Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 751–773

773 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

A network administrator notices that HTTP traffic to a specific website is being blocked by the web filter profile, but the website is categorized as 'General – Personal' in FortiGuard, which is allowed. What could cause this block?

A.The web filter profile has an incorrect FortiGuard category override
B.The antivirus profile is blocking the website
C.A URL filter entry is blocking the specific website
D.DNS filter is blocking the domain
AnswerC

URL filter entries are local, rule-based patterns evaluated before FortiGuard category lookup. If a block entry matches the specific domain or URL, the session is dropped immediately, regardless of the category's default action. This is why a single website can be blocked while other sites in the same FortiGuard category remain accessible, as described in the scenario.

Why this answer

A URL filter entry can explicitly block a specific website regardless of its FortiGuard category. Even if the category 'General – Personal' is allowed in the web filter profile, a more specific URL filter rule with a higher priority (lower order number) can override the category-based action. This is a common scenario where an administrator creates a custom URL block for a particular domain or URL pattern, which takes precedence over the FortiGuard category lookup.

Exam trap

The trap here is that candidates often assume the FortiGuard category is the sole determinant of web access, forgetting that URL filter entries have higher precedence and can block individual sites even when their category is permitted.

How to eliminate wrong answers

Option A is wrong because a FortiGuard category override would change the category assigned to the website, but if the override incorrectly set it to a blocked category, the traffic would be blocked for that reason—however, the question states the category is allowed, so an override would not cause a block unless it changed the category to a blocked one, which is not indicated. Option B is wrong because antivirus profiles inspect file downloads and HTTP content for malware, not the initial HTTP request to a website; they would not block the website itself unless a virus was detected in a downloaded file, which is not mentioned. Option D is wrong because DNS filter blocks domains at the DNS query level, preventing resolution entirely, but the question indicates HTTP traffic is blocked, implying the DNS query succeeded and the TCP connection was attempted, so a DNS filter block would manifest as a DNS resolution failure, not an HTTP block.

752
MCQmedium

An admin wants to block traffic from a specific geographic region (e.g., North Korea) from reaching the FortiGate's external interface. Which address object type should be used in the firewall policy?

A.Subnet address object
B.Geography address object
C.FQDN address object
D.Wildcard FQDN address object
AnswerB

A geography address object in FortiOS matches traffic based on the country or region mapped to the source or destination IP address, using the FortiGuard GeoIP database. When you add it to a firewall policy as the source address and set the action to DENY, all traffic originating from that geopolitical area is blocked dynamically, with no need to track individual IP ranges. This is the correct object type because it directly maps IP addresses to geographic locations.

Why this answer

A geography address object allows the firewall to match traffic based on the source or destination IP address's registered country. FortiGate uses a built-in GeoIP database to map IP addresses to geographic regions, making it the correct choice for blocking traffic from a specific country like North Korea.

Exam trap

The trap here is that candidates may confuse geography address objects with subnet or FQDN objects, thinking they can manually list IP ranges for a country, but FortiGate requires the use of the built-in GeoIP database for country-based filtering.

How to eliminate wrong answers

Option A is wrong because a subnet address object matches traffic based on a specific IP range or CIDR, not by geographic region. Option C is wrong because an FQDN address object resolves a domain name to IP addresses and cannot represent an entire country. Option D is wrong because a wildcard FQDN address object matches multiple domain names using wildcards, which is unrelated to geographic location.

753
MCQeasy

What is the primary difference between flow-based and proxy-based Antivirus inspection on a FortiGate?

A.Flow-based inspection is only available on hardware models with CP8
B.Proxy-based inspection reassembles the file before scanning, while flow-based scans as the file passes through
C.Proxy-based inspection uses fewer resources than flow-based
D.Flow-based inspection supports virus outbreak detection, but proxy-based does not
AnswerB

Proxy-based inspection buffers and reassembles the complete file before scanning, enabling full content inspection and blocking. Flow-based scanning examines packets as they traverse the FortiGate, trading depth for throughput and lower latency. This directly satisfies the stem's request for the primary architectural difference between the two antivirus inspection modes.

Why this answer

The primary difference is that proxy-based antivirus inspection fully reassembles the file in memory before scanning, allowing for more thorough detection of threats like polymorphic viruses and archives. Flow-based inspection scans data as it passes through the FortiGate in a single pass, using pattern matching without full file reassembly, which reduces latency but may miss threats that require file-level analysis.

Exam trap

The trap here is that candidates often assume proxy-based is always more resource-efficient because it is 'thorough,' but in reality, proxy-based consumes more memory and CPU due to file buffering and reassembly, while flow-based is optimized for performance.

How to eliminate wrong answers

Option A is wrong because flow-based inspection is not limited to hardware models with CP8; it is available on all FortiGate models and leverages CP8/CP9 accelerators for performance but does not require them. Option C is wrong because proxy-based inspection typically uses more resources (memory and CPU) due to file reassembly and buffering, while flow-based is designed for lower resource consumption. Option D is wrong because both flow-based and proxy-based inspection support virus outbreak detection through FortiGuard updates; the difference is in the scanning method, not feature support.

754
MCQmedium

A network administrator is configuring a new FortiGate and needs to ensure that all traffic from the internal network to the internet is source NATed to the public IP address on port1. The default route points to port1. Which configuration step is required to achieve this?

A.Configure a static route to the internet with NAT enabled
B.Enable NAT on the firewall policy from internal to internet
C.Set the interface port1 to NAT mode in its settings
D.Create an IP pool with the public IP and reference it in the policy
AnswerB

In FortiGate, source NAT is performed by enabling the NAT option on the firewall policy that matches the internal-to-internet traffic. This setting causes the FortiGate to masquerade the source IP of each packet with the IP address assigned to the egress interface, which is typically the public IP of the WAN port. This is the standard and correct method for allowing internal users to share a single public IP address when accessing the internet.

Why this answer

Source NAT (SNAT) on a FortiGate is configured at the firewall policy level, not on the interface or via a static route. By enabling NAT on the firewall policy from the internal network to the internet, the FortiGate automatically translates the source IP of traffic egressing port1 to the interface's primary IP address (the public IP). This is the standard method for implementing source NAT in FortiOS, as defined in the FortiGate Administration Guide.

Exam trap

The trap here is that candidates often confuse NAT configuration with interface settings or static routes, mistakenly thinking NAT must be enabled on the egress interface or as part of the route, whereas FortiOS applies NAT exclusively at the firewall policy level.

How to eliminate wrong answers

Option A is wrong because static routes in FortiOS do not have a NAT toggle; NAT is not a property of a route but of a firewall policy. Option C is wrong because interfaces in FortiOS do not have a 'NAT mode' setting; NAT is applied per policy, not per interface. Option D is wrong because an IP pool is only required when you need to translate to a specific IP address that is not the interface IP (e.g., for load balancing or PAT with a pool), but the question states the public IP is on port1, so the default interface NAT (enabled in the policy) suffices without an IP pool.

755
Multi-Selecthard

Which THREE statements about SD-WAN rules are correct?

Select 3 answers
A.SD-WAN rules are evaluated in order of priority.
B.SD-WAN rules must use a 'load balancing' strategy.
C.SD-WAN rules can match based on application, destination, or source.
D.Each SD-WAN rule can only contain one member.
E.If no SD-WAN rule matches, the traffic is processed by the implicit rule.
AnswersA, C, E

SD-WAN rules are evaluated in order of priority, meaning the rule with the lowest priority number (highest precedence) is inspected first and the first matching rule is applied exclusively. FortiGate processes rules top-down, and once a match is found, no subsequent SD-WAN rule is considered for that session, making priority sequencing critical for deterministic traffic steering.

Why this answer

SD-WAN rules are evaluated in order of priority, meaning the rule with the highest priority (lowest number) is matched first. This sequential evaluation ensures deterministic traffic steering based on the most specific match criteria defined by the administrator.

Exam trap

The trap here is that candidates often assume SD-WAN rules must use load balancing, but Fortinet allows multiple strategies including 'best quality' and 'manual', and they also mistakenly think each rule can only have one member, whereas member groups are supported for redundancy and load distribution.

756
MCQmedium

You are troubleshooting an IPsec VPN between two FortiGates. The Phase 1 is up, but Phase 2 is not coming up. You check the Phase 2 configuration on both sides. What is a common cause of this issue?

A.Mismatch in Phase 2 settings such as encryption algorithm, authentication algorithm, or PFS group
B.Firewall policy not allowing ESP traffic
C.Incorrect local or remote gateway IP
D.Mismatch in Phase 1 pre-shared key
AnswerA

Phase 2 negotiation (Quick Mode in IKEv1) is separate from Phase 1 and uses its own proposal set. For a FortiGate-to-FortiGate VPN, the encryption algorithm (e.g., AES128 vs AES256), authentication/HMAC algorithm (e.g., SHA1 vs SHA256), and Perfect Forward Secrecy (PFS) group (e.g., None vs DH14) must match exactly on both peers. If PFS is enabled on one side but not the other, or the DH groups differ, Phase 2 will fail with a proposal or no-proposal-match error even though Phase 1 is healthy.

Why this answer

When Phase 1 is up but Phase 2 fails, the most common cause is a mismatch in Phase 2 parameters. Phase 2 uses IPsec SA proposals that must match exactly on both sides, including encryption algorithm (e.g., AES256), authentication algorithm (e.g., SHA256), and Perfect Forward Secrecy (PFS) group (e.g., DH14). Even a single mismatch, such as one side using PFS and the other not, will prevent Phase 2 from establishing.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 issues, assuming any mismatch in authentication or encryption must be Phase 1, but FortiGate separates these phases, and Phase 2 mismatches are a distinct and common cause of partial VPN failure.

How to eliminate wrong answers

Option B is wrong because firewall policies not allowing ESP traffic would typically affect Phase 1 or all IPsec traffic, not specifically Phase 2; Phase 1 uses UDP ports 500/4500, and if ESP were blocked, Phase 1 would also fail. Option C is wrong because incorrect local or remote gateway IPs would prevent Phase 1 from coming up, as Phase 1 relies on matching peer IPs and IKE negotiation. Option D is wrong because a mismatch in Phase 1 pre-shared key would cause Phase 1 to fail, not Phase 2; Phase 2 only begins after Phase 1 is successfully established.

757
MCQmedium

An administrator wants to log all traffic that is denied by the implicit deny rule. How can this be achieved?

A.Configure a firewall policy with action ACCEPT and enable logging
B.Enable logging on the implicit deny rule
C.Create a firewall policy with action DENY and enable logging, placed above the implicit deny
D.Use the 'diagnose debug flow' command to capture all traffic
AnswerC

Creating an explicit firewall policy with DENY action and enabling logging, then placing it above the implicit deny rule, meets the administrator's requirement. This explicit policy will match traffic that would otherwise fall through to the implicit deny, block it, and generate a traffic log entry with details such as source, destination, and service. Because the policy is above the implicit deny, it takes precedence and ensures that denied traffic is properly logged.

Why this answer

The implicit deny rule at the bottom of the firewall policy list cannot be modified to enable logging. To log traffic denied by the implicit deny, you must create an explicit firewall policy with action DENY and logging enabled, placed above the implicit deny rule. This explicit deny policy will match traffic that would otherwise hit the implicit deny, and because it is an explicit policy, logging can be enabled on it.

Exam trap

The trap here is that candidates assume the implicit deny rule can be modified to enable logging, but FortiOS does not allow any configuration changes to the implicit deny rule, so you must create an explicit deny policy above it to log denied traffic.

How to eliminate wrong answers

Option A is wrong because an ACCEPT action would allow the traffic, not deny it, and logging would only show allowed traffic, not the denied traffic you want to capture. Option B is wrong because the implicit deny rule is a built-in, non-configurable rule; you cannot enable logging on it directly in the FortiGate GUI or CLI. Option D is wrong because 'diagnose debug flow' is a real-time troubleshooting tool that captures packet flow information for a specific session, not a method to log all denied traffic persistently.

758
MCQeasy

What is the primary advantage of using route-based IPsec VPN over policy-based IPsec VPN?

A.Route-based VPN allows the use of dynamic routing protocols over the tunnel
B.Route-based VPN requires fewer firewall policies
C.Route-based VPN is easier to configure for hub-and-spoke
D.Route-based VPN supports higher encryption algorithms
AnswerA

Route-based IPsec VPN creates a virtual tunnel interface, allowing the underlying IPsec connection to participate in dynamic routing protocols such as OSPF, EIGRP, or BGP. This enables automatic route advertisement and convergence, eliminating the need for static proxy-IDs for each destination network, and making large-scale, redundant VPN topologies far more practical to deploy and maintain.

Why this answer

Route-based IPsec VPNs create a virtual tunnel interface (e.g., `tunnel` or `ipsec` interface) that acts as a logical routing endpoint. This allows the tunnel to participate in dynamic routing protocols like OSPF or BGP, enabling automatic route advertisement and failover across the VPN. Policy-based VPNs, in contrast, rely on static security policies that match traffic based on source/destination addresses and ports, which cannot be dynamically updated by routing protocols.

Exam trap

The trap here is that candidates often confuse 'fewer firewall policies' (Option B) as the primary advantage, but the NSE4 exam emphasizes that the key differentiator is the ability to use dynamic routing protocols over the tunnel, which is not possible with policy-based VPNs.

How to eliminate wrong answers

Option B is wrong because route-based VPNs typically require fewer firewall policies only in the sense that traffic is matched via routing rather than per-flow policies, but this is not the primary advantage; the core benefit is dynamic routing. Option C is wrong because while route-based VPNs can simplify hub-and-spoke topologies, this is a consequence of dynamic routing support, not the primary advantage; policy-based VPNs can also be used for hub-and-spoke with manual configuration. Option D is wrong because both route-based and policy-based VPNs support the same encryption algorithms (e.g., AES-256, SHA-256) as defined by the IPsec proposal; the choice of algorithm is independent of the VPN type.

759
MCQhard

A FortiGate administrator configures a policy-based NAT using an IP pool with type 'Fixed Port Range' for internal users accessing a specific external server. Users report that after some time, they cannot establish new connections to the server. 'diagnose ip pool list' shows many entries with 'used_port=65535'. What is the MOST likely cause?

A.The external server is rate-limiting connections
B.The firewall policy has a timeout setting that is too low
C.The IP pool has run out of IP addresses
D.The fixed port range is too small, causing port exhaustion
AnswerD

Fixed port range NAT assigns a block of ports to each source IP. If the range is small (e.g., 1 port), it fills quickly and blocks new sessions. The 'used_port=65535' indicates the last port in a range is in use.

Why this answer

The 'Fixed Port Range' IP pool type allocates a specific range of ports per IP address for NAT translations. When all ports in the range are exhausted (indicated by 'used_port=65535'), no new connections can be established, causing the reported issue. This is classic port exhaustion, making D correct.

Exam trap

The trap here is that candidates may confuse IP address exhaustion (Option C) with port exhaustion, but the diagnostic output clearly shows IP addresses are still available while ports are maxed out, pointing directly to the fixed port range being too small.

How to eliminate wrong answers

Option A is wrong because the external server rate-limiting would affect all users equally and would not cause the specific symptom of 'used_port=65535' entries in the IP pool list. Option B is wrong because a low firewall policy timeout would cause connections to be dropped prematurely, not prevent new connections from being established due to port exhaustion. Option C is wrong because the 'diagnose ip pool list' output shows many entries with 'used_port=65535', indicating that IP addresses are still available but all ports within the fixed range are in use, not that IP addresses have run out.

760
MCQeasy

A FortiGate administrator needs to block all traffic from a specific geographic region (country) from accessing the internal network. Which type of address object should be used in the firewall policy?

A.Geography object
B.FQDN object
C.Wildcard FQDN object
D.Subnet object
AnswerA

In FortiGate, a geography object (GeoIP object) represents a country or region using the FortiGuard GeoIP database, which maps IP address ranges to geographic locations. This object type is the only one among the listed options that inherently supports country-based identification, so it is the correct choice for blocking all traffic from a specific source country. The GeoIP database is regularly updated by FortiGuard to reflect new IP allocations, ensuring policy accuracy.

Why this answer

A Geography object is specifically designed to represent a geographic region (such as a country) based on IP address geolocation data. When used in a firewall policy, it allows the FortiGate to match traffic sources or destinations by country, enabling the administrator to block all traffic from that region. This is the correct and only address object type that supports country-based filtering.

Exam trap

The trap here is that candidates may confuse a Geography object with a Subnet object, thinking they can manually list all IP ranges for a country, but FortiGate's dynamic geolocation database makes the Geography object the only practical and correct choice for country-based blocking.

How to eliminate wrong answers

Option B (FQDN object) is wrong because it resolves a fully qualified domain name to an IP address and cannot represent a geographic region. Option C (Wildcard FQDN object) is wrong because it matches multiple domain names using wildcards, not geographic locations. Option D (Subnet object) is wrong because it defines a specific IP address range or subnet, which cannot dynamically represent all IPs belonging to a country.

761
MCQmedium

When creating a firewall policy, an admin wants to ensure that traffic from a specific user group is allowed only during business hours (Monday to Friday, 09:00-18:00). Which object type must be configured and applied to the policy?

A.A security profile with time-based filtering
B.A schedule object with a recurring schedule
C.A user group object with time restrictions
D.A traffic shaping policy with a time-based rule
AnswerB

A schedule object with a recurring schedule is the correct Fortinet approach because it explicitly defines days-of-week and time-of-day ranges that are then bound directly to the firewall policy. When a schedule is attached to a policy, the policy becomes active only during the configured time window, and the firewall automatically disables enforcement outside that period. This matches the administrator's requirement precisely, and no other object type in FortiOS provides this built-in time-enforcement capability for policy activation.

Why this answer

To restrict traffic based on time, a firewall policy must reference a schedule object. A recurring schedule defines specific days and hours (e.g., Monday–Friday, 09:00–18:00) and is applied directly to the policy. This allows the FortiGate to permit or deny traffic based on the current time without additional profiles or user group modifications.

Exam trap

The trap here is that candidates confuse security profiles (which can have time-based filtering for web categories) with the schedule object required at the policy level, but only the schedule object controls whether the entire policy is active.

How to eliminate wrong answers

Option A is wrong because a security profile (e.g., antivirus, web filter) inspects content, not time; it cannot enforce time-based access. Option C is wrong because user group objects define users, not time windows; time restrictions are not a property of user groups. Option D is wrong because a traffic shaping policy controls bandwidth and QoS, not access permission; it cannot allow or deny traffic based on time.

762
MCQhard

An administrator is configuring a VIP to map a public IP to an internal server. The server hosts both HTTP and HTTPS services. The admin creates a VIP with port forwarding for port 80 to internal port 80, and another VIP for port 443 to internal port 443. Both VIPs use the same public IP. Users can access HTTP but not HTTPS. What is the most likely issue?

A.The firewall policy for HTTPS traffic is missing or has incorrect destination
B.The server's HTTPS service is not running
C.VIPs cannot share the same public IP address
D.The HTTPS VIP is configured with the wrong internal port
AnswerA

In FortiGate, VIPs only perform destination NAT; they do not implicitly permit traffic. A firewall policy must explicitly allow HTTPS traffic with the destination set to the VIP object, and the service must include HTTPS (or port 443). If the existing policy only allows HTTP to the same VIP, HTTPS packets are dropped due to no matching policy, so the connection never reaches the server.

Why this answer

The most likely issue is that the firewall policy for HTTPS traffic is missing or has an incorrect destination. Even with a correctly configured VIP, traffic must be allowed by a firewall policy that matches the destination (the VIP's public IP and port 443) and the action must be set to ACCEPT. Without this policy, the FortiGate will drop the HTTPS packets, while HTTP traffic works because its corresponding policy exists.

Exam trap

The trap here is that candidates assume a correctly configured VIP automatically allows traffic, but FortiGate requires an explicit firewall policy to permit the translated traffic, and the exam tests this separation of NAT and policy functions.

How to eliminate wrong answers

Option B is wrong because if the server's HTTPS service were not running, the admin would typically see connection refused or timeout errors, not a complete lack of access; the issue is at the firewall level, not the server. Option C is wrong because FortiGate VIPs can share the same public IP address as long as they use different ports (e.g., 80 and 443), which is a standard port-based VIP configuration. Option D is wrong because the admin explicitly configured the HTTPS VIP with internal port 443, which is correct for HTTPS; if the internal port were wrong, the traffic would reach the server but on the wrong port, causing a different failure mode.

763
MCQmedium

An admin wants users to authenticate once via AD and have their network access controlled without repeated logins. Which feature should be used?

A.Local user authentication
B.FSSO with Active Directory polling
C.Captive portal with LDAP
D.SSL VPN with certificate authentication
AnswerB

FSSO with AD polling provides true single sign-on by having the FortiGate (via the FSSO agent) monitor the domain controller's security event log for successful logons. When a user logs into the domain, the agent maps the user name to the workstation's IP address and updates the FortiGate's user list, enabling firewall policies to be applied without any user prompt. This transparently authenticates the user for network access and exactly matches the 'authenticate once via AD' requirement.

Why this answer

FSSO with Active Directory polling allows users to authenticate once at Windows logon, and FortiGate polls the AD domain controllers to capture authentication events. This enables transparent network access control without repeated logins, as the user's identity and group memberships are mapped to firewall policies automatically.

Exam trap

The trap here is that candidates often confuse FSSO with captive portal or LDAP authentication, thinking any AD integration provides single sign-on, but only FSSO (polling or agent-based) captures the Windows logon event to avoid repeated authentication prompts.

How to eliminate wrong answers

Option A is wrong because local user authentication requires users to manually log in to the FortiGate (e.g., via captive portal or SSL VPN) and does not provide single sign-on from AD. Option C is wrong because captive portal with LDAP still requires users to enter credentials each time they open a browser, and it does not leverage the initial Windows logon for transparent access. Option D is wrong because SSL VPN with certificate authentication is a remote access VPN method, not a solution for controlling network access for on-net users without repeated logins.

764
MCQmedium

A FortiGate is configured with an IPsec VPN to a remote site using IKEv1. The VPN tunnel goes down intermittently. The admin runs 'diagnose vpn ike gateway list' and sees 'state=UP' but no Phase2 selectors. What is the most likely cause?

A.The firewall policy allowing IPsec traffic is misconfigured
B.The remote gateway has a different PSK
C.Mismatched Phase2 parameters between the local and remote gateways
D.Dead Peer Detection (DPD) is disabled
AnswerC

Phase2 negotiation, also known as Quick Mode in IKEv1, is dedicated to agreeing on IPsec SA parameters such as encryption algorithm, integrity algorithm, DH group, PFS, and SA lifetimes. If the local FortiGate proposes a set of algorithms that do not overlap with the remote gateway's configured Phase2 proposal, the negotiation ends in a NO_PROPOSAL_CHOSEN error and no IPsec SA is created. The tunnel may appear to be up (Phase1 complete) but never passes traffic because Phase2 is stuck or continuously re-negotiating. Matching every parameter, including subtle settings like PFS and key lifetime, is mandatory for successful Phase2 establishment.

Why this answer

When 'diagnose vpn ike gateway list' shows the IKE gateway state as UP but no Phase2 selectors are present, it indicates that the IKE Phase1 (main mode or aggressive mode) has completed successfully, but the IPsec Phase2 (quick mode) negotiation has failed. The most common cause for this is a mismatch in Phase2 parameters such as encryption algorithm, authentication algorithm, or proxy IDs (local/remote subnets) between the local and remote gateways. Since the tunnel goes down intermittently, the Phase2 rekey may be failing due to these mismatches, causing the tunnel to drop until a successful renegotiation occurs.

Exam trap

The trap here is that candidates often assume a UP gateway state means the entire VPN tunnel is working, but in IKEv1, Phase1 can be UP while Phase2 is down, leading to intermittent connectivity; the key is to check Phase2 selectors separately.

How to eliminate wrong answers

Option A is wrong because a misconfigured firewall policy allowing IPsec traffic would typically prevent the IKE gateway from reaching the UP state at all, as Phase1 would fail to complete. Option B is wrong because a different PSK would cause Phase1 authentication to fail, resulting in the gateway state being DOWN or NEGO_FAIL, not UP. Option D is wrong because disabling DPD would not cause the gateway to show UP without Phase2 selectors; DPD is used to detect peer liveness and would affect the gateway state if the peer is unreachable, but it does not directly prevent Phase2 negotiation.

765
Multi-Selectmedium

An administrator needs to configure a FortiGate to send logs to a FortiAnalyzer. Which two configurations are required? (Choose two.)

Select 2 answers
A.Configure FortiAnalyzer IP under config system central-management
B.Set log-fortianalyzer to enable under config log setting
C.Enable log transfer under config log fortianalyzer setting
D.Configure a firewall policy to allow logs to leave
E.Create a log filter to send all logs
AnswersA, B

The FortiAnalyzer IP address is specified under config system central-management, in the fortianalyzer sub-table. This is the mandatory server address that the FortiGate uses to register and connect to the FortiAnalyzer unit. Without this IP, the FortiGate cannot establish the log upload session, even if log settings are enabled.

Why this answer

The FortiGate must be configured to know the FortiAnalyzer's IP address under `config system central-management` to establish the logging connection. Option B is correct because the `set log-fortianalyzer enable` command under `config log setting` activates the log transmission to the configured FortiAnalyzer. Without both, the FortiGate will not send logs to the FortiAnalyzer.

Exam trap

The trap here is that candidates mistakenly think a firewall policy is required to allow log traffic out, but FortiGate's log transmission to FortiAnalyzer uses the management VDOM and bypasses regular firewall policies.

766
MCQmedium

An admin is configuring a dial-up IPsec VPN for remote users. The users will connect from various public IP addresses. Which Phase 1 configuration is required for the FortiGate to accept connections from unknown remote gateways?

A.Enable aggressive mode
B.Set the remote gateway to 0.0.0.0
C.Configure a static route to the remote users' subnet
D.Set the remote gateway to a specific IP address
AnswerB

Setting the remote gateway to 0.0.0.0 is the core dialup Phase 1 setting on a FortiGate: it instructs the device to accept incoming IKE connections from any source IP address rather than from one fixed peer. This wildcard is what enables remote users with dynamic public IPs to build a tunnel, because the actual peer address is learned automatically when the client initiates Phase 1 negotiation. Combined with peer type 'one', this makes the FortiGate operate as the dialup VPN server.

Why this answer

For a dial-up IPsec VPN where remote users connect from dynamic public IP addresses, the FortiGate must be configured to accept connections from any remote gateway. Setting the remote gateway to 0.0.0.0 (or 0.0.0.0/0) in Phase 1 tells the FortiGate to accept IKE negotiation from any source IP, which is essential for dial-up scenarios. This is the standard method to allow unknown remote gateways to initiate the VPN tunnel.

Exam trap

The trap here is that candidates often confuse the need for aggressive mode (option A) with the requirement to accept unknown remote gateways, but aggressive mode is about identity protection and faster negotiation, not about allowing any source IP to initiate the tunnel.

How to eliminate wrong answers

Option A is wrong because aggressive mode is not required for dial-up VPNs; it is an optional IKE mode that sends the identity in clear text and is less secure, but the key requirement is the remote gateway wildcard, not the mode. Option C is wrong because a static route to the remote users' subnet is needed for traffic forwarding after the tunnel is established, but it does not affect Phase 1 acceptance of unknown remote gateways. Option D is wrong because setting the remote gateway to a specific IP address would restrict the FortiGate to only accept connections from that single IP, which defeats the purpose of a dial-up VPN for users with dynamic public IPs.

767
MCQmedium

After upgrading FortiGate firmware from 6.0 to 7.2, an administrator notices that a static route pointing to a next-hop IP 10.0.0.1 is no longer working. The route is present in the configuration but the FortiGate shows it as 'not active'. What is the MOST likely cause?

A.FortiGate now requires a default administrative distance of 10 for static routes
B.The route was deleted during the upgrade and needs to be re-added
C.The next-hop IP is not directly connected to any FortiGate interface
D.The remote gateway is down
AnswerC

FortiGate static routes require the next-hop IP (gateway) to be on a directly connected subnet of the outgoing interface. If the gateway is not directly connected to any FortiGate interface, the route cannot be resolved via ARP or neighbor discovery, so FortiGate marks the route as inactive and does not install it in the forwarding table. This is the most common and specific cause of an inactive static route after a configuration change or upgrade that alters interface IPs or subnet masks.

Why this answer

In FortiOS 7.2, a static route is considered 'active' only if the next-hop IP is reachable via a directly connected interface. If the next-hop IP 10.0.0.1 is not on a directly connected subnet, the route will be present in the configuration but marked as 'not active'. This is a fundamental routing principle: the next hop must be directly reachable (i.e., the router must have an ARP entry for it) for the route to be installed in the routing table.

Exam trap

The trap here is that candidates often assume a static route will be active as long as the configuration is present and the remote gateway is reachable, but FortiGate (and most routers) require the next-hop IP to be directly connected for the route to be installed in the routing table.

How to eliminate wrong answers

Option A is wrong because the default administrative distance for static routes in FortiOS remains 10 (unchanged from 6.0 to 7.2), and administrative distance does not affect whether a route is 'active'—it only influences route selection among multiple routes to the same destination. Option B is wrong because the route is still present in the configuration, so it was not deleted during the upgrade; the issue is that it is not active, not that it is missing. Option D is wrong because the remote gateway being down would cause the route to be present but possibly inactive only if the next hop is directly connected; if the next hop is not directly connected, the route would be inactive regardless of the remote gateway's state.

768
Multi-Selecthard

Which THREE conditions must be met for a firewall policy with FSSO authentication to work correctly?

Select 3 answers
A.The FortiGate must be able to communicate with the domain controller
B.The user's IP address must be in the destination address range of the policy
C.The user must be a member of a group that is referenced in the firewall policy
D.The FSSO collector agent must be running and properly configured
E.The user must be authenticated to the FortiGate locally
AnswersA, C, D

FSSO relies on the FortiGate or Collector Agent receiving user login events from the domain controller. Without network connectivity to the DC, the FortiGate cannot learn which user logged in or which groups that user belongs to, so the policy cannot match the user. This communication is typically via LDAP or a proprietary FSSO polling/eventing protocol, and any firewall rule blocking it will break FSSO.

Why this answer

FSSO (Fortinet Single Sign-On) relies on the FortiGate communicating with the domain controller to retrieve user login events via NetAPI or WMI. Without this communication, the FortiGate cannot map user identities to IP addresses, which is essential for FSSO-based authentication in firewall policies.

Exam trap

The trap here is that candidates often confuse source and destination address fields in the policy, mistakenly thinking the user's IP must be in the destination range, or assume FSSO requires local FortiGate authentication, when in fact it relies on domain authentication and the collector agent.

769
MCQeasy

A FortiGate administrator needs to allow SMTP traffic from the internal network to an external mail server. The internal network uses source NAT to the external interface IP. Which firewall policy configuration is correct?

A.Policy: source internal, destination external, service SMTP, enable NAT
B.Policy: source internal, destination external, service SMTP, disable NAT
C.Policy: source internal, destination external, service SMTP (port 587), enable NAT
D.Policy: source internal, destination external, service SMTP (UDP), enable NAT
AnswerA

Enable NAT on the policy so the FortiGate performs source NAT (hide/PAT), translating the internal source IP (e.g., 10.0.0.10) to the interface's public IP address. This makes the SMTP connection appear to originate from a routable public address, and the stateful session table ensures replies from the external mail server are returned to the correct internal host. Without this translation, the outbound SYN would carry a private source address that ISPs drop.

Why this answer

SMTP traffic from the internal network to an external mail server requires source NAT (masquerading) to translate private source IPs to the FortiGate's external interface IP. This ensures return traffic is routed back correctly. The default SMTP service uses TCP port 25, and enabling NAT on the policy is the standard configuration for outbound traffic to the internet.

Exam trap

The trap here is that candidates may confuse SMTP ports (25 vs 587) or assume SMTP can use UDP, but the exam tests the fundamental requirement that outbound internet traffic must have NAT enabled and that SMTP is TCP-based.

How to eliminate wrong answers

Option B is wrong because disabling NAT would send packets with private source IPs, which are not routable on the internet, causing the external mail server to drop replies or the packets to be discarded by intermediate routers. Option C is wrong because SMTP typically uses TCP port 25, not port 587 (which is SMTP submission, often used for authenticated client-to-server submission); the question specifies SMTP traffic, not SMTP submission, and the service should match the standard SMTP port. Option D is wrong because SMTP uses TCP, not UDP; SMTP relies on reliable, connection-oriented transport, and UDP would break the protocol's delivery guarantees.

770
MCQhard

An admin configures a VIP to map a public IP to an internal server. The firewall policy uses the VIP as the destination. External users can access the server, but the server's logs show the source IP as the FortiGate's internal interface IP instead of the original client IP. Why is this happening?

A.The VIP is configured with port forwarding and the server is expecting a different port
B.The VIP is using a different public IP than expected
C.The firewall policy has NAT enabled, which changes the source IP to the FortiGate's egress interface IP
D.The server's routing is misconfigured and traffic is returning via a different path
AnswerC

When the firewall policy matching the VIP traffic has NAT enabled, FortiGate replaces the original source IP with the IP of the egress interface used to forward the packet. This source NAT (SNAT) hides the client's real address, so the internal server logs show the FortiGate's interface IP as the connection source. This is the standard behavior, explaining why the admin observes the FortiGate IP instead of the client's public IP.

Why this answer

When a firewall policy has NAT enabled (typically 'Enable NAT' or 'Use Outgoing Interface Address'), the FortiGate performs source NAT (SNAT) on the traffic, replacing the original client source IP with the IP of its egress interface (the internal interface in this scenario). This is standard behavior for source NAT, which hides the original client IP from the internal server, causing the server logs to show the FortiGate's internal interface IP instead of the actual client IP.

Exam trap

The trap here is that candidates often assume NAT only applies to outbound traffic, but FortiGate policies apply NAT bidirectionally unless explicitly disabled, causing the source IP to be overwritten even for inbound VIP traffic.

How to eliminate wrong answers

Option A is wrong because port forwarding configuration on the VIP does not affect source IP preservation; it only translates destination ports, and the server expecting a different port would cause connectivity failure, not a source IP mismatch. Option B is wrong because using a different public IP than expected would result in the server not receiving traffic at all or traffic being dropped, not in the server seeing the FortiGate's internal IP as the source. Option D is wrong because misconfigured server routing causing asymmetric return traffic would typically lead to dropped connections or timeouts, not to the server logging the FortiGate's internal IP as the source; the source IP seen by the server is determined by the inbound packet's source address, which is already modified by NAT before the server processes it.

771
MCQeasy

What is the purpose of policy-based routing (PBR) in FortiGate?

A.To load balance traffic across multiple WAN links
B.To filter traffic based on application signatures
C.To route traffic based on source address, destination, or other attributes instead of the routing table
D.To authenticate users before allowing traffic
AnswerC

Policy-based routing (PBR) allows a FortiGate to choose the next hop for a packet based on policy criteria such as source address, destination address, or incoming interface, rather than performing a normal longest-prefix routing table lookup. When a policy route matches, the FortiGate follows its configured action (e.g., send to a specific gateway or tunnel) and skips the destination-based routing decision for that packet. This is an essential tool when traffic must be forced down a specific path independent of what the routing table would select.

Why this answer

Policy-based routing (PBR) in FortiGate allows you to override the default routing table lookup by forwarding traffic based on criteria such as source IP address, destination IP address, protocol, or even application. This is configured under the 'policy route' feature and is evaluated before the routing table, enabling granular control over traffic paths that static or dynamic routes cannot provide.

Exam trap

The trap here is that candidates often confuse PBR with SD-WAN or load balancing, but PBR is strictly about overriding routing decisions based on packet attributes, not about distributing traffic across multiple links for bandwidth or redundancy.

How to eliminate wrong answers

Option A is wrong because load balancing across multiple WAN links is achieved using ECMP (Equal-Cost Multi-Path) routing or SD-WAN rules, not PBR. Option B is wrong because filtering traffic based on application signatures is the function of Application Control, a feature within firewall policies, not PBR. Option D is wrong because authenticating users before allowing traffic is handled by firewall authentication (e.g., FSSO, LDAP) or captive portal, not by PBR.

772
MCQhard

A company uses FortiGate with firewall policies to control access between internal VLANs. Users in VLAN 10 report they can access internet but cannot reach a server in VLAN 20 on port 443. The server is reachable from other VLANs. The administrator checks the firewall policy configuration: there is a policy from VLAN10 to VLAN20 allowing HTTPS, with NAT disabled and logging enabled. The policy has a schedule set to 'Always'. The administrator also checks that there are no overlapping policies. What is the most likely cause?

A.NAT is disabled, so the server cannot send replies back.
B.The policy order is incorrect; a deny policy above is blocking traffic.
C.A security profile applied to the policy is blocking the HTTPS traffic.
D.The schedule is configured incorrectly and the policy is inactive during the current time.
AnswerC

A security profile (e.g., SSL inspection or application control) applied to the firewall policy can intercept HTTPS sessions and enforce actions like blocking based on certificate validation failure, URL category, or application signature. If the server presents an untrusted or expired certificate, the SSL inspection profile may block the HTTPS handshake while allowing other traffic, which matches the symptom of only HTTPS being affected.

Why this answer

Security profiles (such as web filtering, application control, or SSL inspection) applied to a firewall policy can inspect and block HTTPS traffic even when the policy itself allows the service. Since the server is reachable from other VLANs and the policy explicitly permits HTTPS with NAT disabled and logging enabled, the most likely cause is that a security profile is dropping or denying the traffic.

Exam trap

The trap here is that candidates often assume a policy allowing a service with NAT disabled is sufficient for reachability, overlooking that security profiles can independently block traffic at a higher layer, especially for HTTPS where inspection is required.

How to eliminate wrong answers

Option A is wrong because NAT is not required for reachability between internal VLANs; the server can send replies directly to the client's private IP address without NAT. Option B is wrong because the administrator has already confirmed there are no overlapping policies, so a deny policy above cannot be blocking traffic. Option D is wrong because the schedule is set to 'Always', meaning the policy is active at all times, and the users can access the internet, confirming the policy is not inactive.

773
MCQeasy

Which protocol does FortiGate use to synchronize sessions between HA cluster members?

A.HSRP
B.OSPF
C.VRRP
D.FGCP
AnswerD

FGCP (FortiGate Clustering Protocol) is FortiGate's proprietary protocol designed to synchronize firewall sessions, configuration, and state information across HA cluster members. It continuously replicates session tables, including NAT mappings, TCP state, and UDP flows, over a dedicated heartbeat or HA link, enabling transparent failover with no session interruption. FGCP supports both active-passive and active-active HA modes and is the correct answer because it directly fulfills the requirement of session synchronization.

Why this answer

FortiGate uses the FortiGate Cluster Protocol (FGCP) to synchronize session tables, configuration, and state information between HA cluster members. FGCP is a proprietary protocol that ensures seamless failover by replicating session data in real time, allowing the backup unit to take over active sessions without interruption.

Exam trap

The trap here is that candidates familiar with Cisco or open-standard redundancy protocols (HSRP, VRRP) may assume FortiGate uses one of those, but FortiGate relies on its proprietary FGCP for HA session synchronization.

How to eliminate wrong answers

Option A is wrong because HSRP (Hot Standby Router Protocol) is a Cisco-proprietary protocol for router redundancy, not used by FortiGate for session synchronization. Option B is wrong because OSPF (Open Shortest Path First) is a dynamic routing protocol for exchanging routing information, not for synchronizing sessions in an HA cluster. Option C is wrong because VRRP (Virtual Router Redundancy Protocol) is an open-standard protocol for default gateway redundancy, but FortiGate does not use it for session synchronization; FGCP is the dedicated HA protocol.

Page 10

Page 11 of 11

All pages