Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 76–150

773 questions total · 11pages · All types, answers revealed

Page 1

Page 2 of 11

Page 3
76
MCQmedium

An administrator notices that traffic to a particular subnet is being load-balanced across two WAN links, but they want all traffic to that subnet to use a single link. Which feature should be configured?

A.Policy routing
B.ECMP routing
C.Static route with higher distance
D.Route summarization
AnswerA

Policy routing (also called policy-based routing) uses a route map to match specific packet attributes—such as source IP, destination IP, or protocol—and forwards those packets to a defined next-hop or interface, bypassing the normal longest-prefix-match routing table lookup. For traffic to a particular subnet, this allows an administrator to override the default routing decision and force that traffic out a specific interface, which is exactly what the scenario requires.

Why this answer

Policy routing (also called PBR) allows you to override the routing table based on criteria such as source/destination IP, protocol, or port. By configuring a policy route that matches traffic to the specific subnet and sets the output interface to a single WAN link, you can force all that traffic to use one link instead of being load-balanced.

Exam trap

The trap here is that candidates often confuse ECMP load-balancing with the ability to pin traffic to a single link, mistakenly thinking that adjusting ECMP weights or distances will achieve the same result as policy routing.

How to eliminate wrong answers

Option B is wrong because ECMP (Equal-Cost Multi-Path) routing is exactly what causes load-balancing across multiple equal-cost routes; disabling or not using ECMP would not selectively force traffic to a single link without affecting other traffic. Option C is wrong because a static route with a higher distance would only be used as a backup if the primary route fails, but it does not prevent load-balancing when multiple equal-cost routes exist. Option D is wrong because route summarization aggregates multiple subnets into a single prefix to reduce routing table size, but it does not control which link is used for traffic to a specific subnet.

77
MCQeasy

What is the default action of the implicit deny policy at the end of the firewall policy list?

A.Monitor (log only)
B.Allow
C.Deny
D.Redirect to authentication
AnswerC

Deny is correct because FortiOS includes an unmodifiable, last-resort implicit deny policy that drops any packet that does not match an explicit IPv4 or IPv6 firewall policy. This policy is evaluated only after all explicit policies have been checked and no match is found, meaning it effectively enforces a default-close security posture. It is not visible in the policy list, cannot be removed or reordered, and by default does not log, so administrators often create an explicit deny-all rule with logging to gain visibility into blocked traffic.

Why this answer

In FortiGate firewalls, the implicit deny policy at the end of the firewall policy list has a default action of 'Deny'. This means any traffic that does not match an explicit firewall policy is automatically dropped. This is a fundamental security principle to ensure that only explicitly permitted traffic is allowed through the firewall.

Exam trap

The trap here is that candidates may confuse the implicit deny with the 'deny' action available in explicit policies, or mistakenly think that the implicit deny can be changed to 'allow' or 'monitor' to simplify troubleshooting, but FortiGate's design enforces a strict default-deny stance for unmatched traffic.

How to eliminate wrong answers

Option A is wrong because 'Monitor (log only)' is not a default action for the implicit deny policy; logging is a separate setting that can be enabled on any policy, but the implicit deny itself does not log by default. Option B is wrong because 'Allow' would violate the security model of a firewall, which is designed to block unauthorized traffic by default; allowing all unmatched traffic would create a significant security hole. Option D is wrong because 'Redirect to authentication' is a feature used for captive portal or user authentication policies, not for the implicit deny; the implicit deny simply drops traffic without any redirection.

78
MCQhard

A FortiGate administrator runs the command 'diagnose application urlfilter 0 status' and sees 'status: enable' but users report that some malicious URLs are not blocked. The web filter profile uses FortiGuard categories with 'block' action. What should the administrator check next?

A.The antivirus profile is blocking URL filtering
B.The FortiGuard web filter rating service is reachable
C.The DNS filter is overriding the web filter
D.The firewall policy is set to 'accept' without inspection
AnswerB

For web filtering to function, the FortiGate must be able to contact the FortiGuard rating service to obtain URL category information. When the rating service is unreachable, the FortiGate may fall back to local cached ratings or fail open, allowing all URLs to pass if no local rating exists. Therefore, checking connectivity to FortiGuard servers is a primary diagnostic step. This is the correct explanation because without reachability, real-time URL categorization cannot occur.

Why this answer

The 'diagnose application urlfilter 0 status' command shows that the URL filter process is enabled locally, but if the FortiGate cannot reach the FortiGuard rating service, it cannot retrieve category ratings for URLs. Without a valid rating, the device may allow malicious URLs by default (depending on the 'unrated' action), even if the profile is set to block certain categories. Option B is correct because checking the reachability of the FortiGuard web filter rating service is the logical next step to diagnose why categories are not being enforced.

Exam trap

The trap here is that candidates assume 'status: enable' means the web filter is fully operational, but they overlook that the FortiGuard rating service must be reachable for category-based blocking to work; the exam tests whether you understand the difference between the local filter process being enabled and the external rating service being available.

How to eliminate wrong answers

Option A is wrong because antivirus profiles do not block URL filtering; they scan files for malware and operate independently of web filter category blocking. Option C is wrong because DNS filtering controls access based on domain reputation and can coexist with web filtering, but it does not override the web filter's category-based blocking; the issue is that categories are not being applied at all. Option D is wrong because if the firewall policy were set to 'accept' without inspection, no web filtering would occur at all, but the administrator already confirmed the URL filter status is 'enable', indicating inspection is configured; the problem is that the rating service is unreachable, not that inspection is missing.

79
MCQhard

An admin runs the command 'diagnose firewall iprope list 100000' and sees the following output: id=2000000000 action=deny flag=0x0 src-interface=any dst-interface=any proto=0 src-addr=0.0.0.0-255.255.255.255 dst-addr=0.0.0.0-255.255.255.255 What does this entry represent?

A.A loopback interface policy
B.The implicit deny policy at the end of the policy list
C.A user-created deny policy that blocks all traffic
D.A NAT policy that translates all addresses
AnswerB

The all-zero source and destination with proto=0 and deny action is the default drop rule FortiGate applies after all configured policies are evaluated. Its id=2000000000 confirms it is the final implicit deny, not an admin-created policy.

Why this answer

The output shows an entry with id=2000000000, action=deny, and source/destination addresses covering all possible IPs (0.0.0.0-255.255.255.255). In FortiGate, the implicit deny policy is automatically inserted at the end of the policy list with a high ID (typically 2000000000) and matches any traffic that hasn't been permitted by earlier policies. This is not a user-created policy but the built-in default deny rule.

Exam trap

The trap here is that candidates may confuse the high ID (2000000000) with a user-created policy or think it's a NAT rule, but FortiGate reserves this ID specifically for the implicit deny, which is automatically generated and cannot be manually created or removed.

How to eliminate wrong answers

Option A is wrong because a loopback interface policy would reference a specific loopback interface (e.g., 'loopback') in the src-interface or dst-interface field, not 'any'. Option C is wrong because user-created deny policies have IDs in the normal range (e.g., 1-65535), not the reserved high ID 2000000000, and they would not automatically cover all IP ranges unless explicitly configured. Option D is wrong because NAT policies are configured under 'config firewall policy' with action set to 'accept' and include NAT-related options (e.g., 'set nat enable'), not a deny action with a catch-all address range.

80
Multi-Selecthard

An administrator is configuring a FortiGate HA cluster in active-passive mode with two units. Which two conditions must be met for failover to occur? (Choose two.)

Select 2 answers
A.A monitored interface on the primary unit goes down
B.The primary unit loses all heartbeat communication with the secondary unit
C.The secondary unit receives a higher priority configuration
D.The primary unit's CPU usage exceeds 90%
E.The primary unit stops sending session synchronization packets
AnswersA, B

A monitored interface failing triggers failover because FortiGate HA actively tracks link health; when a monitored interface on the primary goes down, the cluster treats it as a failure condition and promotes the secondary. This satisfies the stem's requirement for a valid failover trigger in active-passive mode.

Why this answer

Option A is correct because in an active-passive FortiGate HA cluster, failover is triggered when a monitored interface (configured under config system ha with monitor-interface) goes down on the primary unit, causing the cluster to renegotiate and the secondary to take over. Option B is correct because loss of all heartbeat communication (via the HA heartbeat interfaces, using FGCP over UDP/703 or Ethernet frames) causes the secondary to conclude the primary has failed and assume the primary role. Option C is not correct because priority is only evaluated at cluster formation or when a unit rejoins; a higher priority on the secondary does not by itself force a failover of an established cluster.

Option D is not correct because CPU usage thresholds are not a native HA failover trigger in FortiOS. Option E is not correct because session synchronization packets are not heartbeats; stopping session sync alone does not trigger failover, only loss of heartbeat or a monitored interface failure does.

Exam trap

The trap is that candidates may think there are three valid failover conditions, but only two are standard. Often, they mistakenly include CPU threshold or session sync loss as triggers, but FortiGate HA does not use resource utilization or session sync status to initiate failover unless custom configurations are applied.

81
MCQeasy

Which security profile type requires a FortiSandbox license to enable advanced detection features?

A.Application Control
B.DNS Filter
C.Antivirus
D.Web Filter
AnswerC

Antivirus profile is the correct answer because FortiSandbox integration is a feature of the antivirus security profile in FortiOS. When an antivirus profile encounters an unknown file, it can send a copy to FortiSandbox for advanced static and dynamic analysis if the FortiSandbox license is available. This extends the signature-based antivirus capability to detect zero-day and advanced persistent threats. Without a license, the AV profile still scans using FortiGuard signatures, but cannot offload files to sandbox.

Why this answer

The Antivirus security profile (Option C) is correct because FortiGate's advanced antivirus features, such as outbreak prevention and cloud-based pattern matching, require a FortiSandbox license to offload suspicious files for dynamic analysis. Without this license, the antivirus engine relies solely on local signatures and cannot leverage sandboxing for zero-day threat detection.

Exam trap

The trap here is that candidates often assume all security profiles can leverage FortiSandbox for advanced detection, but only the Antivirus profile requires the license to enable its core advanced features like outbreak prevention and cloud-based pattern matching.

How to eliminate wrong answers

Option A is wrong because Application Control uses signatures and behavioral heuristics to identify applications, and its advanced features (e.g., cloud-based application database updates) do not require a FortiSandbox license. Option B is wrong because DNS Filter relies on FortiGuard DNS reputation and category databases, not sandbox analysis, to block malicious domains. Option D is wrong because Web Filter uses URL categorization and rating from FortiGuard, and while it can integrate with FortiSandbox for URL rating, the core filtering function does not require a sandbox license.

82
MCQmedium

A FortiGate administrator wants to ensure that in an active-passive HA cluster, a specific unit becomes the primary (active) unit after a reboot. Which configuration parameter should be set to a higher value on that unit?

A.HA session pickup delay
B.HA override
C.HA priority
D.HA group-id
AnswerC

HA priority is the configurable value (1 to 255, with higher being better) that directly determines which FortiGate unit becomes the active unit in an HA cluster. During the election process, the unit with the highest priority is selected as active; if priorities are equal, other factors like uptime and port monitoring are used as tie-breakers. This is the standard and primary method for controlling the active/standby role in FortiGate HA, making it the correct answer.

Why this answer

In a FortiGate active-passive HA cluster, the HA priority value determines which unit becomes the primary (active) unit. The unit with the higher priority value will be elected as the primary, provided that HA override is enabled. Therefore, setting a higher HA priority on the desired unit ensures it becomes active after a reboot.

Exam trap

NSE4 often tests the interaction between HA priority and HA override, and candidates may forget that override must be enabled for priority to take effect in preemption.

How to eliminate wrong answers

Option A is wrong because HA session pickup delay is used to delay session pickup after a failover to allow the network to converge, not to determine primary election. Option B is wrong because HA override is a setting that allows a unit with higher priority to preempt the current primary, but by itself it does not set the priority; it must be enabled along with a higher priority. Option D is wrong because HA group-id is used to identify the HA cluster and must match on all members; it does not influence primary election.

83
MCQhard

A FortiGate is configured with SSL inspection and web filtering. The administrator notices that some HTTPS traffic is being blocked even though the URL is in an allowed category. What could be the cause?

A.The FortiGate's DNS server is not resolving the domain correctly.
B.The web filter's 'allow' list is misconfigured.
C.The web filter profile has 'safe-search' enabled.
D.The SSL inspection profile has 'certificate-validation-failed' action set to 'block'.
AnswerD

When an SSL inspection profile has the 'certificate-validation-failed' action set to 'block', the FortiGate actively terminates the TLS handshake whenever the server certificate fails validation, such as due to an expired certificate, an untrusted CA, or a hostname mismatch. This action is evaluated during the SSL inspection proxy phase, before any decrypted content is passed to the web filter for URL categorisation. Consequently, the user sees a connection reset or block page even though the web filter profile itself may have no rule blocking the URL. This direct cause-and-effect matches the scenario exactly.

Why this answer

When SSL inspection is enabled, the FortiGate acts as a man-in-the-middle and validates the server's certificate. If the certificate is invalid (e.g., expired, self-signed, or mismatched), the FortiGate can block the session based on the 'certificate-validation-failed' action in the SSL inspection profile. Even if the URL belongs to an allowed web filter category, a failed certificate validation will cause the traffic to be blocked before the web filter policy is applied.

Exam trap

The trap here is that candidates often assume web filtering categories alone control HTTPS traffic, forgetting that SSL inspection's certificate validation can preemptively block sessions even for allowed URLs.

How to eliminate wrong answers

Option A is wrong because DNS resolution issues would prevent the FortiGate from reaching the server at all, but the symptom here is that HTTPS traffic is blocked specifically, not that the domain is unreachable. Option B is wrong because the 'allow' list being misconfigured would affect all traffic, not just HTTPS, and the question states the URL is in an allowed category, so the web filter should permit it. Option C is wrong because 'safe-search' enforces search engine restrictions (e.g., Google SafeSearch) and does not block entire HTTPS sessions; it modifies search queries, not certificate validation.

84
MCQeasy

What is the purpose of the 'override' setting in FortiGate HA?

A.It enables the higher-priority unit to reclaim the primary role after recovery
B.It allows management access to the cluster via a virtual IP
C.It disables HA failover during maintenance windows
D.It forces the secondary unit to become primary immediately
AnswerA

Override is an HA election control in FortiGate. When enabled, if a unit with a higher configured priority fails and later recovers, it will preempt the current primary (which may have a lower priority) and reclaim the primary role automatically. This ensures the preferred unit is always active after recovery, but it can cause a brief service interruption. Without override, the recovered higher-priority unit would rejoin the cluster as a secondary and remain so until the active primary fails.

Why this answer

The 'override' setting in FortiGate HA allows a higher-priority unit to reclaim the primary role after it recovers from a failure. Without override, the primary role does not automatically revert to the original unit even if it comes back online with a higher priority. This ensures predictable failback behavior.

Exam trap

NSE4 often tests the difference between HA priority and override, where candidates might think priority alone causes failback, but without override, the original primary does not automatically reclaim the role.

How to eliminate wrong answers

Option B is wrong because management access via a virtual IP is enabled by configuring an HA management interface, not by the override setting. Option C is wrong because disabling HA failover during maintenance is done by setting the device to standby or using maintenance mode, not by override. Option D is wrong because override does not force the secondary to become primary immediately; it only allows the higher-priority unit to take over when it is available.

85
MCQhard

You run the following diagnose command on a FortiGate and see the output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 ... What does the 'proto_state=01' indicate?

A.The session is UDP, indicated by proto_state 01
B.The session is in a half-open state (SYN_SENT)
C.The session has been fully established
D.The session is being terminated
AnswerB

proto_state=01 in a FortiGate session table represents TCP SYN_SENT, which occurs when a client has sent a SYN packet and is waiting for the server's SYN-ACK reply. This is a half-open state because the TCP three-way handshake has not yet completed; the connection is not fully established. If the handshake completes, the state advances to ESTABLISHED (06), so seeing 01 means the session is in the initial connection-attempt phase.

Why this answer

In FortiGate session diagnostics, 'proto_state=01' for a TCP session (proto=6) indicates the session is in a half-open state, specifically SYN_SENT, meaning the initial SYN packet has been sent but the three-way handshake has not yet completed. This is a transient state before the session becomes fully established (proto_state=02).

Exam trap

The trap here is that candidates confuse 'proto_state=01' with a fully established session because they see 'duration' and 'expire' values that look normal, not realizing that a half-open TCP session can still have a duration counter if the initial SYN was sent.

How to eliminate wrong answers

Option A is wrong because proto_state=01 is a TCP state indicator, not UDP; UDP sessions do not use proto_state values in the same way and proto=6 explicitly indicates TCP. Option C is wrong because a fully established TCP session is indicated by proto_state=02 (ESTABLISHED), not 01. Option D is wrong because a session being terminated would show a state like FIN_WAIT or TIME_WAIT, not proto_state=01 which represents an incomplete handshake.

86
MCQhard

An administrator configures a Central SNAT policy to translate traffic from the internal network (10.0.0.0/8) to the internet using the IP pool 'pool1'. The administrator also has a firewall policy that uses policy-based NAT with an IP pool 'pool2'. Both policies match the same traffic. Which NAT will be applied?

A.Central SNAT using pool1
B.Both NAT rules are applied in sequence
C.The traffic is dropped due to conflicting NAT configurations
D.Policy-based NAT using pool2
AnswerA

Central SNAT rules are evaluated before any policy-based NAT. In FortiGate's NAT execution order, central source NAT takes precedence over the NAT settings configured inside a firewall policy, so a matching central SNAT rule using pool1 is selected. The session's source IP is translated to an address from pool1, and the policy's NAT configuration is completely bypassed.

Why this answer

Central SNAT policies have higher priority than policy-based NAT when both match the same traffic. In FortiOS, Central SNAT is evaluated before firewall policies, and if a match is found, the policy-based NAT within the firewall policy is ignored. Therefore, pool1 is applied.

Exam trap

The trap here is that candidates assume policy-based NAT within a firewall policy takes precedence because it is more specific, but FortiOS gives Central SNAT higher priority regardless of specificity.

How to eliminate wrong answers

Option B is wrong because FortiOS does not apply both NAT rules in sequence; only the Central SNAT policy is used, and the policy-based NAT is bypassed. Option C is wrong because there is no conflict that causes traffic to be dropped; the system deterministically selects the Central SNAT policy. Option D is wrong because policy-based NAT using pool2 is overridden by the higher-priority Central SNAT policy when both match the same traffic.

87
MCQeasy

Which of the following log types on FortiGate records traffic that is denied by a firewall policy?

A.HA logs
B.Event logs
C.Traffic logs
D.Security logs
AnswerC

Traffic logs are the FortiGate log type that records every session attempt processed by the firewall, including both permitted and denied traffic. Each traffic log entry contains source and destination addresses, ports, service, action (allow/deny), policy ID, and byte counts, and it is generated from the session table when a session closes or at a configured periodic interval. This is the correct answer because traffic logs are specifically designed to log all session activity.

Why this answer

Traffic logs on a FortiGate record all traffic that passes through or is denied by the firewall, including the source/destination, service, action (accept/deny), and policy that matched. When a firewall policy blocks traffic, the deny action is captured in the traffic log with the corresponding policy ID, making it the correct log type for identifying denied sessions.

Exam trap

NSE4 often tests the confusion between traffic logs (per-session allow/deny records) and security logs (UTM inspection events) — candidates incorrectly assume any 'denied' event belongs in the security log category.

How to eliminate wrong answers

Option A is wrong because HA logs record high availability cluster events such as failover, heartbeat status, and synchronization issues between FortiGate units — they have nothing to do with per-session traffic decisions. Option B is wrong because event logs capture system-level events such as administrator logins, configuration changes, and system daemon activity, not individual traffic flows. Option D is wrong because security logs (also called security event logs) record IPS, antivirus, web filter, and other UTM inspection events — while a denied session may generate a UTM event, the canonical record of a policy deny is in the traffic log.

88
MCQhard

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is in established state and has been active for 1 hour
B.The session is in FIN_WAIT state
C.The session is in TIME_WAIT state and will close soon
D.The session is in SYN_SENT state waiting for a SYN-ACK
AnswerA

The session entry shows proto_state=01, which in Fortinet's session table maps to TCP-established. The duration field of 3600 is expressed in seconds, so the session has been continuously active for exactly one hour. This is the normal state for an ongoing HTTPS connection on port 443, so this option correctly interprets the output.

Why this answer

The output shows `proto=6` (TCP), `proto_state=01` (ESTABLISHED state per Fortinet's session state encoding), `duration=3600` seconds (1 hour), and `expire=3599` seconds (nearly full lifetime remaining). This indicates the session is actively established and has been ongoing for one hour, matching the description of an established state session.

Exam trap

The trap here is that candidates misinterpret `proto_state=01` as a generic 'active' state without knowing Fortinet's specific numeric encoding, leading them to confuse it with FIN_WAIT or TIME_WAIT states that have different numeric values and shorter expire times.

How to eliminate wrong answers

Option B is wrong because `proto_state=01` corresponds to TCP ESTABLISHED, not FIN_WAIT (which would be state 05 or 06 in Fortinet's session table). Option C is wrong because TIME_WAIT state (state 09) would show a short expire value near zero, not 3599 seconds, and the session is not closing soon. Option D is wrong because SYN_SENT state (state 02) would show `proto_state=02` and a very short duration, not 3600 seconds of activity.

89
MCQhard

An administrator configures a Virtual IP (VIP) to map public IP 203.0.113.10 to internal server 10.0.1.10 on port 443. The firewall policy uses the VIP as the destination address. External users report they cannot connect. The administrator checks the policy and sees the destination interface is 'wan1' and source interface is 'wan1'. What is the most likely issue?

A.The destination interface should be the internal interface, not wan1
B.The policy needs NAT enabled
C.The source interface should be the internal interface
D.The VIP is not associated with the policy
AnswerA

After the virtual IP (VIP) performs destination NAT (DNAT), the packet's destination IP becomes the internal server's private address. To deliver that packet, the firewall must route it out the interface that connects to that server, which is the internal interface. If the policy's destination interface is mistakenly set to wan1, the firewall will attempt to send the packet back out the WAN interface, causing the traffic to fail or be misrouted. Therefore, the destination interface must be the internal interface to match the post-DNAT forwarding path.

Why this answer

The VIP maps the public IP to the internal server, but the firewall policy's destination interface is set to 'wan1', which is the external interface. Traffic arriving on wan1 and destined for the VIP must be processed by a policy where the destination interface is the internal interface (e.g., 'internal' or 'lan') so that the firewall can route the decapsulated traffic to the private server. Setting the destination interface to wan1 prevents the firewall from forwarding the traffic to the internal network, breaking connectivity.

Exam trap

The trap here is that candidates often confuse the source and destination interface roles in a VIP policy, assuming the destination interface should match the incoming interface (wan1) rather than the internal interface where the server resides.

How to eliminate wrong answers

Option B is wrong because NAT is already implicitly handled by the VIP configuration; the VIP performs destination NAT (DNAT) and does not require an explicit NAT policy. Option C is wrong because the source interface should remain 'wan1' as traffic originates from the external network; changing it to the internal interface would block legitimate inbound traffic. Option D is wrong because the VIP is associated with the policy via the destination address field; the issue is the interface mismatch, not a missing association.

90
MCQeasy

An administrator wants to allow access to an internal web server from the internet using a public IP address 203.0.113.10. The internal server has IP 10.0.0.5. Which FortiGate feature should be configured to translate the destination IP?

A.Virtual IP (VIP)
B.Central SNAT
C.Policy-based routing
D.IP Pool
AnswerA

A Virtual IP (VIP) is the correct object for destination NAT on FortiGate. It maps an external public IP address (and optionally a port) to a private, internal server IP, so inbound traffic destined for the public address is forwarded to the internal web server. The translation applies to the destination address of the packet, exactly what is required to expose an internal web server to the internet.

Why this answer

A Virtual IP (VIP) is the correct feature because it performs destination NAT (DNAT), translating the public destination IP 203.0.113.10 to the internal server IP 10.0.0.5. This allows inbound traffic from the internet to reach the internal web server by rewriting the destination IP address in the packet header as it traverses the FortiGate.

Exam trap

The trap here is confusing destination NAT (VIP) with source NAT (IP Pool or Central SNAT), leading candidates to select a source NAT option when the question explicitly asks for destination IP translation.

How to eliminate wrong answers

Option B (Central SNAT) is wrong because Central SNAT is used for source NAT (SNAT), translating the source IP of outbound traffic, not the destination IP of inbound traffic. Option C (Policy-based routing) is wrong because policy-based routing controls the path a packet takes based on routing policies, not IP address translation. Option D (IP Pool) is wrong because an IP Pool is used for source NAT (SNAT) to translate the source IP of outbound traffic to a range of public IPs, not for destination translation of inbound traffic.

91
MCQhard

A FortiGate has a policy that allows traffic from 10.0.0.0/8 to any destination with NAT enabled using an IP pool 'Pool1' (203.0.113.10-203.0.113.20). The admin notices that internal servers using fixed ports (e.g., SIP) are failing. What is the likely cause?

A.The policy order is incorrect
B.The IP pool is configured with one-to-one NAT
C.The IP pool uses fixed port range, which should work
D.The IP pool is configured with overload (PAT), which changes source ports
AnswerD

Overload (PAT) translates many internal IPs to a single external IP by dynamically assigning unique source ports for each session. This changes the original SIP source port (e.g., 5060) to some random high port, breaking protocol expectations because SIP and RTP require consistent port mapping. The FortiGate's overload mode is exactly the condition that alters ports, leading to call setup and media failures. Thus, this is the correct explanation for the reported symptom.

Why this answer

When an IP pool is configured with overload (PAT), the FortiGate translates the source IP address and also changes the source port to a random high port. For protocols like SIP that rely on fixed source ports (e.g., UDP 5060), this port remapping breaks the application because the SIP server expects traffic from a specific port. Option D correctly identifies this as the root cause.

Exam trap

The trap here is that candidates assume any IP pool will preserve source ports, but overload (PAT) mode explicitly changes them, which breaks applications that require fixed source ports like SIP, DNS, or TFTP.

How to eliminate wrong answers

Option A is wrong because policy order is irrelevant here; the traffic is matching the correct policy, but the NAT behavior is causing the issue. Option B is wrong because one-to-one NAT preserves the source port, so fixed-port protocols like SIP would work; the problem is with overload (PAT) changing ports. Option C is wrong because a fixed port range in the IP pool does not prevent PAT from altering source ports; the pool's overload mode overrides any fixed port configuration.

92
MCQmedium

A network administrator configured an IPsec VPN between two FortiGates. Phase 1 is up, but Phase 2 fails to establish. The diagnose output shows 'no matching proposal'. What is the MOST likely cause?

A.The firewall policy allowing the VPN traffic is missing
B.The Phase 2 encryption and authentication algorithms do not match between peers
C.The pre-shared keys do not match
D.The remote gateway IP address is incorrect
AnswerB

Phase 2 negotiation requires both peers to select an identical set of encryption and authentication algorithms for the IPsec SA, such as AES256-GCM or AES128-SHA256, along with matching DH group and optional PFS. If the Phase 2 proposals are not aligned, the initiator's SA payload cannot find an acceptable combination in the responder's proposal list, causing a 'no proposal chosen' error and preventing the IPsec SAs from being created. This occurs after Phase 1 has already succeeded, which is exactly the symptom of a Phase 2-specific failure, such as when the tunnel status shows Phase 1 up but Phase 2 down.

Why this answer

The 'no matching proposal' error in Phase 2 indicates that the IPsec security association (SA) parameters—specifically the encryption algorithm, authentication algorithm, or Diffie-Hellman group—do not match between the two FortiGate peers. Phase 2 uses these proposals to negotiate the IPsec SA for protecting data traffic, and a mismatch prevents the tunnel from establishing. Since Phase 1 completed successfully, the pre-shared keys and gateway IP are already verified, isolating the issue to Phase 2 configuration.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 failures, assuming any 'no matching proposal' error relates to authentication or peer reachability, when it specifically points to mismatched IPsec SA parameters like encryption or authentication algorithms.

How to eliminate wrong answers

Option A is wrong because a missing firewall policy would not cause a 'no matching proposal' error; it would instead result in traffic not being matched to the VPN tunnel or being dropped after Phase 2 is up. Option C is wrong because mismatched pre-shared keys would cause Phase 1 to fail, not Phase 2, as Phase 1 authentication occurs before Phase 2 negotiation. Option D is wrong because an incorrect remote gateway IP would prevent Phase 1 from establishing, as IKE cannot reach the peer; Phase 2 cannot be attempted if Phase 1 is not up.

93
Multi-Selectmedium

A FortiGate administrator is troubleshooting why traffic from a specific host (10.0.1.100) to a web server (203.0.113.50) is being denied. The administrator has confirmed that a firewall policy exists that should allow the traffic. Which TWO diagnostic commands would help identify the issue?

Select 2 answers
A.get system performance status
B.diagnose firewall policy list
C.diagnose debug flow
D.execute ping-options source 10.0.1.100
E.diagnose sniffer packet any 'host 203.0.113.50' 4
AnswersB, C

Executing `diagnose firewall policy list` prints every firewall policy entry with its ID, sequence, source, destination, service, action, and status in the exact evaluation order. This lets an administrator verify that a policy allowing 10.0.1.100 to 203.0.113.50 actually exists, is enabled, and is not overshadowed by an earlier deny-all or more specific deny rule. Because FortiGate matches first-match, checking the ordered list is an essential step in confirming whether the configuration matches the expected permit.

Why this answer

'diagnose firewall policy list' displays the effective policy table, including policy IDs, match criteria, and action (accept/deny). This helps verify whether the policy intended for the traffic is actually present and in the correct order. Option C is correct because 'diagnose debug flow' enables real-time packet flow tracing, showing exactly which policy is matched (or not) and why the traffic is denied, such as a policy hit with action 'deny' or a session table lookup failure.

Exam trap

The trap here is that candidates often confuse packet sniffing (which shows raw traffic) with flow debugging (which shows the firewall's internal decision process), leading them to choose 'diagnose sniffer packet' instead of 'diagnose debug flow' for identifying policy-based denials.

94
MCQeasy

An administrator wants to send logs from a FortiGate to an external syslog server. Which log forwarding method should they configure?

A.Syslog
B.SMTP
C.NetFlow
D.SNMP
AnswerA

Syslog is the standard protocol for forwarding system logs from network devices to a centralized log collector. FortiGate supports sending syslog messages to external servers over UDP (default 514), TCP, or TLS, with configurable severity and formats like RFC 3164 or RFC 5424. This makes it the correct choice for delivering FortiGate's full event logs to an external system.

Why this answer

FortiGate supports external log forwarding via syslog, which is the standard protocol for sending event and traffic logs to a remote server. Configuring syslog on the FortiGate involves specifying the server IP, port (default 514), and facility, and it allows the FortiGate to send logs in a structured format that can be parsed by SIEM or log management tools. SMTP is for email alerts, NetFlow is for traffic flow metadata, and SNMP is for monitoring and traps, not for general log transport.

Exam trap

NSE4 often tests the confusion between log forwarding methods and monitoring protocols, so candidates might mistakenly choose SNMP or NetFlow because they are also used for network management, but only syslog is designed for sending detailed logs to an external server.

How to eliminate wrong answers

Option B is wrong because SMTP is used for sending email notifications or alerts, not for streaming logs to a syslog server. Option C is wrong because NetFlow exports summarized traffic flow information (IP addresses, ports, byte counts) for analysis, but it does not carry the detailed event logs that syslog provides. Option D is wrong because SNMP is a protocol for monitoring device health and receiving traps, not for forwarding full log messages to an external log server.

95
Multi-Selectmedium

A FortiGate has two firewall policies for HTTP traffic to the internet: Policy A (source: 10.0.1.0/24) and Policy B (source: 10.0.2.0/24). Both policies have the same destination and service. The admin wants to apply a traffic shaper to limit bandwidth for Policy B. Which TWO actions are correct? (Choose two.)

Select 2 answers
A.Apply the shaper to both policies and use a different shaper for Policy B
B.Use a QoS queue on the outgoing interface
C.Create a traffic shaping policy that matches Policy B's source and apply the shaper
D.Enable traffic shaping on the VDOM
E.Configure a traffic shaper and apply it directly to Policy B in the firewall policy settings
AnswersC, E

A traffic shaping policy (under Firewall Objects > Traffic Shapers or Policy & Objects > Traffic Shaping Policies) allows you to create a separate rule that matches traffic based on source and destination addresses, services, and even the firewall policy. By configuring a shaping policy that matches Policy B's source address and applying the desired shaper to it, you can shape exactly the traffic permitted by Policy B without modifying Policy A. This is a valid alternative to per-policy shaper assignment and is useful when you need to shape traffic across multiple policies or when the shaper should apply to both forward and reverse directions.

Why this answer

A traffic shaping policy can match the source address of Policy B (10.0.2.0/24) and apply a specific shaper, allowing granular bandwidth control without affecting Policy A. Option E is correct because FortiGate allows a traffic shaper to be applied directly within a firewall policy's 'Traffic Shaping' settings, which overrides any default or VDOM-level shaping. Both methods achieve the goal of limiting bandwidth for Policy B only.

Exam trap

The trap here is that candidates often think a QoS queue on the interface is sufficient for per-policy shaping, but it applies to all egress traffic indiscriminately, whereas FortiGate requires explicit shaper assignment at the policy or traffic shaping policy level to differentiate between source subnets.

96
MCQhard

An administrator configures an aggregate interface (port1 and port2) on a FortiGate. After connecting the switch ports, the aggregate interface shows 'down'. The individual member ports are up. What is the MOST likely cause?

A.The member ports are set to different speeds
B.The switch ports are not configured for LACP or static aggregation
C.The aggregate interface IP address is in the same subnet as the management interface
D.The FortiGate needs a reboot after creating an aggregate interface
AnswerB

An aggregate interface on a FortiGate requires the connected switch ports to be placed in a matching port-channel or LACP group. If the switch ports are left as ordinary access or trunk ports without LACP or static aggregation, the FortiGate does not receive the expected LACP protocol data units, and the aggregate interface remains down because the link-aggregation handshake never completes. This is the most common cause of an aggregate that is administratively up but physically down.

Why this answer

The aggregate interface remains down because the switch ports are not configured for LACP or static aggregation. For a FortiGate aggregate interface to come up, both the FortiGate member ports and the corresponding switch ports must be configured with the same aggregation protocol (LACP active/passive or static). Without this, the switch treats the ports as individual links, causing a mismatch that keeps the aggregate interface down.

Exam trap

The trap here is that candidates assume the aggregate interface will come up automatically if the member ports are physically up, overlooking the requirement for matching aggregation configuration on the switch side.

How to eliminate wrong answers

Option A is wrong because different speeds on member ports would cause the aggregate interface to fail to form or degrade performance, but the individual ports would still show up; the aggregate interface would not necessarily show 'down' due to speed mismatch alone, as FortiGate can still form an aggregate with speed differences in some configurations. Option C is wrong because an IP address conflict between the aggregate interface and the management interface would cause routing or connectivity issues, not prevent the aggregate interface from coming up at Layer 1/2. Option D is wrong because a reboot is not required after creating an aggregate interface; the interface state updates dynamically once the configuration and physical connections are correct.

97
MCQeasy

What is the purpose of enabling 'Safe Search' in a web filter profile on a FortiGate?

A.It blocks all searches containing the word 'safe'.
B.It redirects users to a safe landing page when a blocked site is accessed.
C.It forces search engines to filter explicit content from search results.
D.It encrypts search queries to protect user privacy.
AnswerC

Enabling Safe Search on a FortiGate instructs the device to enforce the SafeSearch parameter on supported platforms like Google, Bing, and Yahoo, forcing those engines to exclude adult and explicit material from query results. This is accomplished through URL parameter injection or API calls when the user's request is inspected, typically requiring HTTPS inspection to see and modify the query. It ensures that even if a user manually attempts to disable safe search in the browser, the security policy overrides the setting. This filtering shields users from pornography and violent content appearing directly in search result listings.

Why this answer

Safe Search in a FortiGate web filter profile forces supported search engines (e.g., Google, Bing, Yahoo) to filter explicit content from search results by appending specific URL parameters (e.g., `&safe=active` for Google) to search queries. This ensures that when users perform searches, the search engine's own safe search setting is enforced at the network level, preventing access to adult or inappropriate material regardless of the user's browser settings.

Exam trap

The trap here is that candidates often confuse Safe Search with URL filtering or block pages, thinking it blocks or redirects users, rather than understanding it modifies search engine parameters to filter content at the source.

How to eliminate wrong answers

Option A is wrong because Safe Search does not block searches containing the word 'safe'; it modifies search engine behavior to filter explicit content. Option B is wrong because redirecting users to a safe landing page when a blocked site is accessed is the function of a block message or replacement message, not Safe Search. Option D is wrong because Safe Search does not encrypt search queries; encryption of web traffic is handled by SSL/HTTPS inspection or VPN policies, not by the web filter profile's Safe Search feature.

98
Multi-Selectmedium

An administrator is troubleshooting an IPsec VPN between two FortiGates. Phase 1 is up but Phase 2 is down. The admin runs 'diagnose vpn ike log' and sees 'no matching proposal'. To resolve this issue, which TWO settings should be checked on both ends?

Select 2 answers
A.Phase 2 PFS (Perfect Forward Secrecy) group
B.Phase 1 authentication method
C.Phase 2 local and remote subnets
D.Phase 2 encryption algorithm (e.g., AES128, AES256)
E.Phase 1 encryption algorithm
AnswersA, D

Phase 2 'no matching proposal' commonly stems from PFS group mismatch. If one peer enables Perfect Forward Secrecy with a specific Diffie-Hellman group and the other uses a different group or disables PFS, the Phase 2 proposal cannot match, so both ends must use identical PFS settings.

Why this answer

The 'no matching proposal' error during Phase 2 negotiation means the two peers cannot agree on the Phase 2 (IPsec SA) parameters, so the administrator must verify the Phase 2 proposal settings on both ends. Option A is correct because the Phase 2 PFS (Perfect Forward Secrecy) group (e.g., DH group 5, 14, 19) is part of the Phase 2 proposal; if one side enables PFS with a different DH group than the other, or one side omits PFS entirely, the proposals will not match and Quick Mode will fail. Option D is correct because the Phase 2 encryption algorithm (e.g., AES128, AES256) must be identical on both peers; a mismatch in the encryption transform is a classic cause of 'no matching proposal' at Phase 2.

Options B and E are incorrect because the Phase 1 authentication method and Phase 1 encryption algorithm are negotiated during Phase 1 (Main/Aggressive Mode), and since Phase 1 is already up, those parameters have already matched successfully. Option C is incorrect because the Phase 2 local and remote subnets are the selectors used to build the IPsec SA; a subnet mismatch typically causes traffic to not match the tunnel or produces a 'no policy' or traffic-selector error, not a 'no matching proposal' error.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 parameters, assuming that a Phase 1 mismatch (like encryption algorithm or authentication method) could cause a Phase 2 'no matching proposal' error, when in fact Phase 2 has its own independent set of proposals including PFS and encryption algorithms.

99
Multi-Selecteasy

Which TWO statements about firewall policy order are true?

Select 2 answers
A.If a packet does not match any policy, it is allowed by default
B.Policies are evaluated in the order they appear (top-down)
C.A more specific policy should be placed below a less specific one to avoid shadowing
D.Once a policy is matched, subsequent policies are still evaluated for logging purposes
E.Policy order can be changed by dragging policies in the GUI or using CLI commands
AnswersB, E

FortiGate firewall policies are stored in an ordered sequence and are evaluated from top to bottom when a new session's first packet arrives. The first policy that matches the packet's attributes (source, destination, service, interface) is applied, and no further policies are checked. This first-match model ensures that the administrator's intended precedence dictates the outcome.

Why this answer

FortiGate firewalls evaluate policies sequentially from top to bottom. The first policy that matches the packet's source, destination, service, and other attributes is applied, and no further policies are checked. This top-down evaluation is fundamental to policy design and troubleshooting.

Exam trap

The trap here is that candidates often confuse the default action (implicit deny) with an allow-all, or they mistakenly think that logging can be performed by multiple policies after a match, when in reality only the matched policy's logging settings apply.

100
MCQmedium

An administrator is configuring a FortiGate in a transparent mode. Which of the following features is NOT available in transparent mode?

A.Source NAT
B.VLAN tagging
C.Intrusion Prevention System (IPS)
D.Security profiles (AV, web filter)
AnswerA

Source NAT is not available in transparent mode because the FortiGate acts as a Layer 2 bridge, forwarding frames based on MAC addresses without performing any Layer 3 routing decisions. NAT requires modifying source IP addresses during packet routing, which is inherently a Layer 3 function, so it cannot be applied to traffic that passes through transparently.

Why this answer

In transparent mode, the FortiGate operates as a Layer 2 bridge without routing capabilities, meaning it cannot perform Source NAT (SNAT) because SNAT requires Layer 3 routing to translate source IP addresses. Transparent mode does not have an IP address on its interfaces for routing, so features dependent on Layer 3 forwarding, such as NAT, are unavailable.

Exam trap

The trap here is that candidates often assume security features like IPS or AV require Layer 3 routing, but they actually operate at higher layers and work in transparent mode, while NAT is the only option that explicitly depends on Layer 3 functionality.

How to eliminate wrong answers

Option B is wrong because VLAN tagging is fully supported in transparent mode; the FortiGate can pass and even tag/untag VLAN frames as a Layer 2 device. Option C is wrong because IPS operates at Layer 2-7 and inspects traffic passing through the bridge, so it works in transparent mode without requiring Layer 3 routing. Option D is wrong because security profiles like antivirus and web filtering inspect application-layer content and are independent of Layer 3 routing, making them available in transparent mode.

101
MCQmedium

An administrator needs to block traffic from a specific geographic region (e.g., country) from reaching the corporate web server. Which type of address object should be used to define the source?

A.Wildcard FQDN object
B.FQDN object
C.Subnet object
D.Geography object
AnswerD

A geography object groups IP addresses by country, letting the policy match traffic by geographic origin rather than by individual IP or FQDN. This satisfies the requirement to block a specific region from reaching the web server without maintaining manual address lists.

Why this answer

A Geography object in FortiGate is specifically designed to represent traffic based on geographic location (e.g., country, continent). When used in a firewall policy's source field, it allows the administrator to block or allow traffic originating from an entire country without needing to manage individual IP addresses or subnets, leveraging FortiGate's GeoIP database.

Exam trap

The trap here is that candidates may confuse Geography objects with FQDN or Subnet objects, mistakenly thinking they can manually define country IP ranges via subnets, but FortiGate's GeoIP feature automates this with a dedicated object type.

How to eliminate wrong answers

Option A is wrong because a Wildcard FQDN object matches domain names with wildcard patterns (e.g., *.example.com) and is used for web filtering or DNS-based policies, not for blocking traffic based on geographic region. Option B is wrong because an FQDN object resolves to a specific IP address or set of IP addresses via DNS, which cannot represent an entire country's IP range. Option C is wrong because a Subnet object defines a specific IP range (e.g., 192.168.1.0/24) and would require manually aggregating all IP ranges for a country, which is impractical and error-prone.

102
MCQmedium

An administrator configures a captive portal on the FortiGate to authenticate guest users via a local user database. Users can connect to the SSID, but after entering credentials on the captive portal, they are not redirected to the internet. What is the most likely missing configuration?

A.A firewall policy allowing traffic from the captive portal interface to the internet with the user group
B.The DNS server is not configured on the FortiGate
C.The captive portal timeout is set too low
D.The SSID is not configured with the captive portal security mode
AnswerA

Authentication alone does not grant internet access; FortiGate requires a firewall policy permitting traffic from the captive portal interface outbound, referencing the authenticated user group. Without this policy, credentials succeed but no forwarding rule matches, so users are never redirected.

Why this answer

A captive portal authenticates users but does not automatically grant network access. A firewall policy must explicitly allow traffic from the captive portal interface to the internet and include the authenticated user group as a source. Without this policy, even after successful authentication, traffic is dropped and users are not redirected to the internet.

Exam trap

The trap here is that candidates assume captive portal authentication alone grants internet access, but FortiGate requires a separate firewall policy with the authenticated user group to allow traffic, and the exam tests this distinction between authentication and authorization.

How to eliminate wrong answers

Option B is wrong because DNS server configuration is not required for captive portal redirection; the FortiGate can use DNS proxy or forward queries without a local DNS server. Option C is wrong because a low captive portal timeout would cause the session to expire prematurely, but it would not prevent redirection after successful authentication. Option D is wrong because the SSID must already be configured with captive portal security mode for users to be prompted for credentials; if it were missing, users would not even see the captive portal page.

103
MCQmedium

A network administrator configures an IPsec VPN between two FortiGate devices. Phase 1 completes successfully, but Phase 2 fails to establish. The administrator runs 'diagnose vpn ike log' and sees the error 'proposal mismatch'. What is the MOST likely cause?

A.The IKE version is mismatched (IKEv1 vs IKEv2)
B.The pre-shared key is incorrect
C.The firewall policies are blocking IKE traffic on UDP port 500
D.The Phase 2 local and remote subnets do not match on both ends
AnswerD

During Phase 2, both peers exchange proxy IDs (traffic selectors) that define the exact local and remote subnets to be protected. For the IPsec SA to be established, the local selector on each peer must be the mirror image of the remote selector on the other peer. If the configured subnets differ on either side (for example, 192.168.1.0/24 versus 192.168.2.0/24), the IKE daemon rejects the proposal with a 'no proposal chosen' error, which is a Phase 2 proposal mismatch. While encryption or integrity algorithms can also cause a Phase 2 failure, mismatched subnet selectors are the most common issue in policy-based VPNs.

Why this answer

The error 'proposal mismatch' in the Phase 2 IKE log indicates that the IPsec security associations (SAs) proposed by one FortiGate do not match the configured Phase 2 parameters on the other. Since Phase 1 completed successfully, the IKE version and pre-shared key are already validated. The mismatch specifically refers to the local and remote subnet definitions, encryption algorithms, or authentication methods in the Phase 2 selectors.

Therefore, the most likely cause is that the Phase 2 local and remote subnets are not correctly mirrored on both ends.

Exam trap

The trap here is that candidates confuse Phase 1 and Phase 2 failures: because Phase 1 completed, they might incorrectly suspect pre-shared key or IKE version issues, but the 'proposal mismatch' error is specific to Phase 2 parameters like subnets or encryption settings.

How to eliminate wrong answers

Option A is wrong because an IKE version mismatch (IKEv1 vs IKEv2) would cause Phase 1 to fail, not Phase 2, and the error would typically be 'no proposal chosen' or 'version mismatch' during Phase 1 negotiation. Option B is wrong because an incorrect pre-shared key would prevent Phase 1 from completing, as it is used during IKE authentication (e.g., Main Mode or Aggressive Mode). Option C is wrong because firewall policies blocking UDP port 500 would prevent IKE packets from reaching the peer, causing Phase 1 to fail entirely, not just Phase 2.

104
MCQeasy

Which security profile is used to detect and prevent spam email messages?

A.DLP profile
B.Web filter profile
C.Email filter profile
D.Antivirus profile
AnswerC

The email filter profile is the dedicated antispam engine within FortiGate, combining sender IP/domain blacklists, DNS-based blocklists, and real-time content analysis with ML-based classification. It inspects SMTP sessions by examining the message envelope, MIME headers, and body against a library of spam signatures and heuristics, while also performing Sender Policy Framework, DKIM, and DMARC verification. This profile can automatically quarantine, tag, or drop unwanted messages, making it the correct choice for spam detection.

Why this answer

The Email Filter profile is specifically designed to detect and prevent spam by analyzing SMTP traffic, applying techniques such as DNS-based Blackhole Lists (DNSBL), email reputation filtering, and heuristic analysis to identify unsolicited bulk email. Unlike other security profiles, it operates at the application layer for email protocols (SMTP, POP3, IMAP) to enforce anti-spam policies.

Exam trap

The trap here is that candidates confuse the Email Filter profile with the Antivirus profile, assuming spam detection is part of malware scanning, but FortiGate separates these functions: Antivirus handles file-based threats, while Email Filter handles message-based classification.

How to eliminate wrong answers

Option A is wrong because DLP (Data Loss Prevention) profiles focus on detecting and blocking sensitive data (e.g., credit card numbers, PII) in transit or at rest, not on identifying spam patterns or email content classification. Option B is wrong because Web Filter profiles control HTTP/HTTPS traffic by categorizing URLs and blocking malicious or inappropriate websites, but they do not inspect email message headers or bodies for spam characteristics. Option D is wrong because Antivirus profiles scan for malware signatures and heuristics in files and attachments, but they lack the specific anti-spam engines (e.g., Bayesian filtering, greylisting) needed to detect unsolicited bulk email.

105
MCQmedium

A FortiGate administrator needs to prevent employees from using peer-to-peer file sharing applications such as BitTorrent. The administrator creates an application control profile with a rule to block the 'Peer-to-Peer' application category. After applying the profile to the firewall policy, users can still use BitTorrent. What is the most likely cause?

A.The application control profile is applied to the outbound policy but not to the inbound policy.
B.The application control profile is set to 'Monitor' instead of 'Block' for the Peer-to-Peer category.
C.BitTorrent is not a recognized application in the FortiGuard application control database.
D.The firewall policy has SSL inspection set to certificate inspection, so the FortiGate cannot see the application.
AnswerB

In FortiOS, an application control profile defines per-category actions such as Monitor, Allow, or Block. If the Peer-to-Peer category is left as 'Monitor', the FortiGate identifies BitTorrent, writes a log entry, but still forwards the packets, so employees can keep using it. Only changing the action to 'Block' (or adding a specific BitTorrent rule with block) will actually deny the traffic. Thus, the correct fix is to edit the profile's Peer-to-Peer setting to enforce blocking rather than merely monitoring.

Why this answer

In FortiGate application control, each application category can be set to 'Block', 'Monitor', or 'Allow'. If the administrator creates a profile with a rule for the 'Peer-to-Peer' category but leaves the action as 'Monitor' (the default in some cases), the FortiGate will only log the traffic and not block it. Therefore, users can still use BitTorrent.

The most likely cause is that the action is set to Monitor instead of Block.

Exam trap

NSE4 often tests the default action of application control rules, and candidates may assume that adding a category to a profile automatically blocks it, when in fact the action must be explicitly set to Block.

How to eliminate wrong answers

Option A is wrong because application control is typically applied to the outbound policy that carries the user traffic; applying it to the inbound policy is not required to block outbound P2P usage, and the question states the profile was applied to the firewall policy. Option C is wrong because BitTorrent is a well-known application in the FortiGuard database, so it is recognized. Option D is wrong because application control can identify P2P applications using deep packet inspection even with certificate inspection for SSL, though full SSL inspection may be needed for some encrypted P2P; however, the question's scenario does not indicate SSL inspection is the blocker, and the most direct cause is the action setting.

106
MCQmedium

You run 'diagnose debug application sslvpn -1' and see the following output: sslvpn: SSL VPN tunnel mode connection from 10.0.0.5:12345 to 192.168.1.100:443 sslvpn: User 'john' authenticated successfully sslvpn: Error: no matching policy for the request. What does this indicate?

A.There is no SSL VPN policy that allows the user to access the destination IP/port
B.The user's password has expired
C.The SSL VPN interface is administratively down
D.The FortiGate is not licensed for SSL VPN
AnswerA

The debug message 'no matching policy' occurs after a successful authentication exchange, indicating the FortiGate has already validated the user's credentials and is now performing a firewall policy lookup. For SSL VPN traffic to be permitted, a policy must exist on the SSL VPN interface (e.g., ssl.root) with the user's source, the destination IP/port, and the appropriate action. When none matches, the FortiGate drops the session and logs this exact error, even though the user is fully authenticated. Correctly diagnosing this requires checking `show firewall policy` for a rule that matches the tunnel traffic and the intended internal resource.

Why this answer

The error 'no matching policy for the request' indicates that the SSL VPN tunnel mode connection from user 'john' (source IP 10.0.0.5) to destination 192.168.1.100:443 did not match any SSL VPN policy configured on the FortiGate. SSL VPN policies define which users or user groups can access specific destination IP addresses and ports. Since authentication succeeded but no policy matched, the connection is denied at the policy layer, not due to authentication or interface issues.

Exam trap

The trap here is that candidates often confuse authentication success with authorization success, assuming that because the user authenticated, the connection should proceed, but SSL VPN policies are a separate authorization layer that must explicitly permit the destination.

How to eliminate wrong answers

Option B is wrong because the user 'john' authenticated successfully, as shown in the debug output, so an expired password would have caused an authentication failure, not a policy mismatch. Option C is wrong because if the SSL VPN interface were administratively down, the debug output would show a connection failure or interface error, not a successful authentication followed by a policy error. Option D is wrong because a licensing issue would typically prevent the SSL VPN service from starting or accepting connections entirely, not allow authentication and then fail on policy lookup.

107
MCQhard

A FortiGate administrator is configuring ZTNA to secure access to an internal application. The administrator creates a ZTNA access proxy and a ZTNA rule. However, users connecting from the internet receive a 403 Forbidden error. The administrator verifies that the users are authenticated and the application is reachable. What is the MOST likely cause?

A.The firewall policy allowing traffic to the application is placed after a deny-all policy
B.The application's IP address is not included in the ZTNA access proxy's destination
C.The ZTNA access proxy does not have a valid SSL certificate
D.The ZTNA rule requires a specific client posture tag that the users' devices do not have
AnswerD

A 403 Forbidden from a ZTNA access proxy typically means the proxy accepted the connection but the ZTNA rule's enforcement conditions were not satisfied. Specifically, if the ZTNA rule requires a client posture tag (e.g., 'OS-Updated' or 'Compliant') and the user's FortiClient does not report that tag, the proxy denies access, returning 403. This is the core posture-check mechanism of ZTNA, distinguishing it from network-level firewall rules or proxy-layer connectivity failures.

Why this answer

The 403 Forbidden error in ZTNA typically indicates that the client device does not meet the required security posture. Even though users are authenticated and the application is reachable, the ZTNA rule enforces a specific client posture tag (e.g., antivirus enabled, OS patch level) via FortiClient telemetry. If the device lacks the required tag, FortiGate denies access with a 403, as the ZTNA access proxy validates both identity and device compliance before proxying traffic.

Exam trap

The trap here is that candidates often assume a 403 Forbidden is always due to firewall policy misconfiguration or authentication failure, but in ZTNA, it specifically indicates a posture compliance failure enforced by the ZTNA rule's tag requirement.

How to eliminate wrong answers

Option A is wrong because firewall policy order is irrelevant in ZTNA; the ZTNA access proxy intercepts traffic at the application layer before any firewall policy is evaluated, and a deny-all policy after the ZTNA rule would not cause a 403 from the proxy itself. Option B is wrong because the ZTNA access proxy's destination is the application's FQDN or IP, and if the IP were missing, the proxy would return a 502 Bad Gateway or connection timeout, not a 403 Forbidden. Option C is wrong because an invalid SSL certificate would cause a certificate warning or error in the browser (e.g., NET::ERR_CERT_AUTHORITY_INVALID), not a 403 Forbidden; the proxy would still attempt the connection but the client would reject it.

108
Multi-Selecteasy

An organization wants to implement ZTNA (Zero Trust Network Access) on their FortiGate. Which TWO components are essential for ZTNA? (Select two.)

Select 2 answers
A.Client certificates for device posture verification
B.Identity Provider (IdP) for user authentication
C.A dedicated VPN tunnel
D.A static IP address for the client
E.A RADIUS server for two-factor authentication
AnswersA, B

In Fortinet ZTNA, client certificates serve as the primary mechanism for device posture verification. A certificate installed on an endpoint allows the FortiGate access proxy to verify that the device has been provisioned by the organization, is not compromised, and meets compliance requirements such as OS version, antivirus status, or patch level. This certificate-based device trust is crucial for zero trust because it ties the user's session to a validated, healthy endpoint, and it overrides any assumptions based on network location.

Why this answer

Client certificates are essential for ZTNA because they enable device posture verification, ensuring that only trusted and compliant devices can access protected resources. FortiGate uses client certificates to validate the device's identity and health status before granting access, which is a core principle of Zero Trust.

Exam trap

The trap here is that candidates often confuse ZTNA with traditional VPN solutions, mistakenly thinking a dedicated tunnel or static IP is required, when in fact ZTNA operates at the application layer without persistent network tunnels.

109
MCQmedium

A network administrator configures a new FortiGate as the default gateway for a subnet. The FortiGate has two WAN interfaces (port1 and port2) connected to different ISPs. The admin wants to load-balance outbound traffic across both links. Which configuration method will achieve this goal?

A.Configure a single default gateway and rely on ARP for failover
B.Configure a policy route for each subnet directing traffic to a different ISP
C.Configure two static default routes with different distances
D.Configure two static default routes with the same distance and metric
AnswerD

Two static default routes with equal distance and metric create ECMP, so the FortiGate distributes outbound sessions across port1 and port2. This satisfies the load-balancing requirement without policy routes. Unequal distance would make one route standby only, defeating the goal.

Why this answer

Configuring two static default routes with the same distance and metric enables ECMP (Equal-Cost Multi-Path) routing on FortiGate. This allows the FortiGate to load-balance outbound traffic across both WAN interfaces (port1 and port2) using a per-flow or per-packet algorithm, distributing sessions between the two ISPs.

Exam trap

The trap here is that candidates often confuse ECMP (same distance/metric) with floating static routes (different distances), mistakenly thinking that multiple default routes with different distances will load-balance, when in fact they only provide failover.

How to eliminate wrong answers

Option A is wrong because relying on a single default gateway with ARP failover does not provide load balancing; it only offers failover if the gateway becomes unreachable, and ARP is not a load-balancing mechanism. Option B is wrong because policy routes direct traffic based on source/destination criteria, not for general load balancing of all outbound traffic; they are used for selective routing, not equal distribution across two default paths. Option C is wrong because configuring two static default routes with different distances creates a primary/backup scenario (floating static route), where only the route with the lower distance is active, and the other is used only if the primary fails—no load balancing occurs.

110
MCQmedium

A FortiGate admin configures a remote user for SSL VPN tunnel mode. The user can connect but cannot access resources on the internal network. The admin checks the SSL VPN settings: tunnel mode enabled, split tunneling disabled. What is the issue?

A.The user's FortiClient is outdated
B.The SSL certificate is expired
C.The firewall policy from the SSL VPN interface to the internal network is missing or incorrectly configured
D.The user's client software is not configured to route all traffic through the tunnel
AnswerC

After the SSL VPN tunnel interface comes up, the FortiGate enforces its implicit-deny policy without a matching firewall rule; to reach internal servers, an explicit policy must exist with source set to the SSL VPN interface (e.g., ssl.vpn or ssl.root), destination set to the internal network, and appropriate services/action. A missing or misconfigured policy, such as using the wrong protocol, source address, or interface, silently drops the user's packets, which perfectly matches the symptom of a successful login but no access to internal resources.

Why this answer

When split tunneling is disabled, all traffic from the SSL VPN client is expected to be routed through the FortiGate. However, even with the tunnel established, the FortiGate must have a firewall policy that permits traffic from the SSL VPN interface (e.g., ssl.root) to the internal network interface, with the appropriate source (the user's assigned IP pool) and destination. Without this policy, packets are dropped by the FortiGate's implicit deny rule, preventing access to internal resources.

Exam trap

The trap here is that candidates assume a successful VPN connection automatically grants access to internal resources, overlooking the mandatory firewall policy that must explicitly permit traffic from the SSL VPN interface to the internal network.

How to eliminate wrong answers

Option A is wrong because an outdated FortiClient would typically cause connection failures or feature incompatibility, not a successful connection with no internal access. Option B is wrong because an expired SSL certificate would cause the SSL handshake to fail or generate a security warning, preventing the VPN tunnel from being established at all. Option D is wrong because when split tunneling is disabled on the FortiGate, the client is forced to route all traffic through the tunnel; the client's local routing configuration cannot override the server-side setting.

111
MCQhard

An administrator is configuring ZTNA on a FortiGate. The goal is to allow access to an internal web server only if the client device has a specific security posture (e.g., antivirus running). Which ZTNA component is responsible for verifying the client's security posture?

A.ZTNA access proxy
B.IPsec VPN interface
C.SSL VPN portal
D.FortiClient EMS
AnswerD

FortiClient EMS is the component that collects endpoint posture, compliance, and security status from managed FortiClient endpoints and reports that information to FortiGate through the EMS connector. It assigns ZTNA tags based on real-time endpoint telemetry, which FortiGate access proxy policies use to make allow or deny decisions. This makes FortiClient EMS essential for posture-aware ZTNA, as the FortiGate cannot independently assess endpoint trust.

Why this answer

FortiClient EMS (Endpoint Management Server) is the ZTNA component that verifies the client's security posture by collecting endpoint telemetry (e.g., antivirus status, OS patch level) and enforcing compliance policies. The FortiGate queries FortiClient EMS via the FortiTelemetry protocol to determine if the client meets the required security posture before granting access. Without EMS, the FortiGate has no mechanism to assess endpoint health in a ZTNA flow.

Exam trap

The trap here is that candidates confuse the ZTNA access proxy (which enforces the policy) with the component that actually verifies the client's security posture, leading them to select Option A instead of recognizing that FortiClient EMS is the dedicated posture verification engine.

How to eliminate wrong answers

Option A is wrong because the ZTNA access proxy handles traffic forwarding and access control decisions based on tags from EMS, but it does not directly verify client security posture—it relies on EMS for that verification. Option B is wrong because an IPsec VPN interface is a site-to-site or remote-access tunnel that provides network-layer connectivity, not endpoint posture assessment; it has no integration with FortiClient EMS for security checks. Option C is wrong because the SSL VPN portal is a web-based interface for remote access that can enforce some client checks (e.g., host check), but it is not the ZTNA component responsible for posture verification; ZTNA uses EMS for dynamic posture-based access, not the legacy SSL VPN portal.

112
MCQmedium

A company wants to ensure that administrative access to FortiGate is only allowed from the internal trusted network (192.168.1.0/24) and that all other access attempts are blocked. Which CLI command should the administrator configure first?

A.config system admin; edit admin; set trusthost 192.168.1.0 255.255.255.0; end
B.config system interface; edit port1; set allowaccess ping https ssh; end
C.config system global; set admin-http-redirect enable; end
D.set admin-sport 443
AnswerA

The 'trusthost' command under 'config system admin' defines an allowed source IP or subnet for administrative logins to that specific admin account. By setting '192.168.1.0 255.255.255.0', only clients originating from the 192.168.1.0/24 network can authenticate as 'admin' — all other source IPs are rejected at the management daemon level, regardless of credentials. This is the only provided option that actually restricts administrative access to a specific source address range.

Why this answer

The `config system admin` command with `set trusthost` restricts administrative login attempts to only the specified source IP address or subnet. By setting `trusthost 192.168.1.0 255.255.255.0`, the FortiGate will only allow admin access from the 192.168.1.0/24 network, blocking all other sources. This is the foundational step to enforce source-based access control for administrative interfaces.

Exam trap

The trap here is that candidates often confuse `set allowaccess` (which enables protocols on an interface) with `set trusthost` (which restricts source IPs for admin login), leading them to select Option B thinking it controls who can access the device.

How to eliminate wrong answers

Option B is wrong because `config system interface` with `set allowaccess` controls which administrative protocols (e.g., HTTPS, SSH, PING) are enabled on a specific interface, not the source IP addresses allowed to connect. Option C is wrong because `config system global` with `set admin-http-redirect enable` only redirects HTTP admin traffic to HTTPS for encryption, it does not restrict the source network of admin access. Option D is wrong because `set admin-sport 443` changes the administrative HTTPS port to 443 (or another port), but it does not filter which source IPs can reach that port.

113
MCQhard

An administrator is configuring HA on two FortiGates. Both units have the same model and firmware. When they are connected, neither unit becomes active. The admin checks the HA status and sees that the cluster is not formed. What is the MOST likely cause?

A.The heartbeat interface is not configured
B.The management interface is used as a heartbeat
C.The HA password is incorrect
D.The HA group-id does not match
AnswerA

In FortiGate HA, dedicated heartbeat interfaces are mandatory because they carry the Hello packets that allow units to discover each other and elect the active unit. If no heartbeat interface is configured, the FortiGates never exchange any HA traffic, so they remain in standalone mode even if all other HA settings, such as group ID and password, are correctly set. This is the most direct and fundamental cause of the inability to form a cluster.

Why this answer

For a FortiGate HA cluster to form, the heartbeat interfaces must be properly configured and connected. The heartbeat interface is used for HA synchronization and monitoring between the units. If the heartbeat interface is not configured, the FortiGates cannot communicate, and the cluster will not form, leaving both units in a non-active state.

Since both units have the same model and firmware, and the issue is that neither becomes active, the most likely cause is that the heartbeat interface is not configured.

Exam trap

NSE4 often tests the misconception that HA cluster formation only requires matching model, firmware, and HA password, overlooking the necessity of a properly configured heartbeat interface.

How to eliminate wrong answers

Option B is wrong because using the management interface as a heartbeat is not a recommended practice and would not prevent cluster formation if configured correctly; however, it is not the most likely cause when the heartbeat is not configured at all. Option C is wrong because an incorrect HA password would cause authentication failures, but the units would still attempt to form a cluster and might show specific error messages; moreover, the password is typically set during configuration and would be a less likely oversight if both units are newly configured. Option D is wrong because a mismatched HA group-id would prevent cluster formation, but it is a less common cause than a missing heartbeat interface configuration, especially when the units are connected and neither becomes active.

114
MCQmedium

A FortiGate is deployed at a branch office with a single WAN link. The administrator wants to ensure that the FortiGate itself can resolve external hostnames for features like FortiGuard lookups, but does not want internal clients to use the FortiGate as their DNS server. Which configuration should the administrator apply?

A.Configure a DNS filter profile on the outbound firewall policy and set the FortiGate as the primary DNS in the DHCP server.
B.Configure DNS servers under System > DNS on the FortiGate, and leave the internal interface DNS settings unchanged.
C.Set the FortiGate as a DNS forwarder under Network > DNS Servers and configure a firewall policy to allow DNS.
D.Enable DNS server on the internal interface and set the same DNS servers in the DHCP scope.
AnswerB

The System > DNS settings define the DNS servers the FortiGate uses for its own lookups, such as FortiGuard and DNS filtering. This does not enable the FortiGate to answer DNS queries from clients. Internal clients continue using their own DNS servers because the interface DNS settings are not modified.

Why this answer

The FortiGate needs its own DNS settings for system lookups, which are configured under System > DNS. This does not affect clients unless the interface DNS server feature is enabled or DHCP hands out the FortiGate as a DNS server. Leaving the internal interface DNS settings unchanged ensures clients continue using their own DNS servers.

Exam trap

The trap here is assuming that configuring DNS servers under System > DNS automatically makes the FortiGate a DNS server for connected clients.

115
Multi-Selectmedium

An administrator is configuring web filtering on a FortiGate. Which TWO statements about web filtering profiles are correct?

Select 2 answers
A.Web filtering profiles can be used together with application control profiles.
B.Web filtering profiles can only be applied to users who are authenticated.
C.Web filtering profiles can block access to websites based on URL categories and ratings.
D.Web filtering profiles are applied globally by default.
E.Web filtering profiles are used to configure SSL certificate inspection.
AnswersA, C

On FortiGate, web filtering and application control profiles are complementary UTM features that can both be inserted into the same firewall policy. A web filtering profile evaluates HTTP/HTTPS requests against URL categories and FortiGuard ratings, while an application control profile identifies and controls the applications traversing the network, regardless of the URL used. This allows you to block, for example, a URL category while simultaneously allowing or restricting the specific applications that the traffic uses.

Why this answer

Web filtering profiles and application control profiles operate independently at different layers of the FortiGate security fabric. Web filtering inspects HTTP/HTTPS traffic against URL categories and ratings, while application control identifies and controls application-level traffic (e.g., Facebook, Skype) using deep packet inspection. They can be applied together in a single security policy to provide layered protection without conflict.

Exam trap

The trap here is that candidates often confuse the scope of web filtering profiles, assuming they require authentication (B) or are global by default (D), or they mistakenly think SSL inspection is configured within the web filtering profile (E) instead of as a separate inspection profile.

116
MCQhard

A FortiGate administrator is diagnosing a performance issue. They notice that the CPU usage is consistently high. Which command can provide a real-time view of the processes consuming CPU?

A.get system performance status
B.diagnose sys session stat
C.diagnose debug flow
D.diagnose sys top
AnswerD

This command functions like the Linux 'top' utility, presenting a real-time, updating list of FortiOS processes with per-process CPU and memory consumption. It is the correct tool for identifying which specific process is causing high CPU during a performance issue. By observing the process list, an administrator can pinpoint the culprit, such as an overactive log daemon or the antivirus scanning engine, and take targeted action.

Why this answer

'diagnose sys top' provides a real-time, top-like view of running processes on the FortiGate, sorted by CPU and memory consumption, refreshing periodically. It is the correct tool to identify which specific process (e.g., ipsengine, wad, scanunitd) is driving sustained high CPU. This directly answers the need for a live process-level CPU view.

Exam trap

NSE4 often tests the distinction between summary performance commands ('get system performance status') and live per-process monitoring ('diagnose sys top'), so candidates choose the summary command thinking it shows process-level detail.

How to eliminate wrong answers

Option A is wrong because 'get system performance status' gives a one-shot summary of overall CPU, memory, and uptime averages, not a per-process real-time breakdown. Option B is wrong because 'diagnose sys session stat' reports session table statistics (session counts, setup rates) and does not show process CPU usage. Option C is wrong because 'diagnose debug flow' traces individual packet flows through the policy engine and is used for traffic troubleshooting, not for identifying CPU-consuming processes.

117
MCQeasy

Refer to the exhibit. An administrator has configured the SSL/SSH profile shown. However, users are unable to access HTTPS websites. What is the most likely cause?

A.The 'untrusted-caname' should be set to a trusted CA certificate to handle untrusted server certificates.
B.The port is set to 443, but HTTPS also uses port 8443.
C.The 'caname' is set to 'Fortinet_CA_SSL', which is not a valid certificate name.
D.The 'whitelist-mode' is disabled, which prevents inspection.
AnswerA

In FortiGate SSL inspection profiles, the 'untrusted-caname' parameter specifies a CA certificate used to re-sign server certificates that are not already trusted by the FortiGate, such as self-signed or internally issued certificates. If this field is left blank or points to an untrusted CA, the FortiGate will fall back to a default CA that clients do not recognize, causing certificate validation warnings and potential connection failures in web browsers. To ensure seamless inspection of sites with untrusted server certificates, the administrator must assign a trusted CA—typically the FortiGate's built-in CA or a corporate CA—so clients accept the re-signed certificates without alerts.

Why this answer

When the SSL/SSH profile has 'untrusted-caname' set to 'Fortinet_CA_SSL' (an untrusted CA), the FortiGate cannot re-sign certificates from untrusted servers with a trusted CA. This causes HTTPS websites to fail as the client receives an untrusted certificate warning or connection error. Setting 'untrusted-caname' to a trusted CA certificate ensures that even untrusted server certificates are re-signed with a certificate the client trusts.

Exam trap

The trap here is that candidates confuse the 'caname' and 'untrusted-caname' fields, assuming any CA name is sufficient, without understanding that the CA must be trusted by the client for the re-signed certificate to be accepted.

How to eliminate wrong answers

Option B is wrong because HTTPS uses port 443 by default, and the profile is configured for port 443; port 8443 is an alternative HTTPS port but not required for standard HTTPS access. Option C is wrong because 'Fortinet_CA_SSL' is a valid default certificate name used by FortiGate for SSL inspection; the issue is not the name but its trust status. Option D is wrong because 'whitelist-mode' being disabled is the default and does not prevent inspection; it simply means all traffic is inspected unless explicitly whitelisted.

118
MCQmedium

A network administrator is troubleshooting why certain web-based applications are not being identified by application control. The applications are accessed over HTTPS. What is the most likely missing configuration?

A.Web filter profile is not applied to the firewall policy.
B.SSL inspection is not configured and applied to the firewall policy.
C.Deep packet inspection is not enabled on the firewall policy.
D.IPS is not enabled on the firewall policy.
AnswerB

Application control must inspect the contents of an HTTP conversation to identify the application; but when the session is HTTPS, the payload is encrypted and opaque to the security engine. Without an SSL/SSH inspection profile applied to the firewall policy, FortiGate sees only the TLS handshake and the SNI field, so the protocol decoders cannot match application signatures. Enabling SSL inspection decrypts the HTTPS stream and makes the full payload available to application control. Therefore, the correct fix is to add and apply an SSL inspection profile on the same firewall policy that carries the application control profile.

Why this answer

Application control relies on inspecting the content of traffic to identify applications. When traffic is encrypted with HTTPS, the firewall cannot inspect the payload without decrypting it first. Therefore, SSL inspection must be configured and applied to the firewall policy to allow the FortiGate to decrypt the traffic and match it against application control signatures.

Exam trap

The trap here is that candidates confuse 'deep packet inspection' with 'SSL inspection,' but DPI is a broader concept that includes many inspection types, and the specific missing piece for HTTPS application identification is SSL inspection, not DPI as a whole.

How to eliminate wrong answers

Option A is wrong because a web filter profile controls access to URLs and categories, not the identification of applications; application control is a separate feature. Option C is wrong because deep packet inspection (DPI) is a general term that includes SSL inspection, but the specific missing configuration for encrypted traffic is SSL inspection, not DPI in general. Option D is wrong because IPS is an intrusion prevention system that detects and blocks threats, not a mechanism for identifying applications; it does not decrypt HTTPS traffic.

119
MCQeasy

A FortiGate administrator wants to allow traffic from the internal network to a specific external server using its fully qualified domain name (FQDN) rather than an IP address, because the server's IP changes frequently. Which type of address object should the administrator create for the destination?

A.Subnet object
B.Wildcard FQDN object
C.Geography object
D.FQDN object
AnswerD

An FQDN object represents a single, fully qualified domain name and dynamically resolves it to the current IP address at connection time. The FortiGate periodically refreshes the resolved IP addresses based on DNS TTL, so if the server's address changes, the policy remains valid without manual edits. This makes it the correct choice when allowing traffic to a specific server known by a domain name, especially when its IP is not static.

Why this answer

FQDN object. FortiGate FQDN objects resolve domain names to IP addresses dynamically, allowing the firewall to update the destination IP automatically when the server's IP changes. This is ideal for scenarios where the external server uses a fully qualified domain name and its IP address is not static.

Exam trap

The trap here is that candidates may confuse Wildcard FQDN objects (used for domain pattern matching) with standard FQDN objects (used for DNS resolution to a single IP), leading them to select Option B incorrectly.

How to eliminate wrong answers

Option A is wrong because a Subnet object defines a range of IP addresses using a network prefix (e.g., 10.0.0.0/24), which cannot accommodate a dynamically changing IP address tied to an FQDN. Option B is wrong because a Wildcard FQDN object is used for matching multiple subdomains (e.g., *.example.com) in firewall policies, not for resolving a single FQDN to its current IP address. Option C is wrong because a Geography object identifies traffic based on geographic location (country or region) using IP geolocation databases, not by domain name resolution.

120
MCQhard

A FortiGate administrator has configured a hub-and-spoke IPsec VPN. The hub FortiGate has two Phase 2 selectors with spokes, but traffic between spokes is not routed via the hub. What must be configured on the hub to allow spoke-to-spoke communication?

A.Set the hub as the default gateway on each spoke
B.Use policy-based VPN instead of route-based
C.Configure NAT on the hub
D.Enable 'add-route' on the hub Phase 2
AnswerD

Enabling 'add-route' on the hub's Phase 2 configuration is the correct solution because it instructs FortiGate to automatically install static routes for each spoke's protected subnet via the respective IPsec tunnel interface. With these routes in place, when the hub receives traffic from one spoke destined for another spoke, it can route the packets out the appropriate tunnel. This eliminates the need for manual static routes or a dynamic routing protocol and is the intended method for simple hub-and-spoke IPsec VPNs.

Why this answer

In a hub-and-spoke IPsec VPN, the hub FortiGate must have 'add-route' enabled on its Phase 2 selectors to automatically install routes for the spoke subnets into its routing table. Without this, the hub knows how to reach each spoke but does not have routes to forward traffic between spokes, so spoke-to-spoke traffic is dropped. Enabling 'add-route' on the hub's Phase 2 configurations ensures the hub learns the remote subnets and can route traffic between spokes.

Exam trap

The trap here is that candidates often assume spoke-to-spoke communication requires only Phase 2 selectors to be configured, but they overlook the need for the hub to have routes to both spoke subnets, which 'add-route' provides automatically.

How to eliminate wrong answers

Option A is wrong because setting the hub as the default gateway on each spoke only ensures spokes send their default traffic to the hub, but does not install the necessary routes on the hub to forward traffic between spoke subnets. Option B is wrong because policy-based VPN does not inherently solve the routing issue; it still requires proper routing or policies to forward inter-spoke traffic, and route-based VPN is actually more flexible for hub-and-spoke topologies. Option C is wrong because NAT on the hub would hide spoke addresses and break direct spoke-to-spoke communication, as the hub would need to translate and forward traffic, which is not the intended solution.

121
MCQhard

A FortiGate has a policy that enables NAT with an IP pool that uses overload (port address translation). The administrator notices that some applications are failing because they require a fixed source port range. What should the administrator do to resolve this?

A.Change the IP pool type to 'Fixed Port Range'
B.Disable NAT and use policy-based routing
C.Use Central SNAT instead of policy-based NAT
D.Enable 'Preserve Source Port' in the firewall policy
AnswerA

In FortiOS, an IP pool configured as Fixed Port Range allocates source ports from a contiguous range for each NAT session rather than randomly selecting them as in Overload mode. This deterministic port assignment is essential when the destination service expects a stable or predictable source port per connection, such as legacy protocols or inter-server communications with port-based ACLs. Select this pool type in the IP pool configuration and reference it in the firewall policy's Dynamic IP Pool setting to satisfy the application requirement.

Why this answer

When an IP pool uses overload (PAT), the FortiGate dynamically assigns source ports from a default range (typically 1024-65535). Some applications require a fixed source port range (e.g., SIP or FTP) to function correctly. Changing the IP pool type to 'Fixed Port Range' allows the administrator to define a specific, static range of source ports that the FortiGate will use for NAT, ensuring the application receives traffic on the expected ports.

Exam trap

The trap here is that candidates may confuse 'Preserve Source Port' (a valid IP pool setting) with a firewall policy option, or assume that Central SNAT inherently provides fixed port ranges, when in fact the IP pool type must be explicitly changed to 'Fixed Port Range'.

How to eliminate wrong answers

Option B is wrong because disabling NAT and using policy-based routing would bypass NAT entirely, which does not address the need for a fixed source port range and could break connectivity for other traffic. Option C is wrong because Central SNAT is a different method of configuring NAT (centralized vs. policy-based) but does not inherently provide a fixed source port range; the IP pool type must still be set to 'Fixed Port Range'. Option D is wrong because 'Preserve Source Port' is not a valid option in FortiGate firewall policies; the correct feature to preserve the original source port is 'Preserve Source Port' in the IP pool configuration, not in the policy itself.

122
MCQhard

A FortiGate is configured in an HA active-passive cluster. The primary unit fails. After the secondary takes over, a policy route configured on the primary is not working. What is the MOST likely reason?

A.The secondary unit does not support policy routes
B.The policy route configuration is not synchronized in HA
C.The HA cluster requires a reboot after failover
D.The policy route references an interface that does not exist on the new primary
AnswerD

The most plausible cause is that the policy route specifies a destination or source interface that only exists on the original primary, not on the new primary. In an HA cluster, configuration is synced as a whole, but if the physical interfaces are named differently on the secondary (for example, due to different hardware models) or the interface is a VLAN/subinterface whose underlying port is not present, the policy route becomes invalid after failover. FortiGate will then skip or deactivate the route because the referenced interface is missing, resulting in traffic not being routed as expected.

Why this answer

When a FortiGate HA cluster fails over, the new primary unit assumes the configuration synchronized from the original primary. However, if a policy route references a specific interface (e.g., port1 or a VLAN subinterface) that is physically present on the failed unit but not on the new primary (or has a different name/index), the policy route will fail because the kernel cannot resolve the egress interface. FortiGate HA synchronizes the configuration, but interface mappings must match across cluster members for policy routes to work after failover.

Exam trap

The trap here is that candidates assume HA synchronizes everything perfectly, but they overlook that interface-dependent objects like policy routes can break if the physical interface mapping differs between cluster members.

How to eliminate wrong answers

Option A is wrong because FortiGate secondary units in an active-passive HA cluster fully support policy routes; there is no feature restriction based on role. Option B is wrong because HA synchronization includes policy route configuration by default (via the HA configuration synchronization mechanism), so the configuration is present on the secondary. Option C is wrong because HA failover does not require a reboot; the secondary takes over seamlessly without a reboot, and a reboot would only be needed if the cluster is recovering from a split-brain or other severe error.

123
MCQmedium

An administrator needs to configure a firewall policy that allows internal users to access a specific web server on the internet using its domain name. The web server's IP address may change. Which type of address object should be used as the destination in the policy?

A.IP Range object that covers the entire public IP space
B.Subnet object with the current IP address
C.FQDN address object
D.Geography object
AnswerC

An FQDN address object resolves the domain name to its current IP addresses and refreshes them via DNS, so the policy keeps working when the server's address changes. A static IP object would break on change, failing the requirement that the destination track the domain.

Why this answer

An FQDN (Fully Qualified Domain Name) address object allows the firewall to resolve the domain name to an IP address dynamically. This is essential when the web server's IP address may change, as the firewall will periodically perform DNS resolution to update the destination IP in the policy, ensuring continuous access without manual reconfiguration.

Exam trap

The trap here is that candidates often confuse FQDN objects with static DNS entries or assume a subnet object is sufficient, overlooking the dynamic IP change scenario that FQDN objects are specifically designed to handle.

How to eliminate wrong answers

Option A is wrong because an IP Range object covering the entire public IP space would allow traffic to any internet destination, violating the principle of least privilege and creating a massive security risk. Option B is wrong because a Subnet object with the current IP address is static; if the server's IP changes, the policy will fail to match the new IP, blocking access. Option D is wrong because a Geography object matches traffic based on geographic location (country), not a specific host or domain, and cannot ensure traffic reaches the correct web server.

124
MCQeasy

A network administrator wants to authenticate VPN users against an existing LDAP server. Which authentication method should be configured on the FortiGate?

A.FSSO
B.LDAP
C.RADIUS
D.Local
AnswerB

LDAP authentication is the correct choice because the FortiGate directly binds to the LDAP directory server using the user's distinguished name (DN) and supplied password. A successful bind indicates that the entered credentials are valid, and the FortiGate can also retrieve group memberships to apply access policies. This method validates the remote user against the central enterprise directory without storing passwords locally, making it ideal for a network that already relies on LDAP.

Why this answer

To authenticate VPN users against an existing LDAP server, the FortiGate must be configured to query the LDAP directory directly for user credentials. The LDAP authentication method (option B) allows the FortiGate to bind to the LDAP server using the user's DN and password, verifying identity against the directory. This is the correct choice because the question explicitly specifies an LDAP server, and FortiGate supports native LDAP authentication for SSL/IPsec VPNs without requiring an intermediate RADIUS or FSSO server.

Exam trap

The trap here is that candidates often confuse 'authentication source' with 'authentication method' and select RADIUS (option C) because they assume LDAP must be proxied through RADIUS, but FortiGate can authenticate directly against LDAP for VPN users without any intermediary.

How to eliminate wrong answers

Option A (FSSO) is wrong because FSSO (Fortinet Single Sign-On) is designed for transparent authentication of users on a Windows domain by polling domain controllers for login events, not for direct authentication of VPN users against an LDAP server; it requires a domain controller and does not perform credential validation against LDAP. Option C (RADIUS) is wrong because while RADIUS can proxy authentication to an LDAP server, it introduces an unnecessary intermediary and is not the direct LDAP authentication method the question asks for; the FortiGate can authenticate directly against LDAP without RADIUS. Option D (Local) is wrong because local authentication uses user accounts stored in the FortiGate's local database, not against an external LDAP server, and would require manual duplication of all LDAP users.

125
Multi-Selectmedium

A security administrator wants to ensure that all DNS queries from internal users are filtered to block access to known malicious domains. Which TWO configurations must be applied?

Select 2 answers
A.Enable deep inspection on the firewall policy
B.Apply the DNS Filter profile to the firewall policy that allows DNS traffic
C.Enable DNS inspection on the SSL/SSH inspection profile
D.Create a DNS Filter profile to block malicious domains
E.Configure a DNS server on the FortiGate
AnswersB, D

A DNS filter profile is a set of blocking rules and categories, but it is inert until it is attached to a firewall policy. When the policy matches DNS traffic, FortiGate applies the profile's rules — such as blocking malicious domains — and returns a 'blocked' response to the client. This is the enforcement point that makes DNS filtering actually work for traffic traversing the FortiGate.

Why this answer

Option B is correct because the DNS Filter profile only takes effect when it is attached to the firewall policy that permits the DNS traffic, so applying it to that policy is what actually enforces filtering on users' queries. Option D is correct because the DNS Filter profile itself is the object that defines which domains are blocked (e.g., via FortiGuard category-based filtering or static domain lists), so it must be created before it can be applied. Option A is not required because deep inspection applies to content/AV scanning of traffic, not to DNS query filtering.

Option C is incorrect because DNS inspection is not enabled through the SSL/SSH inspection profile; DNS filtering is handled by the DNS Filter profile. Option E is not needed because configuring a DNS server on the FortiGate does not filter or block malicious domains for internal users.

Exam trap

NSE4 often tests that DNS filtering requires both a profile and policy application, and candidates may mistakenly think deep inspection or SSL inspection is needed for DNS.

126
MCQmedium

A FortiGate is configured with an IPS profile to protect a web server. The administrator notices that some attacks are not being detected. The IPS signature database is up to date. What should the administrator check first?

A.Increase the severity level of the IPS sensor.
B.Ensure the IPS profile is applied to the firewall policy that handles traffic to the web server.
C.Disable flow-based inspection and enable proxy-based inspection.
D.Change the IPS signature action from 'default' to 'block'.
AnswerB

To protect a web server, the IPS profile must be attached to the firewall policy that controls access to that server, and that policy must actually match the traffic's source, destination, port, and interface. Without this attachment, the FortiGate forwards traffic based on the policy's action alone and never passes the packets to the IPS engine for inspection. Verify that the policy order places this rule before any catch-all policy, and confirm that the 'Security Profiles' section lists the desired IPS sensor; otherwise, the sensor is effectively dormant.

Why this answer

The most common reason an IPS profile fails to detect attacks is that the profile is not actually applied to the firewall policy processing the traffic. In FortiGate, an IPS sensor must be referenced in the security profile settings of the specific firewall policy that permits traffic to the web server. Without this binding, the IPS engine never inspects the packets, regardless of signature database freshness or sensor configuration.

Therefore, verifying policy association is the first and most fundamental troubleshooting step.

Exam trap

NSE4 often tests the misconception that IPS detection depends solely on signature database updates or sensor configuration, while overlooking the critical step of applying the IPS profile to the correct firewall policy.

How to eliminate wrong answers

Option A is wrong because increasing the severity level in the IPS sensor only changes which signatures are active based on severity; if the sensor is not applied to the policy, no signatures are evaluated at all. Option C is wrong because flow-based inspection is the default and fully supports IPS; switching to proxy-based inspection is not required for IPS detection and may introduce other issues. Option D is wrong because changing the action from 'default' to 'block' only affects whether a detected attack is blocked or allowed; it does not enable detection itself, and if the profile is not applied, no action occurs.

127
Multi-Selectmedium

An administrator is configuring policy-based routing (PBR) on a FortiGate to route traffic from a specific subnet (172.16.1.0/24) through a different internet connection (wan2) instead of the default route via wan1. The administrator has created a PBR rule matching source 172.16.1.0/24 and set the gateway to the next-hop IP on wan2. The traffic is still using wan1. Which THREE of the following could be causing the issue? (Choose three.)

Select 3 answers
A.The PBR rule's gateway is not reachable from the FortiGate
B.The PBR rule's priority is set too high (e.g., 100) and a static route with lower priority is used instead
C.The PBR rule is applied to the wrong incoming interface
D.The PBR rule is disabled
E.The PBR rule's destination is set to 'all' but the traffic's destination is not covered
AnswersA, C, D

For a PBR rule to be used, the FortiGate must be able to reach the configured gateway (next-hop). If the gateway is on a directly connected network, the FortiGate must resolve its MAC address via ARP; if the gateway is on a remote network, it must have a valid route to that gateway. When the next-hop is unreachable, the PBR rule is marked as inactive and is skipped during evaluation, causing the traffic to fall through to the normal routing table lookup. Even if a default static route exists, an unreachable PBR next-hop will never be used, so this directly explains why the rule is not matching.

Why this answer

PBR requires the specified next-hop gateway to be reachable via a directly connected route or a static route; if the gateway IP on wan2 is not reachable (e.g., due to a missing ARP entry or link failure), the FortiGate will fall back to the routing table and use the default route via wan1. The FortiGate performs a reachability check on the PBR gateway before applying the rule.

Exam trap

The trap here is that candidates often overlook the gateway reachability requirement for PBR, assuming any IP can be used as a next-hop, or they confuse PBR priority with static route administrative distance.

128
MCQmedium

A FortiGate administrator needs to integrate with FortiAnalyzer for centralized logging. After configuring the FortiAnalyzer IP and enabling logging, the FortiGate shows 'connection status: disconnected'. What is the most likely cause?

A.The FortiGate is in transparent mode.
B.The FortiAnalyzer firmware version is newer than the FortiGate's.
C.The administrator forgot to enable HTTPS for log upload.
D.The FortiGate does not have a route to the FortiAnalyzer.
AnswerD

Without a valid matching route to the FortiAnalyzer's IP address, the FortiGate cannot establish the TCP/HTTPS connection needed for log forwarding. The packet will be dropped, and the FortiGate will report communication failures or timeouts. This is a direct and necessary condition for successful integration, making it the correct explanation.

Why this answer

The most likely cause is that the FortiGate does not have a route to the FortiAnalyzer. Even with the correct IP and logging enabled, the FortiGate must be able to reach the FortiAnalyzer over the network; without a valid route, the TCP connection (typically on port 514 for syslog or port 443/541 for FortiGate-FortiAnalyzer protocol) will fail, resulting in a 'disconnected' status.

Exam trap

The trap here is that candidates often assume a configuration or protocol mismatch (like HTTPS or firmware version) is the cause, when the fundamental issue is simple network reachability—FortiGate cannot connect to FortiAnalyzer without a valid route.

How to eliminate wrong answers

Option A is wrong because transparent mode does not inherently prevent connectivity to FortiAnalyzer; the FortiGate can still send logs as long as it has a management IP and a route. Option B is wrong because firmware version differences do not cause a 'disconnected' status; FortiAnalyzer and FortiGate can interoperate across versions, though some features may be limited. Option C is wrong because HTTPS is not required for log upload; FortiGate typically uses syslog (UDP/TCP 514) or the FortiGate-FortiAnalyzer protocol (TCP 541) for logging, and HTTPS is used for web management, not log transport.

129
MCQhard

An admin is configuring a policy-based NAT rule (central NAT) to translate internal users' source IPs to the external IP of the FortiGate interface. However, users complain that some applications fail. The admin notices that the NAT rule is using 'dynamic IP pool' with overload. What is the MOST likely cause of the application failures?

A.The IP pool is exhausted and no more translations are available
B.The route to the destination is missing
C.The applications are sensitive to NAT and require a fixed port range
D.The firewall policy does not have NAT enabled
AnswerC

Several application-layer protocols, including SIP and FTP, embed IP addresses and TCP/UDP port numbers inside the payload. When overload NAT (PAT) dynamically assigns a different source port for each translation, the embedded port may no longer match the actual translated port, causing the peer to reject the session. A policy-based central NAT rule can be configured with a fixed port range or static port mapping, ensuring that the translated source port always matches what the application advertises. This is why application sensitivity is the correct reason for setting up such a NAT rule.

Why this answer

Applications sensitive to NAT, such as SIP, H.323, or FTP, often require a fixed port range or an explicit NAT rule that preserves the original source port. When a dynamic IP pool with overload (PAT) is used, the FortiGate may change the source port, breaking protocols that embed IP addresses or port information in the payload. This is the most likely cause of application failures in this scenario.

Exam trap

The trap here is that candidates often assume IP pool exhaustion (Option A) is the cause, but the question specifies 'some applications fail' rather than all traffic failing, pointing to application-layer NAT sensitivity rather than resource exhaustion.

How to eliminate wrong answers

Option A is wrong because an exhausted IP pool would cause new sessions to fail, but existing sessions would continue; the complaint is about application failures, not a complete inability to connect. Option B is wrong because a missing route would prevent all traffic to the destination, not just specific applications. Option D is wrong because the question states a policy-based NAT rule is configured, which inherently enables NAT; the firewall policy does not need a separate NAT enable checkbox when central NAT is used.

130
MCQeasy

A FortiGate administrator needs to authenticate VPN users against an LDAP server. What is the primary purpose of the 'CN=,OU=,DC=' distinguished name (DN) configured in the LDAP server settings?

A.It is used to encrypt LDAP communication
B.It defines the IP address of the LDAP server
C.It specifies the base DN for searching users
D.It specifies the bind user credentials to connect to the LDAP server
AnswerD

The DN and the associated password serve as the bind user credentials. When the FortiGate connects to the LDAP server, it performs a bind operation using this DN and password to authenticate itself before it can search for VPN users. This account must have read privileges over the user subtree to enable successful authentication and group lookups.

Why this answer

The DN configured in the LDAP server settings on FortiGate specifies the bind user credentials (username and password) that the FortiGate uses to authenticate itself to the LDAP server before performing user searches. This bind DN is required because LDAP servers typically require a valid authenticated session to query the directory; the bind DN provides the necessary identity and privileges for the FortiGate to search for VPN users.

Exam trap

The trap here is that candidates confuse the bind DN (used for authenticating the FortiGate to the LDAP server) with the base DN (used for searching user objects), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because LDAP encryption is configured separately via the 'Secure Connection' option (LDAPS or StartTLS), not by the DN field. Option B is wrong because the IP address of the LDAP server is configured in the 'Server IP/Name' field, not in the DN field. Option C is wrong because the base DN for searching users is configured in the 'Common Name Identifier' and 'Distinguished Name' fields under the user group or LDAP server's 'Member' settings, not in the bind DN field.

131
MCQmedium

An administrator is configuring a site-to-site IPsec VPN between two FortiGates. After applying the configuration, the VPN status shows 'down'. Phase 1 parameters are identical on both sides. What is the most likely cause of the failure?

A.The Phase 2 selectors (local and remote subnets) are mismatched.
B.The pre-shared keys do not match.
C.The firewall policies are not configured.
D.NAT traversal is disabled but both FortiGates are behind NAT.
AnswerA

Phase 2 selectors define which traffic is encrypted; mismatched local and remote subnet pairs cause the quick mode negotiation to fail even when Phase 1 succeeds, leaving the tunnel down. Identical Phase 1 parameters rule out authentication or encryption mismatches.

Why this answer

When Phase 1 parameters are identical and the VPN is down, the most common cause is a mismatch in Phase 2 selectors (local and remote subnets). Phase 2 uses these selectors to negotiate the IPsec security associations (SAs); if they do not match exactly on both sides, the IKEv1/v2 Quick Mode or Child SA exchange will fail, leaving the tunnel in a 'down' state even though Phase 1 (IKE SA) may be up.

Exam trap

The trap here is that candidates often assume a Phase 1 mismatch (like pre-shared keys) is the cause when the VPN is down, but the question explicitly states Phase 1 parameters are identical, forcing the focus to Phase 2 selector mismatches, which is a classic NSE4 exam trick.

How to eliminate wrong answers

Option B is wrong because if the pre-shared keys did not match, Phase 1 authentication would fail, and the VPN status would show 'down' with a Phase 1 error, but the question states Phase 1 parameters are identical, implying the pre-shared keys match. Option C is wrong because firewall policies are required to permit traffic through the tunnel, but their absence does not cause the VPN tunnel itself to be 'down'; the tunnel can be up even without policies, but traffic will not pass. Option D is wrong because NAT traversal (NAT-T) being disabled while both FortiGates are behind NAT would cause Phase 1 to fail due to encapsulation issues, but the question states Phase 1 parameters are identical and does not indicate a Phase 1 failure; NAT-T mismatch typically manifests in Phase 1, not Phase 2.

132
MCQmedium

A FortiGate administrator has configured a firewall policy with SSL deep inspection using a forward trust CA certificate. When users access an HTTPS website with a valid certificate, they still receive a certificate warning. What is the MOST likely reason?

A.The website certificate is expired
B.The forward trust CA certificate is not installed on the users' devices
C.The firewall policy is set to certificate inspection instead of deep inspection
D.The FortiGate's CA certificate is not trusted by the browser
AnswerB

SSL deep inspection re-signs each server certificate with the FortiGate's forward trust CA. Browsers only accept that forged certificate if the CA is trusted locally, so without the certificate installed in each device's trust store, every HTTPS site triggers a warning.

Why this answer

When SSL deep inspection is configured, the FortiGate generates a new certificate for each HTTPS session, signed by the forward trust CA. If the forward trust CA certificate is not installed in the trusted root store on the users' devices, the browser will not trust the generated certificate and will display a certificate warning. This is the most common cause of such warnings even when the original website certificate is valid.

Exam trap

The trap here is that candidates often confuse certificate inspection with deep inspection, or assume the FortiGate's own certificate is automatically trusted by clients, when in fact the forward trust CA must be explicitly deployed to all user devices.

How to eliminate wrong answers

Option A is wrong because if the website certificate were expired, the warning would be about an expired certificate, not a generic untrusted warning, and the question states the website has a valid certificate. Option C is wrong because certificate inspection does not re-sign certificates; it only checks the CN or SNI, so it would not cause a certificate warning from the browser. Option D is wrong because the FortiGate's CA certificate is the forward trust CA; if it were not trusted by the browser, that is exactly what option B describes — the CA certificate not being installed on the users' devices.

133
MCQeasy

A remote user reports that they can connect to the FortiGate SSL VPN portal but cannot access internal resources. The administrator checks the SSL VPN settings and sees that the tunnel mode is enabled with split tunneling. What is the most likely cause?

A.The IP pool is exhausted and no IP address was assigned.
B.The firewall policy allowing SSL VPN traffic to internal resources is missing.
C.The routing table on the client is missing the internal network routes.
D.The SSL VPN authentication timeout is too short.
AnswerC

This is the correct explanation. With split tunneling enabled, the FortiGate sends a list of internal subnets to the client, which must be installed into the client's routing table. If those routes are missing or incomplete, traffic destined for internal resources will be sent out the physical interface to the local gateway instead of into the SSL VPN tunnel, causing the connection to the FortiGate to succeed while internal resources remain unreachable. The user's report confirms the tunnel is up, so the next most logical place to look is the client-side routing table.

Why this answer

With split tunneling enabled, the FortiGate SSL VPN portal connection succeeds, but the client's routing table does not automatically include routes for the internal network. Without those routes, traffic to internal resources is sent to the default gateway instead of through the VPN tunnel, causing access failure. This is the most likely cause because the user can authenticate and establish the tunnel but cannot reach internal subnets.

Exam trap

The trap here is that candidates assume split tunneling automatically includes all internal routes, but in FortiGate SSL VPN, split tunneling requires explicit route configuration to direct internal traffic through the tunnel.

How to eliminate wrong answers

Option A is wrong because an exhausted IP pool would prevent the tunnel from establishing entirely, not just block resource access while the portal connects. Option B is wrong because a missing firewall policy would block all SSL VPN traffic, including portal access, not just internal resource access. Option D is wrong because an authentication timeout would cause disconnection or reauthentication prompts, not a persistent inability to access internal resources while remaining connected.

134
MCQhard

A network administrator is configuring a site-to-site IPsec VPN between two FortiGates. Phase 1 and Phase 2 are both up, but traffic is not passing through the tunnel. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which configuration change is most likely to resolve this issue?

A.Add a firewall policy that allows traffic from the local subnet to the remote subnet through the IPsec tunnel.
B.Modify the Phase 2 selector to match the remote subnet.
C.Configure a static route for the remote subnet pointing to the IPsec tunnel interface.
D.Enable 'auto-negotiate' in Phase 2 settings to allow dynamic routing.
AnswerA

The 'iprope_in_check() check failed' error indicates that the FortiGate is dropping packets due to a missing or misconfigured firewall policy. For traffic to pass through the IPsec tunnel, a firewall policy must explicitly allow traffic from the local subnet to the remote subnet, with the correct incoming and outgoing interfaces. Without this policy, the FortiGate drops the packets.

Why this answer

The error 'iprope_in_check() check failed, drop' is generated by the FortiGate when a packet is denied by a firewall policy. For IPsec VPN traffic to pass, a firewall policy must allow traffic from the local subnet to the remote subnet, with the correct source and destination interfaces. Even if Phase 1 and Phase 2 are up, without this policy, the FortiGate will drop the packets.

The administrator should verify that the policy exists and is correctly ordered.

Exam trap

The trap here is focusing on Phase 2 or routing when the error clearly indicates a firewall policy drop, so the missing policy is the actual cause.

135
MCQmedium

An administrator needs to configure a FortiGate to send logs to an external FortiAnalyzer. Which setting is required?

A.Setting the log disk quota
B.Configuring syslog server
C.Enabling FortiCloud logging
D.Configuring FortiAnalyzer under Log Settings
AnswerD

Configuring FortiAnalyzer under Log Settings is the correct procedure: in the FortiGate GUI, navigate to Log & Report > Log Config > Log Settings, and add a new FortiAnalyzer entry by specifying its IP address, serial number (optional), and communication settings. This enables the FortiGate to send logs to the FortiAnalyzer using the proprietary FortiAnalyzer protocol, which supports efficient log forwarding, encryption, and integration with FortiAnalyzer's analytics and reporting engines. It is the dedicated method for forwarding logs to a FortiAnalyzer device.

Why this answer

FortiGate uses the 'Log Device' or 'FortiAnalyzer' configuration to send logs to an external FortiAnalyzer.

136
MCQeasy

Which authentication method allows a FortiGate to transparently authenticate users based on their Active Directory login events without prompting for credentials?

A.RADIUS authentication
B.FSSO (Fortinet Single Sign-On)
C.Local database authentication
D.LDAP authentication
AnswerB

FSSO (Fortinet Single Sign-On) is the correct method because it actively monitors a domain controller for user logon events, either via a Collector Agent or by polling the Windows Security Log. When a user logs into the Windows domain, FSSO fetches the username and the workstation IP/MAC and sends this information to the FortiGate, which then automatically maps the user to the web filter, firewall policy, or application control profiles. The user is never prompted for authentication because the AD authentication is captured transparently, making FSSO the only listed option that meets the requirement.

Why this answer

Fortinet Single Sign-On (FSSO) allows FortiGate to transparently authenticate users by collecting login events from Active Directory domain controllers. It uses the NetAPI or a polling mechanism to capture user logon events without requiring any user interaction or credential prompts, enabling seamless identity-based policy enforcement.

Exam trap

The trap here is that candidates often confuse LDAP or RADIUS with SSO capabilities, but neither provides transparent authentication without credential prompts—only FSSO captures existing Windows logon events to achieve true single sign-on.

How to eliminate wrong answers

Option A is wrong because RADIUS authentication requires users to actively enter credentials (username/password) when prompted by the FortiGate, and it does not passively capture existing AD login events. Option C is wrong because local database authentication stores user credentials locally on the FortiGate and always prompts for manual login, lacking any single sign-on capability. Option D is wrong because LDAP authentication performs a direct bind to the LDAP server (e.g., Active Directory) using user-supplied credentials, which still requires a prompt and does not leverage pre-existing Windows logon events.

137
Multi-Selectmedium

An administrator configures a DLP profile to detect Social Security numbers in outbound traffic. The profile is applied to an outbound HTTP policy. Which TWO additional configurations are necessary for the DLP to inspect HTTPS traffic?

Select 2 answers
A.Set the firewall policy inspection mode to proxy-based
B.Add an SSL exemption for the destination servers
C.Enable SSL/TLS deep inspection on the firewall policy
D.Create a DLP sensor with the correct pattern and apply it to the policy
E.Configure a web filter profile to allow the traffic
AnswersC, D

SSL/TLS deep inspection is mandatory for DLP to detect sensitive data in HTTPS traffic. When enabled, FortiGate terminates the TLS session using its certificate as a trusted CA, decrypts the payload, and hands the plaintext to security profiles—including the DLP sensor—for inspection. Without deep inspection, only non-encrypted traffic or traffic subject to certificate inspection (which examines only certificate metadata) can be evaluated, making DLP blind to the content of an encrypted web session.

Why this answer

DLP inspection of HTTPS traffic requires the firewall to decrypt the encrypted payload. Enabling SSL/TLS deep inspection on the firewall policy allows FortiGate to perform man-in-the-middle decryption, re-encrypt, and then inspect the decrypted content for sensitive data like Social Security numbers. Without deep inspection, the DLP engine sees only encrypted traffic and cannot match patterns.

Exam trap

The trap here is that candidates often confuse SSL exemptions (which bypass inspection) with SSL deep inspection (which enables inspection), or assume that proxy-based mode alone is sufficient for HTTPS DLP, ignoring the mandatory decryption step.

138
MCQeasy

An administrator wants to troubleshoot a traffic flow issue on a FortiGate. They suspect packets are being dropped. Which command should they use to perform a real-time packet capture on an interface?

A.diagnose sniffer packet
B.get system performance status
C.diagnose sys session list
D.diagnose debug flow
AnswerA

diagnose sniffer packet is the standard FortiGate packet capture tool, analogous to tcpdump or Wireshark. It captures raw packets at the kernel level on specified interfaces or VLANs, displaying actual packet headers and payload in real time. This command is essential for analyzing the exact traffic content, checksums, and any malformed packets, making it the correct choice for troubleshooting traffic flow issues at Layer 2-4.

Why this answer

The command 'diagnose sniffer packet' is used on FortiGate to perform real-time packet capture on an interface. It allows administrators to see packet details, including headers and payloads, to troubleshoot traffic flow issues and identify dropped packets.

Exam trap

NSE4 often tests the distinction between packet capture tools (sniffer) and flow tracing tools (debug flow), causing candidates to confuse their specific purposes.

How to eliminate wrong answers

Option B is wrong because 'get system performance status' displays system resource usage (CPU, memory) and is not used for packet capture. Option C is wrong because 'diagnose sys session list' shows current session information but does not capture live packets. Option D is wrong because 'diagnose debug flow' traces packet flow through the FortiGate's policy engine and provides debug output, but it is not a packet capture tool; it shows how packets are processed, not the raw packets themselves.

139
Matchingmedium

Match each Fortinet security feature to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Detects and prevents network intrusions

Identifies and controls application traffic

Blocks access to malicious or unauthorized websites

Scans and removes malware from traffic

Decrypts and inspects encrypted traffic

Why these pairings

The correct matches are: Antivirus scans for malware, IPS detects network attacks, Application Control identifies applications, Web Filtering blocks websites. Common confusions include mixing antivirus with anti-spam and IPS with antivirus.

140
MCQmedium

A network administrator has configured a static route on a FortiGate with a distance of 10 and a priority of 0. Later, they add another static route to the same destination with a distance of 15 and priority of 0. Which route will be used for traffic forwarding?

A.The route with distance 15 because it has a higher priority
B.Both routes will be used for ECMP load balancing
C.The route with distance 15 will be used because it was added last
D.The route with distance 10 because it has a lower administrative distance
AnswerD

Administrative distance is the primary metric FortiGate uses to choose between routes to the same destination, with lower values being more trustworthy. A static route with AD 10 is considered more reliable than one with AD 15, so it is installed in the routing table and used for forwarding. Only if both routes had an equal AD would other factors like priority be considered as a tiebreaker.

Why this answer

The FortiGate uses administrative distance as the primary metric for route selection when multiple static routes exist to the same destination. A lower administrative distance (10) is preferred over a higher one (15), regardless of the order in which the routes were added. Priority (0 in both cases) is a tie-breaker only when distances are equal, so it does not affect this decision.

Exam trap

The trap here is that candidates often confuse administrative distance with priority or assume that the most recently added route takes precedence, but FortiGate strictly follows the lower administrative distance rule for route selection.

How to eliminate wrong answers

Option A is wrong because a higher distance value indicates lower preference, not higher priority; administrative distance is the primary metric, and lower is better. Option B is wrong because ECMP (Equal-Cost Multi-Path) requires routes to have the same administrative distance and metric; here distances differ (10 vs 15), so ECMP does not apply. Option C is wrong because the FortiGate does not use the order of addition as a routing decision factor; the route with the lower administrative distance is always preferred, regardless of which was added last.

141
Multi-Selectmedium

An admin needs to configure NAT so that internal users (10.0.0.0/24) accessing the internet (any destination) are translated using an IP pool (203.0.113.10-203.0.113.20) with overload. The admin also needs to ensure that traffic from a specific server (10.0.0.100) always uses a fixed source port range (10000-20000) when translated. Which TWO configuration steps are required? (Choose two.)

Select 2 answers
A.Configure the IP pool with one-to-one NAT
B.Create a central SNAT rule for 10.0.0.0/24 using the IP pool with overload enabled
C.Use policy-based NAT instead of central SNAT
D.Disable NAT on the firewall policy for the server
E.Create a central SNAT rule for 10.0.0.100 using the IP pool with fixed port range enabled
AnswersB, E

A central SNAT rule for 10.0.0.0/24 using an IP pool with overload enabled is the correct approach because it implements many-to-one NAT via Port Address Translation (PAT). This allows all internal users in the subnet to share the public IP addresses in the pool, with each connection being distinguished by its source port. Central SNAT is consulted before firewall policy lookup, making it efficient and independent of policy sequencing for simple outbound translation.

Why this answer

Central SNAT allows you to translate traffic from the entire 10.0.0.0/24 subnet using an IP pool (203.0.113.10-203.0.113.20) with overload (PAT), which is the standard method for enabling many internal users to share a smaller pool of public IPs. Option E is correct because you need a separate, more specific central SNAT rule for the server 10.0.0.100 that uses the same IP pool but with a fixed port range (10000-20000) enabled, ensuring its translated source ports always fall within that range.

Exam trap

The trap here is that candidates often think a single SNAT rule can handle both the subnet translation and the server's fixed port requirement, but FortiOS requires two separate rules with different specificity and the fixed port range option enabled only on the server's rule.

142
MCQhard

An admin runs the following command on a FortiGate: 'diagnose sys session filter dport 443' and sees output: 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate?

A.The session is stuck in a half-open state due to a firewall policy misconfiguration
B.The session is in the SYN_SENT state and is not yet fully established
C.The session is fully established and has been active for 3600 seconds
D.The session is using UDP protocol
AnswerB

In FortiGate session output, proto_state=01 maps to TCP SYN_SENT in the TCP state machine. This means the session originated with a SYN packet and is currently awaiting a SYN-ACK from the server; the three-way handshake has not yet completed. Therefore, the session is not fully established and should not be treated as an active, fully formed session. This is the correct interpretation of the diagnostic data.

Why this answer

The output shows 'proto=6' (TCP), 'proto_state=01', 'duration=3600', and 'expire=3599'. In FortiGate's session table, proto_state=01 for TCP indicates the SYN_SENT state, meaning the session has sent a SYN but has not yet received the SYN-ACK. This confirms the session is not fully established.

Option B correctly identifies this as a half-open session in the SYN_SENT state.

Exam trap

The trap here is that candidates often assume 'duration=3600' means the session has been active for an hour and thus must be established, but the proto_state field (01) overrides that assumption by indicating the session is still in the SYN_SENT phase of the TCP handshake.

How to eliminate wrong answers

Option A is wrong because a half-open state due to firewall policy misconfiguration would typically show a different state or no session at all; the session is present but in SYN_SENT, which is a normal TCP handshake phase, not a misconfiguration. Option C is wrong because a fully established TCP session would show proto_state=02 (ESTABLISHED), not 01, and the duration/expire values do not indicate establishment status. Option D is wrong because proto=6 explicitly indicates TCP, not UDP (which would be proto=17).

143
MCQeasy

Which log severity level indicates a failure that requires immediate attention?

A.Debug
B.Emergency
C.Warning
D.Information
AnswerB

Emergency is the highest severity level in FortiGate logging, reserved for conditions that render the system unusable or that require immediate administrator intervention, such as a detected power loss, fatal system error, or hardware malfunction. Unlike other levels, Emergency signals an active, often catastrophic failure that demands urgent action to restore service and prevent data loss or security compromise. This directly matches the question's requirement for a failure that necessitates immediate response, making Emergency the correct choice.

Why this answer

In Fortinet's FortiOS, log severity levels follow the standard syslog protocol (RFC 5424). The 'Emergency' level (severity 0) indicates a system is unusable or has experienced a critical failure that requires immediate administrator intervention, such as a hardware failure or a security breach. This is the highest severity level, designed to alert for urgent action.

Exam trap

The trap here is that candidates often confuse 'Warning' with a critical failure, but 'Warning' only indicates a potential problem, while 'Emergency' is the only level that signifies a system-wide failure requiring immediate attention.

How to eliminate wrong answers

Option A is wrong because 'Debug' (severity 7) is the lowest severity level, used for detailed troubleshooting information and does not indicate any failure. Option C is wrong because 'Warning' (severity 4) indicates a potential issue that might require attention but does not denote an immediate failure requiring urgent action. Option D is wrong because 'Information' (severity 6) is a normal operational message, such as a successful login or configuration change, and does not represent any failure.

144
MCQmedium

A FortiGate is configured with two WAN interfaces in an active-passive HA cluster. The administrator notices that the passive unit is not synchronizing configuration changes from the active unit. What is the MOST likely cause?

A.The HA heartbeat interface is not configured or is down.
B.The passive unit has a different firmware version.
C.The HA mode is set to active-active instead of active-passive.
D.The administrator must manually trigger a sync from the active unit.
AnswerA

Configuration synchronization in a FortiGate HA cluster depends on the heartbeat link, which carries both liveness detection and configuration/session sync traffic. If the heartbeat interface is not physically assigned or is down, the primary cannot push configuration updates to the secondary, even though the cluster may still be considered up. This results in configuration drift while failover behavior appears normal, exactly matching the symptom described in the question.

Why this answer

In an HA cluster, the heartbeat interface is responsible for synchronizing configuration changes and monitoring peer status between the active and passive units. If the heartbeat interface is not configured or is down, the passive unit cannot receive configuration updates from the active unit, leading to a synchronization failure. This is the most likely cause because without a functional heartbeat link, the cluster cannot maintain state or configuration consistency.

Exam trap

The trap here is that candidates often assume synchronization is triggered manually or that HA mode affects sync behavior, but FortiGate HA relies entirely on a functional heartbeat link for automatic configuration replication, regardless of the active-passive or active-active mode.

How to eliminate wrong answers

Option B is wrong because while different firmware versions can cause compatibility issues, the HA cluster typically prevents formation or logs a version mismatch error, but the passive unit would not even join the cluster; the question states the passive unit is present but not synchronizing, so a missing or down heartbeat is more likely. Option C is wrong because the HA mode (active-active vs. active-passive) affects failover behavior and load sharing, not the synchronization mechanism itself; both modes use the heartbeat interface for sync, so changing the mode would not prevent sync if the heartbeat is functional. Option D is wrong because configuration synchronization in FortiGate HA is automatic and continuous via the heartbeat link; there is no manual trigger required from the active unit—if the heartbeat is up, sync happens automatically.

145
MCQhard

A FortiGate is configured with two equal-cost default routes to different ISPs. The administrator notices that traffic for a specific destination is load-balanced across both links as expected. However, they want all traffic from a specific source IP to use only ISP1, while other traffic remains load-balanced. Which configuration should be applied?

A.Increase the administrative distance of the ISP2 default route to 20
B.Create a policy route with source address set to the specific IP and set the gateway to ISP1
C.Configure SD-WAN rules to steer the traffic
D.Add a static host route for the specific source IP via ISP1
AnswerB

Policy routes are evaluated before the routing table, so a route matching the specific source IP overrides the equal-cost default routes and forces that traffic out ISP1. Other sources match no policy route and remain load-balanced across both ISPs.

Why this answer

Policy routing allows you to override the routing table for specific traffic based on criteria such as source IP. By creating a policy route that matches the specific source IP and sets the next-hop gateway to ISP1, you ensure that traffic from that source always uses ISP1, while all other traffic continues to be load-balanced across both equal-cost default routes. This is the most direct and flexible method for source-based path selection without altering the global routing behavior.

Exam trap

The trap here is that candidates often confuse policy routing with static routing or administrative distance changes, mistakenly thinking that modifying route preference or adding a host route for the source IP will achieve source-based forwarding, when in fact policy routing is the only method that allows traffic selection based on source IP without affecting other traffic.

How to eliminate wrong answers

Option A is wrong because increasing the administrative distance of the ISP2 default route to 20 would make it less preferred than the ISP1 route (default AD 10), causing all traffic to use ISP1 only, not just traffic from the specific source IP. Option C is wrong because SD-WAN rules are designed for advanced traffic steering and load balancing across multiple WAN links, but they require SD-WAN to be enabled and configured, which is an unnecessary complexity for this simple source-based policy requirement; a policy route is the standard and simpler solution. Option D is wrong because a static host route is used for a specific destination IP, not a source IP; adding a static host route for the source IP would be syntactically incorrect and would not achieve the desired behavior.

146
Multi-Selecthard

A FortiGate administrator is troubleshooting an IPsec VPN that is dropping traffic intermittently. The administrator runs 'diagnose vpn ike log' and sees many 'DPD' messages. Which THREE conditions could cause frequent DPD (Dead Peer Detection) retransmissions? (Choose three.)

Select 3 answers
A.High network latency causing DPD timeouts
B.The remote peer is rebooting or unstable
C.Mismatched IKE version
D.Incorrect Phase 2 proxy IDs
E.A firewall between the peers dropping UDP port 500 packets
AnswersA, B, E

High network latency can exceed the DPD dead-peer detection timeout. When FortiGate sends R-U-THERE messages to the peer, it expects an ACK within a configured interval (often multiple retries with a given timeout). On WAN links with significant latency or jitter, that round-trip time can exceed the threshold, causing FortiGate to declare the peer dead and take down the VPN tunnel even though the remote peer is actually operational. This is a common cause of intermittent tunnel flaps on satellite or transcontinental links.

Why this answer

High network latency can cause DPD packets to exceed the configured timeout interval, triggering retransmissions. DPD relies on timely responses; if the round-trip time (RTT) consistently exceeds the DPD retry interval, the FortiGate will send repeated DPD messages, leading to intermittent traffic drops as the tunnel may be torn down.

Exam trap

The trap here is that candidates often confuse DPD retransmissions with Phase 2 misconfigurations, but DPD operates at Phase 1 and is unrelated to proxy IDs or IKE version mismatches, which prevent tunnel establishment entirely.

147
MCQeasy

In an active-active HA cluster, which of the following must be identical on both FortiGate units?

A.HA priority
B.Management IP address
C.Virtual cluster ID
D.Hostname
AnswerC

The virtual cluster ID is a mandatory HA parameter that must be the same on both units to ensure they belong to the same cluster and can synchronize correctly. This ID is used in heartbeat negotiation and for VDOM partitioning to separate multiple clusters on the same Layer 2 segment. If the virtual cluster IDs differ, the units will not form an HA cluster, even if all other settings are identical.

Why this answer

In an active-active HA cluster, the virtual cluster ID must be identical on both FortiGate units because it defines the cluster group and ensures that only units with the same ID can form an HA cluster. This ID is used in heartbeat packets to verify cluster membership and prevent accidental merging of separate clusters. Without a matching virtual cluster ID, the units will not recognize each other as part of the same HA group.

Exam trap

The trap here is that candidates often confuse 'must be identical' with configuration values that are typically synchronized (like priority or hostname), but the virtual cluster ID is the only parameter that must match before cluster formation can occur, while others can differ or are overwritten during synchronization.

How to eliminate wrong answers

Option A is wrong because HA priority determines the role (primary or secondary) within the cluster and can differ between units to establish a preferred leader; it does not need to be identical. Option B is wrong because the management IP address is a unique per-unit setting used for individual administrative access, and in an HA cluster, a separate virtual management IP (or floating IP) is used for cluster management, not the individual unit's management IP. Option D is wrong because the hostname is a local identifier for each FortiGate and can be different; it does not affect HA cluster formation or operation.

148
MCQmedium

An admin configures a firewall policy with a schedule object that restricts access to Monday to Friday from 9:00 to 17:00. A user attempts to connect on Saturday at 10:00. Which of the following best describes what happens?

A.The traffic is allowed because the schedule is only used for logging
B.The traffic is allowed because the schedule is optional
C.The FortiGate skips this policy and tries the next policy; if no match, implicit deny blocks the traffic
D.The traffic is denied because the schedule is not valid
AnswerC

During firewall policy lookup, the FortiGate checks all match criteria in sequence per policy, including the schedule. If the current time does not fall within the configured schedule for a policy, that policy is skipped and evaluation proceeds to the next policy with its own schedule and other conditions. If no subsequent policy matches, the packet is dropped by the implicit deny rule, which is the default drop-all behavior at the end of the policy table.

Why this answer

When a firewall policy includes a schedule, the policy is only active during the specified time. Outside that schedule, the policy is skipped entirely, and the FortiGate evaluates the next policy in the list. If no subsequent policy matches, the implicit deny rule at the end blocks the traffic.

Therefore, on Saturday at 10:00, the policy is skipped, and if no other policy allows it, the traffic is denied.

Exam trap

NSE4 often tests the behavior of schedules in firewall policies, and candidates may incorrectly think that the schedule itself denies traffic or that the policy is still evaluated but with a different action, rather than being skipped entirely.

How to eliminate wrong answers

Option A is wrong because schedules are not used for logging; they actively control whether a policy is enforced. Option B is wrong because schedules are not optional; if a schedule is configured, it dictates when the policy is active. Option D is wrong because the traffic is not denied by the schedule itself; the schedule simply makes the policy inactive, and the denial occurs due to the implicit deny if no other policy matches.

149
MCQmedium

A FortiGate administrator observes that traffic from a specific subnet is being denied even though there is an allow policy for that subnet. The administrator checks the policy list and sees an explicit deny policy above the allow policy. What should the administrator do to allow the traffic?

A.Add a new policy with a higher ID
B.Move the allow policy above the deny policy
C.Disable the deny policy
D.Delete the deny policy
AnswerB

FortiGate evaluates policies top-down and stops at the first match, so the explicit deny above the allow policy blocks the subnet before the allow is reached. Moving the allow policy above the deny makes it match first, satisfying the requirement to permit that traffic.

Why this answer

FortiGate policies are evaluated sequentially from top to bottom (lowest ID to highest ID). The first matching policy is applied. If an explicit deny policy appears above an allow policy for the same subnet, the deny policy will match first and drop the traffic.

Moving the allow policy above the deny policy ensures it is evaluated first, allowing the traffic.

Exam trap

The trap here is that candidates may think adding a new policy with a higher ID (Option A) will override the deny policy, but they fail to understand that FortiGate evaluates policies in order of ID (lowest to highest), so a higher ID policy is evaluated later and will never be reached if a deny policy with a lower ID matches first.

How to eliminate wrong answers

Option A is wrong because adding a new policy with a higher ID places it below the existing policies in the list, so it would still be evaluated after the deny policy and never be reached. Option C is wrong because disabling the deny policy is an unnecessary workaround that leaves a disabled policy in the configuration, potentially causing confusion and not addressing the root cause of policy ordering. Option D is wrong because deleting the deny policy is overly aggressive; the deny policy may be needed for other traffic, and the correct solution is to reorder policies rather than remove a potentially valid rule.

150
MCQmedium

An admin needs to allow traffic from a specific IP to a web server on port 8080. The web server is behind a VIP that forwards port 80 to port 8080. When configuring the security policy, which destination should be used?

A.The virtual IP address of the FortiGate
B.The real server IP address
C.The VIP object
D.Any destination, because the VIP translates automatically
AnswerC

The correct method is to define a firewall policy that uses the VIP object as the destination. The VIP object links the public IP to the internal server, and when a packet matches the policy, FortiGate automatically performs destination NAT, rewriting the destination to the real server IP. This policy also allows you to specify the allowed source IP, fulfilling the requirement to permit traffic from that specific IP to the web server.

Why this answer

When a VIP is used to translate the destination IP and port (e.g., from public IP:80 to private server IP:8080), the security policy must reference the VIP object as the destination. FortiGate matches the policy using the original destination IP before destination NAT is applied. The VIP object represents the original destination (the external IP) that clients use, so referencing it ensures the policy correctly permits the traffic.

Exam trap

The trap is that candidates may incorrectly select the real server IP (the post-NAT destination) instead of the VIP object. However, FortiGate checks the original destination IP against the policy, so the VIP object must be used as the destination.

How to eliminate wrong answers

Option A is wrong because the virtual IP address of the FortiGate (the interface IP) is not the destination after translation; the VIP object represents the translated destination, not the interface IP. Option B is wrong because the real server IP address is the internal, private IP of the web server, but the security policy must match the destination after NAT (the VIP object), not the pre-translation real server IP. Option D is wrong because the destination is not 'any'; the policy must explicitly specify the VIP object to correctly match the translated traffic, as the VIP translation does not automatically apply to all destinations.

Page 1

Page 2 of 11

Page 3

All pages