Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 151–225

773 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
MCQeasy

What is the purpose of the heartbeat interface in a FortiGate HA cluster?

A.To exchange HA heartbeat messages for health monitoring
B.To synchronize session tables and configuration
C.To provide out-of-band management access
D.To forward user traffic between cluster members
AnswerA

The heartbeat interface is dedicated to carrying HA heartbeat packets—typically UDP probes—that each cluster member sends and expects to receive. Loss of these heartbeats indicates a peer, link, or interface failure, prompting the primary unit to initiate failover and the backup to take over. Its sole primary purpose is to continuously assess peer liveness and trigger the designated failover logic, not to move user traffic or serve as a management path.

Why this answer

The heartbeat interface in a FortiGate HA cluster is dedicated to exchanging HA heartbeat messages between cluster members. These messages are used to monitor the health and availability of each unit, enabling failover detection and ensuring cluster stability. It does not handle session synchronization, management access, or user traffic forwarding.

Exam trap

The trap here is that candidates often confuse the heartbeat interface with the HA sync interface, assuming it handles session synchronization or configuration replication, when in fact it only performs health monitoring.

How to eliminate wrong answers

Option B is wrong because session table and configuration synchronization is performed over the dedicated HA sync interface, not the heartbeat interface. Option C is wrong because out-of-band management access is typically provided by a dedicated management interface or VLAN, not the heartbeat interface. Option D is wrong because forwarding user traffic between cluster members is the role of the cluster link or inter-chassis links, while the heartbeat interface only carries health-check messages.

152
MCQmedium

A FortiGate has multiple VDOMs. The administrator needs to allow traffic from VDOM A (port1) to VDOM B (port2). What type of firewall policy is required?

A.An inter-VDOM policy on the inter-VDOM link interface
B.A policy using a virtual wire pair
C.A regular intra-VDOM policy on VDOM A with destination interface port2
D.A policy on each VDOM with the same source/destination
AnswerA

An inter-VDOM link provides a virtual connection between two VDOMs, and traffic crossing that link is controlled by an inter-VDOM policy. This policy is configured on the inter-VDOM link interface and functions as a firewall rule that specifies permitted source/destination addresses and services between the VDOMs. Without this policy, the inter-VDOM link will deny all traffic by default, so it is the essential configuration element for inter-VDOM communication.

Why this answer

When traffic must cross from one VDOM to another on a FortiGate, an inter-VDOM policy is required. This policy is applied to the inter-VDOM link interface, which acts as the logical boundary between VDOMs. It allows the firewall to enforce separate routing and security contexts while forwarding traffic between VDOMs.

Exam trap

The trap here is that candidates often assume a regular intra-VDOM policy with a cross-VDOM destination interface will work, but FortiGate enforces strict VDOM isolation and requires the explicit inter-VDOM link and policy to route traffic between VDOMs.

How to eliminate wrong answers

Option B is wrong because a virtual wire pair is used to transparently bridge two interfaces within the same VDOM, not to route traffic between separate VDOMs. Option C is wrong because a regular intra-VDOM policy on VDOM A cannot specify port2 as the destination interface if port2 belongs to a different VDOM; the destination interface must be in the same VDOM. Option D is wrong because placing a policy on each VDOM with the same source/destination does not create an inter-VDOM link; inter-VDOM traffic requires a dedicated inter-VDOM link interface and a single inter-VDOM policy on that link.

153
MCQhard

An administrator runs 'diagnose debug flow' for a specific policy and sees the following output: id=20085 trace_id=10 func=vf_ip_route_in msg='No matching interface to route packet' What does this indicate?

A.The packet is being blocked by a firewall policy
B.The source interface is down
C.The destination IP address has no matching route in the routing table
D.The session table is full
AnswerC

The debug flow message 'No matching interface to route packet' means the FortiGate found no route entry for the destination IP, so the packet cannot be forwarded. The routing table lookup failed, indicating a missing or incorrect route rather than a policy or interface issue.

Why this answer

The trace indicates that FortiGate cannot find a route to forward the packet, meaning the destination is unreachable.

154
MCQhard

An administrator runs 'diagnose debug application ike -1' and sees the following output: ike 0:come to x.x.x.x:500, IKEv1, cookie 123456789abcdef0 ike 0:incoming IKE packet: src y.y.y.y:500, dst x.x.x.x:500, len 456 ike 0:send IKE packet: src x.x.x.x:500, dst y.y.y.y:500, len 456 ike 0:phase 1 negotiation failed due to time out. What is the likely cause?

A.The remote FortiGate's Phase 1 proposal does not match
B.A firewall rule is blocking UDP 500/4500 between the peers
C.The pre-shared key is incorrect
D.The local FortiGate's external interface is down
AnswerB

IKEv1 Phase 1 uses UDP port 500 for normal negotiation, and UDP port 4500 for NAT traversal and ESP-in-UDP encapsulation. If a firewall silently blocks these UDP ports, the outgoing IKE packets are dropped without any ICMP or TCP RST, so the initiator never receives a response. The FortiGate will retransmit the IKE SA proposal multiple times and, after exhausting retries, log a timeout with a 'negotiate' error. This matches the debug output showing packets sent but no reply, making a firewall rule blocking UDP 500/4500 the most likely cause of the timeout.

Why this answer

The output shows that the IKE packet is being sent and received (no proposal mismatch or interface down), but the negotiation fails due to a timeout. This indicates that the packet is leaving the local FortiGate but the response is not arriving back, which is classic behavior when a firewall (or ACL) between the peers is blocking UDP 500 or 4500. The timeout occurs because the remote peer never receives the initial packet or the local peer never receives the reply, preventing any IKE exchange from completing.

Exam trap

The trap here is that candidates see 'phase 1 negotiation failed due to time out' and incorrectly assume a configuration mismatch (like proposals or PSK), but the debug output clearly shows packets being sent and received locally, pointing to a network-level blockage rather than a VPN parameter mismatch.

How to eliminate wrong answers

Option A is wrong because a Phase 1 proposal mismatch would typically result in an immediate 'no proposal chosen' or 'attribute mismatch' error in the debug output, not a timeout after sending and receiving packets. Option C is wrong because an incorrect pre-shared key would cause a Phase 1 authentication failure (e.g., 'invalid cookie' or 'mismatch') after the proposal is accepted, not a timeout before any cryptographic exchange completes. Option D is wrong because if the local FortiGate's external interface were down, the 'send IKE packet' line would not appear, and the debug would show a local routing or interface error, not a timeout waiting for a response.

155
MCQhard

An admin configures an IP Pool with type 'Overload' for outbound traffic from the 192.168.1.0/24 subnet. The pool uses a single public IP 203.0.113.10. After a few hours, users are unable to access external websites. The admin checks the session table and sees many sessions with the same public IP and different source ports. What is the most likely issue?

A.The session helper is misconfigured
B.The IP Pool has run out of available source ports
C.The IP Pool's public IP has been blacklisted by external websites
D.The firewall policy is not referencing the IP Pool
AnswerB

With overload NAT (also called PAT or IP masquerading), all internal hosts are mapped to a single public IP address. The FortiGate must assign a unique source port number to each concurrent session per protocol (TCP and UDP have separate port spaces). The theoretical maximum is around 65,535 ports per protocol, minus reserved ports and those held in TIME_WAIT. When every available source port is already used, the IP pool becomes exhausted and the FortiGate cannot translate new sessions, causing connection failures for new traffic even though existing sessions continue to work.

Why this answer

The IP Pool is configured with type 'Overload' (Port Address Translation), which maps multiple internal hosts to a single public IP by using unique source ports. With a single public IP (203.0.113.10), the maximum number of concurrent sessions is limited by the available source ports (approximately 65,535 per IP, minus reserved ports). Once all source ports are consumed, new outbound sessions cannot be established, causing users to lose access to external websites.

Exam trap

The trap here is that candidates may confuse 'Overload' with 'Static NAT' or think the issue is policy-related, but the key clue is the session table showing many sessions with the same public IP and different source ports, which directly points to source port exhaustion under PAT.

How to eliminate wrong answers

Option A is wrong because a misconfigured session helper would affect specific application-layer protocols (e.g., FTP, SIP) by failing to translate embedded IP addresses or ports, not cause a complete exhaustion of source ports for all outbound traffic. Option C is wrong because blacklisting by external websites would block traffic to specific destinations, not prevent new sessions from being created due to port exhaustion; the session table would still show active sessions with the same public IP. Option D is wrong because if the firewall policy were not referencing the IP Pool, no NAT would be applied, and sessions would use the egress interface's IP directly, not the pool's IP; the symptom of many sessions with the same public IP and different source ports indicates that the IP Pool is indeed being used.

156
MCQhard

An administrator configures a policy-based NAT rule to translate traffic from 10.0.0.0/8 to 203.0.113.1 using an IP Pool with overload. Later, they also enable Central SNAT for the same traffic. The traffic is not being NAT'd as expected. What is the MOST likely reason?

A.Both NAT methods are applied, causing double NAT
B.Central SNAT overrides policy-based NAT
C.The IP Pool used in policy-based NAT is also used in Central SNAT, causing a conflict
D.Policy-based NAT always overrides Central SNAT
AnswerB

Central SNAT is evaluated before policy-based NAT, so once enabled it takes precedence and the policy-based rule no longer translates the 10.0.0.0/8 traffic. Disabling Central SNAT or consolidating the rules restores the intended overload translation.

Why this answer

Central SNAT (Source NAT) is a centralized NAT policy that takes precedence over policy-based NAT rules when both are configured for the same traffic. In FortiGate, Central SNAT is evaluated before policy-based NAT, and if a matching Central SNAT rule exists, it will override any policy-based NAT configuration. This is by design to provide a more predictable and manageable NAT architecture.

Exam trap

The trap here is that candidates often assume policy-based NAT is always applied because it is configured directly on the firewall policy, but FortiGate's Central SNAT has a higher precedence, leading to unexpected NAT behavior when both are enabled.

How to eliminate wrong answers

Option A is wrong because double NAT would occur only if both NAT methods were applied sequentially, but Central SNAT overrides policy-based NAT, so only one NAT translation is applied. Option C is wrong because using the same IP Pool in both Central SNAT and policy-based NAT does not inherently cause a conflict; the conflict arises from the precedence order, not the pool itself. Option D is wrong because policy-based NAT does not always override Central SNAT; in fact, Central SNAT has higher priority and overrides policy-based NAT when both are configured for the same traffic.

157
Multi-Selectmedium

An administrator needs to block users from uploading files containing credit card numbers to external websites. Which TWO actions must be configured? (Choose two.)

Select 2 answers
A.Apply an antivirus profile to the policy
B.Enable SSL deep inspection on the firewall policy
C.Create a DLP profile with a credit card number sensor set to block
D.Configure application control to block file transfer applications
E.Use a web filter to block all upload websites
AnswersB, C

Enabling SSL deep inspection on the firewall policy is a prerequisite for any content-aware inspection of HTTPS traffic. It forces the firewall to decrypt outbound SSL/TLS sessions so that security profiles, including DLP, can examine the actual file contents being uploaded. By itself it does not block uploads; rather, it provides the visibility needed for a DLP sensor to detect and enforce a block on credit card data. This step is essential because without decryption, the firewall would merely see encrypted bytes and cannot apply data-loss prevention rules.

Why this answer

SSL deep inspection is required to decrypt HTTPS traffic so the firewall can inspect the content of encrypted uploads for sensitive data like credit card numbers. Without decryption, the DLP profile cannot see the payload of encrypted sessions, rendering the DLP sensor ineffective.

Exam trap

The trap here is that candidates often forget that DLP requires SSL inspection to see the content of encrypted traffic, and mistakenly think a DLP profile alone is sufficient to block credit card numbers in HTTPS uploads.

158
MCQmedium

A FortiGate has two policies for traffic from port1 to port3: Policy 1 (destination 10.0.1.0/24, schedule always, action accept) and Policy 2 (destination 10.0.2.0/24, schedule 'Weekdays', action accept). A packet destined to 10.0.2.10 arrives on Wednesday at 2 PM. Which policy is applied?

A.Policy 2 because it matches the destination and the schedule is active
B.Both policies are applied sequentially
C.Neither; the implicit deny applies
D.Policy 1 because it is listed first
AnswerA

Policy 2 is the effective policy because FortiGate selects the first policy from the top that matches ALL required criteria: source interface/address, destination interface/address, service, and schedule. Policy 1 does not match the destination (its destination does not include port3 or the target IP), so it is skipped. Policy 2 matches the destination and its schedule is currently active, so it both matches and is the first matching policy; therefore traffic is permitted. In FortiGate's sequential top-down evaluation, only the first full match is used.

Why this answer

Policy 2 is applied because it matches the destination IP (10.0.2.10) and the schedule 'Weekdays' is active on Wednesday at 2 PM. FortiGate uses a first-match approach only when multiple policies have the same priority; here, Policy 1 does not match the destination, so Policy 2 is the only matching policy. Since the schedule is valid, the action 'accept' is executed.

Exam trap

The trap here is that candidates assume policy order alone determines matching (Option D), but they overlook that the destination must match first, and schedules must be active for the policy to be considered.

How to eliminate wrong answers

Option B is wrong because FortiGate does not apply multiple policies sequentially to a single session; it uses a first-match model where only the first matching policy is applied. Option C is wrong because the implicit deny only applies when no explicit policy matches the traffic, but Policy 2 matches and is active. Option D is wrong because Policy 1 does not match the destination (10.0.2.10 is not in 10.0.1.0/24), so it is not considered regardless of its order.

159
Multi-Selecthard

An administrator is configuring an active-passive HA cluster on two FortiGate devices. The administrator wants to ensure that the cluster can fail over if the primary unit's internal interface (port1) fails, and also wants to minimize the chance of a split-brain scenario. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Configure two heartbeat interfaces and enable heartbeat failover.
B.Configure port1 as a monitored interface in the HA settings.
C.Enable HA override to force the primary unit to always be primary.
D.Set the HA mode to active-active to avoid split-brain.
E.Enable session synchronization to prevent split-brain.
AnswersA, B

Configuring two heartbeat interfaces provides redundancy for heartbeat communication. If one heartbeat link fails, the other can still carry heartbeat packets, reducing the risk of split-brain. Enabling heartbeat failover allows the cluster to use the secondary heartbeat interface when the primary fails. This is a recommended practice to maintain cluster integrity and avoid both units becoming primary.

Why this answer

To fail over on internal interface failure, port1 must be monitored. To minimize split-brain, redundant heartbeat interfaces should be configured, and heartbeat failover should be enabled so that if one heartbeat link fails, the other maintains communication. Session synchronization and active-active mode do not prevent split-brain, and HA override does not address heartbeat redundancy.

Exam trap

The trap here is confusing session synchronization or HA override with split-brain prevention, when actually split-brain is mitigated by redundant heartbeat links.

160
MCQhard

A FortiGate in a hub-and-spoke VPN topology is configured with a single IPsec tunnel to each spoke. The hub has a route-based VPN with a tunnel interface for each spoke. After a reboot, traffic between spoke A and spoke B fails, although each spoke can reach the hub. What is the likely cause?

A.The hub is missing static routes to the spoke networks via the respective tunnel interfaces
B.The firewall policies on the hub do not allow traffic between the spoke networks
C.The spokes have mismatched IKE versions
D.The hub's IPsec Phase1 is not configured for DPD
AnswerA

In route-based IPsec VPNs, the hub must have a static route for each spoke's protected network, pointing to the corresponding tunnel interface. Without these routes, the hub cannot determine the correct egress tunnel for inter-spoke packets, so even though the IPsec tunnels are established and firewall policies permit the traffic, the packets are dropped or never forwarded. After a reboot, these static routes are critical because they are not dynamically learned unless a routing protocol is running over the tunnel.

Why this answer

In a hub-and-spoke route-based VPN, the hub uses tunnel interfaces for each spoke. After a reboot, the hub's routing table is cleared, and without static routes pointing to the spoke networks via the respective tunnel interfaces, the hub cannot forward traffic between spokes. Even though each spoke can reach the hub, inter-spoke traffic requires the hub to have explicit routes to the remote spoke networks, as dynamic routing protocols are not mentioned in this scenario.

Exam trap

The trap here is that candidates often assume firewall policies are the only control for inter-spoke traffic, overlooking that route-based VPNs require explicit routing entries on the hub to forward traffic between spokes.

How to eliminate wrong answers

Option B is wrong because firewall policies on the hub control whether traffic is allowed, but the question states traffic fails after a reboot, and each spoke can reach the hub, indicating the issue is routing, not policy. Option C is wrong because mismatched IKE versions would prevent the IPsec tunnels from establishing at all, yet each spoke can reach the hub, proving the tunnels are up. Option D is wrong because DPD (Dead Peer Detection) is used to detect tunnel failures, not to cause inter-spoke routing failures after a reboot; DPD misconfiguration would not prevent the hub from forwarding traffic between spokes.

161
MCQmedium

A FortiGate administrator wants to send logs to a FortiAnalyzer. The FortiAnalyzer IP is 192.168.1.100, and logging is configured under Log & Report. However, no logs are being received. Which command should the administrator use on the FortiGate to verify connectivity to the FortiAnalyzer?

A.diagnose log device status
B.execute ping 192.168.1.100
C.show full-configuration log fortianalyzer
D.get system ha status
AnswerA

diagnose log device status is the correct diagnostic command because it directly queries the FortiGate's logging subsystem to report the operational state of configured log devices, such as a FortiAnalyzer. This command displays fields like connection state (e.g., 'valid' or 'invalid'), the last log message timestamp, and any error counters, verifying whether the FortiAnalyzer is reachable and accepting logs. Unlike ping or configuration views, it reflects the live status of the log-forwarding pipeline, making it the definitive tool for confirming that logs are being transmitted successfully.

Why this answer

The 'diagnose log device status' command specifically checks the connectivity status and last-acknowledged sequence number between the FortiGate and the configured FortiAnalyzer. This command verifies whether the FortiGate can reach the FortiAnalyzer at the logging protocol level (FGFM), which is essential for log transmission, unlike a basic ICMP ping that only tests network-layer reachability.

Exam trap

The trap here is that candidates assume a successful ping (Option B) proves log connectivity, but the NSE4 exam tests the distinction between network-layer reachability and application-layer log protocol status, making the diagnostic command the only correct verification method.

How to eliminate wrong answers

Option B is wrong because 'execute ping 192.168.1.100' only tests basic ICMP reachability at the network layer; it does not verify that the FortiAnalyzer is accepting logs or that the FGFM (FortiGate-to-FortiAnalyzer) tunnel is established. Option C is wrong because 'show full-configuration log fortianalyzer' displays the current logging configuration (e.g., IP, encryption settings) but does not test live connectivity or the status of the log transmission channel. Option D is wrong because 'get system ha status' shows High Availability cluster state and has no relevance to FortiAnalyzer connectivity or log forwarding.

162
Multi-Selectmedium

Which TWO actions can cause SSL inspection to fail with certificate errors on client browsers? (Choose two.)

Select 2 answers
A.The FortiGate's CA certificate has expired.
B.The firewall policy allows the traffic.
C.The web server's certificate is signed by a public CA.
D.The client browser has the FortiGate CA certificate installed.
E.The FortiGate's generated server certificate does not match the requested domain name.
AnswersA, E

When the FortiGate's internal CA certificate is past its validity period, the FortiGate can no longer sign or re-sign the server certificates it presents to clients. Even if the generated leaf certificate has a future validity window, the browser will validate the entire chain and immediately flag the root/intermediate CA as expired, breaking trust and causing an 'untrusted authority' error during SSL inspection.

Why this answer

The FortiGate acts as a certificate authority (CA) for SSL inspection. If the FortiGate's CA certificate has expired, any server certificate it generates and signs for intercepted HTTPS sessions will be considered invalid by client browsers. Browsers will display a certificate error because the signing CA (the FortiGate) is no longer trusted due to expiration, even if the client has the CA certificate installed.

Exam trap

The trap here is that candidates often assume a public CA-signed server certificate is always trusted during inspection, forgetting that the FortiGate re-signs the certificate with its own CA, so the browser only sees the FortiGate's CA certificate and the generated server certificate, not the original public CA certificate.

163
MCQmedium

After enabling SSL inspection, a user receives a warning 'The certificate is not trusted' in the browser. The administrator has installed the CA certificate on the client. What else could be the cause?

A.The firewall policy denies the traffic.
B.The CA certificate is not added to the browser's trusted root store.
C.The FortiGate is not decrypting the traffic.
D.The web server's certificate has expired.
AnswerB

When SSL inspection is enabled on the FortiGate, it terminates the client's TLS connection and re-signs a new certificate for the requested website using its own local Certificate Authority. The browser will only trust this dynamically generated certificate if the FortiGate's CA certificate has been installed in the client's trusted root certificate store. If that CA is missing or untrusted, the browser warns that the certificate was not issued by a trusted authority, which is exactly the warning the user sees — this is the correct cause of the issue.

Why this answer

Even though the administrator installed the CA certificate on the client, the browser uses its own trusted root store, which is separate from the operating system's certificate store. If the CA certificate is not specifically added to the browser's trusted root store (e.g., Chrome uses the system store but Firefox maintains its own), the browser will still flag the certificate as untrusted. This is a common misconfiguration when deploying SSL inspection with FortiGate.

Exam trap

The trap here is that candidates assume installing the CA certificate on the client OS is sufficient for all browsers, but browsers like Firefox maintain their own certificate trust store, and even Chrome on some platforms may require the certificate to be in the correct store (e.g., the 'Trusted Root Certification Authorities' store) for the warning to disappear.

How to eliminate wrong answers

Option A is wrong because a firewall policy denying traffic would block the connection entirely, not generate a certificate trust warning in the browser. Option C is wrong because if FortiGate were not decrypting the traffic, the browser would receive the original web server certificate, which would be trusted (assuming it is a valid public CA), so no untrusted warning would appear. Option D is wrong because an expired web server certificate would cause a different error (e.g., 'expired certificate'), not specifically 'The certificate is not trusted' — and the FortiGate's re-signed certificate would be the one presented to the client, not the original server certificate.

164
MCQhard

An organization wants to authenticate VPN users using an LDAP server. They configure an LDAP server object and a user group. However, users are unable to authenticate. The administrator checks the logs and sees 'authentication failed' errors. What is the most common misconfiguration?

A.The user group is not configured with the correct members
B.The LDAP server uses SSL/TLS but the FortiGate is not configured for it
C.The LDAP server bind DN or password is incorrect
D.The LDAP server is not reachable from the FortiGate
AnswerC

The bind DN (distinguished name) and password constitute the FortiGate's service account credentials for connecting to the LDAP directory. If either is incorrect, the LDAP server rejects the bind operation with an 'invalid credentials' error (LDAP result code 49). This prevents the FortiGate from performing any directory queries, so the authentication process fails immediately at the initial bind stage, which is exactly what the user would see as an authentication failure.

Why this answer

The most common misconfiguration when LDAP authentication fails is an incorrect bind DN or password. The FortiGate uses the bind DN to authenticate to the LDAP server before it can search for users; if these credentials are wrong, the LDAP server rejects the bind request, resulting in an 'authentication failed' log entry. This error occurs even before user credentials are checked, making it a frequent root cause.

Exam trap

The trap here is that candidates assume 'authentication failed' refers to the VPN user's credentials, but it actually indicates the LDAP server rejected the FortiGate's bind request due to incorrect bind DN or password.

How to eliminate wrong answers

Option A is wrong because the user group membership affects authorization (which users are allowed), not the initial LDAP bind authentication; the 'authentication failed' error occurs at the bind stage, not after a successful user lookup. Option B is wrong because if the LDAP server uses SSL/TLS but FortiGate is not configured for it, the error would typically be a connection timeout or TLS handshake failure, not a generic 'authentication failed' message. Option D is wrong because if the LDAP server were unreachable, the log would show a connection error or timeout, not an 'authentication failed' error, which indicates the server was reached but rejected the bind.

165
Multi-Selectmedium

An organization uses LDAP authentication for firewall policies. Users complain that they are frequently prompted for credentials. Which TWO settings can reduce the frequency of authentication prompts?

Select 2 answers
A.Increase the authentication timeout on the firewall policy.
B.Increase the idle timeout on the LDAP server.
C.Enable single sign-on (SSO) authentication method.
D.Disable captive portal on the interface.
E.Use a longer password for LDAP accounts.
AnswersA, C

Increasing the authentication timeout on the firewall policy extends how long an LDAP-authenticated user's session remains valid before the FortiGate forces a re-authentication. After successful LDAP validation, the firewall caches the user's access rights for the duration of this timeout; once it expires, the user must re-enter credentials for that policy. A longer timeout reduces the frequency of prompts, but it also widens the security window in which a session could be hijacked or reused by an unauthorized user on a shared machine. This is the direct, policy-level control that governs prompt frequency.

Why this answer

Increasing the authentication timeout on the firewall policy (Option A) allows the firewall to cache the user's authentication state for a longer period, so users are not re-prompted for credentials as frequently when traffic matches that policy. Enabling single sign-on (SSO) authentication (Option C) leverages Kerberos or NTLM to automatically authenticate users based on their domain logon, eliminating repeated manual credential prompts.

Exam trap

The trap here is that candidates confuse the LDAP server's idle timeout (a connection keepalive) with the firewall's authentication timeout (a cached credential timer), leading them to incorrectly select Option B.

166
MCQmedium

A FortiGate administrator needs to send logs to an external FortiAnalyzer for centralized monitoring. Which log configuration step is required?

A.Configure syslog server
B.Add the FortiAnalyzer as a logging device in System > FortiAnalyzer
C.Enable FortiCloud logging
D.Enable disk logging on the FortiGate
AnswerB

Adding the FortiAnalyzer as a logging device in System > FortiAnalyzer is the correct method because FortiGate communicates with FortiAnalyzer using the FortiAnalyzer protocol—a proprietary, secure connection that registers the FortiGate, handles authentication, and forwards logs to the FortiAnalyzer's dedicated log database. In the FortiAnalyzer settings you specify the FortiAnalyzer IP address, the serial number for registration, and optionally enable SSL encryption; this creates a direct log-forwarding pipeline beyond simple syslog. This integration is the designed path for an external FortiAnalyzer to receive logs, enabling centralized management, advanced search, and reporting.

Why this answer

To send logs from a FortiGate to an external FortiAnalyzer for centralized monitoring, the administrator must add the FortiAnalyzer as a logging device under System > FortiAnalyzer. This step establishes the secure, authenticated connection (typically using FortiGate's proprietary protocol over TCP/514 or TCP/3000) and enables log forwarding to the FortiAnalyzer. Without this configuration, the FortiGate will not send logs to the FortiAnalyzer, even if other logging methods are enabled.

Exam trap

The trap here is that candidates often confuse the FortiAnalyzer configuration with a generic syslog server setup, assuming any external logging destination works the same way, but FortiAnalyzer requires a specific device registration and protocol that differs from standard syslog.

How to eliminate wrong answers

Option A is wrong because configuring a syslog server sends logs in standard syslog format (RFC 3164/5424) to a generic syslog collector, not to a FortiAnalyzer, which uses a proprietary protocol for enhanced features like log correlation and reporting. Option C is wrong because enabling FortiCloud logging sends logs to FortiGate Cloud, not to an on-premises FortiAnalyzer, and is a separate service requiring a different subscription. Option D is wrong because enabling disk logging on the FortiGate stores logs locally on the FortiGate's hard disk or SSD, which does not forward logs to an external FortiAnalyzer; it only retains logs for local viewing and troubleshooting.

167
MCQeasy

An administrator is creating firewall policies for a FortiGate that separates the internal network (10.0.1.0/24) from a DMZ (192.168.1.0/24). The goal is to allow HTTP traffic from the internal network to the DMZ web server (192.168.1.10) but deny all other traffic. What is the recommended security posture for the implicit deny policy?

A.Set the allow policy to also deny all other traffic using security profiles
B.Disable the implicit deny policy and create a catch-all deny policy
C.Create an explicit deny policy with logging enabled before the allow policy
D.Rely on the implicit deny policy at the end of the policy list, which will block all traffic not explicitly allowed
AnswerD

FortiGate's implicit deny is the last policy in the lookup chain, dropping any packet that does not match an earlier explicit policy. This default-deny behavior implements a least-privilege model, ensuring only services explicitly permitted by firewall policies are reachable. It is always active and cannot be removed, making it a reliable baseline for secure network segmentation.

Why this answer

The implicit deny policy is a default, hidden policy at the end of the FortiGate policy list that denies all traffic not explicitly allowed by preceding policies. Since the administrator wants to allow only HTTP traffic from internal to the DMZ web server and deny all other traffic, relying on the implicit deny is the correct and recommended security posture. It automatically blocks everything else without requiring manual configuration, ensuring no unintended traffic is permitted.

Exam trap

The trap here is that candidates may think they need to create an explicit deny policy with logging to block unwanted traffic, not realizing that the implicit deny already performs this function and that placing a deny policy before the allow policy would break the intended traffic flow.

How to eliminate wrong answers

Option A is wrong because setting the allow policy to also deny all other traffic using security profiles is not a valid approach; security profiles inspect allowed traffic but do not deny traffic that is not explicitly permitted. Option B is wrong because disabling the implicit deny policy and creating a catch-all deny policy is unnecessary and introduces risk; the implicit deny already provides the same functionality without manual intervention. Option C is wrong because creating an explicit deny policy with logging enabled before the allow policy would block all traffic, including the desired HTTP traffic, since FortiGate processes policies in sequential order from top to bottom.

168
MCQhard

An administrator configured SSL inspection with 'deep-inspection' profile. Users report that some websites fail to load with certificate errors. The firewall policy is correct. What is the most likely reason?

A.The CA certificate has expired.
B.The web server uses a cipher that the FortiGate cannot re-encrypt.
C.The user's browser is outdated.
D.The firewall needs a policy to allow DNS traffic.
AnswerB

When a FortiGate performs deep inspection, it terminates the client's TLS connection and then initiates a second TLS connection to the web server to re-encrypt traffic. If the web server negotiates a cipher suite, key exchange method, or TLS version that the FortiGate's SSL engine does not support or is not configured to allow, the outbound handshake fails. This manifests as a 'Cannot communicate securely' or certificate-related error for that specific server, while other sites that use supported ciphers continue to work. The administrator should review the SSL inspection profile's cipher list and ensure it aligns with the server's capabilities.

Why this answer

When deep-inspection is used, the FortiGate decrypts the client-to-server traffic, inspects the content, and then re-encrypts it before forwarding to the client. If the web server uses a cipher suite that the FortiGate does not support for re-encryption (e.g., an obsolete or non-standard cipher), the FortiGate cannot complete the SSL handshake with the client, causing certificate errors or connection failures. This is the most likely reason because the firewall policy is correct and the CA certificate is valid.

Exam trap

The trap here is that candidates often assume certificate errors are always due to an expired CA certificate, but the question specifies that only some websites fail, which points to a cipher mismatch during re-encryption rather than a global CA issue.

How to eliminate wrong answers

Option A is wrong because if the CA certificate had expired, the FortiGate would not be able to generate valid signed certificates for any inspected site, causing all deep-inspection sessions to fail, not just some websites. Option C is wrong because an outdated browser might cause compatibility issues with modern ciphers, but the error described is a certificate error specifically from the FortiGate's re-encryption process, not a browser-side cipher mismatch. Option D is wrong because DNS traffic is typically allowed by default in the implicit allow policy or a separate DNS policy; a missing DNS policy would prevent name resolution entirely, not cause certificate errors on specific websites.

169
MCQeasy

Which command is used to display the current FortiGate firmware version?

A.get system statistics
B.get hardware status
C.get system status
D.get system performance status
AnswerC

The 'get system status' command is the standard FortiGate CLI command to display the current firmware version, along with build number, serial number, hostname, uptime, and the configured operating mode. This output is essential for troubleshooting, verifying patch compliance, and confirming that the device is running an expected FortiOS release. It is the authoritative source for firmware identification.

Why this answer

The 'get system status' command is the correct way to display the current FortiGate firmware version. This command outputs a comprehensive summary of the system state, including the firmware version (e.g., FortiOS v7.4.0), the system uptime, serial number, and HA status. It is the standard CLI command for verifying the exact build and patch level of the FortiGate.

Exam trap

The trap here is that candidates often confuse 'get system status' with 'get system statistics' because both commands start with 'get system', but only 'get system status' provides the firmware version, while 'get system statistics' focuses on performance counters.

How to eliminate wrong answers

Option A is wrong because 'get system statistics' displays real-time traffic statistics such as CPU and memory usage, session counts, and packet rates, not the firmware version. Option B is wrong because 'get hardware status' shows hardware-related information like chassis temperature, fan speed, and power supply status, not the firmware version. Option D is wrong because 'get system performance status' provides a snapshot of system performance metrics (e.g., CPU load, memory utilization, disk usage) but does not include the firmware version.

170
MCQmedium

An administrator configures a firewall policy allowing traffic from the internal network to the internet with NAT enabled. Users report that some outbound connections fail intermittently. The administrator runs 'diagnose sys session list' and sees many sessions in 'proto_state=01' with a short TTL. What is the most likely cause?

A.The firewall policy has the wrong source interface
B.The destination port is blocked by an implicit deny rule
C.The antivirus profile is blocking the connections
D.The IP pool used for SNAT has exhausted its address range
AnswerD

When a firewall policy uses SNAT with a configured IP pool, the FortiGate must select an available IP address and a free port from that address to translate the source IP for new outbound sessions. If the IP pool's address range is exhausted — meaning all IPs are already assigned to active sessions with all their port ranges used — the FortiGate cannot allocate a source IP, so it drops the connection and logs an event such as 'no source IP available' or 'IP pool exhausted.' This exactly matches the symptom: the policy is matched, but connections fail due to a NAT resource shortage, which is the correct answer.

Why this answer

The 'diagnose sys session list' output showing many sessions in 'proto_state=01' with a short TTL indicates that sessions are failing to establish properly. When the IP pool used for Source NAT (SNAT) exhausts its address range, new outbound connections cannot obtain a translated source IP, causing them to fail intermittently. This matches the symptom of intermittent failures as the pool becomes temporarily depleted.

Exam trap

The trap here is that candidates may misinterpret 'proto_state=01' as a protocol or state machine error, rather than recognizing it as a symptom of NAT resource exhaustion, leading them to incorrectly select options related to policy misconfiguration or security profiles.

How to eliminate wrong answers

Option A is wrong because a wrong source interface would cause all traffic to fail consistently, not intermittently, and the session list would show no matching policy hits rather than specific proto_state values. Option B is wrong because an implicit deny rule would block traffic entirely, not intermittently, and would not produce sessions with a short TTL in the session table. Option C is wrong because an antivirus profile blocking connections would typically show specific virus detection logs or content inspection failures, not a proto_state=01 indicating a NAT resource exhaustion issue.

171
MCQmedium

An administrator needs to ensure that a firewall policy applies only during business hours (Monday to Friday, 9:00 AM to 6:00 PM). What object should be configured and applied to the policy?

A.Service group
B.Address group
C.Schedule object
D.Traffic shaper
AnswerC

A schedule object is the FortiGate construct designed specifically to define when a policy is valid and enforceable, using either a recurring weekly/daily pattern or a one-time date and time range. By attaching a schedule object such as 'Business Hours' (e.g., 08:00–18:00, Monday–Friday) to the policy, FortiGate will evaluate and apply that policy only within the defined window; outside that window the policy is skipped entirely. This is exactly what the administrator needs to ensure the policy applies only at the intended times.

Why this answer

A schedule object in FortiGate defines time-based conditions (e.g., recurring weekly windows like Monday–Friday 09:00–18:00) that can be applied directly to a firewall policy. When a schedule is attached, the policy is enforced only during the specified time range, making it the correct object for restricting policy activation to business hours.

Exam trap

The trap here is that candidates confuse a schedule object with a service group or traffic shaper, mistakenly thinking time-based access can be achieved via port grouping or QoS policies, whereas FortiGate explicitly requires a schedule object for time-of-day policy enforcement.

How to eliminate wrong answers

Option A is wrong because a service group is used to group multiple protocol/port definitions (e.g., TCP/80, TCP/443) for application-layer matching, not for time-based enforcement. Option B is wrong because an address group aggregates IP addresses or FQDN objects for source/destination matching, not for controlling when a policy is active. Option D is wrong because a traffic shaper controls bandwidth allocation and QoS (e.g., guaranteed/ maximum bandwidth), not the temporal activation of a firewall policy.

172
MCQeasy

An administrator wants to allow remote users to access internal resources using a web browser without installing any client software. Which VPN type should be configured on the FortiGate?

A.ZTNA access proxy
B.IPsec VPN with dial-up mode
C.SSL VPN tunnel mode
D.SSL VPN web mode
AnswerD

SSL VPN web mode provides agentless, browser-based access to internal web applications through a reverse-proxy portal. The user only needs a supported web browser and credentials, then receives a resource-list portal to reach specific HTTP/HTTPS URLs. This matches the requirement of allowing remote users to access internal web resources without installing any software or VPN client.

Why this answer

SSL VPN web mode (option D) is correct because it provides clientless remote access to internal resources via a web browser, requiring no software installation. The FortiGate acts as a reverse proxy, translating HTTPS requests from the user's browser to internal HTTP/HTTPS servers, which matches the requirement for browser-only access without client software.

Exam trap

The trap here is confusing SSL VPN web mode (clientless) with SSL VPN tunnel mode (client-required), as both use SSL/TLS but differ fundamentally in whether a software client is needed for full network-layer access.

How to eliminate wrong answers

Option A is wrong because ZTNA access proxy is a zero-trust solution that typically requires a FortiClient or endpoint agent for identity verification and device posture checks, not a clientless browser-only approach. Option B is wrong because IPsec VPN with dial-up mode requires a dedicated VPN client (e.g., FortiClient or third-party IPsec software) to establish the tunnel, which violates the 'no client software' requirement. Option C is wrong because SSL VPN tunnel mode requires the FortiClient SSL VPN plugin or a full VPN client to create a virtual adapter and route traffic, whereas the question specifies web browser access without installation.

173
MCQmedium

An administrator configures a Virtual IP (VIP) to map the public IP 203.0.113.10 port 8080 to the internal server 192.168.1.100 port 80. External users report they cannot connect. The firewall policy allows inbound traffic to the VIP. What is the MOST likely missing configuration?

A.The destination in the firewall policy is set to the public IP directly instead of the VIP object
B.The VIP is configured with port forwarding disabled
C.The server's default gateway is not set to the FortiGate
D.The source NAT is not configured
AnswerA

FortiGate matches inbound traffic against the VIP object, not the public IP. If the policy destination is the raw public IP, the connection never maps to the internal server, so external users fail despite the policy appearing to permit traffic.

Why this answer

When a Virtual IP (VIP) is configured, the firewall policy must reference the VIP object as the destination, not the public IP address directly. If the policy uses the public IP (203.0.113.10) as the destination, the FortiGate will not perform the destination NAT translation to the internal server (192.168.1.100). The VIP object contains the mapping logic, so the policy must point to that object for the translation to occur.

Exam trap

The trap here is that candidates assume the firewall policy should use the public IP as the destination, not realizing that the VIP object must be referenced in the policy for the NAT translation to be applied.

How to eliminate wrong answers

Option B is wrong because port forwarding is implicitly enabled when you define a VIP with a specific port mapping (8080 to 80); there is no separate 'port forwarding disabled' toggle that would block this. Option C is wrong because the server's default gateway does not need to be the FortiGate for inbound connections; return traffic can be routed via the FortiGate if the VIP uses source NAT (central NAT) or if the server's gateway points to the FortiGate, but this is not the most likely missing configuration for inbound connectivity failure. Option D is wrong because source NAT is not required for inbound VIP traffic; the VIP handles destination NAT, and source NAT (e.g., for return traffic) is a separate configuration that is not essential for initial inbound connections.

174
MCQhard

A FortiGate administrator has configured an active-passive HA cluster. After a failover event, the former primary unit comes back online and immediately takes over as primary again, causing another failover. The administrator wants the original primary to stay in standby until the current primary fails. Which setting should be configured?

A.Enable HA override on both units
B.Set the HA mode to active-active
C.Disable HA override on both units
D.Increase the HA priority on the primary unit
AnswerC

Disabling HA override on both units is the correct solution because this setting prevents a unit with a higher priority from preempting the current primary as long as that primary is functioning normally. With override disabled, the active primary remains the primary until it actually fails, eliminating the automatic failback event that would otherwise occur when the recovered unit comes online. This ensures stable operation and avoids unnecessary traffic interruption in an active-passive HA deployment.

Why this answer

HA override (set ha-override enable) causes a device to resume primary role when it becomes available with higher priority. Disabling override prevents this preemptive behavior.

175
Multi-Selecthard

A FortiGate administrator is troubleshooting an IPsec VPN that fails to establish. The Phase 1 status shows 'init' and then resets. The administrator runs 'diagnose debug application ike -1' and sees the message 'no acceptable proposal'. Which TWO parameters are MOST likely mismatched?

Select 2 answers
A.Pre-shared key
B.Phase 2 local and remote networks
C.IKE version (IKEv1 vs IKEv2)
D.Encryption algorithm (e.g., AES256 vs AES128)
E.Diffie-Hellman group (e.g., group 14 vs group 2)
AnswersD, E

'No acceptable proposal' means Phase 1 negotiation found no matching transform set. Mismatched encryption algorithms, such as AES256 on one peer and AES128 on the other, prevent any proposal from being accepted, so the tunnel resets.

Why this answer

The IKE debug message 'no acceptable proposal' means the two peers could not agree on the Phase 1 (IKE SA) proposal parameters, which are negotiated during IKE SA establishment. Option D (encryption algorithm, e.g., AES256 vs AES128) is correct because the encryption algorithm is a Phase 1 proposal attribute, and if the local and remote FortiGates offer different encryption algorithms, no matching proposal exists and negotiation fails. Option E (Diffie-Hellman group, e.g., group 14 vs group 2) is also correct because the DH group is another Phase 1 proposal attribute; mismatched DH groups (modp2048/group 14 vs modp1024/group 2) prevent the peers from agreeing on a proposal.

Option A (pre-shared key) is not the cause here because a PSK mismatch produces authentication failure messages (e.g., 'probable pre-shared key mismatch'), not 'no acceptable proposal'. Option B (Phase 2 local and remote networks) is a Phase 2 quick-mode/selector issue and would not generate a Phase 1 proposal rejection. Option C (IKE version) can cause negotiation problems, but a version mismatch typically shows different errors such as 'received IKEv2 packet on IKEv1 tunnel' or invalid version messages rather than the specific 'no acceptable proposal' text.

Exam trap

The trap here is that candidates often confuse Phase 1 proposal mismatches (encryption, DH group) with authentication failures (pre-shared key) or Phase 2 mismatches (networks), but the 'no acceptable proposal' error specifically points to cryptographic parameter negotiation failure in Phase 1.

176
Multi-Selecteasy

A FortiGate administrator needs to block all traffic from a specific IP address (10.0.0.100) to the internet, but allow all other internal users. The administrator has created a firewall policy with source=10.0.0.100, destination=all, service=all, action=DENY, and placed it at the top of the policy list. Which TWO additional steps should the administrator take to ensure the block is effective? (Choose two.)

Select 2 answers
A.Enable the policy
B.Configure an IP Pool for the deny policy
C.Add a schedule to the policy for business hours
D.Ensure no other policy above this one allows traffic from 10.0.0.100
E.Set the action to ACCEPT
AnswersA, D

In FortiGate, firewall policies are created in a disabled state by default unless explicitly enabled at creation. A disabled policy is not evaluated in the policy lookup, so even if it matches the source/destination/service, traffic will not be denied. For the deny action to be enforced, the policy must have its status set to 'enable' so the FortiOS kernel includes it in the ordered rule evaluation.

Why this answer

A newly created firewall policy in FortiGate is disabled by default. The administrator must explicitly enable the policy for it to be enforced. Without enabling, the deny rule will not process traffic, leaving the block ineffective.

Exam trap

The trap here is that candidates often forget that new policies are disabled by default, and they may overlook the importance of policy order when a deny rule is placed at the top but a previous ACCEPT rule exists for the same source.

177
MCQmedium

A company uses deep SSL inspection to filter traffic. Users report that some HTTPS sites are not loading. The administrator checks the FortiGate and sees that the certificate for the sites is not trusted on the client machines. What is the most likely cause?

A.The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients.
B.The FortiGate is using a self-signed certificate for the SSL inspection policy.
C.The SSL inspection policy is set to 'no-inspection' for the affected sites.
D.The FortiGate's web filter profile is blocking the certificate.
AnswerA

The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients. Deep SSL inspection works by having the FortiGate intercept TLS traffic and present a real-time generated certificate signed by a FortiGate-owned CA. If that CA is not present in the client's trusted root store, the browser cannot verify the chain of trust and will display a certificate error or block the connection entirely. Installing the FortiGate CA in the Trusted Root Certification Authorities store on all clients is a mandatory prerequisite for seamless deep inspection.

Why this answer

When deep SSL inspection is enabled, the FortiGate acts as a man-in-the-middle by decrypting HTTPS traffic using a local CA certificate. For clients to trust the decrypted connections, the FortiGate's CA certificate must be installed in the Trusted Root Certification Authorities store on each client machine. If it is missing, the browser will display a certificate trust error and may block the site, causing the reported loading failures.

Exam trap

The trap here is that candidates may confuse the FortiGate's self-signed certificate used for its own web interface with the CA certificate required for deep inspection, or assume that 'no-inspection' would cause loading failures rather than bypassing inspection entirely.

How to eliminate wrong answers

Option A is correct because the root cause is the missing CA certificate on clients. Option B is wrong because a self-signed certificate in the SSL inspection policy is used for the FortiGate's own management interface or for certificate re-signing, but the core issue is the CA certificate not being trusted by clients, not the type of certificate used in the policy. Option C is wrong because setting the policy to 'no-inspection' would bypass SSL inspection entirely, allowing HTTPS sites to load normally without certificate errors.

Option D is wrong because a web filter profile blocks URLs or categories based on policy, not certificates; certificate trust is handled by the SSL inspection configuration, not the web filter.

178
MCQmedium

An administrator has configured an active-passive HA cluster. During a failover test, the standby unit becomes active but existing user sessions are lost, requiring users to re-establish connections. Which configuration change would prevent this behavior?

A.Lower HA priority on the primary
B.Enable session pickup
C.Set HA override to enabled
D.Increase the heartbeat interval
AnswerB

Enabling session pickup enables FortiOS to continuously replicate the active unit's session table, including NAT mappings and firewall state, to the standby unit over the synchronization link. On failover, the standby unit promotes itself to primary and already has all active sessions queued, enabling established connections to survive without re-handshake. This is the only option that directly addresses the requirement for stateful failover and is the standard way to preserve sessions in an active-passive HA cluster.

Why this answer

In an active-passive FortiGate HA cluster, session pickup (also called session synchronization) is the feature that replicates the session table from the primary to the standby unit. Without it enabled, when failover occurs the standby unit has no knowledge of existing sessions and drops them, forcing users to reconnect. Enabling session pickup ensures the standby has a mirrored session table so established connections continue through the failover.

Exam trap

NSE4 often tests the confusion between HA election/priority settings (override, priority) and stateful failover features (session pickup, session synchronization) — candidates pick priority or override thinking it preserves sessions, when only session pickup does.

How to eliminate wrong answers

Option A is wrong because lowering HA priority on the primary only affects which unit becomes primary during election (or with override enabled, forces the other unit to take over) — it does not synchronize session state. Option C is wrong because HA override controls whether a higher-priority unit preempts the current primary after it recovers; it has no bearing on session table synchronization. Option D is wrong because the heartbeat interval (hb-interval) only controls how frequently HA heartbeat packets are sent to detect failures; increasing it actually slows failure detection and does nothing to preserve sessions.

179
MCQeasy

Which FortiGate operating mode is used when the device acts as a Layer 2 bridge without performing NAT?

A.HA mode
B.Transparent mode
C.VPN mode
D.NAT/Route mode
AnswerB

Transparent mode makes the FortiGate operate as a Layer 2 bridge, forwarding frames based on MAC addresses without performing routing or NAT. All of its interfaces share the same IP subnet, and the device is invisible to IP routing, which is why it is often described as a 'bump in the wire.' This mode is ideal for inserting security controls into an existing network segment without changing the IP addressing scheme.

Why this answer

Transparent mode (Option B) is correct because in this mode the FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses without performing any NAT or routing. The device is invisible to the network, and all interfaces share the same IP subnet, allowing it to inspect and filter traffic at the application layer while remaining transparent to connected devices.

Exam trap

The trap here is that candidates often confuse Transparent mode with NAT/Route mode, assuming that a firewall must always route or perform NAT, when in fact Transparent mode allows Layer 2 inspection without altering the IP path.

How to eliminate wrong answers

Option A is wrong because HA mode (High Availability) is a clustering configuration for redundancy and failover, not an operating mode that determines Layer 2 bridging or NAT behavior. Option C is wrong because VPN mode is not a standard FortiGate operating mode; VPNs are configured as features within either NAT/Route or Transparent mode. Option D is wrong because NAT/Route mode operates at Layer 3, performing routing and NAT by default, which contradicts the requirement of acting as a Layer 2 bridge without NAT.

180
MCQmedium

You run the following CLI command on a FortiGate: # diagnose debug flow filter saddr 192.168.1.10 # diagnose debug flow show function enable # diagnose debug enable You then initiate a ping from 192.168.1.10 to 8.8.8.8. The output shows 'no matching policy'. What does this indicate?

A.The traffic is being NAT'd but not logged
B.The debug filter is incorrectly configured
C.There is a routing issue preventing the traffic
D.The traffic is dropped by the implicit deny rule
AnswerD

The implicit deny rule is the final entry in the FortiGate policy table, and it drops any traffic that does not match an explicit allow or deny policy. By default, the implicit deny rule does not generate log entries, which explains the absence of logs in the output. The diagnose flow would show the packet count incrementing at this rule, confirming that the traffic is silently dropped here. This is the correct and most common reason for traffic failing to pass through a FortiGate when policies appear to be missing.

Why this answer

The 'no matching policy' output from the debug flow indicates that the FortiGate evaluated the packet against its firewall policy table and found no explicit policy permitting the traffic from source 192.168.1.10 to destination 8.8.8.8. Since no matching policy exists, the packet is implicitly denied by the default deny-all rule at the end of the policy table, which drops the traffic without logging unless explicitly configured. This is the expected behavior when no permit policy is configured for the traffic flow.

Exam trap

The trap here is that candidates often confuse 'no matching policy' with a routing problem or NAT misconfiguration, but the debug flow output explicitly pinpoints the firewall policy layer as the point of failure, not routing or NAT.

How to eliminate wrong answers

Option A is wrong because NAT is applied after a policy match, and 'no matching policy' means the traffic never reached the NAT stage; logging is also a policy-level action that only occurs after a match. Option B is wrong because the debug filter is correctly configured with the source address 192.168.1.10, and the output specifically shows the packet being processed; the filter is not the cause of the 'no matching policy' result. Option C is wrong because routing is evaluated before firewall policies, and if there were a routing issue, the debug flow would show 'no route to destination' or similar, not 'no matching policy'; the presence of a route is implied by the packet reaching the policy lookup stage.

181
MCQmedium

A FortiGate admin configures a captive portal for guest users on a wireless network. Users can connect to the SSID but cannot access the internet. The admin verifies the firewall policy permits traffic from the captive portal interface to the internet. What is missing?

A.The firewall policy must have 'Enable Captive Portal' selected
B.A DNS server must be configured on the FortiGate
C.The users must be added to the local user database
D.The wireless controller must be configured with a RADIUS server
AnswerA

The captive portal is a firewall-policy-level feature: on the FortiGate, you must enable 'Captive Portal' on the specific policy controlling the guest traffic (CLI: set captive-portal enable). This instructs the FortiGate to intercept HTTP/HTTPS sessions from unauthenticated clients and redirect them to the portal login page. Without this enablement, the portal page is never presented, and the guest traffic is simply blocked or forwarded according to the policy's normal settings.

Why this answer

For a captive portal to redirect unauthenticated users to the authentication page, the firewall policy that permits traffic from the captive portal interface to the internet must have the 'Enable Captive Portal' option selected. Without this setting, the FortiGate will not intercept HTTP/HTTPS requests and redirect them to the captive portal login page, so users remain unauthenticated and cannot access the internet even though the policy allows traffic.

Exam trap

The trap here is that candidates assume captive portal is automatically enabled when a firewall policy allows traffic from the captive portal interface, but in FortiGate, the 'Enable Captive Portal' checkbox must be explicitly set on the policy to trigger the authentication redirect.

How to eliminate wrong answers

Option B is wrong because a DNS server is not required for captive portal functionality; the FortiGate can use its own DNS proxy or forward queries, and DNS resolution is separate from the captive portal redirection process. Option C is wrong because captive portal for guest users typically uses authentication via a local user database or external authentication, but the question states users can connect to the SSID but cannot access the internet, indicating the issue is the missing captive portal enforcement on the firewall policy, not the absence of user accounts. Option D is wrong because a RADIUS server is not mandatory for a captive portal; the FortiGate can authenticate users locally or via other methods, and the wireless controller configuration is unrelated to the firewall policy setting that enables captive portal redirection.

182
MCQhard

You execute 'get firewall policy 5' and see the following output: policyid=5 name="test" status=enable schedule="always" logtraffic=all What does 'logtraffic=all' mean?

A.Only the first packet of each session will be logged
B.Only traffic that triggers a security profile will be logged
C.Only traffic that is denied by the policy will be logged
D.All traffic matching the policy will be logged, regardless of action
AnswerD

The 'all' setting for the 'logtraffic' option on a Fortinet firewall policy instructs the device to log every session that matches the policy, regardless of the action taken (accept or deny). This includes sessions that are allowed through as well as those that are explicitly blocked. It is the most comprehensive logging mode for a policy and is often used for audit compliance or troubleshooting. Therefore, this option correctly describes the behavior of 'logtraffic=all'.

Why this answer

'logtraffic=all' in FortiGate firewall policy configuration means that every packet belonging to a session matching this policy will be logged, regardless of whether the action is accept or deny. This is distinct from other log settings like 'logtraffic=utm' or 'logtraffic=disable', and it ensures full audit trail for all traffic handled by the policy.

Exam trap

The trap here is that candidates often confuse 'logtraffic=all' with 'logtraffic=session-start' or think it only logs denied traffic, but FortiGate's granular log options require precise understanding of each keyword's behavior.

How to eliminate wrong answers

Option A is wrong because logging only the first packet of each session is the behavior of 'logtraffic=session-start', not 'logtraffic=all'. Option B is wrong because logging only traffic that triggers a security profile is the behavior of 'logtraffic=utm' (UTM-based logging), not 'logtraffic=all'. Option C is wrong because logging only denied traffic is the behavior of 'logtraffic=deny', not 'logtraffic=all'.

183
MCQhard

An administrator configures a dial-up IPsec VPN using IKEv2 with certificates. Remote users can connect, but traffic is not routed through the tunnel. The Phase 1 status shows 'up', but Phase 2 shows 'down'. What is the most likely issue?

A.The firewall policy for the VPN traffic is missing.
B.The Phase 2 proposals do not match between the FortiGate and the client.
C.The pre-shared key for Phase 2 is incorrect.
D.The remote user's client does not support IKEv2.
AnswerB

In IKEv2, the CREATE_CHILD_SA exchange negotiates the IPsec SA parameters, including encryption, integrity, and DH group. If the FortiGate's configured Phase 2 proposal set does not include at least one transform that exactly matches what the client proposes, the negotiation fails and no Phase 2 SA is established. The Phase 1 IKE SA may still be up, but the tunnel remains down because the two peers cannot agree on a common traffic protection algorithm suite. This is the most direct cause of a failed Phase 2 while Phase 1 is successful.

Why this answer

In IKEv2 VPNs, Phase 1 establishes the secure control channel (ISAKMP SA) and shows 'up' even if Phase 2 fails. Phase 2 creates the IPsec SA for actual data traffic; if it remains 'down', the most common cause is a mismatch in Phase 2 proposals (encryption, authentication, or PFS settings) between the FortiGate and the remote client. Since the client can connect but traffic is not routed, the tunnel is not fully established for data, pointing directly to a Phase 2 proposal mismatch.

Exam trap

The trap here is that candidates assume a successful Phase 1 means the entire VPN is working, but NSE4 tests the understanding that Phase 2 must also be up for traffic to flow, and proposal mismatches are the primary cause of Phase 2 failures.

How to eliminate wrong answers

Option A is wrong because a missing firewall policy would block traffic even if both Phase 1 and Phase 2 were up, but here Phase 2 is down, indicating the issue is at the SA negotiation level, not policy. Option C is wrong because IKEv2 with certificates does not use a pre-shared key for Phase 2; Phase 2 authentication is derived from the IKE SA established in Phase 1, and certificates handle authentication. Option D is wrong because the remote users can connect (Phase 1 is up), so the client does support IKEv2; the problem is specifically with Phase 2 negotiation.

184
MCQhard

Refer to the exhibit. An administrator configures the policies as shown. Traffic from 10.0.0.0/8 to the internet on HTTP is denied. What is the most likely reason?

A.The Allow-HTTP policy uses service HTTP but the traffic uses HTTPS
B.The Deny-All policy is placed above the Allow-HTTP policy
C.The Allow-HTTP policy has the wrong source interface
D.The Allow-HTTP policy is disabled
AnswerB

In FortiOS, policy evaluation is top-down and first-match; the first policy whose source/destination/service matches the traffic is applied. The Deny-All policy has a lower sequence number (e.g., policy ID 0) and appears above the Allow-HTTP policy, so it matches all traffic and denies the HTTP session before the allow policy is ever evaluated. Specificity does not override order, so the deny-all wins.

Why this answer

In FortiGate firewall policies, the first matching policy is applied to traffic. The Deny-All policy is placed above the Allow-HTTP policy, so traffic from 10.0.0.0/8 to the internet on HTTP matches the Deny-All policy first and is denied before reaching the Allow-HTTP policy. This is a classic policy ordering issue.

Exam trap

The trap here is that candidates often assume policies are evaluated based on a 'most specific match' logic rather than the actual sequential order, leading them to overlook the policy placement as the root cause.

How to eliminate wrong answers

Option A is wrong because the question states traffic uses HTTP, not HTTPS, so the service mismatch is not the reason. Option C is wrong because the source interface is not specified as incorrect in the exhibit; the issue is policy order, not interface mismatch. Option D is wrong because the Allow-HTTP policy is not disabled; it is simply never evaluated due to the higher priority of the Deny-All policy.

185
MCQmedium

An administrator configures an antivirus profile in proxy-based inspection mode on a FortiGate. However, SMTP traffic is not being scanned for viruses. The firewall policy includes the antivirus profile and the FortiGate has a valid FortiGuard subscription. What is the most likely cause?

A.Flow-based inspection is required for SMTP scanning
B.The SMTP protocol is not enabled in the proxy options of the security profile
C.The FortiGate does not have a valid SSL certificate for SMTP inspection
D.The antivirus profile is configured to scan only HTTP traffic
AnswerB

In proxy-based inspection, each protocol must be explicitly enabled in the proxy options of the security profile. If SMTP is left unchecked, the FortiGate will not decode or scan SMTP traffic, causing the antivirus profile to appear non-functional for email. Navigate to the AV profile's protocol options and ensure SMTP is enabled, then apply the profile to the firewall policy that carries SMTP traffic.

Why this answer

In proxy-based inspection mode, the antivirus profile relies on the proxy options to determine which protocols to scan. If SMTP is not explicitly enabled in the proxy options of the security profile, the FortiGate will not inspect SMTP traffic for viruses, even if the antivirus profile is applied to the policy and the FortiGuard subscription is valid.

Exam trap

The trap here is that candidates assume a valid FortiGuard subscription and a correctly applied antivirus profile guarantee scanning of all traffic, overlooking the requirement to enable the specific protocol in the proxy options for proxy-based inspection.

How to eliminate wrong answers

Option A is wrong because flow-based inspection is not required for SMTP scanning; proxy-based inspection supports SMTP scanning when the protocol is enabled in the proxy options. Option C is wrong because SMTP traffic does not require SSL inspection for antivirus scanning; SSL certificates are only relevant for HTTPS or SMTPS inspection. Option D is wrong because antivirus profiles do not have a setting to scan only HTTP traffic; they scan all protocols enabled in the proxy options or flow-based configuration.

186
MCQmedium

An administrator is troubleshooting a FortiGate firewall policy that is supposed to allow HTTP traffic from the internal network to the internet. The policy is configured with source 'all', destination 'all', service 'HTTP', and action 'ACCEPT'. However, users report that HTTP traffic is being blocked. The administrator checks the policy list and sees that the policy is enabled. What is the most likely reason for the block?

A.The service 'HTTP' is not defined in the FortiGate services list.
B.The policy is placed below a more specific deny policy that matches the traffic.
C.The policy has NAT disabled, so return traffic cannot find its way back.
D.The policy does not have a schedule applied, so it is always active.
AnswerB

Firewall policies are evaluated top-down, and the first matching policy is applied. If a deny policy appears above the allow policy and matches the same traffic (e.g., source 'all', destination 'all', service 'ALL'), then HTTP traffic will be blocked before reaching the allow policy. The administrator should check the policy order and move the allow policy above any conflicting deny policy.

Why this answer

Firewall policies on a FortiGate are processed sequentially from top to bottom. The first policy that matches the traffic determines the action. If a deny policy appears earlier in the list and matches the same source, destination, and service, the traffic will be blocked regardless of a later allow policy.

Therefore, the most likely cause is that the allow policy is positioned below a conflicting deny policy.

Exam trap

The trap here is assuming that an enabled allow policy will always permit traffic, ignoring the sequential evaluation order where an earlier deny policy can override it.

187
MCQeasy

A network administrator needs to allow SSH access to the FortiGate from a management subnet 10.0.1.0/24. Which configuration step is required on the interface connected to that subnet?

A.Enable HTTPS administrative access only
B.Set the administrative access to 'any'
C.Enable SSH administrative access on the interface
D.Configure a firewall policy allowing SSH from the subnet
AnswerC

SSH access terminates on the FortiGate interface facing the management subnet, so administrative access must be enabled per-protocol on that interface. Without SSH ticked under Administrative Access, the firewall silently drops inbound TCP 22 even if a permissive policy exists.

Why this answer

To allow SSH access to the FortiGate from a specific subnet, you must enable SSH administrative access on the interface connected to that subnet. This setting controls which management protocols are permitted to reach the FortiGate itself at the interface level, independent of firewall policies. Without enabling SSH on the interface, the FortiGate will drop SSH packets at Layer 3 before any policy lookup occurs.

Exam trap

The trap here is that candidates often assume a firewall policy is sufficient to allow management traffic, forgetting that administrative access must be explicitly enabled on the interface for protocols like SSH, HTTPS, or Telnet.

How to eliminate wrong answers

Option A is wrong because enabling only HTTPS administrative access would allow HTTPS but not SSH; SSH requires its own administrative access toggle on the interface. Option B is wrong because there is no 'any' administrative access setting; administrative access is configured per protocol (e.g., HTTPS, SSH, PING) and cannot be set to a wildcard value. Option D is wrong because a firewall policy allowing SSH from the subnet is not sufficient; the interface-level administrative access must first permit SSH management traffic, otherwise the FortiGate discards the packets before they reach the firewall engine.

188
MCQmedium

A FortiGate administrator runs the following command and sees output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate about the session?

A.The session has expired
B.The session is being blocked by a firewall policy
C.The session is an active TCP connection that has been established for 1 hour
D.The session is using UDP
AnswerC

This is correct because 'duration=3600' means the connection has been established for exactly 3600 seconds, which is 1 hour, and 'proto=6' is the IP protocol number for TCP. The 'expire=3599' field shows the remaining lifetime in seconds, so the session is still active. An established TCP session with bidirectional traffic is exactly what a FortiGate tracks in its session table, confirming it is not merely a one-way packet but an ongoing connection.

Why this answer

The output shows `proto=6`, which is the protocol number for TCP, and `proto_state=01`, which in FortiGate's session table indicates an established TCP connection (state ESTABLISHED). The `duration=3600` seconds means the session has been active for exactly 1 hour, and `expire=3599` seconds shows the remaining time before the session times out. This confirms the session is an active TCP connection that has been established for 1 hour, making option C correct.

Exam trap

The trap here is that candidates confuse `duration` with `expire`, assuming a high duration means the session is about to end, when in fact `expire` shows the remaining lifetime, and `proto_state=01` is the key indicator of an active established TCP session.

How to eliminate wrong answers

Option A is wrong because `expire=3599` indicates the session still has 3599 seconds left before expiry, not that it has expired. Option B is wrong because a blocked session would not appear in the session list at all; the `diagnose sys session list` command only shows active sessions that have passed firewall policy inspection. Option D is wrong because `proto=6` explicitly identifies the protocol as TCP, not UDP (which would be proto=17).

189
MCQeasy

A company wants to block all peer-to-peer file sharing applications on the network. Which FortiGate feature should be used to achieve this goal?

A.Application Control
B.Web Filter
C.DNS Filter
D.Intrusion Prevention System (IPS)
AnswerA

Application Control is the correct security feature because it uses deep packet inspection and application signatures to identify P2P traffic regardless of port or protocol. It can block specific applications like BitTorrent, eMule, or LimeWire by matching their unique traffic patterns, even when they use non-standard ports or encryption. This is the only option that directly governs application usage rather than relying on ancillary factors such as URLs or hostnames.

Why this answer

Application Control is the correct feature because it is specifically designed to identify and block peer-to-peer (P2P) file-sharing applications by inspecting traffic patterns and signatures, regardless of the port or protocol used. Unlike port-based blocking, Application Control uses deep packet inspection (DPI) to recognize P2P protocols such as BitTorrent, eDonkey, and Gnutella, even when they attempt to evade detection by using non-standard ports or encryption.

Exam trap

The trap here is that candidates often confuse Application Control with IPS, assuming that IPS can block any unwanted traffic, but IPS focuses on threats and exploits, not on enforcing acceptable use policies for specific applications like P2P file sharing.

How to eliminate wrong answers

Option B (Web Filter) is wrong because it controls access to URLs and web content categories, not the application-layer protocols used by P2P file-sharing software. Option C (DNS Filter) is wrong because it blocks or redirects DNS queries to specific domains, but P2P applications often use hardcoded IP addresses or peer discovery mechanisms that bypass DNS entirely. Option D (Intrusion Prevention System) is wrong because IPS is designed to detect and block network-based attacks and vulnerabilities, not to enforce application usage policies like blocking P2P file sharing.

190
Multi-Selectmedium

A FortiGate admin wants to implement ZTNA to secure access to an internal application. Which TWO components are required for a basic ZTNA configuration?

Select 2 answers
A.A FortiClient EMS server
B.An IPsec VPN tunnel to the client
C.A ZTNA rule (policy) that specifies access conditions
D.A ZTNA application gateway
E.A static route to the application server
AnswersC, D

The ZTNA rule defines the access conditions — source, user or device posture, and protected application — that the FortiGate evaluates before granting access. Without this policy, no enforcement decision occurs, so it is essential alongside the application gateway.

Why this answer

Option C is correct because a ZTNA rule (policy) is the enforcement point on the FortiGate that defines the access conditions—such as user/device identity, posture tags, and application—that must be met before traffic is allowed to the protected resource. Option D is correct because the ZTNA application gateway (configured as a ZTNA server with a virtual host, real server, and access proxy) is the component that publishes the internal application and brokers the client connection through the FortiGate. Options A, B, and E are not required for a basic ZTNA configuration: FortiClient EMS is only needed for advanced posture/tag-based checks, an IPsec VPN tunnel is a separate remote-access method rather than a ZTNA requirement, and a static route is ordinary routing that does not constitute a ZTNA component.

Exam trap

The trap here is that candidates often confuse ZTNA with traditional VPN solutions and incorrectly assume that an IPsec tunnel or a static route is required, when in fact ZTNA relies on application-layer gateways and policy rules without a full network tunnel.

191
MCQmedium

A FortiGate receives log messages with severity 'warning'. What is the log severity level number for 'warning' according to FortiGate's log severity levels?

A.3
B.6
C.4
D.5
AnswerC

In FortiGate's syslog-compatible severity numbering, 4 is exactly Warning, which signals that an abnormal condition has been detected that may require action before a failure occurs. Examples include a VPN tunnel flapping or a security policy denying traffic; these are logged and displayed with the warning icon. Determining that a received log has severity 'warning' therefore maps to the numeric value 4, making this the correct answer.

Why this answer

FortiGate severity levels: Emergency=0, Alert=1, Critical=2, Error=3, Warning=4, Notification=5, Information=6, Debug=7.

192
Multi-Selectmedium

An administrator needs to block access to a specific website using FQDN address objects. Which TWO steps are necessary?

Select 2 answers
A.Create an FQDN address object for the website
B.Add a firewall policy with destination set to the FQDN object and action DENY
C.Create a wildcard FQDN address object
D.Configure a DNS filter to block the FQDN
E.Create a VIP for the website
AnswersA, B

An FQDN address object allows the FortiGate to resolve the website's fully qualified domain name to one or more IP addresses dynamically, referencing the site by name in security policies. This object is a required building block because websites frequently change their IPs, and a static address object would become stale quickly. Creating the object alone does not block traffic; it must be combined with a deny policy to enforce the block.

Why this answer

Creating an FQDN address object (Option A) is necessary because it allows the firewall to resolve the fully qualified domain name to an IP address dynamically, enabling policy enforcement based on the domain rather than a static IP. Adding a firewall policy with destination set to that FQDN object and action DENY (Option B) is required to actually block traffic to the website by matching the resolved IP addresses against the policy. Without both steps, the firewall cannot identify and deny traffic to the specific website using FQDN-based control.

Exam trap

The trap here is that candidates often confuse DNS filtering (Option D) with FQDN-based firewall policies, but DNS filtering only prevents DNS resolution, not direct IP access, while FQDN address objects in a firewall policy block traffic at the network layer regardless of how the destination IP is obtained.

193
MCQeasy

What is the primary purpose of configuring a loopback interface on a FortiGate?

A.To provide a stable IP address for management and routing protocols
B.To aggregate bandwidth from multiple physical interfaces
C.To enable NAT for internal networks
D.To increase the number of available physical ports
AnswerA

A loopback interface supplies a permanent, always-up IP address independent of any physical link state, satisfying the need for stable management access and reliable routing protocol peering. Because it never goes down unless manually removed, it anchors BGP router IDs and management connectivity even when physical interfaces flap.

Why this answer

A loopback interface on a FortiGate is a virtual interface that is always up, independent of physical link states. It provides a stable and reachable IP address for management access (e.g., HTTPS, SSH) and for routing protocols like OSPF or BGP to use as the router ID or source interface, ensuring consistent connectivity even if physical interfaces fail.

Exam trap

The trap here is that candidates often confuse a loopback interface with a physical interface used for link aggregation or NAT, not realizing its primary role is to provide a stable, always-up logical endpoint for management and routing protocol stability.

How to eliminate wrong answers

Option B is wrong because aggregating bandwidth from multiple physical interfaces is achieved through link aggregation (LACP or static aggregation), not a loopback interface. Option C is wrong because NAT for internal networks is configured using policies and IP pools, not by creating a loopback interface. Option D is wrong because a loopback interface is virtual and does not increase the number of physical ports; it only provides a logical addressing endpoint.

194
MCQmedium

A FortiGate admin creates a new firewall policy with source address object 'Internal_Net' and destination 'All'. After saving, traffic from 'Internal_Net' is not matching the new policy but instead matches an older policy with a broader source. What is the MOST likely cause?

A.The source address object 'Internal_Net' has an incorrect subnet mask
B.The new policy is placed below the older policy in the policy list
C.The new policy is disabled
D.Traffic shaping is applied to the new policy and is interfering
AnswerB

FortiGate firewall policies are evaluated sequentially from the top of the policy list downward, and the first policy whose source, destination, and service match the packet is applied. If the new policy is created below an older, broader policy that also matches the same traffic, the older policy will intercept the traffic before the new policy is ever considered. This first-match behavior is the reason traffic appears to hit the older policy, regardless of the new policy's content. The fix is to move the new policy above the older one in the policy list.

Why this answer

A FortiGate firewall evaluates policies sequentially from top to bottom, applying the first match. If the new policy is placed below an older policy with a broader source definition, traffic from 'Internal_Net' will match the older policy first and never reach the new policy. Therefore, option B is the correct answer.

Exam trap

The trap here is that candidates assume a newly created policy will automatically take precedence over older policies, but FortiGate requires manual reordering to enforce policy priority, unlike some vendors that use a most-specific-match logic.

How to eliminate wrong answers

Option A is wrong because an incorrect subnet mask on 'Internal_Net' would cause the object to not match the source IP, but the question states traffic is matching an older policy, implying the source object is functional. Option C is wrong because a disabled policy would show as greyed out in the GUI and generate a log entry indicating 'deny' or 'no match', but the traffic is matching an older policy, not being dropped. Option D is wrong because traffic shaping does not prevent policy matching; it only affects bandwidth allocation after a policy is matched, and would not cause traffic to skip the new policy.

195
MCQmedium

A FortiGate is configured as an SSL VPN server with tunnel mode. Remote users authenticate successfully, but after connecting they cannot reach any internal subnet. The administrator verifies that the SSL VPN firewall policy allows the tunnel interface and that the internal routes exist. Which SSL VPN configuration setting must be checked next to ensure that the correct routes are pushed to the clients?

A.Configure the 'Routing Address' in the SSL VPN portal to include the internal subnets.
B.Enable 'client-certificate' authentication in the SSL VPN settings.
C.Set the SSL VPN to use 'web mode' instead of 'tunnel mode'.
D.Enable 'split-tunneling' in the SSL VPN portal settings.
AnswerA

In tunnel mode, the SSL VPN portal's 'Routing Address' setting defines the destination subnets that are pushed to the client and routed through the tunnel. If it is empty or incorrect, clients will not have routes for internal networks, causing the described failure. This setting is the primary method to control which subnets are reachable over the SSL VPN tunnel.

Why this answer

In SSL VPN tunnel mode, the FortiGate pushes routes to the client based on the 'Routing Address' defined in the SSL VPN portal. If this setting is empty or does not include the internal subnets, the client will not have routes for those networks, even though the tunnel is up and the firewall policy permits traffic. Verifying and correcting the Routing Address is the direct solution.

Exam trap

The trap here is assuming that enabling split tunneling automatically defines which subnets are routed through the tunnel, when in fact the Routing Address setting must be populated.

196
MCQmedium

A FortiGate administrator wants to synchronize the system time with an external NTP server. Which CLI command should be used to configure the NTP server?

A.execute date
B.diagnose ntp status
C.config system ntp
D.config system global
AnswerC

The 'config system ntp' command enters the NTP configuration subtree, which is the correct place on a FortiGate to define NTP servers and enable automatic time synchronization. Under this hierarchy, administrators can set primary and secondary NTP server addresses, configure poll intervals, and optionally configure authentication keys. This persistent configuration is what the FortiGate uses to continuously sync its system clock, fulfilling the requirement to synchronize time via NTP.

Why this answer

The `config system ntp` command enters the NTP configuration context in FortiOS, where you can specify NTP servers, authentication, and synchronization settings. This is the standard CLI path for configuring NTP on FortiGate devices, as opposed to other commands that only display status or set the date manually.

Exam trap

The trap here is that candidates confuse `config system ntp` with `config system global` because both are under the `config system` hierarchy, but NTP configuration has its own dedicated subcommand and is not a global setting.

How to eliminate wrong answers

Option A is wrong because `execute date` is used to manually set the system date and time, not to configure an NTP server for automatic synchronization. Option B is wrong because `diagnose ntp status` is a diagnostic command that shows the current NTP synchronization status, not a configuration command. Option D is wrong because `config system global` is used for global system settings like hostname and admin password, not for NTP server configuration.

197
MCQmedium

An administrator configures an LDAP user group for firewall authentication. Users are able to authenticate, but the FortiGate does not retrieve group membership information. What is likely misconfigured?

A.The LDAP server's IP address is incorrect
B.SSL is not enabled for LDAP
C.The LDAP bind account does not have permission to read group attributes
D.The FortiGate is not joined to the domain
AnswerC

When the FortiGate authenticates a user via LDAP, it also performs a directory search to resolve that user's group memberships, using the credentials of the configured bind account. If the bind account has permission to read the user object but lacks read access to the group objects or their membership attributes (e.g., memberOf, uniqueMember, member), the LDAP search returns an empty or partial result. Because the FortiGate builds its firewall user groups from these returned attributes, insufficient read privileges on group data directly cause the correct behavior that the administrator is seeing: authentication succeeds, but no matching LDAP group is found.

Why this answer

The LDAP bind account must have sufficient permissions to read the memberOf or group membership attributes from the directory. If the bind account can authenticate users but cannot query group membership, the FortiGate will not be able to enforce policies based on LDAP groups. This is the most common cause when authentication succeeds but group information is missing.

Exam trap

The trap here is that candidates assume authentication success means all LDAP functions work, but Fortinet specifically tests the distinction between authentication (bind) and attribute retrieval (search), which require different permissions.

How to eliminate wrong answers

Option A is wrong because if the LDAP server's IP address were incorrect, users would not be able to authenticate at all. Option B is wrong because SSL is not required for LDAP group membership retrieval; LDAP over TCP (port 389) works fine for reading attributes, and SSL/TLS only adds encryption. Option D is wrong because the FortiGate does not need to be joined to the domain; it acts as an LDAP client and only needs to communicate with the LDAP server using the configured bind credentials.

198
MCQmedium

A FortiGate is configured to integrate with FortiSandbox for advanced threat detection. The antivirus profile is set to send files to FortiSandbox when a virus is detected. What action does FortiGate take on the file while it is being analyzed by FortiSandbox?

A.Quarantines the file on the FortiGate
B.Blocks the file until a verdict is received from FortiSandbox
C.Immediately blocks the file and logs the event
D.Allows the file to pass through and logs the event
AnswerB

When the FortiGate is integrated with FortiSandbox, the administrator can configure the sandbox profile to 'block' while the file is being analyzed, meaning the FortiGate holds or buffers the file and does not deliver it to the client until a verdict is received from FortiSandbox. This approach ensures that unknown files are not released to the endpoint unless the sandbox deems them clean, with a fallback action applied if the verdict times out. This is the correct behavior for a blocking integration, as it prevents potential malware from reaching the user during the analysis window.

Why this answer

When the antivirus profile is configured to send files to FortiSandbox for analysis, FortiGate holds the file in a temporary buffer and does not forward it to the client until a verdict is received. This is known as 'block until verdict' mode. The file is not quarantined on the FortiGate, nor is it immediately blocked or allowed; the session is paused pending the sandbox result.

Exam trap

NSE4 often tests the difference between 'block until verdict' and 'quarantine' actions in antivirus profiles, confusing candidates about whether the file is held or stored.

How to eliminate wrong answers

Option A is wrong because quarantine on FortiGate is a separate action used for infected files that are stored for further inspection, not for files awaiting sandbox analysis. Option C is wrong because immediate blocking occurs only if a virus is already detected by the local AV engine, not when the file is sent to FortiSandbox for analysis. Option D is wrong because allowing the file to pass through would defeat the purpose of sandboxing; FortiGate does not permit the file until a verdict is received.

199
MCQmedium

A FortiGate is configured as a DHCP server for the internal network. The administrator wants to ensure that clients receive the FortiGate's internal IP address as the default gateway and a specific DNS server. Which configuration step is required?

A.In the DHCP server settings, configure the default gateway and DNS server options, and ensure the internal interface IP is set as the gateway.
B.Configure a DHCP relay on the internal interface pointing to the FortiGate's internal IP address.
C.Enable DNS forwarding on the internal interface and set the DNS server in the system settings.
D.Create a firewall policy that allows DHCP traffic from the internal network to the FortiGate's internal interface.
AnswerA

The DHCP server settings allow you to specify the default gateway and DNS servers that clients receive. Setting the default gateway to the FortiGate's internal IP ensures clients route traffic through it. This is the correct way to provide these parameters to DHCP clients.

Why this answer

When configuring a DHCP server on a FortiGate, you can specify the default gateway and DNS servers that clients receive in the DHCP options. Setting the default gateway to the FortiGate's internal IP ensures clients use it as their gateway. The DNS server option provides the desired DNS server.

Other options do not achieve this.

Exam trap

The trap here is thinking that a firewall policy or DNS forwarding is needed to provide DHCP options, when the DHCP server settings already include those parameters.

200
MCQhard

A FortiGate in an active-active HA cluster is experiencing asymmetric routing. The administrator runs 'diagnose debug flow' on a packet from a client to a server. The flow trace shows the packet is allowed by policy, but the response is dropped. What is the most likely cause?

A.The TTL of the packet is too low
B.The HA mode should be changed to active-passive
C.The policy on the secondary unit has a different schedule
D.The session synchronization is not enabled between cluster members
AnswerD

In an active-active HA cluster, traffic for a single connection can egress and ingress through different members, and each member must have a copy of the session table. Without session synchronization, the secondary unit that receives the response has no record of the session created by the primary, so it treats the packet as unsolicited traffic and drops it. Enabling session synchronization (for example with 'set session-sync-dev' or using session pickup on FortiGate) ensures both units share session state and can forward replies correctly.

Why this answer

In an active-active HA cluster, session synchronization (session-pickup / session-sync) must be enabled so that return traffic arriving on a different cluster member finds the existing session. If sync is disabled, the secondary unit has no session entry and drops the response, producing the asymmetric-routing drop seen in the debug flow.

Exam trap

NSE4 often tests HA session synchronization — candidates blame HA mode or routing when the real issue is that session-pickup is disabled, causing the secondary to drop return traffic.

How to eliminate wrong answers

Option A is wrong because a low TTL would cause the packet to be dropped with a TTL-expired message, not a response drop after policy allow. Option B is wrong because changing to active-passive does not fix asymmetric routing by itself and is not the root cause; session sync is the actual fix. Option C is wrong because schedule mismatches would cause the initial packet to be denied, not the response to be dropped after the policy allowed it.

201
MCQeasy

An admin wants to block all traffic from the internet to a specific internal server except for the IP address 203.0.113.50. Which firewall policy configuration achieves this using the principle of least privilege?

A.Configure a VIP with restricted source
B.Use a local-in policy to block the server IP
C.Create a deny policy from internet to server with any source, then an allow policy from source 203.0.113.50 to the server above it
D.Create a single allow policy from source 203.0.113.50 to the server and rely on implicit deny for all other traffic
AnswerC

This approach follows the least-privilege principle by creating a broad deny policy for any internet source to the server, then placing a more specific allow policy above it for source 203.0.113.50. Because FortiGate evaluates policies top-down with first-match logic, the allow policy captures the permitted host while all other sources fall through to the explicit deny and are blocked. Without the explicit deny, the implicit deny at the bottom would still block other traffic, but an explicit deny makes the intent clear and reduces reliance on a default behavior.

Why this answer

It follows the principle of least privilege by explicitly denying all traffic from the internet to the internal server (with a deny policy using any source), then placing an explicit allow policy above it for source 203.0.113.50. In FortiGate firewall policy processing, policies are evaluated top-down, so the more specific allow rule for the trusted source is matched first, while the broader deny rule below it blocks all other internet traffic. This ensures only the permitted IP address can reach the server, and all other traffic is explicitly blocked.

Exam trap

The trap here is that candidates often think a VIP with restricted source (Option A) can control source access, but VIPs only handle destination translation and do not enforce source-based filtering; the actual access control must be done via firewall policies.

How to eliminate wrong answers

Option A is wrong because a VIP (Virtual IP) with restricted source is used for destination NAT (port forwarding) and does not control source-based access; it translates the destination IP/port but still relies on firewall policies to permit or deny traffic, so it does not achieve the explicit block-all-except-one requirement. Option B is wrong because a local-in policy controls traffic destined to the FortiGate itself (management traffic), not traffic passing through the FortiGate to an internal server; it cannot be used to filter transit traffic to a specific server. Option D is wrong because relying on implicit deny alone violates the principle of least privilege; while it would block other traffic, it does not provide an explicit deny rule, making it harder to audit and potentially allowing unintended traffic if the implicit deny is accidentally overridden or if there are other policies that match before it.

202
MCQmedium

A FortiGate is configured as a hub in a hub-and-spoke IPsec VPN. The spokes are remote branches. The hub has a Phase 2 selector set to 0.0.0.0/0 for both local and remote subnets. What is the advantage of this configuration?

A.It reduces the number of IPsec SAs needed
B.It simplifies configuration by not needing specific subnet definitions per spoke
C.It allows direct spoke-to-spoke communication without passing through the hub
D.It enables dynamic routing protocols over the VPN
AnswerB

This is correct. Configuring the Phase 2 selector as 0.0.0.0/0 on the hub means the hub will accept any source and destination subnet from the spoke during Phase 2 negotiation, so there is no need to define each spoke's LAN subnets explicitly. When a spoke adds, removes, or changes a protected subnet behind it, the hub's Phase 2 configuration remains valid and no reconfiguration is required. This greatly simplifies hub management in a dynamic environment where spoke subnets are not stable or are unknown in advance.

Why this answer

Using 0.0.0.0/0 as the Phase 2 selector on the hub allows the hub to accept any remote subnet from any spoke without defining each spoke's specific subnet in the Phase 2 configuration. This dramatically simplifies hub configuration in a hub-and-spoke topology because new spokes can be added without modifying the hub's Phase 2 selectors.

Exam trap

NSE4 often tests the misconception that a 0.0.0.0/0 Phase 2 selector enables spoke-to-spoke direct communication or dynamic routing, when it actually only simplifies hub configuration.

How to eliminate wrong answers

Option A is wrong because the number of IPsec SAs is determined by the number of Phase 2 selectors and tunnels, not by using 0.0.0.0/0 — in fact, a wildcard selector can create more SAs, not fewer. Option C is wrong because spoke-to-spoke communication still traverses the hub unless the hub is configured to forward traffic between spokes; the wildcard selector does not enable direct spoke-to-spoke tunnels. Option D is wrong because dynamic routing protocols (like OSPF or BGP over IPsec) require separate configuration such as GRE or VTI interfaces; the Phase 2 selector alone does not enable dynamic routing.

203
MCQhard

A company has two FortiGate 100F units in an active-passive HA cluster with firmware version 7.2.5. The cluster is configured with session pickup and all interfaces are monitored. The network consists of three VLANs: VLAN10 (Users), VLAN20 (Servers), and VLAN30 (DMZ). The cluster is connected to two ISPs: ISP1 (port1) and ISP2 (port2). The internal network uses a single aggregated link (port3 and port4) as a LAG to the core switch. One day, the primary FortiGate experiences a hardware failure and the secondary takes over. After the primary is replaced and rejoins the cluster, the administrator notices that traffic passing through the cluster is intermittently dropping for a few seconds every minute. The administrator checks the cluster status and sees that the new primary (previously secondary) is in 'primary' state and the old primary (newly replaced) is in 'secondary' state. What is the most likely cause of the intermittent traffic drops?

A.The LAG configuration on the new FortiGate does not match the active cluster configuration.
B.Session pickup is not enabled on the new FortiGate.
C.The HA cluster is in split-brain state.
D.The heartbeat interface is configured on the LAG, causing HA instability.
AnswerA

In an HA cluster, all interface and link aggregation group (LAG) settings—including member ports, negotiation mode, and hashing algorithm—must be identical across both units. If the replacement FortiGate's LAG configuration differs from the active cluster configuration, the cluster members cannot synchronize interface states, resulting in link instability, frequent flapping, and interrupted traffic. Traffic drops occur because the secondary's mismatched LAG is unable to pass traffic in the same manner as the primary, violating HA consistency requirements. This matches the symptom, making it the correct root cause.

Why this answer

The most likely cause is that the LAG configuration on the newly replaced FortiGate does not match the active cluster configuration. In an HA cluster, all LAG member interfaces (port3 and port4) must have identical settings—including LACP mode, speed, duplex, and VLAN membership—on both units. When the secondary FortiGate became primary and the replaced unit rejoined as secondary, any mismatch in the LAG configuration would cause the cluster to continuously renegotiate or flap the aggregated link, leading to intermittent traffic drops every few seconds as the HA cluster attempts to synchronize and stabilize the interface state.

Exam trap

The trap here is that candidates often attribute intermittent traffic drops to session pickup or split-brain issues, but the key clue is the periodic nature of the drops (every minute), which points to a configuration mismatch on the aggregated link rather than a session synchronization or HA state problem.

How to eliminate wrong answers

Option B is wrong because session pickup is a feature that synchronizes existing sessions between HA members to prevent traffic loss during failover; it does not cause intermittent drops after the cluster is stable, and it is already enabled on the cluster per the scenario. Option C is wrong because a split-brain state would cause both units to claim primary status and actively forward traffic, leading to duplicate packets and network loops, not intermittent drops every minute, and the cluster status shows one primary and one secondary. Option D is wrong because the heartbeat interface is typically a dedicated interface (e.g., port5 or a separate management port) and is not configured on the LAG; even if it were, HA instability would manifest as constant failovers or loss of heartbeat, not as periodic traffic drops of a few seconds every minute.

204
MCQmedium

An administrator needs to allow VoIP traffic from a remote branch (192.168.2.0/24) to the main office (10.0.0.0/8) using UDP ports 5060 and 10000-20000. What is the most efficient way to define the service in the firewall policy?

A.Create a service group containing both service objects
B.Use a custom service object with port range 5060-20000
C.Create two separate firewall policies, one for each port range
D.Use the predefined 'VoIP' service object
AnswerA

Creating a service group that contains both the SIP service object (UDP/TCP 5060) and the RTP service object (UDP 10000-20000) lets a single firewall policy match the full VoIP call flow. This is the correct approach because FortiGate service groups are logical sets of service objects that allow you to consolidate multiple protocols without expanding the policy count.

Why this answer

Creating a service group allows you to combine two separate service objects (one for UDP 5060 and one for UDP 10000-20000) into a single logical group, which can then be applied in one firewall policy. This is the most efficient method as it avoids duplicating policies or using an overly broad port range, and it leverages FortiGate's service group feature for clean, manageable rule sets.

Exam trap

The trap here is that candidates often assume a single port range (5060-20000) is acceptable for efficiency, overlooking the security risk of opening unnecessary ports, or they mistakenly rely on the predefined 'VoIP' service object without verifying its exact port definitions.

How to eliminate wrong answers

Option B is wrong because using a single custom service object with port range 5060-20000 would incorrectly include ports 5061-9999, which are not required for VoIP traffic and could introduce security risks by allowing unintended traffic. Option C is wrong because creating two separate firewall policies for each port range is inefficient and increases administrative overhead; it also violates the principle of least complexity in firewall design. Option D is wrong because the predefined 'VoIP' service object in FortiGate typically includes a broader set of ports and protocols (e.g., SIP over TCP, RTP over UDP) that may not match the exact requirement of UDP ports 5060 and 10000-20000, potentially allowing unwanted traffic or missing necessary ports.

205
MCQeasy

What is the purpose of a 'realm' in FortiGate SSL VPN configuration?

A.To enable two-factor authentication.
B.To specify the authentication server for the VPN.
C.To create distinct portals with separate authentication and access policies.
D.To define the encryption algorithm for SSL VPN.
AnswerC

A realm in FortiGate SSL-VPN creates a separate URL-based virtual portal, each with its own authentication realm, user group mappings, portal preferences, and access privileges. This allows an administrator to present a tailored VPN login and resource set to different user groups without deploying extra FortiGate units. For example, /remote/employees and /remote/partners can be distinct realms sharing the same physical interface but enforcing independent security policies.

Why this answer

In FortiGate SSL VPN, a 'realm' allows the administrator to create distinct login portals, each with its own authentication requirements and access policies. This enables different user groups (e.g., employees vs. contractors) to have separate VPN experiences without requiring multiple FortiGate interfaces or IP pools. The realm is appended to the VPN URL (e.g., https://fortigate:10443/remote/portal) to direct users to the correct portal.

Exam trap

The trap here is confusing 'realm' with 'authentication server' or 'encryption settings', as candidates often assume a realm is tied to a specific backend authentication source rather than being a portal-level abstraction for access control.

How to eliminate wrong answers

Option A is wrong because two-factor authentication is configured via authentication policies or security realms, not by the realm itself; realms can enforce different authentication methods, but they do not inherently enable two-factor auth. Option B is wrong because the authentication server (e.g., LDAP, RADIUS) is specified in the user group or authentication rule, not in the realm definition; a realm references a portal, not an authentication source. Option D is wrong because encryption algorithms (e.g., AES, 3DES) are defined in the SSL VPN settings or the firewall policy, not in the realm configuration.

206
Multi-Selectmedium

A FortiGate administrator is configuring a firewall policy to allow inbound HTTPS traffic from the internet to an internal web server. The web server has a private IP address 10.0.0.10. The administrator wants to translate the destination IP to the internal server using a Virtual IP (VIP). Which TWO of the following must be configured for the VIP to work correctly? (Choose two.)

Select 2 answers
A.An IP Pool must be configured for the web server's return traffic
B.The VIP must have port forwarding enabled with the external and internal ports set to 443
C.The VIP must have the external IP set to a public IP address assigned to the FortiGate's WAN interface
D.The firewall policy must use the VIP as the destination address object
E.The firewall policy must have NAT enabled
AnswersC, D

The external IP of a virtual IP must be one of the IP addresses assigned to the FortiGate's incoming interface, typically a public IP on the WAN. That address is the destination of the inbound packet, and only traffic addressed to the FortiGate itself can be intercepted and translated to the mapped internal server. If the external IP is not configured on the interface, the FortiGate has no way to receive that packet and the VIP cannot work.

Why this answer

A Virtual IP (VIP) must map a public IP address (typically assigned to the FortiGate's WAN interface) to the internal private IP of the web server. Without setting the external IP to a public address, the VIP cannot receive inbound traffic from the internet. Option D is correct because the firewall policy must reference the VIP as the destination address object; this triggers the destination NAT translation from the public IP to the private IP 10.0.0.10.

Exam trap

The trap here is that candidates often think port forwarding must be explicitly enabled for any port-based VIP, but FortiGate's VIP automatically performs port mapping without requiring the 'port forwarding' checkbox when the external and internal ports are the same.

207
MCQeasy

A junior admin is creating firewall policies and wants to ensure that all traffic not explicitly permitted is denied. Which FortiGate mechanism provides this behavior by default?

A.The security profile group
B.The default route
C.The last explicit deny policy in the policy list
D.The implicit deny rule
AnswerD

The implicit deny rule is a built-in, invisible final policy on every FortiGate firewall; any session that does not match an explicit allow or explicit deny policy is automatically dropped and logged. This rule cannot be deleted or disabled, ensuring that the firewall always enforces a default-deny posture for all unpermitted traffic. It is the true answer to the question because it is automatically applied, requiring no configuration, and it closes the gap that would otherwise allow traffic to pass unchecked.

Why this answer

The implicit deny rule is a default, hidden policy at the end of the FortiGate firewall policy list that denies all traffic not explicitly permitted by any user-created policy. This behavior is inherent to the FortiGate operating system and ensures a default-deny posture without requiring manual configuration. It is always present and cannot be deleted or moved, providing a safety net that blocks any unmatched traffic.

Exam trap

The trap here is that candidates may think the last explicit deny policy (Option C) is the default mechanism, but FortiGate's implicit deny rule is always present and active by default, whereas an explicit deny policy must be manually added and is not a default behavior.

How to eliminate wrong answers

Option A is wrong because a security profile group is a collection of security profiles (e.g., antivirus, web filter) applied to a firewall policy, not a mechanism that denies traffic by default. Option B is wrong because the default route controls where traffic is forwarded, not whether it is permitted or denied; it does not enforce access control. Option C is wrong because while an explicit deny policy can be added to the policy list, it is not present by default; the implicit deny rule is the built-in mechanism that denies all unmatched traffic without requiring any explicit policy.

208
MCQmedium

A FortiGate administrator needs to send logs to a FortiAnalyzer device for long-term storage and analysis. Which log configuration must be set up?

A.Configure an IPsec tunnel to FortiAnalyzer
B.Add the FortiAnalyzer as a logging destination in Log Settings
C.Enable disk logging on the FortiGate
D.Configure syslog server pointing to FortiAnalyzer IP
AnswerB

To forward logs to FortiAnalyzer, you must explicitly configure it as a remote logging destination under Log & Report > Log Setting. You add the FortiAnalyzer's IP address, specify the log types to transmit, and set the upload schedule or real-time mode. This action enables the FortiGate to establish a session using the FortiTelemetry protocol (or FortiTelemetry over SSL/TLS) and stream logs to FortiAnalyzer, which then stores them centrally and provides reporting and analysis.

Why this answer

To send logs to FortiAnalyzer, the administrator must add FortiAnalyzer as a logging destination in the FortiGate's Log Settings (under Log & Report > Log Settings or via CLI 'config log fortianalyzer setting'). This enables the FortiGate to forward logs to the FortiAnalyzer IP address for storage and analysis.

Exam trap

NSE4 often tests the confusion between syslog and FortiAnalyzer logging, so candidates pick 'configure syslog server' thinking any log forwarding works, missing the FortiAnalyzer-specific protocol and features.

How to eliminate wrong answers

Option A is wrong because an IPsec tunnel is not required for FortiAnalyzer logging; FortiAnalyzer communication uses its own protocol (OFTP) over TCP port 514 or 443, and encryption can be enabled without IPsec. Option C is wrong because enabling disk logging on the FortiGate stores logs locally, not on FortiAnalyzer; it is a separate local storage setting. Option D is wrong because configuring a generic syslog server pointing to the FortiAnalyzer IP does not use the FortiAnalyzer protocol and will not provide the full FortiAnalyzer features like log indexing, reports, and dashboards.

209
MCQhard

A FortiGate administrator configures a Central SNAT policy to translate internal IPs to a single public IP for internet access. However, traffic from a specific internal server (10.0.1.100) must use a different public IP. The administrator also creates a policy-based NAT rule in the firewall policy for that server. Which NAT method takes precedence?

A.Central SNAT takes precedence over policy-based NAT
B.Policy-based NAT takes precedence because it is more specific
C.Central SNAT takes precedence because it is evaluated after policy-based NAT
D.The most recently created rule takes precedence
AnswerA

Central SNAT policies are evaluated independently of firewall policies and always take precedence over legacy policy-based NAT on FortiGate. Once central NAT is enabled, any existing policy-based NAT entries are effectively bypassed, and the translator uses the central SNAT rule regardless of how specific or general the policy-based NAT rule is. This precedence is deterministic: the central NAT engine runs first, and a matched central SNAT rule directly defines the source address translation.

Why this answer

In FortiGate, when both Central SNAT and policy-based NAT (configured within a firewall policy) are present, Central SNAT takes precedence. This is because Central SNAT is evaluated before policy-based NAT in the NAT processing order, and once a match is found in Central SNAT, the system applies it and does not proceed to policy-based NAT. The specific server's traffic (10.0.1.100) would still be subject to the Central SNAT rule unless a more specific Central SNAT rule is created for that IP.

Exam trap

The trap here is that candidates often assume policy-based NAT is more specific and thus takes precedence, but FortiGate's NAT evaluation order is fixed and Central SNAT always overrides policy-based NAT regardless of specificity.

How to eliminate wrong answers

Option B is wrong because policy-based NAT does not take precedence over Central SNAT; FortiGate evaluates Central SNAT first, and a match there overrides any policy-based NAT configuration. Option C is wrong because Central SNAT is evaluated before policy-based NAT, not after; the order is Central SNAT → policy-based NAT → VIP/load balancing. Option D is wrong because FortiGate does not use a 'most recently created rule' precedence for NAT; it follows a strict evaluation order based on NAT type, not creation time.

210
Multi-Selecthard

An administrator is troubleshooting a FortiGate that is not passing traffic. The policy allows traffic, but the session table shows no sessions. Which THREE steps should the administrator take to diagnose the issue? (Choose three.)

Select 3 answers
A.Verify the interface status and link state.
B.Run 'diagnose npu np6 show' to check offloading.
C.Check the ARP table to ensure the next-hop MAC is resolved.
D.Examine the routing table for the destination network.
E.Disable the firewall policy and check if traffic flows.
AnswersA, C, D

Verifying the physical and logical interface state is the first step in any FortiGate connectivity troubleshooting. If the interface is administratively down or the link has no carrier (e.g., bad cable, remote device powered off), all traffic through that interface is dropped regardless of routes or policies. Use `get system interface physical` and `diagnose hardware deviceinfo nic` to confirm link status, speed, and duplex.

Why this answer

If the interface is down or has a link issue, the FortiGate cannot send or receive any traffic, resulting in no sessions being created even if the policy allows traffic. Verifying interface status and link state is a fundamental first step in troubleshooting connectivity issues, as it ensures the physical or logical layer is operational before checking higher-layer configurations.

Exam trap

The trap here is that candidates may assume a policy allowing traffic guarantees session creation, but they overlook that the FortiGate must first be able to physically receive and forward the traffic, which depends on interface, ARP, and routing being correctly configured.

211
MCQhard

A FortiGate in HA active-passive cluster is experiencing failover events. The administrator runs 'get system ha status' and sees that the 'sync status' is 'out of sync'. What is the most likely cause?

A.The HA mode is set to active-active.
B.The session synchronization is disabled.
C.The passive unit has a different firmware version.
D.The heartbeat interface is down.
AnswerC

In FortiGate FGCP HA, both members must run the exact same firmware version and build. If the passive unit has a different firmware version, the cluster will fail to synchronize configurations and may not establish a proper HA relationship, causing failover to fail or behave unpredictably. This is a known requirement: firmware mismatch is one of the most common causes of HA cluster formation and failover problems, and it is the correct answer because it directly prevents the passive unit from serving as a valid standby.

Why this answer

In an HA active-passive cluster, the 'sync status' indicates whether configuration and session data are synchronized between the primary and secondary units. When the passive unit has a different firmware version, the FortiGate cannot synchronize its configuration or sessions because the data structures and features may differ between versions, leading to an 'out of sync' status. This is a common prerequisite: both units must run the exact same firmware image for HA synchronization to function.

Exam trap

The trap here is that candidates often confuse 'session synchronization' with 'configuration synchronization' and assume that disabling session sync (Option B) would cause the 'sync status' to show 'out of sync', but the command output specifically reflects configuration sync status, not session sync.

How to eliminate wrong answers

Option A is wrong because setting the HA mode to active-active does not directly cause an 'out of sync' status; active-active mode still requires synchronization between units, and the sync status would reflect issues like version mismatch or heartbeat failure, not the mode itself. Option B is wrong because disabling session synchronization would only affect session failover capability, not the configuration sync status; the 'sync status' field primarily reflects configuration synchronization, and even with session sync disabled, configuration sync can still be 'in sync'. Option D is wrong because if the heartbeat interface is down, the HA cluster would likely detect a link failure and trigger a failover or show 'heartbeat lost' rather than 'out of sync'; the 'sync status' specifically tracks data synchronization, not heartbeat connectivity.

212
MCQmedium

An admin wants to block access to malicious websites using FortiGuard Web Filtering. Which policy configuration is necessary to apply the web filter profile to HTTP/HTTPS traffic?

A.Configure a DNS filter instead of a web filter
B.Create a policy with action DENY and a web filter profile
C.Create an allow policy for HTTP/HTTPS and apply a web filter profile
D.Use an application control profile to block malicious sites
AnswerC

Creating an allow policy for HTTP/HTTPS and attaching a web filter profile is the correct approach because the web filter profile inspects every allowed web request and compares each URL against FortiGuard categories or a custom block list. If a site is categorized as malicious or matches a blocked URL pattern, the web filter blocks the connection while still permitting access to other legitimate sites. This is the built-in mechanism for controlling web access based on URL reputation and content classification.

Why this answer

FortiGate requires an explicit allow policy for HTTP/HTTPS traffic to pass through the firewall before a web filter profile can inspect and block malicious URLs. The web filter profile is applied as a security policy feature on an allow policy, not on a deny policy, since deny policies drop traffic before inspection can occur. Without an allow policy, the traffic would be blocked by default, and the web filter would never see the traffic to apply its filtering rules.

Exam trap

The trap here is that candidates often think a deny policy can have a web filter profile applied to block malicious sites, but FortiGate only applies security profiles on allow policies, and deny policies simply drop traffic without inspection.

How to eliminate wrong answers

Option A is wrong because a DNS filter is used to block domains based on DNS queries, not to inspect HTTP/HTTPS content for malicious URLs; FortiGuard Web Filtering requires a web filter profile, not a DNS filter. Option B is wrong because a policy with action DENY drops all traffic before any security profiles, including web filter profiles, can be applied; web filter profiles can only be attached to allow policies where traffic is permitted and then inspected. Option D is wrong because an application control profile is designed to identify and control application traffic (e.g., Facebook, YouTube), not to block malicious websites based on URL categories; that is the function of a web filter profile.

213
Multi-Selecthard

An administrator receives reports that some internal users can access Facebook despite a web filtering profile that blocks the 'Social Networking' category. The policy is configured with deep inspection. Which THREE checks should the administrator perform to troubleshoot this issue?

Select 3 answers
A.Check if the users are using HTTPS and if the SSL inspection profile has an exemption for Facebook
B.Ensure that the antivirus profile is enabled on the policy
C.Check if the users are accessing Facebook via an SSL VPN tunnel that bypasses the policy
D.Verify that the web filtering profile is applied to the correct policy and that the policy order is correct
E.Confirm that the 'Social Networking' category is not set to 'Monitor' instead of 'Block'
AnswersA, C, D

When users connect to Facebook over HTTPS, FortiGate must decrypt the TLS session (or at least inspect the Server Name Indication) to determine the destination domain and apply URL category filtering. If the SSL inspection profile configured on the policy includes a certificate exemption for Facebook (often added to avoid certificate pinning errors or breakage), the firewall skips decryption entirely and cannot see the SNI or the full URL. As a result, the web filter is effectively blind to the HTTPS session, and the Social Networking category is never matched, allowing the traffic even though the profile is set to Block.

Why this answer

The troubleshooting should focus on three main areas: (A) SSL inspection exemption – if users access Facebook via HTTPS and the SSL inspection profile exempts Facebook traffic, it bypasses the web filter; (C) SSL VPN bypass – traffic through an SSL VPN tunnel may not match the policy if the tunnel interface is not covered; (D) policy application and order – the web filtering profile must be applied to the correct policy and the policy order must be such that this policy is enforced before any conflicting policy. Option E is a valid check, but since the category is already set to 'Block' in the profile, the issue is more likely related to the other three.

Exam trap

A common pitfall is assuming that simply applying a web filtering profile with a block action is sufficient, overlooking SSL inspection exemptions, VPN bypasses, or policy misapplication. The three key checks are verifying SSL inspection exemptions (A), ensuring traffic isn't bypassing via SSL VPN (C), and confirming the correct policy and order (D). Checking the category action (E) is secondary because the profile is already set to block.

214
MCQmedium

A FortiGate with antivirus in flow-based inspection mode is not detecting a known virus in HTTP traffic. The same virus is detected when using proxy-based inspection. What is the most likely reason?

A.Flow-based inspection does not reassemble files or unpack archives, so it misses some viruses
B.Flow-based inspection requires FortiSandbox integration to detect viruses
C.The antivirus signature database is outdated for flow-based inspection
D.Flow-based inspection only scans on explicit proxy policies
AnswerA

In flow-based inspection, FortiOS scans traffic in a single pass by inspecting packets as they traverse the interface without buffering the entire file. Because it does not reassemble the full content or unpack compressed archives (e.g., ZIP, RAR, or base64-encoded files), malware hidden inside these containers can evade detection. Proxy-based inspection, in contrast, buffers the whole object, unpacks archives, and scans each component individually, offering deeper and more thorough virus detection than flow mode.

Why this answer

Flow-based inspection processes traffic as a stream without performing full file reassembly or unpacking archives that proxy-based inspection performs. This allows some viruses to evade detection.

215
MCQeasy

What is the primary purpose of configuring split tunneling on an SSL VPN?

A.To provide two-factor authentication for the VPN connection
B.To encrypt all traffic from the remote client, including Internet traffic
C.To enable the use of client certificates for authentication
D.To allow the remote client to access both the corporate network and the Internet simultaneously without routing all traffic through the VPN
AnswerD

Split tunneling is a VPN configuration that routes only traffic destined for the corporate network (e.g., private subnets or specific IP ranges) through the encrypted tunnel, while all other Internet-bound traffic exits directly from the client's local interface. This allows the remote user to simultaneously access corporate resources and general Internet services without forcing every packet through the VPN gateway, which reduces bandwidth consumption, lowers latency for unrelated web browsing, and prevents the VPN concentrator from becoming a bottleneck. The FortiGate implements this by adding specific routes for corporate CIDRs to be sent over the tunnel interface, leaving the default route on the physical adapter for direct Internet access.

Why this answer

Split tunneling on an SSL VPN allows the remote client to have simultaneous access to the corporate network (via the encrypted VPN tunnel) and the public Internet (directly, without going through the VPN). This reduces bandwidth load on the VPN gateway and improves user experience by not routing non-corporate traffic through the encrypted tunnel. Option D correctly describes this behavior.

Exam trap

The trap here is that candidates often confuse split tunneling with full tunneling, mistakenly thinking split tunneling encrypts all traffic, when in fact it selectively routes only corporate traffic through the VPN.

How to eliminate wrong answers

Option A is wrong because two-factor authentication is a separate security feature, not a function of split tunneling; it is typically implemented via mechanisms like FortiToken or RADIUS. Option B is wrong because encrypting all traffic (including Internet traffic) is the purpose of full tunnel mode, the opposite of split tunneling. Option C is wrong because client certificate authentication is a method of verifying user identity, unrelated to how traffic is routed or split between corporate and Internet destinations.

216
MCQmedium

An administrator wants to aggregate two physical interfaces (port1 and port2) on a FortiGate to increase bandwidth and provide redundancy. Which interface type should be created?

A.Aggregate interface
B.Loopback interface
C.VLAN interface
D.Software switch interface
AnswerA

An aggregate interface bonds port1 and port2 into a single logical link using LACP, combining their throughput and providing failover if one member fails. This delivers both the increased bandwidth and redundancy the administrator requires.

Why this answer

An aggregate interface (also known as a Link Aggregation Group or LAG) combines multiple physical interfaces into a single logical link, increasing bandwidth and providing redundancy. This is the correct choice because it directly supports the administrator's goal of aggregating port1 and port2 on a FortiGate, using the IEEE 802.3ad standard (LACP) or static aggregation.

Exam trap

The trap here is that candidates often confuse a software switch interface with link aggregation, but a software switch simply bridges ports at Layer 2 without the load-balancing and failover mechanisms of an aggregate interface.

How to eliminate wrong answers

Option B is wrong because a loopback interface is a virtual interface used for management or routing protocol stability, not for aggregating physical links. Option C is wrong because a VLAN interface is a logical interface for 802.1Q VLAN tagging on a single physical or aggregate interface, not a method to combine multiple physical ports. Option D is wrong because a software switch interface creates a Layer 2 bridge between ports, but it does not provide link aggregation for increased bandwidth or redundancy in the same way as an aggregate interface.

217
MCQeasy

What is the purpose of a ZTNA (Zero Trust Network Access) tag on a FortiGate?

A.To enable SNMP monitoring on the device
B.To assign static IP addresses to clients
C.To mark devices or users with attributes used in security policies
D.To tag firewall policies for logging purposes
AnswerC

This is the core function of ZTNA tags in FortiGate. Administrators create tags that mark users/devices with attributes such as device posture (e.g., OS patch level, antivirus status), user group membership, location, or other endpoint intelligence. Security policies then reference these tags to enforce granular, context-aware access decisions, enabling zero-trust principles where trust is based on verified attributes rather than network location.

Why this answer

ZTNA tags are user- or device-specific attributes (e.g., 'OS=Windows', 'Compliant=true') that FortiGate applies to endpoints after posture assessment. These tags can then be referenced in firewall policies to enforce granular, identity-aware access control, which is the core of Zero Trust Network Access.

Exam trap

The trap here is that candidates often confuse ZTNA tags with simple firewall policy tags or logging labels, but ZTNA tags are specifically dynamic attributes applied to endpoints for identity- and posture-based policy enforcement, not for administrative labeling or logging.

How to eliminate wrong answers

Option A is wrong because SNMP monitoring is enabled via SNMP configuration under System > SNMP, not through ZTNA tags, which are used for access control decisions. Option B is wrong because static IP assignment is handled by DHCP reservations or manual configuration, not by ZTNA tags, which are dynamic attributes for policy matching. Option D is wrong because firewall policy logging is enabled via the 'Log' option within a policy, not by tagging policies with ZTNA tags; ZTNA tags mark endpoints, not policies.

218
MCQmedium

An admin needs to create a firewall policy that matches traffic based on the destination being a specific geographic location (e.g., France). Which address object should be used?

A.A geography object
B.An FQDN object
C.A subnet object
D.A wildcard FQDN object
AnswerA

A geography object is the correct choice because FortiGate maintains an IP geolocation database that maps IP addresses to countries, and the firewall can match traffic based on the source or destination country directly in the policy. This allows the admin to create a rule that permits or denies all traffic originating from or destined to a specific country without needing to enumerate individual IP ranges. The object type is designed specifically for country-based matching, making it the accurate tool for this requirement.

Why this answer

A geography object is specifically designed to match traffic based on geographic location (country, continent, or region) using the GeoIP database integrated into FortiOS. When a firewall policy needs to allow or deny traffic to or from a specific country like France, a geography object is the correct address object type because it dynamically resolves IP ranges assigned to that country by IANA/RIRs.

Exam trap

The trap here is that candidates may confuse geography objects with FQDN or wildcard FQDN objects, mistakenly thinking domain-based objects can represent geographic regions, when in fact only geography objects leverage the GeoIP database for location-based matching.

How to eliminate wrong answers

Option B is wrong because an FQDN object matches traffic based on a fully qualified domain name, not geographic location, and relies on DNS resolution to IP addresses. Option C is wrong because a subnet object defines a specific IP range or network prefix, which cannot represent an entire country's dynamic IP allocations. Option D is wrong because a wildcard FQDN object matches multiple domain names using a wildcard pattern (e.g., *.example.com), which has no relation to geographic location.

219
Multi-Selectmedium

An administrator needs to integrate a FortiGate with FortiManager for centralized management. Which two steps are required? (Choose two.)

Select 2 answers
A.Enable SNMP on the FortiGate to allow FortiManager to monitor.
B.Configure a firewall policy allowing traffic from FortiGate to FortiManager on port 541 (FGFM).
C.Configure a VPN tunnel between FortiGate and FortiManager.
D.Configure the FortiGate to connect to FortiManager using the 'execute fortimanager register' command.
E.Set the FortiGate's operation mode to transparent.
AnswersB, D

FortiGate and FortiManager communicate exclusively via the FGFM protocol, which uses TCP port 541. A firewall policy must explicitly permit FortiGate-originated traffic to the FortiManager's IP address on port 541, otherwise registration and heartbeat messages are blocked. This policy is a prerequisite for both the 'execute fortimanager register' command and ongoing management operations, such as policy push and firmware updates.

Why this answer

FortiGate and FortiManager communicate using the FortiGate-to-FortiManager (FGFM) protocol over TCP port 541. A firewall policy must be configured on the FortiGate to allow outbound traffic to the FortiManager on this port, enabling registration and ongoing management. Option D is correct because the 'execute fortimanager register' command is the standard CLI method to initiate the registration process, providing the FortiManager IP address and optional registration code.

Exam trap

The trap here is that candidates often confuse SNMP (monitoring) or VPN (tunneling) as requirements for FortiManager integration, when in fact the FGFM protocol on TCP 541 and the registration command are the only mandatory steps.

220
MCQhard

A security administrator is configuring an IPS sensor on a FortiGate to protect a web server. The sensor includes a signature that detects a specific HTTP exploit. The administrator wants to ensure that the signature blocks the attack but also generates a log entry for each detection. Which action should be taken for that signature in the IPS sensor?

A.Set the action to 'Reset' and enable 'Logging'.
B.Set the action to 'Monitor' and enable 'Packet Logging'.
C.Set the action to 'Block' and enable 'Logging' for the signature.
D.Set the action to 'Block' and enable 'Packet Logging'.
AnswerC

In a FortiGate IPS sensor, each signature can be configured with an action and logging. Setting the action to 'Block' drops the matching traffic, and enabling logging ensures an event is recorded. This directly meets the requirement to block the attack and generate a log entry for each detection.

Why this answer

In a FortiGate IPS sensor, the 'Block' action drops packets matching the signature, preventing the exploit from reaching the server. Enabling 'Logging' for that signature ensures an event is recorded each time the signature is triggered. This combination satisfies both the blocking and logging requirements without unnecessary packet capture or connection resets.

Exam trap

The trap here is confusing 'Packet Logging' with standard event logging; packet logging captures raw packets for deep analysis, while standard logging records the event details.

221
MCQeasy

Which mode of SSL VPN provides full network-layer access to the remote network, allowing any application to function as if the client is directly connected?

A.Tunnel mode
B.Web mode
C.Split tunneling mode
D.Clientless mode
AnswerA

Tunnel mode is the SSL VPN operating mode that creates a virtual network adapter on the client and assigns it an IP address from the internal network. This allows the client to participate at Layer 3, with routing entries directing traffic through the TLS-encrypted tunnel, thereby providing full network-layer access to any IP-based service, not just web applications.

Why this answer

Tunnel mode is correct because it creates a virtual network interface on the client that obtains an IP address from the FortiGate's SSL VPN address pool, encapsulating all IP traffic within SSL/TLS packets. This provides full network-layer (Layer 3) access, allowing any application—including those using non-HTTP protocols like SSH, RDP, or custom TCP/UDP services—to function as if the client were directly connected to the remote network.

Exam trap

The trap here is that candidates often confuse 'split tunneling' as a separate VPN mode when it is actually a routing configuration option within tunnel mode, leading them to incorrectly select Option C instead of recognizing that tunnel mode is the only mode providing full network-layer access.

How to eliminate wrong answers

Option B (Web mode) is wrong because it only provides application-layer access via a web portal, proxying HTTP/HTTPS traffic and cannot handle non-web protocols or raw IP packets. Option C (Split tunneling mode) is wrong because it is not a distinct SSL VPN mode; it is a routing policy that can be applied within tunnel mode to direct only specific subnets over the VPN, but it does not define the fundamental access method. Option D (Clientless mode) is wrong because it relies on a web browser and supports only limited applications (e.g., web-based, VNC, RDP via Java/ActiveX) without installing a client, thus lacking full network-layer access.

222
MCQeasy

A company wants to block all HTTP traffic but allow HTTPS. Which SSL inspection method should be used on the firewall policy?

A.No inspection
B.Deep inspection
C.Full SSL inspection
D.Certificate inspection
AnswerA

Applying no SSL inspection to the policy means the FortiGate does not decrypt or examine HTTPS traffic; it simply passes it through based on the destination port (443). This is the appropriate and efficient choice when the requirement is to block HTTP (port 80) while allowing HTTPS, because the firewall can enforce that distinction entirely through policy rules without the overhead or privacy implications of encryption decryption.

Why this answer

To block HTTP (port 80) while allowing HTTPS (port 443), no SSL inspection is needed because the firewall can distinguish traffic by port number alone. SSL inspection is only required when you need to examine the encrypted payload of HTTPS traffic, not to permit or deny it based on the protocol. Therefore, 'No inspection' is correct for this access control requirement.

Exam trap

The trap here is that candidates assume HTTPS traffic must be inspected to be allowed, but the firewall can permit or deny based on the destination port without any SSL inspection at all.

How to eliminate wrong answers

Option B (Deep inspection) is wrong because deep inspection decrypts HTTPS traffic to inspect the payload, which is unnecessary and adds overhead when the goal is simply to allow HTTPS and block HTTP based on port. Option C (Full SSL inspection) is wrong because it also involves decrypting all SSL/TLS traffic, which is not required for port-based allow/deny decisions. Option D (Certificate inspection) is wrong because certificate inspection only validates the server certificate without decrypting the traffic, but it is still an SSL inspection method that is not needed for simple port-based filtering.

223
MCQhard

A FortiGate administrator runs the following command and sees: 'diagnose ips anomaly list' returns no entries, but the IPS sensor is configured with anomaly signatures. What is the MOST likely reason the signatures are not appearing?

A.The IPS sensor is configured in 'passive' mode, which suppresses anomaly detection.
B.The anomaly signatures have not triggered any events yet because traffic thresholds have not been exceeded.
C.Anomaly signatures are not displayed by 'diagnose ips anomaly list'; they require a different command.
D.The IPS sensor is not enabled on any firewall policy.
AnswerB

Anomaly signatures in FortiOS are rate-based detectors that only generate an event when traffic exceeds a configured threshold, such as packets per second or concurrent connections. The command output lists only triggered anomalies, not configured ones. If no traffic has exceeded the threshold, the list remains completely empty, which is a normal operational state.

Why this answer

The 'diagnose ips anomaly list' command displays only anomaly signatures that have been triggered and are currently in a state where thresholds have been exceeded. If no entries appear, it means the configured anomaly signatures have not yet detected traffic surpassing their defined thresholds (e.g., packets per second, connections per second). Anomaly signatures are threshold-based and only become active when the monitored traffic exceeds the configured limits, at which point they would appear in the list.

Exam trap

The trap here is that candidates assume 'diagnose ips anomaly list' shows all configured anomaly signatures, but it only shows those that have been triggered by exceeding thresholds, leading them to incorrectly suspect a configuration or policy issue.

How to eliminate wrong answers

Option A is wrong because IPS sensors do not have a 'passive' mode that suppresses anomaly detection; passive mode in FortiGate refers to the IPS engine's action (e.g., monitoring without blocking), but anomaly signatures still trigger and appear in the list if thresholds are exceeded. Option C is wrong because 'diagnose ips anomaly list' is the correct command to display triggered anomaly signatures; no alternative command is needed for this purpose. Option D is wrong because even if the IPS sensor is not enabled on any firewall policy, the anomaly signatures would still be configured in the sensor and would appear in the 'diagnose ips anomaly list' output if they had triggered, though they would not affect traffic; the absence of entries is due to thresholds not being exceeded, not policy attachment.

224
Multi-Selecthard

A FortiGate administrator notices that some users can bypass the web filter to access prohibited categories. The web filter profile is applied to the firewall policy. Which TWO actions should the admin take to determine why the filter is being bypassed? (Choose two.)

Select 2 answers
A.Ensure that the FortiGate has connectivity to FortiGuard
B.Check if the firewall policy that the traffic matches has the web filter profile applied
C.Verify that the DNS filter is also applied to the same policy
D.Check if SSL deep inspection is enabled on the policy
E.Examine the client's browser proxy settings
AnswersB, D

In FortiOS, web filtering is enforced only when a web filter profile is explicitly attached to the firewall policy that matches the traffic. If the policy used by the affected users does not have the profile selected, the FortiGate will not inspect URLs and will allow all web traffic, creating a bypass. The administrator should examine the policy's Security Profiles section to confirm the web filter profile is applied. This is the most direct and common cause of a partial web filter bypass.

Why this answer

Option B is correct because if the firewall policy that actually matches the user's traffic does not have the web filter profile attached, the filter is never evaluated and users can reach prohibited categories; the admin must confirm the profile is applied on the matching policy, not just on some other policy. Option D is correct because without SSL deep inspection the FortiGate cannot decrypt HTTPS traffic, so it cannot inspect the URL path or content and the web filter is effectively bypassed for HTTPS sites. Option A is not the primary troubleshooting step here since FortiGuard connectivity issues would typically cause rating failures or blocks rather than selective bypass, and the question focuses on why filtering is bypassed.

Option C is incorrect because the DNS filter is a separate feature and its absence does not explain why the web filter profile is not blocking traffic. Option E is incorrect because client browser proxy settings are not a FortiGate web filter configuration element and would not be the standard cause of the filter being bypassed in this scenario.

Exam trap

NSE4 often tests the misconception that attaching a web filter profile is sufficient, ignoring that policy match order and SSL deep inspection are required for the filter to actually see and block HTTPS traffic.

225
MCQmedium

You are configuring a route-based IPsec VPN with BGP over the tunnel. After Phase 2 is up, the BGP session does not establish. You run 'diagnose debug ipsec' and see no errors. What should you check next?

A.Disable anti-replay on the tunnel
B.Enable NAT traversal
C.Ensure the tunnel interface is added to the BGP neighbor configuration
D.Check the Phase 1 proposal
AnswerC

In a route-based IPsec VPN, the tunnel interface is a logical interface that terminates the encrypted traffic and carries the BGP session. For BGP to establish, the neighbor command must reference the correct IP address of the remote peer on that tunnel interface, and the local tunnel interface must be set as the update source (or the source interface must be reachable). Without the tunnel interface being tied to the BGP neighbor configuration, BGP will attempt to use another interface as the source, so the TCP connection fails even though IPsec is up.

Why this answer

When Phase 2 is up and 'diagnose debug ipsec' shows no errors, the IPsec tunnel is functioning correctly at the encryption layer. The BGP session failing to establish typically indicates a routing or interface configuration issue. Option C is correct because the tunnel interface must be explicitly added to the BGP neighbor configuration (e.g., 'config router bgp -> config neighbor -> set interface <tunnel>') so that BGP knows to send its TCP packets (port 179) over that specific tunnel interface; without this, BGP may try to use the physical interface instead, causing the session to fail.

Exam trap

The trap here is that candidates assume a successful Phase 2 means the tunnel is fully operational for all traffic, overlooking that BGP requires explicit interface binding to the tunnel interface to establish the TCP session.

How to eliminate wrong answers

Option A is wrong because disabling anti-replay would not affect BGP session establishment; anti-replay is a security feature that prevents packet replay attacks and does not impact routing protocol connectivity. Option B is wrong because NAT traversal is only needed when a NAT device is present between the VPN peers, and the question does not indicate any NAT scenario; enabling it unnecessarily would not resolve a BGP peering issue. Option D is wrong because Phase 1 is already up (as Phase 2 is established), so checking Phase 1 proposals is irrelevant; the problem lies in the BGP configuration, not the IKE/ISAKMP settings.

Page 2

Page 3 of 11

Page 4

All pages