigured service object for HTTPS in policy ID 10 would cause the policy to not match HTTPS traffic, but it would not explain why policy ID 1 matches the traffic. Option D is wrong because an incorrect destination address in policy ID 10 would prevent matching, but again, it does not account for policy ID 1 matching the traffic.

38
MCQmedium

An administrator wants to prevent data leakage by blocking outbound emails that contain credit card numbers. Which security profile should be configured?

A.Email Filter profile
B.Web Filter profile
C.Antivirus profile
D.DLP profile
AnswerD

A DLP profile inspects email content for sensitive data patterns, such as credit card numbers, and blocks matching messages. This directly satisfies the stem's requirement to prevent data leakage via outbound email, since DLP is the only FortiGate profile that performs content-based pattern matching on data rather than application or protocol control.

Why this answer

DLP (Data Loss Prevention) profiles are specifically designed to inspect content such as credit card numbers in outbound emails and block them to prevent data leakage. While other profiles handle spam, web access, or malware, only DLP can perform pattern-based content inspection on email bodies and attachments.

Exam trap

The trap here is that candidates often confuse DLP with Email Filter or Antivirus profiles, not realizing that DLP is the only profile that performs content-aware inspection for sensitive data patterns in outbound emails.

How to eliminate wrong answers

Option A is wrong because an Email Filter profile is used for anti-spam, email authentication (SPF/DKIM/DMARC), and IP reputation filtering, not for scanning email content for sensitive data patterns like credit card numbers. Option B is wrong because a Web Filter profile controls web access based on URL categories and ratings, not email content inspection. Option C is wrong because an Antivirus profile scans for malware signatures in files and email attachments, but does not perform content-based pattern matching for sensitive data like credit card numbers.

39
MCQeasy

An admin needs to allow outbound HTTP and HTTPS traffic from the internal network to the internet. Which two built-in service objects can be used in a single firewall policy to achieve this?

A.WEB and SSL
B.ANY and HTTPS
C.ALL_TCP and ALL_UDP
D.HTTP and HTTPS
AnswerD

The predefined service objects 'HTTP' (TCP/80) and 'HTTPS' (TCP/443) directly match the two standard ports used for outbound web browsing. Using these built-in objects allows the firewall to enforce the policy narrowly and consistently, without the need to create custom definitions. This is the best practice because it enables the exact traffic required while blocking everything else.

Why this answer

HTTP (TCP/80) and HTTPS (TCP/443) are the two built-in service objects that specifically match outbound web traffic. A single firewall policy can include both service objects to allow HTTP and HTTPS traffic from internal users to the internet, which is the most precise and secure way to permit web browsing without opening unnecessary ports.

Exam trap

The trap here is that candidates may confuse the generic term 'WEB' with the actual built-in service object name 'HTTP', or assume that 'ANY' is acceptable for simplicity, overlooking the security risk of opening all protocols.

How to eliminate wrong answers

Option A is wrong because 'WEB' is not a standard FortiGate built-in service object; the correct objects are HTTP and HTTPS. Option B is wrong because 'ANY' would allow all protocols and ports, which is overly permissive and violates the principle of least privilege, while HTTPS alone would only permit encrypted web traffic, not HTTP. Option C is wrong because ALL_TCP and ALL_UDP would allow all TCP and UDP traffic, including non-web services like SSH, FTP, or DNS, which is too broad and insecure for a web-only policy.

40
MCQhard

A FortiGate is configured with an SSL deep inspection profile that uses 'Certificate Inspection' (not 'Full SSL Inspection'). Which of the following is TRUE about this configuration?

A.Deep inspection can still see client certificates
B.The antivirus profile can scan the HTTPS payload
C.The FortiGate can block HTTPS connections based on the certificate's CN
D.IPS can still inspect the application layer of HTTPS traffic
AnswerC

During the TLS handshake, the server's certificate is sent in plaintext, and certificate inspection extracts the Common Name (CN) and Subject Alternative Name (SAN) to make web filtering decisions. The FortiGate can therefore block or allow an HTTPS request before any application data is exchanged, using the certificate's CN as the classification criterion even with no decryption.

Why this answer

Certificate Inspection only examines the SSL/TLS certificate presented during the handshake, without decrypting the traffic. Because the FortiGate can read the certificate's Common Name (CN) or Subject Alternative Name (SAN), it can block HTTPS connections based on that information, such as by using a URL filter or application control rule that matches the certificate's CN. This is the only deep inspection action possible without full decryption.

Exam trap

The trap here is that candidates often assume 'deep inspection' implies full decryption, but Fortinet distinguishes between Certificate Inspection (no decryption) and Full SSL Inspection (decryption), and the question specifically tests this distinction by asking what is possible without decryption.

How to eliminate wrong answers

Option A is wrong because Certificate Inspection does not decrypt the SSL session, so it cannot see client certificates, which are sent encrypted after the handshake. Option B is wrong because the antivirus profile requires decrypted payload to scan for malware, and Certificate Inspection does not provide decrypted content. Option D is wrong because IPS inspection of the application layer requires full decryption of the HTTPS traffic, which Certificate Inspection does not perform.

41
MCQhard

A company with multiple remote sites uses IPsec VPNs. One site reports intermittent connectivity. The administrator checks the logs and sees 'IPsec phase 2 negotiation failed' messages. Which configuration change is most likely to resolve the issue?

A.Enable Dead Peer Detection (DPD) on the Phase 1 interface.
B.Change the encryption algorithm from AES256 to 3DES.
C.Increase the Phase 2 lifetime.
D.Enable NAT traversal.
AnswerA

DPD (Dead Peer Detection) sends periodic IKE keepalives to the remote gateway to confirm liveness. If no response is received, DPD marks the peer dead, tears down the stale IPsec SA, and triggers a fresh Phase 1/Phase 2 negotiation. This recovers quickly from transient routing or peer failures, which is exactly what your intermittent VPN drops suggest. Without DPD, the SA persists until its natural lifetime expires, causing a long blackout and requiring manual restart.

Why this answer

Intermittent IPsec phase 2 negotiation failures often occur when one peer's Phase 2 security association (SA) expires while the other peer still considers it valid, causing a mismatch. Enabling Dead Peer Detection (DPD) on the Phase 1 interface allows the FortiGate to actively probe the peer's liveness and renegotiate Phase 1 and Phase 2 SAs before they expire, preventing the state mismatch that leads to intermittent failures.

Exam trap

The trap here is that candidates often mistake intermittent phase 2 failures for a cryptographic or NAT issue, but the real cause is typically a mismatch in SA state between peers, which DPD is specifically designed to detect and recover from.

How to eliminate wrong answers

Option B is wrong because changing the encryption algorithm from AES256 to 3DES would weaken security and does not address the root cause of intermittent phase 2 negotiation failures; the issue is not about algorithm strength or compatibility. Option C is wrong because increasing the Phase 2 lifetime would only delay the SA expiration, not prevent the mismatch that occurs when one peer's SA expires before the other's; it may even mask the problem temporarily. Option D is wrong because NAT traversal is used to allow IPsec traffic to pass through NAT devices, and the problem described is intermittent connectivity due to SA state mismatch, not NAT-related packet drops.

42
MCQmedium

A FortiGate administrator configures an email filter profile to block spam. Users report that some legitimate emails are being blocked. The administrator wants to reduce false positives while still blocking spam. What should the administrator do?

A.Disable the email filter profile
B.Increase the spam threshold score
C.Decrease the spam threshold score
D.Enable the FortiGuard spam filter only
AnswerB

The spam threshold score defines the rating at which a message is classified as spam. Raising it means messages must score higher before being blocked, so borderline legitimate emails pass through while clear spam is still caught, reducing false positives.

Why this answer

Increasing the spam threshold score raises the bar for what is classified as spam, so only emails with a higher spam score (indicating stronger spam characteristics) are blocked. This reduces false positives because legitimate emails with lower scores will no longer be blocked, while still blocking high-scoring spam.

Exam trap

The trap here is that candidates often confuse increasing vs. decreasing the threshold, mistakenly thinking a lower threshold is more permissive, when in fact a lower threshold blocks more emails and increases false positives.

How to eliminate wrong answers

Option A is wrong because disabling the email filter profile would stop all spam filtering, which does not address the requirement to reduce false positives while still blocking spam. Option C is wrong because decreasing the spam threshold score would make the filter more aggressive, blocking more emails and likely increasing false positives. Option D is wrong because enabling only the FortiGuard spam filter does not adjust the sensitivity of the filter; it simply changes the source of spam detection, which may not reduce false positives and could still block legitimate emails.

43
MCQmedium

An administrator has configured a firewall policy that allows outbound traffic from a subnet to the internet, with NAT enabled. The external IP is 203.0.113.1. However, the administrator wants all traffic from a specific internal server (10.0.0.10) to appear with source IP 203.0.113.2. What should the administrator do?

A.Create a VIP with the external IP and apply it to the policy
B.Create an IP Pool with 203.0.113.2 and reference it in the policy
C.Configure route-based NAT
D.Set the NAT to 'Use Outgoing Interface Address'
AnswerB

An IP Pool allows selecting a different source NAT IP.

Why this answer

An IP Pool in FortiGate allows you to override the source IP address for specific traffic, even when NAT is enabled on the policy. By creating an IP Pool with the single address 203.0.113.2 and referencing it in the firewall policy, traffic from 10.0.0.10 will be NATed to that specific IP instead of the outgoing interface address (203.0.113.1). This is the standard method for fixed source NAT (also called 'static NAT' or 'one-to-one NAT') for a specific host.

Exam trap

The trap here is confusing Virtual IP (VIP) with IP Pool: VIP is for destination NAT (inbound), while IP Pool is for source NAT (outbound), and many candidates mistakenly apply a VIP to change the source IP of outbound traffic.

How to eliminate wrong answers

Option A is wrong because a Virtual IP (VIP) is used for destination NAT (port forwarding), not for changing the source IP of outbound traffic; applying a VIP to a policy would translate the destination address of incoming traffic, not the source of outgoing traffic. Option C is wrong because route-based NAT is a concept for VPNs or policy-based routing, not a direct method to specify a fixed source IP for NAT; FortiGate uses IP Pools for that purpose. Option D is wrong because setting NAT to 'Use Outgoing Interface Address' would NAT all traffic to the IP of the outgoing interface (203.0.113.1), which is exactly what the administrator wants to avoid for the specific server.

44
MCQhard

A FortiGate is configured with flow-based inspection and an IPS profile. The administrator runs 'diagnose ips session list' and sees many sessions with 'state=bypass'. What does this indicate?

A.The IPS profile is configured with 'pass' action for all signatures
B.The IPS signatures have expired and are not being applied
C.The FortiGate is under DoS attack and is dropping sessions
D.The sessions are being offloaded to the NPU and are not inspected by IPS
AnswerD

In flow-based inspection mode, the FortiGate offloads many sessions to the NPU for high-throughput processing. When a session is offloaded, packets traverse the NPU and are not sent to the CPU, so the IPS engine never inspects them; the session is then marked as 'bypass'. This is expected behavior for traffic that is not explicitly selected for deep inspection, and it explains why the IPS engine reports no inspection. Admins can confirm this by checking the session table via 'diagnose sys session list'.

Why this answer

When a FortiGate uses flow-based inspection, sessions that are offloaded to the Network Processor Unit (NPU) are not inspected by the IPS engine. The 'state=bypass' in the 'diagnose ips session list' output indicates that these sessions are being hardware-accelerated and bypassing the IPS inspection, which is normal behavior for traffic that meets offload criteria.

Exam trap

The trap here is that candidates often misinterpret 'bypass' as a failure or misconfiguration, when in fact it is a normal operational state for hardware-accelerated sessions in flow-based mode.

How to eliminate wrong answers

Option A is wrong because a 'pass' action in an IPS profile means the signature will allow the traffic but still log it; it does not cause sessions to show 'state=bypass' in the IPS session list. Option B is wrong because expired IPS signatures would cause the IPS engine to stop applying signatures entirely, not result in a bypass state for individual sessions. Option C is wrong because a DoS attack would cause session drops or blocks, not a bypass state; the 'bypass' state specifically indicates the session is not being inspected, not that it is being dropped.

45
MCQmedium

A FortiGate administrator is configuring a Virtual IP (VIP) to allow external users to access an internal web server (192.168.1.10) using the public IP 203.0.113.10 on port 80. The admin creates a VIP with mapped IP 192.168.1.10 and port 80. A firewall policy is created from WAN to DMZ with destination set to the VIP. External users report that they can access the web server. What additional step is needed to allow the internal server to respond correctly?

A.No additional step is needed; the FortiGate automatically performs reverse NAT for established sessions
B.Create a second VIP for the return traffic
C.Add a policy from DMZ to WAN allowing the internal server to reply
D.Configure static routing on the internal server to route through the FortiGate
AnswerA

No additional configuration is required because FortiGate's session table maintains bidirectional state for every translated flow. When a server responds to a VIP-mapped connection, the FortiGate identifies the session via the 5-tuple, performs the reverse DNAT, and rewrites the source IP back to the original VIP address. This automatic reverse NAT is inherent to stateful inspection, so any manual return-path setup is unnecessary.

Why this answer

When a FortiGate performs destination NAT (DNAT) via a VIP for inbound traffic, it automatically creates a session entry that includes the reverse NAT mapping. For return traffic from the internal server, the FortiGate uses this session to perform source NAT (SNAT) back to the original public IP (203.0.113.10). This is called 'implicit reverse NAT' and requires no additional configuration; the session state ensures the reply packets are correctly translated and forwarded to the external client.

Exam trap

The trap here is that candidates often think a separate outbound policy or NAT rule is required for return traffic, but FortiGate's stateful firewall and implicit reverse NAT handle this automatically, making additional policies or VIPs unnecessary.

How to eliminate wrong answers

Option B is wrong because a second VIP is not needed; reverse NAT is handled automatically by the session table, not by a separate VIP object. Option C is wrong because no explicit policy from DMZ to WAN is required for return traffic; FortiGate's stateful inspection allows reply packets to traverse based on the existing session created by the inbound policy. Option D is wrong because the internal server does not need static routing through the FortiGate for return traffic; the server's default gateway should point to the FortiGate's DMZ interface, but this is a basic network requirement, not an additional step specific to VIP functionality.

46
Multi-Selectmedium

An administrator wants to use FortiManager to manage multiple FortiGates. Which three steps must be performed to establish communication between a FortiGate and FortiManager? (Choose THREE.)

Select 3 answers
A.Place the FortiGate in transparent mode
B.Ensure network connectivity between the FortiGate and FortiManager
C.Configure the FortiGate's management interface with an IP address
D.Enable FortiManager registration and provide a registration password
E.Set the FortiManager IP address on the FortiGate under System > FortiManager
AnswersB, D, E

Network connectivity between the FortiGate and FortiManager is the fundamental prerequisite for registration. The FortiGate must be able to reach the FortiManager's IP address over TCP port 541, and any intermediate firewalls must permit this traffic, or the registration handshake will time out or be rejected. Without end-to-end IP reachability and correct routing, even the most accurate configuration of other registration parameters will fail, making this the first and most critical requirement.

Why this answer

FortiManager communicates with managed FortiGates over TCP/541 (FGFM protocol). Without IP-level connectivity between the two devices, the registration and management tunnel cannot be established. This is a prerequisite before any configuration steps can succeed.

Exam trap

The trap here is that candidates often confuse general FortiGate interface configuration (Option C) with the specific FortiManager registration steps, or incorrectly assume transparent mode (Option A) is required for management, when in fact the three required steps are ensuring connectivity, enabling registration with a password, and setting the FortiManager IP address on the FortiGate.

47
MCQhard

A FortiGate in NAT/Route mode has a policy with NAT enabled. The admin needs the source IP of traffic from internal users (192.168.1.0/24) to be translated to the interface IP of port1 (203.0.113.1) when accessing the internet. Which configuration is necessary?

A.Add a static route for 192.168.1.0/24 with next-hop 203.0.113.1
B.Set the administrative access to HTTPS on port1
C.Create a central NAT rule with source 192.168.1.0/24 and IP pool 203.0.113.2-203.0.113.10
D.Configure a firewall policy with NAT enabled and the outbound interface set to port1
AnswerD

Enabling NAT on the firewall policy with port1 as the outbound interface triggers source NAT, translating internal 192.168.1.0/24 addresses to port1's interface IP 203.0.113.1. This satisfies the requirement without configuring IP pools or central NAT.

Why this answer

In NAT/Route mode, enabling NAT on a firewall policy with the outbound interface set to port1 causes the FortiGate to translate the source IP of traffic from the internal network (192.168.1.0/24) to the IP address of that interface (203.0.113.1) by default. This is the standard method for source NAT (SNAT) in a policy-based configuration, requiring no additional IP pool or static route for the translation itself.

Exam trap

The trap here is that candidates may confuse the need for an IP pool or static route with the simple policy-based NAT, assuming that translating to the interface IP requires additional configuration beyond enabling NAT on the policy.

How to eliminate wrong answers

Option A is wrong because a static route for 192.168.1.0/24 with next-hop 203.0.113.1 is unnecessary and incorrect; the internal subnet is directly connected, and the next-hop for internet-bound traffic should be the default gateway, not the interface IP. Option B is wrong because setting administrative access to HTTPS on port1 only enables management access to the interface, not source NAT translation. Option C is wrong because creating a central NAT rule with an IP pool of 203.0.113.2-203.0.113.10 would translate the source IP to a range of addresses, not the single interface IP (203.0.113.1), which does not match the requirement.

48
MCQeasy

Which two inspection modes are available for antivirus scanning on a FortiGate?

A.Stateful and stateless
B.Flow-based and proxy-based
C.Inline and passive
D.Kernel-based and user-based
AnswerB

Flow-based and proxy-based are the two security profile inspection modes supported on FortiGate for antivirus and other UTM features. Flow mode performs scanning in a single pass directly on packets transiting the kernel and can be accelerated by FortiASIC content processors (CP), lowering latency and supporting high-throughput links. Proxy mode terminates the TCP session in a dedicated proxy engine, reassembles and buffers the full content before scanning, enabling deeper inspection of files and more granular control at the cost of higher latency and resource consumption.

Why this answer

FortiGate offers two distinct inspection modes for antivirus scanning: flow-based and proxy-based. Flow-based inspection uses a single-pass, low-latency engine that examines traffic as it passes through, while proxy-based inspection buffers and reassembles the entire file before scanning, providing deeper analysis at the cost of higher latency. Both modes are configured within the antivirus security profile to match different performance and security requirements.

Exam trap

The trap here is that candidates confuse firewall inspection modes (stateful/stateless) or IDS/IPS deployment modes (inline/passive) with the two antivirus scanning modes, which are specifically flow-based and proxy-based on FortiGate.

How to eliminate wrong answers

Option A is wrong because 'stateful and stateless' refer to firewall inspection modes (stateful tracking of connections vs. stateless packet filtering), not to antivirus scanning modes. Option C is wrong because 'inline and passive' describe deployment modes for intrusion detection/prevention systems (IDS/IPS), where inline can block traffic and passive only monitors; these are not antivirus scanning modes on FortiGate. Option D is wrong because 'kernel-based and user-based' are not recognized inspection modes for antivirus on FortiGate; the actual modes are flow-based (kernel-level acceleration) and proxy-based (user-space processing), but the official terminology is flow-based and proxy-based.

49
Multi-Selecthard

Which TWO statements about IPS in FortiGate are true?

Select 2 answers
A.IPS can be applied to individual firewall policies via IPS sensors.
B.An IPS sensor can only be applied to one firewall policy.
C.IPS is not supported in transparent mode.
D.IPS only works in flow-based inspection mode.
E.IPS signatures can have their actions overridden in an IPS filter.
AnswersA, E

In FortiGate, IPS is enforced at the firewall policy level by assigning an IPS sensor to the policy's Security Profiles. This design lets each policy pass traffic through the sensor's configured signature rules, enabling selective inspection for different source/destination pairs. Because a sensor is a reusable object, the same sensor can be applied to any number of policies, and changes to the sensor immediately affect all policies referencing it.

Why this answer

IPS sensors are applied directly to individual firewall policies, allowing granular control over which traffic is inspected for intrusions. This enables administrators to enforce different IPS profiles for different traffic flows, such as applying a stricter sensor to internet-bound traffic and a lighter one to internal traffic.

Exam trap

The trap here is that candidates often assume IPS requires routed mode or flow-based inspection only, but FortiGate supports IPS in transparent mode and in both inspection modes, and sensors are reusable across multiple policies.

50
Matchingmedium

Match each Fortinet HA mode to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

One unit handles traffic; standby unit takes over on failure

Both units handle traffic simultaneously for load balancing

Multiple units act as a single logical firewall

Ensures active sessions are preserved after failover

FortiGate Clustering Protocol used for HA synchronization

Why these pairings

Common FortiGate HA modes: Active-Passive (primary/standby) and Active-Active (both active). Distractors swap the definitions.

51
MCQmedium

An admin configures a VIP to map public IP 203.0.113.10 to internal server 10.0.1.100 on port 80. External users can reach the server via the public IP. However, internal users cannot access the server using the public IP. What is the MOST likely cause?

A.The VIP does not have NAT reflection enabled
B.The server is not responding to internal requests
C.The firewall policy for internal to VIP is missing
D.The VIP is configured on a different interface
AnswerA

The VIP lacks NAT reflection (also called NAT hairpin or loopback), which is required for internal users to reach the same VIP that external users can access. With NAT reflection disabled, a packet from an internal client destined to the VIP's public IP hits the FortiGate but is neither source-NATed nor properly routed back, so the session never establishes. This perfectly matches the symptom where external users work, but internal users cannot use the public IP.

Why this answer

The most likely cause is that NAT reflection (also known as hairpin NAT or NAT loopback) is not enabled on the VIP. When an internal user sends a request to the public IP (203.0.113.10), the FortiGate must translate the source IP back to the internal network and loop the traffic back through the VIP to reach the internal server (10.0.1.100). Without NAT reflection, the FortiGate drops the packet because it sees the destination as the VIP's public IP but the source is from the same internal subnet, causing asymmetric routing or no reply.

Exam trap

The trap here is that candidates often assume internal users can always reach a server via its public IP because the VIP is working externally, overlooking the need for NAT reflection to handle traffic sourced from the same subnet as the destination server.

How to eliminate wrong answers

Option B is wrong because the server is reachable from external users, proving it responds to requests; internal users failing to reach it via the public IP is a NAT/routing issue, not a server responsiveness problem. Option C is wrong because internal-to-VIP traffic does not require a separate firewall policy if the VIP is configured with NAT reflection; the existing policy for external-to-VIP traffic typically handles the loopback, and a missing policy would cause a different symptom (e.g., no traffic at all). Option D is wrong because the VIP is configured on the correct interface (the one with the public IP), and if it were on a different interface, external users would also fail to reach the server.

52
MCQhard

An administrator configures HA override on a cluster with priority 200 on primary and 100 on secondary. The primary fails, secondary takes over. When primary recovers, what happens?

A.Both units become active, causing a conflict
B.Secondary remains active until next failover
C.The administrator must manually trigger failback
D.Primary immediately takes over as active
AnswerD

When override is enabled on the cluster, a recovered primary unit with a higher priority will immediately take over as active, preempting the current secondary. The takeover occurs after the cluster re-establishes heartbeat and synchronizes session state, ensuring that traffic convergence is orderly. This preemptive behavior is the defining feature of HA override, and it distinguishes the mode from non-preemptive operation where the current active unit would otherwise remain active.

Why this answer

With HA override enabled, the primary unit with higher priority (200) will preempt the secondary (100) once it recovers and rejoins the cluster. The primary immediately takes over as active because override allows a higher-priority unit to force a failback. This is the intended behavior of override in FortiGate HA.

Exam trap

NSE4 often tests the difference between HA override enabled vs disabled, and candidates may confuse override with manual failback or assume both units become active.

How to eliminate wrong answers

Option A is wrong because HA cluster ensures only one unit is active at a time; both becoming active would cause a split-brain, which is prevented by heartbeat and priority. Option B is wrong because without override, the secondary would remain active; with override, the primary preempts. Option C is wrong because override automates failback; manual intervention is not required.

53
MCQhard

During an SSL VPN tunnel mode connection, the client reports that they cannot access any internal resources, but the VPN connection is established. The FortiGate debug shows 'no matching policy'. The administrator has configured a policy allowing the SSL VPN interface to internal. What else must be configured?

A.Ensure the incoming interface of the policy is set to 'ssl.root' (or the SSL VPN interface)
B.Add the client's assigned IP to a local user group
C.Configure a static route on the FortiGate for the client's tunnel IP
D.Enable split tunneling on the SSL VPN portal
AnswerA

The firewall policy that permits SSL VPN tunnel traffic must use the SSL VPN logical interface (ssl.root) as its incoming interface. When the client establishes a tunnel, the FortiGate terminates the encrypted session on ssl.root and assigns the virtual IP, so packets from the client enter through that interface, not the physical WAN. If the policy's incoming interface is set to WAN or any other interface, the policy lookup fails and the traffic is dropped.

Why this answer

The SSL VPN tunnel mode creates a virtual interface (typically named 'ssl.root' or 'ssl.VDOM') on the FortiGate. Even though the administrator configured a policy allowing the SSL VPN interface to internal, the incoming interface in the policy must explicitly be set to this SSL VPN interface. If it is set to a different interface (e.g., the physical WAN interface), the FortiGate will not match the traffic from the SSL VPN tunnel, resulting in the 'no matching policy' debug message.

Exam trap

The trap here is that candidates often assume that because the VPN connection is established and a policy exists allowing the SSL VPN interface, the traffic should pass, but they overlook that the policy's incoming interface must be explicitly set to the SSL VPN virtual interface (e.g., 'ssl.root') rather than the physical WAN interface.

How to eliminate wrong answers

Option B is wrong because adding the client's assigned IP to a local user group is not required for traffic forwarding; user group membership is used for authentication and policy matching based on user identity, not for IP-based routing or policy interface matching. Option C is wrong because a static route for the client's tunnel IP is unnecessary; the FortiGate automatically installs a route to the client's tunnel IP via the SSL VPN interface when the tunnel is established, and the issue is policy matching, not routing. Option D is wrong because split tunneling controls which traffic goes over the VPN versus the internet, but it does not affect the policy matching on the FortiGate; the 'no matching policy' error indicates the traffic is not hitting any policy, regardless of split tunneling settings.

54
MCQhard

A FortiGate is configured with two policies: Policy A allows traffic from trust to untrust with schedule 'WorkHours' (Mon-Fri 9-17). Policy B allows traffic from trust to untrust with schedule 'Always'. A user sends traffic at 8:00 AM on Saturday. Which policy matches?

A.Policy B because Policy A's schedule is not active
B.Policy A because schedules are evaluated after policy order
C.Both policies match and the first one in order is used
D.No policy matches because Policy A is first but schedule inactive
AnswerA

FortiGate checks schedule objects as part of policy matching. Policy A's WorkHours schedule covers only Monday to Friday 09:00-17:00, so at 08:00 on Saturday it is inactive and cannot match; evaluation continues to Policy B, whose Always schedule is active.

Why this answer

Policy B is correct because at 8:00 AM on Saturday, the 'WorkHours' schedule (Mon-Fri 9-17) is not active. FortiGate evaluates policies sequentially; when the first matching policy's schedule is inactive, the firewall skips it and continues to the next policy. Policy B with schedule 'Always' matches and permits the traffic.

Exam trap

The trap here is that candidates assume the first matching policy in the list always applies, forgetting that an inactive schedule causes the policy to be skipped entirely, allowing a later policy with 'Always' to match.

How to eliminate wrong answers

Option B is wrong because schedules are evaluated during policy matching, not after policy order; an inactive schedule causes the policy to be skipped, not matched. Option C is wrong because only one policy can match per session; FortiGate uses the first policy with all conditions (including active schedule) met. Option D is wrong because Policy A is skipped due to inactive schedule, but Policy B then matches and permits the traffic, so a policy does match.

55
Multi-Selecteasy

Which TWO are valid types of SSL/TLS inspection available on FortiGate?

Select 2 answers
A.Off-box SSL Inspection
B.Proxy SSL Inspection
C.Full SSL Deep Inspection
D.Passive SSL Inspection
E.Certificate Inspection
AnswersC, E

Full SSL Deep Inspection is a valid and correct FortiGate SSL inspection type. It decrypts SSL/TLS traffic in real time, inspects the plaintext content against security policies such as antivirus, web filtering, and intrusion prevention, then re-encrypts it before forwarding. This provides complete visibility into encrypted traffic, making it the most thorough inspection option, but it requires clients to trust the FortiGate's CA certificate to avoid errors.

Why this answer

FortiGate supports two primary SSL/TLS inspection methods: Certificate Inspection, which validates certificates without decrypting traffic, and Full SSL Deep Inspection, which decrypts, inspects, and re-encrypts traffic to apply security profiles. Option C is correct because Full SSL Deep Inspection is the only method that allows the FortiGate to inspect the payload of encrypted sessions for threats like malware or data leakage.

Exam trap

The trap here is that candidates often confuse 'Proxy SSL Inspection' with the proxy-based inspection mode, but FortiGate officially lists only Certificate Inspection and Full SSL Deep Inspection as the valid types, and 'Off-box' or 'Passive' are not recognized terms in the FortiGate SSL inspection architecture.

56
MCQeasy

An admin needs to authenticate remote users connecting via SSL VPN. The users are in an Active Directory domain. Which authentication method should be configured on the FortiGate to allow users to log in with their domain credentials?

A.LDAP server
B.Local user database
C.RADIUS server
D.FSSO
AnswerA

LDAP is the standard protocol for direct authentication against an Active Directory domain. When a remote user submits credentials via the SSL VPN portal, the FortiGate performs an LDAP bind to the domain controller using that username and password, verifying them against the AD directory. This is the most straightforward and native method for AD-based authentication, requiring no intermediate RADIUS infrastructure. LDAP also allows fetching group memberships for granular authorization policies.

Why this answer

LDAP (Lightweight Directory Access Protocol) allows FortiGate to directly query the Active Directory domain controller to authenticate users with their domain credentials. This method validates the username and password against the AD database without requiring an additional RADIUS server or local user accounts, making it the most straightforward choice for SSL VPN authentication with domain users.

Exam trap

The trap here is that candidates often confuse FSSO with direct authentication, assuming it can handle SSL VPN logins, when in fact FSSO only provides passive identity collection and cannot validate passwords for VPN access.

How to eliminate wrong answers

Option B is wrong because the local user database stores credentials only on the FortiGate itself, not in Active Directory, so domain users cannot log in with their domain credentials unless each user is manually duplicated as a local user. Option C is wrong because while a RADIUS server can proxy authentication to AD, it introduces an unnecessary intermediate server and is not the direct method for authenticating against AD; LDAP is the native protocol for directory services. Option D is wrong because FSSO (Fortinet Single Sign-On) is designed for transparent authentication and monitoring of domain users on the network, not for direct SSL VPN authentication; it does not validate passwords and relies on polling or agent-based logon events.

57
MCQeasy

Which authentication method allows FortiGate to authenticate users against an Active Directory domain without storing domain credentials locally?

A.FSSO polling
B.RADIUS authentication
C.LDAP authentication
D.Local user database
AnswerC

LDAP authentication enables the FortiGate to connect directly to an Active Directory server using the LDAP protocol and perform a bind with the user's DN and provided password. This real-time directory bind verifies credentials against AD without storing any user secret on the FortiGate. This direct query and bind is why LDAP is the authentic direct authentication method for AD in FortiGate configurations.

Why this answer

LDAP authentication allows FortiGate to verify user credentials directly against an Active Directory domain controller without storing the domain passwords locally. The FortiGate sends a BIND request with the user's DN and password to the LDAP server, which validates the credentials and returns a success or failure response. This avoids local storage of domain credentials while still enabling centralized authentication.

Exam trap

The trap here is that candidates often confuse FSSO with LDAP authentication, thinking FSSO also authenticates users, when in fact FSSO only collects authentication events from the domain controller and does not perform password verification itself.

How to eliminate wrong answers

Option A is wrong because FSSO polling collects login events from domain controllers to map users to IP addresses, but it does not authenticate users by verifying passwords; it relies on the Windows domain already having authenticated the user. Option B is wrong because RADIUS authentication requires the FortiGate to forward credentials to a RADIUS server, which typically stores or has access to a shared secret and user credentials, but the FortiGate itself does not store domain credentials; however, the question specifies 'without storing domain credentials locally,' and LDAP is the direct method for querying AD without any intermediate credential storage on the FortiGate. Option D is wrong because the local user database stores usernames and password hashes directly on the FortiGate, which violates the requirement of not storing domain credentials locally.

58
MCQhard

A FortiGate is configured with FSSO using a DC agent. Users authenticate to the domain, but the firewall policy using FSSO groups is not matching traffic. The admin runs 'diagnose debug authd fsso list' and sees user entries. However, the traffic is being denied by the default deny policy. What is the most likely issue?

A.The FSSO session timeout is too short
B.The session was established before the user logged in and is not updated with the user identity
C.The firewall policy has the wrong schedule applied
D.The user is not a member of the correct FSSO group in Active Directory
AnswerB

When a client establishes a session (e.g., a TCP connection or UDP flow) before the FSSO DC agent processes the user's login event, the FortiGate's session table entry is initially created with no user identity or with a default guest/anonymous mapping. The FortiGate does not retroactively apply the learned FSSO user to pre-existing sessions; it only assigns the user identity to new sessions created after the login event is synchronized. To resolve this, the existing session must be cleared (via 'execute session clear' or waiting for idle timeout) so that the next packet re-triggers session setup and gets the correct FSSO user attribute.

Why this answer

When a user logs in after a session is already established, the FortiGate does not automatically update that session with the user's identity. The 'diagnose debug authd fsso list' shows the user is authenticated, but the existing session still lacks the FSSO group information, causing it to match the default deny policy instead of the FSSO-based policy.

Exam trap

The trap here is that candidates see the user in the FSSO debug output and assume authentication is fully working, overlooking the fact that session identity is static and not updated for pre-existing sessions.

How to eliminate wrong answers

Option A is wrong because a short FSSO session timeout would cause the user entry to expire and disappear from the FSSO list, but the debug output shows user entries are present, so timeout is not the issue. Option C is wrong because a wrong schedule would cause the policy to be inactive at certain times, but the traffic is being denied by the default deny policy, not by a schedule mismatch. Option D is wrong because the debug output shows user entries, meaning the user is authenticated and the FSSO group membership is correctly retrieved from Active Directory; if the user were not in the correct group, the FSSO list would still show the user but without the expected group, which is not indicated here.

59
MCQmedium

A FortiGate administrator needs to upgrade the firmware from FortiOS 6.4 to 7.0. The administrator downloads the upgrade image but when uploading via the GUI, the FortiGate reboots and comes back with the same firmware version. What is the most likely cause?

A.The firmware image was corrupted during download.
B.The FortiGate does not support firmware upgrade via GUI; CLI must be used.
C.The administrator uploaded the wrong image (e.g., for a different FortiGate model).
D.The administrator must first upgrade to an intermediate version before 7.0.
AnswerC

Uploading a firmware image intended for a different FortiGate model is the most plausible cause. FortiOS image files are model-specific and include a platform identifier in their header. When the FortiGate detects a mismatched platform ID, it rejects the image as invalid and aborts the upgrade, rebooting back into the current firmware without applying any changes. The administrator likely selected the wrong file from the local machine, and the device's built-in compatibility check saved it from becoming unbootable.

Why this answer

Uploading a firmware image intended for a different FortiGate model will cause the upgrade to fail silently. The FortiGate validates the image against its hardware platform; if the image does not match, the device rejects it and reboots with the existing firmware. This is a common issue when administrators accidentally download the image for a different series (e.g., FortiGate 100F vs. 200F).

Exam trap

The trap here is that candidates may assume a reboot with unchanged firmware always indicates corruption or a need for intermediate upgrades, overlooking the critical platform validation that rejects mismatched images.

How to eliminate wrong answers

Option A is wrong because a corrupted image would typically cause a checksum error or fail to upload, not result in a reboot with the same firmware version. Option B is wrong because FortiGate fully supports firmware upgrades via the GUI; CLI is an alternative but not a requirement. Option D is wrong because FortiGate 6.4 to 7.0 is a direct upgrade path supported by Fortinet; no intermediate version is required for this jump.

60
MCQhard

An administrator runs the following CLI command on a FortiGate: 'diagnose sys session filter dport 443' and sees output indicating sessions with proto_state=01 and duration=3600. What does this indicate about the sessions?

A.The sessions are UDP-based and have been active for 3600 seconds.
B.The sessions are TCP connections in SYN state and have a timeout of 3600 seconds.
C.The sessions are TCP connections in established state with a duration of 3600 seconds.
D.The sessions are ICMP packets with a TTL of 3600.
AnswerB

Correct. 'proto_state=01' corresponds to TCP SYN_SENT state, and duration=3600 means the session has been in that state for 3600 seconds.

Why this answer

The command filters sessions on destination port 443. The output field 'proto_state=01' indicates a TCP session in SYN_SENT state (state 1), which is the initial step of a TCP handshake. The 'duration=3600' field shows that the session has been active for 3600 seconds (or represents a time value).

Option B correctly identifies the state as TCP SYN and the number 3600 as a time value, making it the most accurate choice. Option A is wrong because UDP does not have a SYN state. Option C is wrong because state 01 is not established (established is state 06).

Option D is wrong because ICMP does not use ports.

Exam trap

The trap is to associate 'duration' with a timeout or TTL value, and to misinterpret 'proto_state=01' as established (state 6) rather than SYN_SENT (state 1).

How to eliminate wrong answers

Option A is wrong because 'proto_state=01' is specific to TCP, not UDP; UDP sessions use different state codes (e.g., 00 for no state). Option B is wrong because 'proto_state=01' represents the established state, not the SYN state (which would be state 0x02 or similar), and 'duration' is the elapsed time, not a timeout value. Option D is wrong because ICMP packets do not use TCP port numbers like 443, and 'duration' is not related to TTL (Time To Live).

61
MCQmedium

A FortiGate administrator has configured an active-passive HA cluster with two units. During a failover test, they notice that existing TCP sessions are dropped and must be re-established. What configuration change should the administrator make to ensure sessions are preserved during failover?

A.Enable session synchronization between the cluster members
B.Configure a dedicated heartbeat interface
C.Enable HA override
D.Increase the HA priority on the primary unit
AnswerA

Enabling session synchronization (session sync) in the HA cluster causes the active FortiGate to continuously replicate its entire session table — including NAT mappings, TCP sequence numbers, and timers — to the standby unit over the heartbeat link. Because the standby now possesses an up-to-date copy of all state, it can immediately assume forwarding during a failover and existing TCP sessions remain intact without client reconnection. Without this feature, no amount of heartbeat, priority, or override tuning can save sessions; this is the only mechanism that directly addresses session preservation.

Why this answer

Session synchronization (session sync) allows the active unit to share session table entries with the passive unit. During failover, the new active unit has the session table pre-populated, so existing sessions continue without interruption.

62
MCQhard

An admin configures a central SNAT rule to translate source IP 10.0.0.0/24 to IP pool 203.0.113.1-203.0.113.10 using overload (PAT). A policy-based NAT on a specific policy also translates the same source to the interface IP. Traffic from 10.0.0.0/24 to the internet shows source IP as the interface IP, not from the IP pool. What is the reason?

A.The central SNAT rule is disabled
B.The policy is using fixed port range
C.Policy-based NAT overrides central SNAT rules
D.The IP pool is out of addresses
AnswerC

This is correct because FortiOS applies policy-based NAT with higher priority than central NAT objects. When an administrator configures a source NAT directly on the firewall policy (such as selecting an IP pool), that per-policy NAT is evaluated before any central SNAT rule. The central NAT feature only serves as a fallback for policies that do not have their own NAT configuration, so the policy's own NAT action takes precedence and effectively masks the central SNAT rule.

Why this answer

Policy-based NAT (PBNAT) takes precedence over central SNAT rules because it is applied directly to a specific firewall policy. When a policy matches traffic, its NAT configuration (including translation to the interface IP) is evaluated before any central SNAT rules. This override occurs regardless of the central SNAT rule's order or status, as PBNAT is considered more specific and thus higher priority in FortiOS.

Exam trap

The trap here is that candidates often assume central SNAT rules are always evaluated first or that all NAT rules are additive, but FortiOS gives policy-based NAT higher priority, causing the central rule to be silently ignored when a conflicting policy-based translation exists.

How to eliminate wrong answers

Option A is wrong because if the central SNAT rule were disabled, traffic would either not be translated or would use the default behavior (e.g., no SNAT), but the observed behavior shows translation to the interface IP, indicating a different NAT rule is active. Option B is wrong because fixed port range affects port allocation behavior, not the selection of which NAT rule applies; it does not cause a central SNAT rule to be overridden. Option D is wrong because if the IP pool were out of addresses, traffic would typically fail or fall back to no SNAT, not be translated to the interface IP; the pool exhaustion would not trigger a different translation source.

63
MCQmedium

A mid-sized company has a FortiGate 100F running FortiOS 7.2. They have two internal networks: Trusted (10.1.1.0/24) for employees and Guest (10.2.2.0/24) for visitors. The Guest network has a firewall policy that allows internet access only, with an application control profile that blocks all peer-to-peer and gaming applications. Recently, users on the Guest network have been able to play online games (e.g., Fortnite) despite the block. The administrator checks the application control profile and confirms that 'Fortnite' is listed as blocked. There are no other policies allowing Guest traffic. The administrator also notices that the Guest policy has 'set utm-status enable' and the application control profile is applied. What is the most likely reason that Fortnite is not being blocked?

A.The firewall policy is missing 'set deep-inspection enable' for application control to work.
B.SSL inspection is required to block encrypted game traffic, and it is not enabled.
C.The application control profile is not applied to the correct policy.
D.The application control signatures are outdated and do not include the latest Fortnite signatures.
AnswerD

Newer game traffic, such as Fortnite, uses frequently changing update servers and protocols, so a FortiGate with an outdated FortiGuard signature database will fail to match those flows. Application control relies on regularly updated signatures to identify application-specific traffic patterns and unblocked domains. If the signature version predates a major Fortnite update, the traffic is passed as unknown. The solution is to update the FortiGuard application control signatures (either manually or via scheduled updates) and then retest the Guest policy.

Why this answer

If the Application Control signatures are outdated, the FortiGate may not recognize the latest Fortnite traffic patterns or encrypted handshakes, allowing the game to bypass the block. Even though the policy has UTM enabled and the profile is applied, stale signatures cannot match new application variants or updates. Regularly updating the IPS/Application Control database via FortiGuard is essential to maintain effective blocking.

Exam trap

The trap here is that candidates often assume SSL inspection is mandatory for blocking encrypted applications, but the real issue is that outdated signatures fail to recognize the latest application variants, even when the profile is correctly applied and UTM is enabled.

How to eliminate wrong answers

Option A is wrong because 'set deep-inspection enable' is not a valid command for firewall policies; deep inspection is configured via SSL/SSH inspection profiles, not a direct policy flag, and Application Control can work without full SSL inspection if the game uses non-encrypted or partially encrypted traffic. Option B is wrong because while SSL inspection can help identify encrypted game traffic, it is not strictly required for Application Control to block applications; many games use plaintext or proprietary protocols that signatures can match without decryption, and the question states the profile already blocks Fortnite, indicating the issue is signature freshness, not inspection depth. Option C is wrong because the administrator already confirmed the Application Control profile is applied to the Guest policy, and there are no other policies allowing Guest traffic, so the profile is correctly attached.

64
MCQhard

An administrator configures an HA cluster of two FortiGates in active-passive mode. The cluster is synchronized, but after a failover, some existing TCP sessions are dropped. What is the most likely cause?

A.The heartbeat interface is configured as a dedicated management interface
B.Session synchronization (session-pickup) is disabled
C.The cluster is operating in NAT mode
D.The cluster is using a virtual MAC address for the HA interface
AnswerB

Session synchronization, also called session pickup on FortiGate, is the feature that continuously replicates the primary unit's session table to the standby unit. When session-pickup is disabled, the standby device boots or takes over with an empty session table, so every existing TCP and UDP flow must be re-established, causing application interruptions and lost user sessions. This is the only option that directly explains why sessions are dropped during a failover event.

Why this answer

Session synchronization (session-pickup) is required for active-passive HA clusters to replicate TCP session state from the primary FortiGate to the secondary. When disabled, the backup unit has no knowledge of existing sessions after a failover, causing those sessions to be dropped because the new primary cannot match incoming packets to any session table entry.

Exam trap

The trap here is that candidates often confuse virtual MAC addressing or heartbeat configuration with session state replication, but the core requirement for session persistence after failover is session-pickup being enabled.

How to eliminate wrong answers

Option A is wrong because a dedicated management heartbeat interface does not affect session synchronization; it only separates management traffic from HA traffic. Option C is wrong because NAT mode does not inherently cause session drops after failover; session-pickup is still required regardless of the operation mode. Option D is wrong because using a virtual MAC address for the HA interface ensures seamless Layer 2 failover but does not impact session state replication; session-pickup is the mechanism that preserves TCP sessions.

65
MCQmedium

An admin runs 'diagnose sys session filter dport 443' and sees output showing sessions with 'proto=6' and 'expire=3599'. The admin notices that these sessions are not being cleaned up after the firewall policy that allowed them is deleted. What is the reason?

A.The sessions are using UDP protocol, which has a longer timeout
B.The sessions are protected by a different policy that still exists
C.The sessions are in a different VDOM
D.FortiGate does not delete existing sessions when a policy is removed; sessions must be cleared manually
AnswerD

FortiGate evaluates policies only for new sessions; deleting a policy does not tear down sessions already established under it. Those entries persist until expiry or manual clearing via diagnose sys session clear, satisfying the stated scenario.

Why this answer

When a firewall policy is deleted on a FortiGate, the existing sessions that were created by that policy are not automatically removed. The FortiGate continues to process those sessions until they expire naturally based on their timeout values. In this case, the sessions with 'proto=6' (TCP) and 'expire=3599' seconds remaining will persist until the timer counts down, even though the originating policy no longer exists.

The admin must manually clear them using 'diagnose sys session clear' or wait for the timeout to expire.

Exam trap

The trap here is that candidates often assume FortiGate automatically removes sessions when a policy is deleted, similar to how some other firewalls handle stateful inspection, but FortiGate requires manual intervention or timeout expiration to clear sessions.

How to eliminate wrong answers

Option A is wrong because 'proto=6' indicates TCP, not UDP; UDP uses protocol number 17 and has different timeout behavior. Option B is wrong because the output shows sessions with 'expire=3599', meaning they are still active and not yet protected by another policy; if another policy existed, the sessions would still be subject to the same timeout behavior, but the question states the policy that allowed them was deleted. Option C is wrong because the 'diagnose sys session filter dport 443' command without a VDOM filter applies to the current VDOM, and the output does not indicate a different VDOM; sessions in different VDOMs would require explicit VDOM filtering.

66
MCQmedium

A FortiGate administrator wants to block spam emails destined for internal users. The FortiGate receives SMTP traffic on port 25. What is the most effective way to filter spam using the email filter profile?

A.Enable spam filtering in the antivirus profile
B.Apply an email filter profile to a firewall policy that allows SMTP traffic
C.Use a DNS filter to block spam domains
D.Configure a web filter to block webmail
AnswerB

For inbound SMTP, the correct procedure is to create a firewall policy for the SMTP service and attach an email filter profile to that policy; the FortiOS inspection engine then applies FortiGuard Antispam category lookups, IP/DNSBL checks, header and MIME analysis, and banned-word rules to every accepted email. The email filter profile is the sole UTM object that contains antispam capabilities, and it is designed to operate on mail protocols (SMTP, POP3, IMAP) in proxy-based inspection mode. This policy-level attachment is exactly how a FortiGate administrator activates spam blocking in production.

Why this answer

An email filter profile is specifically designed to inspect SMTP traffic and apply anti-spam techniques such as RBL, MIME header checks, and heuristic analysis. By applying the email filter profile to a firewall policy that allows SMTP traffic on port 25, the FortiGate can intercept and filter spam before it reaches internal users.

Exam trap

The trap here is that candidates often confuse the email filter profile with the antivirus profile, assuming antivirus handles all email threats, but antivirus only scans for malware, not spam.

How to eliminate wrong answers

Option A is wrong because the antivirus profile scans for malware signatures in file attachments, not for spam characteristics like bulk email patterns or sender reputation. Option C is wrong because a DNS filter blocks access to domains based on category or reputation, but it does not inspect the content or headers of SMTP messages to identify spam. Option D is wrong because a web filter controls HTTP/HTTPS traffic to block webmail sites, but it does not filter SMTP-based spam arriving on port 25.

67
MCQeasy

A company has a FortiGate with two ISPs: wan1 (primary) and wan2 (backup). They want all outbound traffic from internal users to use wan1, and if wan1 fails, traffic should automatically fail over to wan2. The administrator configures static routes: default route via wan1 gateway with distance 10 and default route via wan2 gateway with distance 20. They also configure an SD-WAN zone with both interfaces and set a strategy of 'Manual' with 'Best Quality' for wan1. After testing, failover does not occur when wan1 goes down. What is the most likely reason?

A.The SD-WAN zone does not include the backup interface wan2.
B.The SD-WAN strategy is set to Manual, which does not automatically failover; the administrator should use an automatic strategy or configure link health monitoring.
C.The static routes have the same distance, so failover does not occur.
D.The firewall policy does not bind to the SD-WAN zone; it binds to wan1 interface directly.
AnswerB

With the SD-WAN strategy set to Manual, FortiGate uses the configured static routes and does not automatically re-evaluate link health to move traffic away from a failed interface. Automatic failover requires either an automatic strategy such as Lowest Cost or Best Quality combined with a performance SLA, or explicit link health monitoring to trigger a route update when wan1 goes down. Since neither is configured, the manual strategy explains why failover does not occur; this is the correct resolution.

Why this answer

When the SD-WAN strategy is set to 'Manual', the FortiGate does not automatically perform failover based on interface or link health. Manual mode requires explicit administrator action or must be combined with link health monitoring to trigger a switch. Without an automatic strategy or configured health checks, the SD-WAN zone will continue to use wan1 even if it goes down, preventing failover to wan2.

Exam trap

The trap here is that candidates assume static route distance alone handles failover, but when SD-WAN is configured with a Manual strategy, the SD-WAN rule overrides the routing table and prevents automatic failover unless link health monitoring is enabled.

How to eliminate wrong answers

Option A is wrong because the SD-WAN zone includes both wan1 and wan2 as stated in the scenario, so the backup interface is present. Option C is wrong because the static routes have different distances (10 and 20), which is the correct configuration for failover; equal distances would cause ECMP, not prevent failover. Option D is wrong because the firewall policy binding to the SD-WAN zone is not the issue; the policy can bind to the zone, but the failover failure is due to the SD-WAN strategy setting, not the policy binding.

68
Matchingmedium

Match each FortiGate firewall policy action to its result.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Allows traffic matching the policy

Blocks traffic and sends a reset or ICMP unreachable

Routes traffic into an IPsec VPN tunnel

Routes traffic into an SSL VPN tunnel

Logs traffic without enforcing action (used for learning)

Why these pairings

The correct matches are ACCEPT for allowing traffic and DENY for silently dropping traffic. Common confusions include mixing ACCEPT with REJECT (which sends a reset) and assuming DENY logs traffic.

69
Multi-Selectmedium

An admin needs to create a firewall policy that allows SMTP traffic (TCP/25) from the internal network (10.0.0.0/24) to a mail server in the DMZ (172.16.1.10). Additionally, the admin wants to ensure that the mail server can only be accessed by the internal network, not from the internet. Which THREE settings must be configured in the firewall policy? (Choose three.)

Select 3 answers
A.Source interface set to 'internal'
B.Set schedule to 'always'
C.Destination interface set to 'dmz'
D.Service set to 'SMTP'
E.Enable NAT to translate source IP
AnswersA, C, D

The source interface is a mandatory field in a FortiGate firewall policy that identifies the ingress interface through which traffic enters the firewall. For internal clients reaching an SMTP server in the DMZ, setting the source interface to 'internal' ensures the policy only matches traffic arriving from the trusted internal segment. Without this specific interface binding, the policy could unintentionally match traffic from other interfaces, creating a security exposure. This interface pair is the first classification criterion that FortiGate uses when building a session.

Why this answer

The source interface must be set to 'internal' to restrict the firewall policy to traffic originating from the internal network (10.0.0.0/24). This ensures that only hosts on the internal interface can reach the mail server, effectively blocking any internet traffic that would arrive on a different interface like 'wan'.

Exam trap

The trap here is that candidates often think NAT is required for traffic between internal and DMZ zones, but FortiGate does not require NAT for inter-zone traffic unless the destination network is private and overlapping, and the question explicitly wants to restrict access from the internet, not translate addresses.

70
MCQmedium

A company wants to use captive portal authentication on a guest Wi-Fi network. The FortiGate is connected to the switchport of the access point. Which firewall configuration is required to redirect unauthenticated users to the captive portal?

A.Set the 'Guest Management' feature in the FortiGate dashboard.
B.Create a policy with source interface 'guest', destination 'any', and action 'ACCEPT' with 'Authentication' set to 'Captive Portal'.
C.Configure a 'Landing Page' under SSL-VPN settings.
D.Enable 'Captive Portal' on the interface under System > Network > Interface.
AnswerB

The correct method is to configure a firewall policy that selects the 'guest' interface as the source, 'any' as the destination, and sets the action to ACCEPT while enabling 'Captive Portal' as the authentication method. When unauthenticated traffic matches this policy, FortiGate intercepts it and redirects the user to the captive portal for credentials. Once authenticated, the same policy permits the traffic, and this is the standard approach to enforce captive portal on a specific interface.

Why this answer

Captive portal authentication on a FortiGate requires a firewall policy that matches the unauthenticated traffic (source interface 'guest', destination 'any') with action 'ACCEPT' and the 'Authentication' setting set to 'Captive Portal'. This policy triggers the FortiGate to intercept HTTP/HTTPS traffic from unauthenticated users and redirect them to the captive portal login page, enforcing authentication before allowing further access.

Exam trap

The trap here is that candidates often think enabling 'Captive Portal' on the interface is sufficient, but they forget that a firewall policy with the correct action and authentication setting is required to actually trigger the redirect for unauthenticated traffic.

How to eliminate wrong answers

Option A is wrong because the 'Guest Management' feature in the FortiGate dashboard is used for managing guest user accounts and vouchers, not for configuring the redirect mechanism of captive portal authentication. Option C is wrong because 'Landing Page' under SSL-VPN settings is specific to SSL VPN portal customization and has no role in captive portal authentication on a physical or VLAN interface. Option D is wrong because enabling 'Captive Portal' on the interface under System > Network > Interface alone does not create the necessary firewall policy to redirect traffic; without a matching policy with authentication enabled, the captive portal will not intercept user traffic.

71
Multi-Selectmedium

An administrator is troubleshooting why traffic from a specific source IP is not being matched by a policy route. Which THREE steps should the administrator take to diagnose the issue?

Select 3 answers
A.Disable all firewall policies to test routing.
B.Change the administrative distance of the default route to 0.
C.Verify the source address object in the policy route matches the traffic's source IP.
D.Check the policy route list order and ensure the matching condition is above the default route.
E.Use the 'diagnose debug flow' command to trace packet flow.
AnswersC, D, E

Policy routes in FortiOS use address objects as match conditions, and the object must contain the exact source IP or subnet for the traffic in question. If the object is misconfigured—wrong subnet, incorrect IP, or a different object type—the policy route will be silently skipped. Verifying this match is the first step to confirm that the traffic can actually hit the intended policy route.

Why this answer

The most fundamental step in troubleshooting a policy route mismatch is to verify that the source address object defined in the policy route exactly matches the source IP of the traffic. If the object is misconfigured (e.g., wrong subnet mask, incorrect IP range, or a typo), the traffic will never hit the policy route, regardless of other settings.

Exam trap

The trap here is that candidates often jump to modifying routing or firewall policies (Options A and B) instead of first verifying the policy route's matching criteria and order, which are the most common root causes of policy route mismatches.

72
Multi-Selecthard

A FortiGate administrator is troubleshooting an issue where a user receives a certificate error when accessing a web server. The administrator has configured SSL deep inspection with a custom CA certificate. The error indicates the certificate is not trusted. Which THREE actions could resolve this issue? (Choose three.)

Select 3 answers
A.Install the FortiGate's CA certificate on the client devices.
B.Disable SSL inspection on the firewall policy entirely.
C.Update the FortiGate firmware to the latest version.
D.Change the SSL inspection profile to 'certificate-inspection' instead of 'deep-inspection'.
E.Add the web server to the SSL exemption list in the SSL inspection profile.
AnswersA, D, E

Deep inspection performs man-in-the-middle interception, presenting a dynamically generated certificate signed by the FortiGate's own CA to the client. If that CA is not in the client's trusted root store, the browser reports a certificate error. Installing the FortiGate's CA certificate on client devices establishes trust for all re-issued certificates, which resolves the error while preserving full inspection of the decrypted payload.

Why this answer

Option A is correct because with SSL deep inspection the FortiGate re-signs the server certificate using its custom CA, so that CA certificate must be imported into the client's trust store (e.g., Windows Certificate Manager or browser trust store) for the re-signed certificate to validate without an untrusted-CA error. Option D is correct because switching the profile to certificate-inspection means the FortiGate only inspects the certificate metadata (SNI, CN, validity) and does not re-sign the server certificate, so the client sees the original, publicly trusted server certificate and no trust error occurs. Option E is correct because adding the web server to the SSL exemption list in the inspection profile bypasses deep inspection for that destination, again letting the client receive the original trusted certificate.

Option B is not the intended fix because disabling SSL inspection entirely removes security inspection rather than resolving the trust problem while preserving inspection. Option C is not relevant because a firmware update does not make the client trust the FortiGate's custom CA certificate or change the re-signing behavior.

Exam trap

NSE4 often tests the misconception that simply enabling deep inspection is enough, forgetting that the client must trust the FortiGate's CA — or that certificate-inspection and exemption are valid alternatives when deep inspection is not feasible.

73
Multi-Selectmedium

A FortiGate admin needs to allow inbound HTTPS traffic to a web server while also applying an application control profile to block certain web applications. The web server has a VIP configured. Which TWO components are necessary for this configuration?

Select 2 answers
A.A central SNAT rule to translate the server's response
B.A VIP configured to map the public IP to the web server's private IP
C.A security profile group containing only the antivirus profile
D.A traffic shaping policy to prioritize HTTPS
E.A firewall policy with destination set to the VIP and application control profile applied
AnswersB, E

The VIP performs destination NAT, translating the public IP to the web server's private IP so inbound HTTPS connections reach the internal host. This satisfies the stem's requirement by providing the address translation the firewall policy references as its destination.

Why this answer

A Virtual IP (VIP) is required to map the public IP address to the web server's private IP, allowing inbound traffic to reach the internal server. Option E is correct because a firewall policy must have the destination set to the VIP and must include an application control profile to enforce blocking of specific web applications on the HTTPS traffic.

Exam trap

The trap here is that candidates often think a central SNAT rule is required for return traffic, but FortiGate automatically handles reverse NAT for VIP traffic, making option A a common distractor.

74
MCQhard

An organization has two FortiGate units in an HA cluster. They need to perform a firmware upgrade on the primary unit without causing a failover. Which procedure should be followed?

A.Upgrade the primary unit first, then the secondary will automatically synchronize
B.Upgrade both units simultaneously using the GUI
C.Disable HA, upgrade both, then re-enable HA
D.Upgrade the secondary unit first, then perform a graceful failover, then upgrade the original primary
AnswerD

Upgrade the secondary (standby) unit first so the active primary continues to pass traffic throughout the upgrade process; the secondary then joins the HA cluster with the new firmware. Once the secondary is fully upgraded and synchronized, perform a graceful failover to make it the new primary, which transfers the active sessions to the upgraded unit. Finally, upgrade the original primary (now standby) during a maintenance window, ensuring only one unit is offline at a time and no traffic is dropped.

Why this answer

In an HA cluster, upgrading the secondary unit first ensures that the primary remains active and can take over if the upgrade fails. After the secondary is upgraded and stable, a graceful failover is performed to make it the new primary, allowing the original primary to be upgraded without causing an unplanned failover or service interruption.

Exam trap

The trap here is that candidates assume upgrading the primary first is safe because the secondary will synchronize, but they overlook that the primary reboot triggers an automatic failover, which is not a 'graceful' upgrade path.

How to eliminate wrong answers

Option A is wrong because upgrading the primary first would cause it to reboot, triggering an automatic failover to the secondary, which is not desired. Option B is wrong because upgrading both units simultaneously can lead to a split-brain scenario or both units rebooting at the same time, causing a complete outage. Option C is wrong because disabling HA breaks the cluster state and requires re-synchronization, which is disruptive and not recommended for a controlled upgrade.

75
MCQmedium

An administrator is configuring email filtering on FortiGate to block spam. Which of the following is required for FortiGate to filter inbound email directly?

A.FortiMail must be deployed as a separate appliance
B.The FortiGate must be configured as an SMTP proxy
C.SSL deep inspection must be enabled for SMTP traffic
D.The email filtering profile must be applied to a policy covering port 110
AnswerB

The FortiGate must be configured to operate as an SMTP proxy in the security policy to intercept and filter email traffic on port 25. In this proxy mode, the FortiGate acts as a relay that receives, inspects, and forwards email, allowing the UTM email filter and antivirus profiles to examine the message body, headers, and attachments. This is the standard method to apply email filtering on FortiGate; without proxy mode, the device would only see IP and port information, not the mail content.

Why this answer

FortiGate can filter inbound email directly only when it is configured as an SMTP proxy, which allows it to intercept and inspect SMTP traffic at the application layer. This proxy mode enables the FortiGate to apply email filtering profiles, including anti-spam and antivirus, to SMTP sessions without requiring a separate appliance.

Exam trap

The trap here is that candidates often assume FortiGate requires a separate FortiMail appliance for any email filtering, but FortiGate's SMTP proxy feature provides direct inbound email filtering without additional hardware.

How to eliminate wrong answers

Option A is wrong because FortiMail is a dedicated email security gateway, but FortiGate can perform SMTP-based email filtering natively without needing FortiMail as a separate appliance. Option B is wrong because it is actually the correct answer, not a wrong option. Option C is wrong because SSL deep inspection is not required for SMTP filtering; FortiGate can filter SMTP traffic in plaintext or with opportunistic TLS without full SSL inspection.

Option D is wrong because port 110 (POP3) is used for email retrieval, not inbound SMTP delivery; email filtering for inbound mail must be applied to a policy covering SMTP on port 25.

Page 1 of 11

Page 2

All pages