Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 226–300

773 questions total · 11pages · All types, answers revealed

Page 3

Page 4 of 11

Page 5
226
MCQhard

A FortiGate admin wants to inspect SSL-encrypted traffic for threats using IPS. The admin creates an SSL inspection profile with 'full SSL inspection' and applies it to the policy. What additional configuration is necessary for the IPS engine to process the decrypted traffic?

A.Enable 'set ssl-ssh-profile' under the IPS sensor
B.Enable 'IPS' under the SSL inspection profile
C.Configure the FortiGate's CA certificate on clients
D.Apply an IPS sensor to the same firewall policy
AnswerD

An IPS sensor must be explicitly applied to the same firewall policy that references the SSL/SSH inspection profile. After the SSL/SSH proxy decrypted the traffic, the flow or proxy engine passes the decrypted payload to the IPS sensor, which matches it against configured intrusion signatures and enforces the defined action. Policy-level binding is essential: without both the SSL/SSH profile and the IPS sensor on the same policy, the FortiGate cannot inspect the decrypted content for threats.

Why this answer

IPS inspection requires that the security profile (IPS sensor) is also applied to the same firewall policy. SSL inspection alone only decrypts; the IPS profile inspects the decrypted traffic.

227
MCQeasy

What is the default administrative account on a FortiGate?

A.master
B.root
C.guest
D.admin
AnswerD

The correct default administrative account is 'admin'. Every FortiGate ships with this local account, which is assigned the 'super_admin' profile and provides full control through the web GUI and CLI. On first login, administrators are required to set a password for the admin account, ensuring the factory state does not remain with an empty secret.

Why this answer

The default administrative account on a FortiGate is 'admin'. This account is created automatically during the initial boot process and has full super-admin privileges, allowing complete access to the device's configuration and management interfaces. It is the only default account with administrative rights, and its password must be set during initial setup.

Exam trap

The trap here is that candidates may confuse the FortiGate default admin account with the default accounts of other operating systems or network devices, such as 'root' on Linux or 'master' on Cisco, leading them to select the wrong option.

How to eliminate wrong answers

Option A is wrong because 'master' is not a default account on FortiGate; it is a common default account on some other network devices like Cisco switches. Option B is wrong because 'root' is the default administrative account on Unix/Linux systems, not on FortiGate, which runs a proprietary FortiOS. Option C is wrong because 'guest' is a default read-only account on FortiGate, not an administrative account; it is intended for limited monitoring access without configuration privileges.

228
MCQmedium

An administrator is troubleshooting a connectivity issue. A ping from the FortiGate to 8.8.8.8 succeeds, but traffic from internal hosts to the internet is failing. The firewall policy allows the traffic. What is the most likely cause?

A.The default route on the FortiGate is missing
B.The internal hosts have the wrong default gateway configured
C.DNS resolution is failing
D.The FortiGate's interface to the internal network is down
AnswerB

Hosts forward traffic to destinations outside their subnet via their configured default gateway; in this network, that gateway should be the FortiGate's internal interface IP. If the hosts point to a different or nonexistent IP, their packets for internet destinations are sent to a device that cannot forward them, so the traffic never reaches the FortiGate. Even though the FortiGate can ping 8.8.8.8, the hosts remain isolated, which precisely matches the reported symptoms.

Why this answer

Since the FortiGate can ping 8.8.8.8, its default route and internet connectivity are working. The issue is that internal hosts cannot reach the internet, which points to a Layer 3 forwarding problem at the host level. The most likely cause is that the internal hosts have the wrong default gateway configured, so their traffic is not being sent to the FortiGate for routing.

Exam trap

The trap here is that candidates assume a successful ping from the FortiGate implies end-to-end connectivity, overlooking that the internal hosts' default gateway configuration is independent of the FortiGate's own routing table.

How to eliminate wrong answers

Option A is wrong because if the default route on the FortiGate were missing, the FortiGate itself would not be able to ping 8.8.8.8, but the ping succeeded. Option C is wrong because DNS resolution failure would prevent name resolution, but the question describes a connectivity issue where traffic to the internet is failing, and the ping to 8.8.8.8 uses an IP address, not a hostname, so DNS is not the bottleneck. Option D is wrong because if the FortiGate's interface to the internal network were down, the FortiGate would not be able to communicate with internal hosts at all, but the firewall policy allows the traffic and the FortiGate can still ping external IPs, indicating the internal interface is operational.

229
MCQeasy

A FortiGate administrator needs to create a firewall policy that allows traffic from the internal network to the DMZ. The internal network is 10.0.0.0/24 and the DMZ network is 172.16.0.0/24. Which source and destination address objects should be used in the policy?

A.Source: 172.16.0.0/24, Destination: 10.0.0.0/24
B.Source: all, Destination: all
C.Source: 10.0.0.0/24, Destination: all
D.Source: 10.0.0.0/24, Destination: 172.16.0.0/24
AnswerD

This policy correctly matches the internal network as the source and the DMZ network as the destination. It restricts traffic to the intended flow. The addresses should be defined as firewall address objects, but the subnets are the correct values. This is the precise configuration required.

Why this answer

The firewall policy must match the specific source and destination networks to allow only the desired traffic. Using the internal subnet as source and DMZ subnet as destination creates a precise policy. Other combinations either reverse the direction or are too permissive, failing to meet the requirement.

Exam trap

The trap here is reversing the source and destination or using 'all' when a specific subnet is required.

230
MCQmedium

An administrator runs 'diagnose debug application fnbamd -1' on a FortiGate to troubleshoot authentication issues. The output shows that the FortiGate successfully contacts the LDAP server but the user authentication fails. What does this indicate?

A.The user's password is incorrect or the user account is locked
B.The LDAP server is unreachable
C.The LDAP bind user password is incorrect
D.The LDAP schema does not match what FortiGate expects
AnswerA

In the fnbamd debug output, "successful contact" confirms that the FortiGate established a TCP session and communicated with the LDAP server; the failure happens during the final bind step where the end user's distinguished name (DN) and password are verified. An LDAP 'invalidCredentials' or 'accountDisabled' result at this stage is the server's definitive rejection of that specific user's password or account state, not a communication problem. Therefore, the correct interpretation is that the user's password is wrong or the user account is locked out, disabled, or expired.

Why this answer

The 'diagnose debug application fnbamd -1' output shows successful contact with the LDAP server, meaning network connectivity and server reachability are fine. Since the server is reachable but authentication fails, the most likely cause is that the user's credentials (password) are incorrect or the account is locked/disabled on the LDAP server. This is a standard LDAP bind failure scenario where the server returns an 'invalid credentials' or 'account locked' error.

Exam trap

The trap here is that candidates often confuse a successful TCP connection or LDAP server response with successful authentication, not realizing that the FortiGate must perform a separate bind with the user's credentials, which can fail independently.

How to eliminate wrong answers

Option B is wrong because the output explicitly indicates the FortiGate successfully contacts the LDAP server, ruling out unreachability. Option C is wrong because the LDAP bind user password is used for the initial bind to search the directory, not for user authentication; a bind user password issue would prevent the search from succeeding, but the output shows contact is successful. Option D is wrong because an LDAP schema mismatch would typically cause attribute retrieval failures (e.g., group membership), not a direct authentication failure during the user bind attempt.

231
MCQeasy

Which of the following statements about FortiGate backup is true?

A.The backup includes all current sessions and logs
B.The backup file contains the full configuration and can be encrypted with a password
C.A backup can be restored only on the same hardware model
D.Backup files are saved in plain text format
AnswerB

The FortiGate backup file is a single archive that contains the complete device configuration, including all firewall policies, address objects, VPN settings, and system parameters. During the backup process, you have the option to encrypt the file with a password, which is then required to restore it. This encryption ensures that even if the backup file is intercepted, the configuration data remains confidential and cannot be read without the password.

Why this answer

FortiGate backup files contain the full device configuration, including all settings and policies, and can be encrypted with a password using the 'execute backup config' command with the 'password' option. This ensures confidentiality during storage or transfer, as the backup is stored in a binary format that requires the password for decryption during restoration.

Exam trap

The trap here is that candidates often assume backups include all runtime data like sessions and logs, or that backups are model-specific, but FortiGate explicitly separates configuration from volatile state data, and restoration is firmware-version dependent, not hardware-model dependent.

How to eliminate wrong answers

Option A is wrong because FortiGate backups do not include current sessions or logs; sessions are volatile and stored in memory, while logs are typically stored separately on local disk or external storage, and only the configuration is backed up. Option C is wrong because a backup can be restored on any FortiGate model that supports the same firmware version, not just the same hardware model, though some model-specific features may require manual adjustment. Option D is wrong because backup files are saved in a binary, encrypted format (not plain text) when a password is set, and even without a password, the file is not plain text but a proprietary format that cannot be easily read.

232
MCQmedium

An administrator needs to configure a loopback interface on a FortiGate for management purposes. Which of the following is true regarding loopback interfaces?

A.Loopback interfaces are virtual and can be used as source IP for management traffic.
B.Loopback interfaces require a physical port to be associated.
C.Loopback interfaces cannot be used in firewall policies.
D.Loopback interfaces are only available in transparent mode.
AnswerA

Loopback interfaces in FortiGate are virtual, software-only interfaces that are always up and not tied to any physical port. They can be assigned an IP address and configured as the source IP for management traffic, such as syslog, SNMP, NTP, or administrative HTTPS/SSH sessions. Because they are independent of physical link states, they provide a stable management address even when a physical interface fails.

Why this answer

Loopback interfaces are virtual interfaces that are always up and do not depend on the physical link state. They can be assigned an IP address and used as the source IP for management traffic (e.g., SNMP, syslog, NTP, or administrative access), ensuring consistent reachability even if physical interfaces fail. This makes option A correct.

Exam trap

The trap here is that candidates often assume loopback interfaces are only for routing protocols or require a physical link, but FortiGate allows them to serve as stable management endpoints independent of physical interface status.

How to eliminate wrong answers

Option B is wrong because loopback interfaces are purely virtual and do not require any physical port association; they exist independently of hardware interfaces. Option C is wrong because loopback interfaces can be used in firewall policies just like any other interface, allowing traffic to be inspected or routed to/from the FortiGate itself. Option D is wrong because loopback interfaces are available in both NAT/Route mode and transparent mode, not exclusively in transparent mode.

233
MCQmedium

A FortiGate administrator configures SNMPv2c on the FortiGate to send traps to a monitoring server. However, no traps are received. The monitoring server can ping the FortiGate. What is the MOST likely cause?

A.SNMPv2c is not supported on FortiGate; only v3 is supported.
B.The FortiGate's firewall policy blocks SNMP traffic from the monitoring server.
C.The SNMP community string does not match between FortiGate and server.
D.The monitoring server's IP is not in the SNMP trap receiver list on FortiGate.
AnswerC

In SNMPv2c, the community string operates as a shared secret in each PDU, and the trap receiver uses it to validate the message. If the community string configured for trap sending on FortiGate does not match what the monitoring server expects, the server will silently discard the trap without any response, since SNMP uses UDP. The FortiGate will continue to show the trap as sent, so the administrator sees a successful configuration but no trap arrives at the monitoring station. This mismatch is the most common reason for traps not appearing when network connectivity and receiver IP are correct.

Why this answer

SNMPv2c uses community strings as a form of authentication. If the community string configured on the FortiGate does not match the one configured on the monitoring server, the server will reject the trap. Since the server can ping the FortiGate, network connectivity is fine, and the issue is most likely an authentication mismatch.

Exam trap

The trap here is that candidates assume SNMP traps are blocked by a firewall policy, but since traps are initiated by the FortiGate (outbound), the server's ability to ping the FortiGate confirms Layer 3 reachability, shifting the focus to authentication or receiver configuration.

How to eliminate wrong answers

Option A is wrong because FortiGate fully supports SNMPv2c, not just v3. Option B is wrong because SNMP traps are sent from the FortiGate to the server, not initiated by the server, so a firewall policy blocking inbound SNMP from the server would not prevent outbound traps. Option D is wrong because the trap receiver list specifies where traps are sent, not which IPs are allowed to receive them; if the server's IP were missing from the list, the FortiGate would not send traps to it, but the question states the administrator configured traps to be sent to the server, so this is less likely than a community string mismatch.

234
MCQmedium

A company is deploying FortiGate for outbound web filtering. They want to block users from accessing social media sites during business hours, but still allow access to cloud-based productivity tools like Office 365. Which approach should the administrator use to meet this requirement?

A.Create a firewall policy to block all traffic to ports commonly used by social media (e.g., TCP 443).
B.Use a web filter profile to block URLs containing 'facebook' or 'twitter'.
C.Configure an application control profile with rules to block social media applications and allow Office 365 applications.
D.Implement a DNS filter to block DNS queries for social media domains.
AnswerC

Application control is the correct approach because it classifies traffic based on application signatures and behaviors rather than static port numbers or URL strings. A properly configured application control profile can identify and block specific social media applications—even when they run over HTTPS or use non-standard ports—while explicitly allowing Office 365 applications, including Outlook, Teams, and SharePoint Online. This granularity meets the exact requirement without disrupting business-critical services, and with SSL inspection enabled, it remains effective against encrypted social media traffic.

Why this answer

Application control is the correct approach because it can identify and control applications like social media and Office 365 based on their unique signatures, regardless of the ports or protocols they use. Unlike URL filtering or port blocking, application control can differentiate between Office 365 traffic and social media traffic even when both use HTTPS on TCP 443, allowing the administrator to block social media while permitting cloud productivity tools.

Exam trap

The trap here is that candidates often assume URL filtering or port blocking is sufficient, but the NSE4 exam tests the understanding that application control is required when applications share the same port (e.g., TCP 443) and need to be differentiated based on their behavior, not just their domain or port.

How to eliminate wrong answers

Option A is wrong because blocking TCP 443 would block all HTTPS traffic, including Office 365 and other legitimate web services, not just social media. Option B is wrong because URL filtering based on keywords like 'facebook' or 'twitter' is unreliable—social media sites often use dynamic URLs, CDNs, or IP addresses that do not contain those keywords, and users can bypass it via direct IP access or HTTPS encryption. Option D is wrong because DNS filtering only blocks domain resolution; users could still access social media by using direct IP addresses, cached DNS entries, or alternative DNS servers, making it an incomplete solution.

235
MCQmedium

The output of 'diagnose debug application ike -1' shows 'no proposal chosen' for a Phase1 negotiation. Which action should the administrator take to resolve this?

A.Increase the Phase1 lifetime on both sides
B.Verify the pre-shared key is correct
C.Check and align the Phase1 encryption, authentication, and DH group settings
D.Change the IKE version from v1 to v2
AnswerC

This is the correct action: 'no proposal chosen' is an IKE Phase1 notification sent by the responder when it cannot find any overlap between its configured Phase1 parameters and the initiator's proposed transforms. The encryption algorithm, authentication/integrity algorithm, and Diffie-Hellman (DH) group must all match on both peers, and if any one of them differs, the proposal is rejected. Checking and aligning these settings directly addresses the root cause and is the standard troubleshooting step for this error.

Why this answer

The 'no proposal chosen' error in Phase 1 IKE negotiation indicates that the two VPN peers cannot agree on a common set of security parameters (proposal). The administrator must check and align the Phase 1 settings, specifically the encryption algorithm, authentication method, and Diffie-Hellman group, because these are the mandatory parameters matched during the IKE SA negotiation. Option C directly addresses this by ensuring both sides use identical Phase 1 proposals.

Exam trap

The trap here is that candidates often confuse 'no proposal chosen' with authentication failures (pre-shared key mismatch) or version incompatibility, but the error specifically occurs during the proposal exchange before authentication or version negotiation takes place.

How to eliminate wrong answers

Option A is wrong because increasing the Phase 1 lifetime does not resolve a proposal mismatch; lifetime is a secondary parameter that is negotiated after the proposal is accepted, and a mismatch here would cause a different error or rekey issue. Option B is wrong because a pre-shared key mismatch typically results in an authentication failure (e.g., 'invalid cookie' or 'authentication failed'), not a 'no proposal chosen' error, which occurs before authentication. Option D is wrong because changing the IKE version from v1 to v2 does not fix a proposal mismatch; both versions require matching encryption, authentication, and DH group settings, and the error would persist if the proposals are still misaligned.

236
MCQmedium

An administrator wants to back up the FortiGate configuration to a TFTP server at 10.10.10.10. Which CLI command should be used?

A.execute backup config tftp 10.10.10.10
B.backup config tftp 10.10.10.10
C.copy config tftp 10.10.10.10
D.execute save config tftp 10.10.10.10
AnswerA

The correct FortiOS command begins with the 'execute' keyword, which is required for privileged system-level operations. 'execute backup config' triggers a configuration export, and the protocol 'tftp' followed by the server IP (10.10.10.10) instructs the FortiGate to send the config file via TFTP to that host. This is the exact syntax documented by Fortinet for backing up the configuration to a TFTP server, and it will generate a file typically named after the device hostname and date.

Why this answer

The correct command to back up a FortiGate configuration to a TFTP server is 'execute backup config tftp <server-ip>'. This is because 'execute' is the FortiOS CLI keyword for initiating operational commands, and 'backup config tftp' specifies the action and protocol. The syntax is case-sensitive and must include the 'execute' prefix to be recognized by the FortiGate CLI.

Exam trap

The trap here is that candidates may forget the 'execute' keyword, which is mandatory for all operational commands in FortiOS, and mistakenly choose a command that looks correct but lacks it, such as 'backup config tftp'.

How to eliminate wrong answers

Option B is wrong because it omits the required 'execute' keyword; FortiOS CLI commands for operational tasks like backup must start with 'execute'. Option C is wrong because 'copy config tftp' is not a valid FortiOS command; the correct verb is 'backup', not 'copy'. Option D is wrong because 'execute save config tftp' uses 'save' instead of 'backup', and 'save config' is used for saving the running configuration to flash memory, not for exporting to a TFTP server.

237
MCQeasy

What is the primary difference between route-based and policy-based IPsec VPNs on a FortiGate?

A.Route-based requires a static route, policy-based uses dynamic routing.
B.Route-based encrypts all traffic, policy-based encrypts only specified services.
C.Route-based supports only IKEv2, policy-based supports both IKEv1 and IKEv2.
D.Route-based uses a tunnel interface, policy-based uses firewall policies to define traffic selectors.
AnswerD

Route-based IPsec binds the tunnel to a virtual tunnel interface, so firewall policies route traffic into it and support dynamic routing. Policy-based IPsec instead matches traffic through firewall policies acting as traffic selectors, without a tunnel interface.

Why this answer

The primary difference is that route-based IPsec VPNs use a tunnel interface (e.g., 'phase1-interface' and 'phase2-interface') which participates in routing, while policy-based IPsec VPNs rely on firewall policies with explicit traffic selectors (source/destination addresses and services) to trigger encryption. In route-based VPNs, the tunnel interface is assigned an IP address and routes are used to direct traffic into the tunnel, decoupling encryption from policy matching. In policy-based VPNs, the firewall policy itself defines what traffic is encrypted, making the traffic selector part of the policy configuration.

Exam trap

The trap here is that candidates often confuse 'route-based' with 'dynamic routing' and 'policy-based' with 'static routing', but in reality, route-based VPNs can use either static or dynamic routing, while policy-based VPNs are inherently static and cannot participate in dynamic routing protocols.

How to eliminate wrong answers

Option A is wrong because route-based VPNs can use static or dynamic routing (e.g., OSPF, BGP) over the tunnel interface, and policy-based VPNs do not support dynamic routing at all—they rely solely on static traffic selectors defined in firewall policies. Option B is wrong because both route-based and policy-based VPNs encrypt only the traffic that matches their respective routing/policy rules; neither encrypts 'all traffic' by default. Option C is wrong because both VPN types support IKEv1 and IKEv2 on FortiGate; the choice of IKE version is independent of whether the VPN is route-based or policy-based.

238
Multi-Selecthard

An administrator is configuring an IPS sensor to protect a web server. The administrator wants to ensure that the IPS blocks attacks targeting the web server, but also wants to minimize false positives. Which two actions should the administrator take when configuring the IPS sensor? (Choose two.)

Select 2 answers
A.Enable IPS signature updates and use the 'recommended' action for signatures.
B.Set the action for all signatures to 'monitor' to avoid false positives.
C.Set the action for critical and high severity signatures to 'block'.
D.Apply the IPS sensor only to the firewall policy that allows traffic to the web server.
E.Enable all signatures and set the action to 'block' for all.
AnswersC, D

Setting critical and high severity signatures to block ensures that the most dangerous attacks are stopped. These signatures are typically well-tested and have low false positive rates. This balances security with minimizing false positives, as lower severity signatures might be more prone to false positives.

Why this answer

To block attacks while minimizing false positives, the administrator should focus on high-severity signatures with block action and apply the IPS sensor only to the relevant traffic. This targeted approach ensures critical threats are stopped without disrupting legitimate traffic. Other options either block everything (causing false positives) or monitor everything (not blocking).

Exam trap

The trap here is thinking that enabling all signatures with block action is the most secure, but it often leads to false positives and network disruption.

239
Multi-Selecthard

A FortiGate administrator is designing an SSL VPN solution for 500 remote users. The users need full network access. Which two design considerations are most important?

Select 2 answers
A.Ensure the SSL VPN IP pool has enough addresses for concurrent users.
B.Create firewall policies that allow traffic from the SSL VPN interface to internal networks.
C.Configure split tunneling to reduce load on the FortiGate.
D.Use certificate-based authentication for all users.
E.Enable port forwarding for RDP and SSH.
AnswersA, B

In tunnel-mode SSL VPN, each remote user must be leased a unique virtual IPv4 address from the configured SSL VPN IP pool. If the pool is smaller than the peak number of concurrent authenticated users, the FortiGate cannot allocate an address for additional sessions, so those users will fail to establish the tunnel even though authentication succeeds. Sizing the pool to the maximum simultaneous connections (not just the total number of registered users) is therefore a hard prerequisite for scalability.

Why this answer

The SSL VPN IP pool must have enough addresses to assign to all concurrent users. Without a sufficient pool, users will fail to obtain an IP address and cannot access the network. Option B is correct because firewall policies are required to permit traffic from the SSL VPN interface (e.g., ssl.root) to internal networks; without them, traffic is dropped even if the tunnel is established.

Exam trap

The trap here is that candidates often confuse optional features (like split tunneling or certificate authentication) with mandatory design requirements, overlooking the fundamental need for IP pool sizing and firewall policies to enable basic connectivity.

240
Multi-Selectmedium

A FortiGate administrator needs to configure source NAT for a group of internal servers (10.0.1.100-10.0.1.110) so that each server uses a unique public IP from the range 203.0.113.20-203.0.113.30. The requirement is that each internal IP maps to a fixed external IP (one-to-one mapping) and not port overload. Which TWO settings should be configured in the IP Pool? (Choose two.)

Select 2 answers
A.Type: Overload
B.Enable 'Fixed Port Range'
C.External IP Range: 203.0.113.20-203.0.113.30
D.Type: One-to-One
E.Use Central SNAT instead of IP Pool
AnswersC, D

Specifying 'External IP Range: 203.0.113.20-203.0.113.30' defines a pool with exactly 11 usable public addresses (203.0.113.20, 21, ..., 30), matching the number of internal servers that must be translated. In one-to-one NAT, each inbound request to a given public IP is forwarded to the associated internal host alongside outbound sessions, preserving the port and eliminating port-exhaustion risk. This range is the correct external IP pool definition because its count precisely satisfies the stated requirement.

Why this answer

The External IP Range must be set to 203.0.113.20-203.0.113.30 to define the pool of public IPs that will be mapped one-to-one to the internal servers. Option D is correct because Type: One-to-One ensures each internal IP is permanently mapped to a unique external IP, without port address translation (PAT), meeting the requirement of fixed one-to-one mapping.

Exam trap

The trap here is that candidates often confuse 'One-to-One' with 'Overload' and select 'Type: Overload' thinking it still provides unique IPs, but Overload always uses PAT and cannot guarantee a fixed external IP per internal host.

241
MCQeasy

Which web filtering feature allows an administrator to force web search engines to filter explicit content in search results, regardless of the user's browser settings?

A.DNS filter
B.URL filter
C.Application control
D.Safe search
AnswerD

Safe search enforcement rewrites search-engine traffic so the engine itself filters explicit results, independent of browser preferences. This satisfies the requirement to force filtering regardless of user browser settings, since the FortiGate modifies the request rather than relying on client-side configuration.

Why this answer

Safe search is a web filtering feature that forces supported search engines (e.g., Google, Bing, Yahoo) to filter explicit content from search results by appending specific query parameters (such as `safe=active` for Google) to the search request. This enforcement occurs at the FortiGate proxy level, overriding the user's browser settings and ensuring compliance with acceptable use policies.

Exam trap

The trap here is that candidates often confuse DNS filter or URL filter with safe search, thinking that blocking explicit content at the domain or URL level is equivalent to filtering search results, but only safe search modifies the actual search engine query parameters to enforce content filtering at the source.

How to eliminate wrong answers

Option A is wrong because DNS filter controls access based on domain name resolution (e.g., blocking or redirecting DNS queries to known malicious or category-based domains), but it does not modify search engine query parameters to enforce content filtering. Option B is wrong because URL filter blocks or allows access based on the full URL path or pattern (e.g., blocking specific URLs or categories), but it cannot inject parameters into search engine requests to enforce safe search. Option C is wrong because application control identifies and controls application traffic (e.g., blocking or shaping social media or streaming apps), but it does not have the capability to modify HTTP request parameters within search engine queries.

242
MCQeasy

Which SSL/TLS inspection mode only validates the server certificate without decrypting the traffic?

A.Deep inspection
B.Flow-based inspection
C.Certificate inspection
D.Proxy-based inspection
AnswerC

Certificate inspection is correct because this SSL/TLS inspection mode only validates the server certificate and does not perform any decryption of the encrypted session. FortiGate forwards the client hello, receives the server certificate, and verifies its validity (e.g., signing chain, issuer, trust, and possible revocation) while leaving the payload encrypted and untouched. This mode is lightweight, preserves performance, and is typically used when you only need to enforce certificate-based policies or ensure clients do not connect to untrusted servers. It does not inspect application content, making it the only mode that strictly only validates the server certificate.

Why this answer

Certificate inspection is the correct answer because it validates the server certificate's authenticity and expiration without decrypting the traffic. This mode checks the certificate chain and revocation status using OCSP or CRLs, but the encrypted payload remains untouched, preserving end-to-end encryption.

Exam trap

The trap here is that candidates confuse 'certificate inspection' with 'deep inspection' because both involve SSL/TLS, but deep inspection requires decryption while certificate inspection does not.

How to eliminate wrong answers

Option A is wrong because deep inspection performs full SSL/TLS decryption and re-encryption to inspect the application-layer content, not just certificate validation. Option B is wrong because flow-based inspection (also known as flow-based SSL inspection) decrypts traffic to analyze flows and signatures, not just certificates. Option D is wrong because proxy-based inspection establishes a man-in-the-middle proxy that decrypts and re-encrypts all traffic, requiring full certificate handling, not mere validation.

243
MCQmedium

An organization has multiple remote sites connected via IPsec VPN. The administrator needs to ensure that traffic from the internal network (10.0.0.0/8) to the VPN destination (10.10.0.0/16) uses a specific interface (port2) instead of the default route. Which feature should be configured?

A.Central NAT
B.Static route with higher distance
C.Policy-based routing
D.Traffic shaping
AnswerC

Policy-based routing (PBR) in FortiOS lets you define a rule that matches specific criteria — such as source IP, source interface, protocol, or port — and then explicitly sets the output interface and next-hop gateway, overriding the routing table lookup. For an organization with multiple remote sites connected via IPSec, PBR can steer traffic from each site's subnet toward the appropriate VPN tunnel or local gateway. This is exactly the capability needed when destination-based routing alone would send all traffic over the same path.

Why this answer

Policy-based routing (PBR) allows you to override the default routing table by matching traffic based on source/destination addresses and directing it to a specific egress interface (port2). This is the correct feature because the requirement is to force traffic from 10.0.0.0/8 to 10.10.0.0/16 out port2, bypassing the default route.

Exam trap

The trap here is confusing policy-based routing with static route manipulation; candidates often think a static route with a higher distance can override the default route, but distance only affects route preference, not the ability to force traffic out a specific interface when a default route with lower distance exists.

How to eliminate wrong answers

Option A is wrong because Central NAT is used for centralized NAT policy management in SD-WAN or hub-and-spoke topologies, not for overriding routing decisions. Option B is wrong because a static route with a higher distance (administrative distance) would only be used as a backup if the primary route fails; it cannot force traffic out a specific interface when a lower-distance default route exists. Option D is wrong because traffic shaping controls bandwidth allocation and QoS, not the path or interface selection for traffic.

244
MCQhard

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A.The session is in an error state
B.The session has been idle for 3600 seconds
C.The session is to port 3600
D.The session is about to expire in 3599 seconds
AnswerD

The expire field in FortiOS session output indicates the remaining time in seconds before the session entry is removed (i.e., its time-to-live). An expire value of 3599 seconds means the session still has approximately one hour of life left, not that it is expiring immediately. This value decreases as the session ages and is reset by traffic matching the session, so it reflects how much longer the session will be tracked if no further packets arrive.

Why this answer

The 'expire=3599' field indicates the session will be removed from the session table in 3599 seconds. The 'duration=3600' shows the session has been active for 3600 seconds, so the total session lifetime is 7200 seconds (3600 + 3599). This is a normal TCP session (proto=6) in state 01 (SYN_SENT), not an error or idle condition.

Exam trap

The trap here is confusing 'duration' (time since session started) with 'expire' (time until session ends), leading candidates to incorrectly interpret the 3600 value as idle time or a port number.

How to eliminate wrong answers

Option A is wrong because 'proto_state=01' indicates a normal TCP SYN_SENT state, not an error state; error states would show different values like 11 (TIME_WAIT) or 0 (CLOSE). Option B is wrong because 'duration=3600' shows the session has been active for 3600 seconds, not idle; idle time is tracked separately via 'idle' field, which is not present here. Option C is wrong because 'dport=443' is the destination port, and 'duration=3600' is the session age in seconds, not a port number.

245
MCQmedium

A FortiGate cluster in active-passive HA is configured with two heartbeat interfaces. The primary unit fails completely. The secondary unit detects the failure and becomes primary. After the original primary recovers, it remains in passive mode. What is the most likely reason for this behavior?

A.The heartbeat interfaces are not properly configured
B.The HA override setting is disabled
C.The priority of the original primary is lower than the current primary
D.The HA override setting is enabled
AnswerB

The HA override setting directly controls preemption after recovery: when override is disabled, a formerly failed primary that rejoins the cluster negotiates as a standby and does not force the active unit to step down, even if it has a higher configured priority. This exactly matches the described behavior of an active-passive cluster that stays with the current primary after the original primary recovers. Since override is disabled by default on FortiGate, the cluster remains in its current role assignment.

Why this answer

When override is disabled (the default), the recovered unit will not preempt the current primary. The cluster stays with the current primary until it fails. This is the expected behavior for graceful recovery.

246
MCQeasy

Which security profile type is used to prevent sensitive data such as credit card numbers from being sent out of the network via email or web traffic?

A.Email filter profile
B.Antivirus profile
C.Web filter profile
D.DLP profile
AnswerD

A DLP (Data Leak Prevention) profile uses dictionaries of sensitive data types—such as credit card numbers, US Social Security numbers, dates of birth, and custom regex patterns—and inspects traffic content at the application layer to detect matches in files, HTTP posts, emails, or FTP transfers. When a match occurs, the DLP sensor can log, alert, quarantine, or block the transaction, and it can be applied in a FortiGate security policy together with antivirus and web-filter profiles. Its purpose is specifically to prevent or control the unauthorized transfer of sensitive data, making it the correct profile for this requirement.

Why this answer

A DLP (Data Loss Prevention) profile is specifically designed to inspect content in transit (e.g., email, web traffic) and block or alert on sensitive data patterns such as credit card numbers, Social Security numbers, or other regulated data. Unlike other security profiles, DLP uses predefined or custom data identifiers and pattern matching to enforce data protection policies, making it the correct choice for preventing sensitive data exfiltration.

Exam trap

The trap here is that candidates often confuse DLP with email filtering or web filtering, assuming that content inspection for sensitive data is handled by those profiles, but DLP is the only profile dedicated to data loss prevention with pattern-based content inspection.

How to eliminate wrong answers

Option A is wrong because an email filter profile focuses on spam, phishing, and malware detection in email traffic, not on scanning for sensitive data patterns like credit card numbers. Option B is wrong because an antivirus profile detects and blocks malicious files or malware signatures, but it does not inspect the content of data for sensitive information patterns. Option C is wrong because a web filter profile controls access to websites based on URL categories or reputation, not on the content of data being transmitted in HTTP/HTTPS requests or responses.

247
Multi-Selectmedium

An active-passive HA cluster is experiencing frequent failovers. Which TWO factors could cause unnecessary failovers? (Choose two.)

Select 2 answers
A.Using a data interface as the heartbeat interface
B.An unstable network link for the heartbeat
C.Different firmware versions on cluster members
D.Mismatched HA passwords between cluster members
E.Mismatched HA priority values
AnswersA, B

Data interfaces may have fluctuating link status, triggering failover.

Why this answer

Incorrect heartbeat interface configuration (e.g., using a busy data port) can cause false positives. A mismatched HA password prevents proper communication, but may not cause failover; mismatched priority affects role selection, not failover frequency. Unstable heartbeat links cause failover.

248
Multi-Selectmedium

A FortiGate administrator is troubleshooting why antivirus scanning is not working for HTTPS traffic. Which TWO steps should be verified?

Select 2 answers
A.Ensure the antivirus profile is set to proxy-based inspection
B.Ensure the firewall policy has SSL/TLS deep inspection enabled
C.Confirm that the web filter profile is also applied
D.Verify that the antivirus profile is applied to the policy
E.Check that the FortiSandbox is online for advanced scanning
AnswersB, D

Without SSL/TLS deep inspection enabled on the firewall policy, HTTPS sessions pass through still encrypted, and the antivirus engine can only see the outer TLS handshake, not the HTTP payload or files inside. Deep inspection forces the FortiGate to terminate the TLS connection, decrypt the content, scan it with the antivirus profile, then re-encrypt the session to the client. This is the most likely root cause when antivirus misses malware in HTTPS traffic, since the profile itself may be correctly configured but cannot see inside the tunnel.

Why this answer

HTTPS traffic is encrypted, so the FortiGate must decrypt it using SSL/TLS deep inspection before the antivirus engine can scan the payload. Without deep inspection, the antivirus profile sees only encrypted packets and cannot detect threats within the HTTPS stream.

Exam trap

The trap here is that candidates often assume proxy-based inspection is required for HTTPS antivirus scanning, but the critical step is enabling SSL/TLS deep inspection on the firewall policy, regardless of the inspection mode.

249
MCQeasy

A FortiGate has two firewall policies: Policy 1 (ID 1) allows HTTP from any to 10.0.0.0/8, and Policy 2 (ID 2) denies all traffic from 192.168.1.0/24 to any. Traffic from 192.168.1.10 to 10.0.0.5 on port 80 is received. Which policy will match first?

A.Policy 1 (ID 1) will match and accept the traffic
B.Both policies will match, and the traffic will be denied
C.Policy 2 (ID 2) will match and deny the traffic
D.Neither policy matches, so the traffic is dropped by default deny
AnswerA

FortiGate firewall policies are evaluated sequentially from the top of the policy list, and Policy 1 (ID 1) is positioned before Policy 2. Because the traffic in question matches all criteria of Policy 1 — source, destination, and service — it triggers the allow action immediately. Once a matching policy is found, the FortiGate stops processing further policies and applies the matched policy's action, thus accepting the traffic.

Why this answer

Policy 1 (ID 1) matches first because FortiGate evaluates firewall policies in sequential order from top to bottom (lowest ID to highest ID) until a match is found. The source IP 192.168.1.10 falls within the 'any' source of Policy 1, and the destination 10.0.0.5 is within 10.0.0.0/8, with HTTP (port 80) matching the service. Since Policy 1 matches, it is applied and the traffic is accepted, even though Policy 2 would also match if reached.

Exam trap

The trap here is that candidates assume a more specific source (192.168.1.0/24) will override a broader source (any) due to specificity, but FortiGate uses sequential order, not longest-prefix matching, for policy selection.

How to eliminate wrong answers

Option B is wrong because FortiGate stops at the first matching policy; it does not evaluate or combine multiple policies for the same traffic. Option C is wrong because Policy 2 has a higher ID (2) than Policy 1 (1), so it is evaluated after Policy 1, which already matches and accepts the traffic. Option D is wrong because Policy 1 explicitly matches the traffic, so the implicit default deny is never reached.

250
MCQmedium

A network administrator notices that traffic from the internal network (10.0.1.0/24) to the internet is not being matched by the intended firewall policy (ID 10). The policy uses source address 'internal_subnet' (10.0.1.0/24) and destination address 'all'. There is another policy (ID 5) with source 'all' and destination 'all' that also matches this traffic. What is the most likely reason policy 10 is not being matched?

A.Policy 5 has a higher priority because it is above policy 10 in the policy list
B.Policy 10 is configured with an expired security certificate
C.The source address object 'internal_subnet' is incorrectly configured
D.Policy 10 has a schedule that is not active
AnswerA

In Fortinet FortiGate, firewall policies are evaluated sequentially from top to bottom; the first matching policy is applied. Since Policy 5 is listed above Policy 10, and both match the same traffic (e.g., source internal_subnet, destination, service), FortiGate selects Policy 5 and stops evaluating further. Therefore, Policy 10 is never reached, making its order, not its settings, the cause of its non-execution.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom, and the first matching policy is applied. Since policy 5 with source 'all' and destination 'all' is listed above policy 10, traffic from 10.0.1.0/24 to the internet matches policy 5 first, preventing policy 10 from ever being evaluated. This is the most likely reason the intended policy is not being matched.

Exam trap

The trap here is that candidates may think policy priority is based on specificity or configuration details like certificates or schedules, but FortiGate strictly uses sequential order from top to bottom, making the position of the 'all' policy the critical factor.

How to eliminate wrong answers

Option B is wrong because security certificates are used for SSL inspection or VPN authentication, not for matching traffic to firewall policies; an expired certificate would not prevent a policy from being matched. Option C is wrong because if the source address object 'internal_subnet' were incorrectly configured, the traffic would not match policy 10 at all, but the question states the traffic is being matched by another policy, implying the object is correct. Option D is wrong because a schedule that is not active would cause the policy to be inactive only during certain times, but the question does not indicate a time-based issue, and the traffic is still being matched by policy 5, which has no schedule restriction.

251
Matchingmedium

Match each FortiGate NAT type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Translates private source IP to public IP for outbound traffic

Translates public destination IP to private IP for inbound traffic

Assigns a range of ports to a private IP for NAT

Translates IPv6 traffic to IPv4 and vice versa

Translates IPv4 traffic to IPv6

Why these pairings

Source NAT modifies source IP of outgoing packets; Destination NAT modifies destination IP of incoming packets; Static NAT provides one-to-one mapping; PAT enables many-to-one translation via ports. Distractors swap the descriptions of Source and Destination NAT.

252
MCQeasy

A FortiGate administrator wants to block all traffic to websites that are categorized as 'Malware' and 'Phishing'. Which security profile should be configured to achieve this goal?

A.DNS Filter profile
B.Web Filter profile
C.IPS profile
D.Application Control profile
AnswerB

A Web Filter profile is the correct mechanism because it applies FortiGuard URL category classification directly to HTTP/HTTPS traffic in the firewall policy. By referencing categories such as Malware and Phishing, the profile can immediately block all sessions to sites in those categories, regardless of the actual IP address, and it supports exemptions and overrides. The profile also integrates with antivirus inspection and SSL deep inspection for encrypted traffic, providing a holistic web access control.

Why this answer

A Web Filter profile on FortiGate is used to block or allow traffic based on website categories, including 'Malware' and 'Phishing'. It leverages FortiGuard category-based filtering to inspect HTTP/HTTPS traffic and apply actions (block, allow, monitor) per category, making it the correct profile to block those specific website categories.

Exam trap

NSE4 often tests the distinction between Web Filter (URL categories) and DNS Filter (DNS-based blocking) — candidates may choose DNS Filter thinking it blocks malware sites, but it does not use the same category database.

How to eliminate wrong answers

Option A is wrong because DNS Filter profiles block based on DNS queries and are used for DNS-based filtering, not for categorizing and blocking website content by FortiGuard categories like Malware/Phishing. Option C is wrong because IPS profiles detect and block exploits and vulnerabilities, not website categories. Option D is wrong because Application Control profiles manage applications (e.g., Facebook, BitTorrent) based on application signatures, not website content categories.

253
MCQmedium

A FortiGate administrator wants to configure ZTNA to secure access to an internal application. Which of the following components is essential for ZTNA to function?

A.FortiCloud
B.FortiClient EMS
C.FortiAnalyzer
D.A VPN tunnel to the client
AnswerB

FortiClient EMS is the cornerstone of Fortinet's ZTNA solution because it collects and reports user identity, endpoint inventory, and device compliance posture to FortiGate. FortiGate then uses this telemetry and EMS tags to make per-session, application-aware access decisions based on the endpoint's trust level. This identity and posture verification is what ZTNA needs to ensure that only authorized users on healthy devices can reach internal applications.

Why this answer

FortiClient EMS (Enterprise Management Server) is essential for ZTNA because it manages endpoints, enforces compliance, and provides the client certificate and posture information required for zero-trust access decisions. Without FortiClient EMS, the FortiGate cannot verify device identity and health.

Exam trap

NSE4 often tests the misconception that ZTNA requires a VPN or FortiCloud, when the essential component is FortiClient EMS for endpoint management and compliance.

How to eliminate wrong answers

Option A is wrong because FortiCloud is a cloud management platform but is not required for ZTNA functionality; it can be used for logging and management but not for endpoint identity. Option C is wrong because FortiAnalyzer is for logging and reporting, not for ZTNA enforcement. Option D is wrong because ZTNA does not require a traditional VPN tunnel; in fact, ZTNA replaces VPN with per-application access, so a VPN tunnel is not essential.

254
MCQeasy

What is the purpose of the DNS filter security profile on a FortiGate?

A.To block DNS queries to known malicious domains
B.To inspect DNS traffic for virus signatures
C.To filter spam emails based on DNS blacklists
D.To prevent DNS tunneling attacks
AnswerA

The DNS filter profile inspects DNS queries and responses, blocking requests to known malicious domains using FortiGuard's domain threat intelligence. This satisfies the stem's requirement by preventing resolution before a connection occurs, stopping malware command-and-control and phishing at the DNS layer rather than at the subsequent HTTP session.

Why this answer

The DNS filter security profile on a FortiGate is designed to block DNS queries to known malicious domains by comparing the domain names in DNS requests against a regularly updated database of malicious or categorized domains. This prevents users from resolving domains associated with malware, phishing, or command-and-control servers, thereby stopping threats before an IP connection is even established.

Exam trap

The trap here is that candidates often confuse DNS filter with antivirus or antispam profiles, mistakenly thinking it inspects payloads or email content, when in fact it operates strictly at the DNS query layer to block domain resolution.

How to eliminate wrong answers

Option B is wrong because DNS filter does not inspect DNS traffic for virus signatures; that function is performed by antivirus profiles, which scan file attachments or payloads for malware patterns. Option C is wrong because filtering spam emails based on DNS blacklists is a feature of antispam profiles, not DNS filter — DNS filter operates at the DNS query level, not on email content. Option D is wrong while DNS tunneling is a real attack, the primary purpose of DNS filter is to block queries to malicious domains, not to detect or prevent DNS tunneling; tunneling detection requires deep packet inspection or anomaly-based analysis, typically handled by IPS or application control profiles.

255
MCQmedium

A FortiGate admin has configured a firewall policy allowing traffic from the internal network (10.0.1.0/24) to the internet (any). Users report that they cannot access a specific website (203.0.113.5). The admin runs 'diagnose firewall fqdn list' and sees that the FQDN object used in a policy above the allow policy resolves to an IP that includes 203.0.113.5. What is the MOST likely cause?

A.The destination NAT on the allow policy is misconfigured
B.The FortiGate's DNS server is not resolving the FQDN correctly
C.The antivirus profile on the allow policy is blocking the website
D.The FQDN object resolved to the IP after the policy was created, but the policy lookup uses the cached IP and matches before the allow policy
AnswerD

FortiGate evaluates policies top-down, and the FQDN object above the allow policy resolves to an IP covering 203.0.113.5. That cached address matches first, so traffic hits the upper policy's action instead of the intended allow rule. Policy order and FQDN cache timing, not routing, cause the block.

Why this answer

The FQDN object in a policy above the allow policy resolved to an IP that includes 203.0.113.5. FortiGate performs policy lookup based on cached IP addresses for FQDN objects. Since the FQDN object's cached IP now matches the destination IP of the website, traffic hits the higher-priority policy (which likely denies or otherwise blocks the traffic) before reaching the allow policy.

This is why users cannot access the website despite the allow policy existing.

Exam trap

The trap here is that candidates assume the allow policy will always match traffic to the website, but they overlook that FortiGate evaluates policies top-down and uses cached IP addresses for FQDN objects, so a higher-priority policy with a matching cached IP can intercept the traffic before the allow policy is reached.

How to eliminate wrong answers

Option A is wrong because destination NAT is not involved in this scenario; the issue is about policy matching order based on cached FQDN resolution, not NAT misconfiguration. Option B is wrong because the FQDN resolved correctly (the admin sees the IP in the list), so DNS resolution is not the problem. Option C is wrong because there is no indication that an antivirus profile is blocking the website; the problem is policy precedence, not security profile filtering.

256
Multi-Selectmedium

A FortiGate administrator is troubleshooting an issue where HTTPS traffic is not being properly inspected by the web filter. The policy has SSL inspection enabled. Which TWO commands would provide the most useful real-time debugging information? (Choose two.)

Select 2 answers
A.diagnose test application ips 1
B.diagnose debug flow filter dport 443 ; diagnose debug flow show function-name ; diagnose debug enable
C.diagnose sys session filter dport 443 ; diagnose sys session list
D.execute log display
E.diagnose sniffer packet any 'port 443' 4
AnswersB, E

This sequence enables real-time flow debugging filtered to destination port 443, with function-name output to display each FortiOS inspection stage (e.g., SSL proxy, application control, IPS). The 'diagnose debug enable' command activates the trace, streaming event details to the console as the packet traverses the engine. It is the most direct way to pinpoint exactly where an HTTPS session is accepted, decrypted, blocked, or dropped.

Why this answer

Option B is correct because the debug flow commands (diagnose debug flow filter dport 443, diagnose debug flow show function-name, diagnose debug enable) provide real-time packet-path tracing that shows whether the HTTPS session is being matched to the firewall policy and whether SSL inspection is applied, which is essential for troubleshooting web-filter inspection issues. Option E is correct because diagnose sniffer packet any 'port 443' 4 captures live packets on port 443 with interface information, allowing the administrator to verify that HTTPS traffic is actually reaching the FortiGate and to observe the handshake behavior in real time. Option A is not appropriate because diagnose test application ips 1 only tests IPS engine operation and does not trace HTTPS web-filter or SSL-inspection processing.

Option C is not the best choice because diagnose sys session filter dport 443 with diagnose sys session list only shows the session table entries and does not provide real-time debugging of the inspection path. Option D is not suitable because execute log display only shows already-generated log entries and does not deliver live debugging information.

Exam trap

NSE4 often tests the specific debug commands for SSL inspection, and candidates may choose session list or logs instead of real-time debug flow and sniffer.

257
MCQeasy

Which FortiGate security profile is BEST suited for blocking DNS queries to known malicious domains?

A.Web Filter profile
B.IPS profile
C.Application Control profile
D.DNS Filter profile
AnswerD

DNS Filter profile is purpose-built to inspect DNS query messages on port 53, comparing the queried domain against FortiGuard’s DNS category database and botnet indicators. It can take actions such as block, monitor, redirect, or allow based on domain category, and it supports sinkholing for botnet C2 domains. By operating below the web and application layers, DNS Filter can block malicious domains even for HTTPS, non-HTTP, or custom applications, making it the correct choice for DNS-level blocking.

Why this answer

The DNS Filter profile on FortiGate is purpose-built to inspect DNS queries and block resolution of known malicious domains by comparing them against FortiGuard DNS threat intelligence. It operates at the DNS layer, so it stops the connection before it is even established. This is the most direct and efficient control for blocking DNS queries to malicious domains.

Exam trap

NSE4 often tests the layer confusion between Web Filter (HTTP/HTTPS) and DNS Filter (DNS), so candidates pick Web Filter thinking it covers all domain-based blocking.

How to eliminate wrong answers

Option A is wrong because a Web Filter profile inspects HTTP/HTTPS requests and categories, not DNS queries, so it cannot block resolution of a malicious domain at the DNS layer. Option B is wrong because an IPS profile inspects packet payloads for exploit signatures and anomalies, not DNS domain reputation. Option C is wrong because Application Control identifies and controls applications by signature, not by DNS domain reputation.

258
MCQmedium

A FortiGate HA cluster is running in active-passive mode with two units. The administrator notices that the primary unit fails over to the secondary unit every few minutes, causing service disruption. The heartbeat interfaces are configured on port1 and port2. What is the MOST likely cause of the frequent failovers?

A.Session synchronization is consuming too much bandwidth
B.The HA priority is set to 0 on the primary unit
C.The heartbeat interfaces are experiencing high packet loss
D.The HA override setting is enabled, causing the secondary to take over
AnswerC

The HA heartbeat link is the liveness mechanism between cluster members. High packet loss or jitter on that link causes heartbeat messages to be dropped, leading the standby unit to believe the primary is unhealthy and triggering a failover. This can result in repeated failover flaps as the primary is falsely deemed dead, then recovers. For this reason, FortiGate recommends a dedicated, reliable physical interface for HA heartbeat, not a link prone to congestion or loss.

Why this answer

In an active-passive FortiGate HA cluster, the primary and secondary units continuously exchange FGCP heartbeats over the configured heartbeat interfaces (port1 and port2). If those links experience packet loss — due to duplex mismatch, cabling issues, or a flapping switch port — the secondary stops receiving heartbeats and triggers a failover. Frequent, periodic failovers every few minutes are the classic symptom of intermittent heartbeat loss rather than a configuration error.

Exam trap

NSE4 often tests the misconception that HA priority or override settings cause failovers, when in fact intermittent heartbeat loss on the HA links is the most common cause of cluster flapping.

How to eliminate wrong answers

Option A is wrong because session synchronization (session pickup) uses a separate path and consumes negligible bandwidth relative to HA heartbeat traffic; it does not cause failovers. Option B is wrong because an HA priority of 0 does not force failover — priority 0 is a valid value and only affects election order when override is enabled; it does not cause repeated flapping. Option D is wrong because enabling override only causes the higher-priority unit to reclaim the primary role after it recovers; it does not cause the primary to fail over every few minutes while it is healthy.

259
Multi-Selectmedium

An administrator is setting up SNMP monitoring on a FortiGate. Which two configurations are necessary for a basic SNMP setup? (Choose two.)

Select 2 answers
A.Create a firewall policy to allow SNMP traffic from the monitoring server
B.Configure an SNMP community with read-only access
C.Enable the SNMP agent under System > SNMP
D.Set the SNMP trap destination IP
E.Configure a user for SNMPv3
AnswersB, C

An SNMP community serves as the authentication credential for SNMPv1/v2c queries. Without a correctly configured community string, the FortiGate will silently discard SNMP requests, even if the agent is enabled and interfaces are available. Defining a community with read-only (RO) access allows the monitoring server to poll system statistics, interface counters, and other OIDs while preventing unauthorized configuration changes, which is the standard requirement for read-only monitoring scenarios.

Why this answer

An SNMP community with read-only access defines the basic authentication and access control for SNMPv1/v2c queries, which is essential for monitoring. Option C is correct because the SNMP agent must be enabled on the FortiGate to process SNMP requests from the monitoring server.

Exam trap

The trap here is that candidates often confuse optional features like trap destinations or SNMPv3 authentication as mandatory for basic monitoring, when only the agent enablement and a community string are required.

260
Multi-Selecthard

An administrator needs to ensure that all HTTPS traffic to a critical server is inspected by the IPS. The server uses a valid certificate from a public CA. Which THREE steps are required to achieve this?

Select 3 answers
A.Apply an IPS profile to the same firewall policy
B.Set the Antivirus profile to 'Deep Inspection'
C.Install the FortiGate's CA certificate on client browsers
D.Enable SSL deep inspection on the firewall policy
E.Upload the server's certificate to the FortiGate
AnswersA, C, D

This is necessary because even with SSL deep inspection enabled, the decrypted traffic is only inspected if an IPS profile is attached to the policy. The IPS engine then examines the plaintext HTTP/HTTPS payloads for signatures, vulnerabilities, and exploits. Without an IPS profile, deep inspection alone just decrypts/encrypts but doesn't provide intrusion prevention.

Why this answer

Option D is correct because SSL deep inspection must be enabled on the firewall policy so the FortiGate decrypts the HTTPS session and can pass the plaintext to the IPS engine; without it, the IPS only sees encrypted traffic. Option A is correct because the IPS profile must be attached to that same firewall policy that carries the inspected traffic, otherwise the decrypted stream is never scanned by the IPS sensors. Option C is correct because deep inspection causes the FortiGate to re-sign the server's certificate with its own CA (the FortiGate's local/protection CA), so client browsers must trust that CA certificate to avoid certificate warnings and failed connections.

Option B is wrong because 'Deep Inspection' is a setting of the SSL/SSH inspection profile, not the Antivirus profile, and antivirus is not what performs IPS inspection. Option E is wrong because the server already presents a valid public CA certificate; the FortiGate does not need the server's certificate uploaded to perform deep inspection.

Exam trap

NSE4 often tests the misconception that uploading the server's certificate is required for deep inspection, when actually the FortiGate's CA certificate must be trusted by clients.

261
MCQhard

An administrator plans to upgrade FortiGate firmware from version 6.0 to 7.2. The current version is 6.0.10. Which upgrade path is correct?

A.Upgrade to 6.4 first, then to 7.2
B.It is not possible to upgrade from 6.0 to 7.2
C.Direct upgrade from 6.0.10 to 7.2.0 is supported
D.Upgrade to 6.2, then 6.4, then 7.0, then 7.2
AnswerD

This sequence—6.0 → 6.2 → 6.4 → 7.0 → 7.2—is exactly the path generated by Fortinet's Upgrade Path tool for FortiOS 6.0 to 7.2. Each intermediate release handles the necessary database migrations and feature changes that cannot be applied in a single jump, ensuring the firewall's configuration, session state, and security policies are preserved. Following this ordered progression avoids the risk of 'upgrade failed' errors and provides the only officially supported route to 7.2.

Why this answer

FortiGate firmware upgrades must follow a supported path that does not skip major versions. Upgrading from 6.0.10 to 7.2.0 requires stepping through 6.2, 6.4, and 7.0 because Fortinet only supports upgrades from one major version to the next major version (e.g., 6.0→6.2→6.4→7.0→7.2). Option D correctly lists this sequential path.

Exam trap

The trap here is that candidates assume a direct upgrade is possible because both versions are relatively recent, but Fortinet strictly enforces sequential major version upgrades to prevent configuration and system incompatibilities.

How to eliminate wrong answers

Option A is wrong because upgrading directly from 6.0 to 6.4 skips version 6.2, which is not supported by Fortinet's upgrade path requirements. Option B is wrong because upgrading from 6.0 to 7.2 is possible, but only by following the correct multi-step path through intermediate versions. Option C is wrong because a direct upgrade from 6.0.10 to 7.2.0 is not supported; Fortinet requires upgrading through each major version in sequence.

262
Multi-Selecthard

An organization is implementing two-factor authentication for SSL VPN access using FortiToken. Which THREE components are necessary for this setup?

Select 3 answers
A.An LDAP server for user synchronization
B.A firewall policy that requires authentication and references the user group
C.A FortiToken assigned to the user
D.A user group with two-factor authentication enabled
E.A RADIUS server for token validation
AnswersB, C, D

The firewall policy is the enforcement point that triggers the authentication process. When a user attempts to match a policy that requires authentication, the FortiGate prompts for credentials and validates them against the referenced user group. Because the policy references the user group with two-factor enabled, it forces the user to provide both the password and the FortiToken code, making this policy a necessary component.

Why this answer

A firewall policy must reference the user group that has two-factor authentication enabled. The policy enforces authentication for SSL VPN traffic, and without this reference, the FortiGate would not require the user to authenticate via FortiToken, defeating the purpose of two-factor authentication.

Exam trap

The trap here is that candidates often assume an external authentication server (LDAP or RADIUS) is mandatory for two-factor authentication, but FortiGate can validate FortiTokens locally without any external server.

263
MCQeasy

A FortiGate administrator needs to capture packets on the DMZ interface to troubleshoot a connectivity issue. Which CLI command should be used to start a packet capture?

A.diagnose sniffer packet
B.diagnose debug flow
C.diagnose sys session list
D.execute packet-capture start
AnswerA

diagnose sniffer packet is the correct FortiGate CLI command for capturing raw packets on an interface. It accepts an interface name (or 'any'), a BPF filter, a count, and a verbosity level, functioning much like tcpdump. This command provides direct visibility into the actual frames on the wire, making it the go-to tool for packet-level troubleshooting.

Why this answer

The correct CLI command to start a packet capture on a FortiGate is 'diagnose sniffer packet'. This command allows you to capture packets on a specific interface with various filters and verbosity levels. It is the standard tool for troubleshooting connectivity issues at the packet level.

Exam trap

NSE4 often tests the correct syntax for packet capture, and candidates may confuse it with debug flow or other diagnose commands.

How to eliminate wrong answers

Option B is wrong because 'diagnose debug flow' is used to trace the flow of packets through the FortiGate, showing policy lookups and forwarding decisions, but it does not capture raw packet data. Option C is wrong because 'diagnose sys session list' displays the current session table, not packet captures. Option D is wrong because 'execute packet-capture start' is not a valid FortiGate CLI command; packet capture is done via the diagnose sniffer command.

264
MCQeasy

Which address object type can be used to match traffic based on the source country?

A.Wildcard FQDN
B.FQDN
C.Geography
D.Subnet
AnswerC

Geography address objects in FortiOS match traffic based on the country, continent, or region associated with an IP address, using the built-in GeoIP database. These objects directly support policies such as geo-blocking or allowing traffic from a specific nation, without requiring the administrator to enumerate IP ranges. This is the only object type in the list whose matching logic is explicitly based on the geopolitical location of the packet endpoints, making it the correct answer.

Why this answer

The Geography address object type in FortiGate allows you to match traffic based on the source or destination country by using the ISO 3166-1 alpha-2 country codes. This is configured within a firewall policy to enforce geo-blocking or geo-allowance, leveraging FortiGuard's GeoIP database to map IP addresses to countries.

Exam trap

The trap here is that candidates may confuse Geography with FQDN or Subnet, assuming that DNS resolution or IP ranges can inherently determine country, but only the Geography object leverages the dedicated GeoIP database for country-based matching.

How to eliminate wrong answers

Option A is wrong because Wildcard FQDN is used to match multiple subdomains with a pattern (e.g., *.example.com) and has no relation to geographic location. Option B is wrong because FQDN resolves to a single IP address or set of IP addresses via DNS, not to a country. Option D is wrong because Subnet defines a range of IP addresses using CIDR notation and cannot inherently identify the source country without external GeoIP mapping.

265
MCQmedium

A network administrator notices that some users can access blocked web categories despite a web filter profile applied to the policy. The admin runs 'diagnose debug rating' and sees 'rating not allow' for the category. What is the MOST likely cause?

A.The web filter profile has an 'override' configured for those users
B.The policy is not using the correct web filter profile
C.DNS filter is allowing the domain
D.The FortiGuard web filter database is outdated
AnswerA

A web filter override is an explicit exemption configured inside the FortiGate profile that lets certain users, groups, or source IPs bypass the FortiGuard rating decision. When an override is in place, the FortiGuard rating may still be evaluated as 'not allow' (blocked), but the override action overrides that result and permits the session. This exactly matches the symptom where only some users, presumably those included in the override rule, can access sites that are otherwise blocked for everyone else.

Why this answer

The 'rating not allow' message in the 'diagnose debug rating' output indicates that the FortiGate's rating engine correctly identified the category as blocked by the web filter profile. However, if an 'override' is configured for specific users or groups, it allows them to bypass the blocked category. This explains why some users can access the site despite the profile blocking it, as the override takes precedence over the profile's default action.

Exam trap

The trap here is that candidates often assume a 'rating not allow' message means the filter is working correctly for everyone, overlooking the possibility that an override configured within the same profile can selectively permit access for certain users.

How to eliminate wrong answers

Option B is wrong because if the policy were not using the correct web filter profile, the 'diagnose debug rating' output would not show 'rating not allow' for the category; it would either show no rating or a different profile reference. Option C is wrong because DNS filter operates independently of web filter rating; even if DNS filter allows the domain, the web filter profile's rating decision (block) would still apply unless overridden. Option D is wrong because an outdated FortiGuard database would cause 'rating not allow' for all users, not selectively for some, and the debug output would typically show 'rating error' or 'unrated' rather than a clear 'rating not allow'.

266
Multi-Selecthard

An administrator is configuring traffic shaping on a firewall policy to limit bandwidth for YouTube. Which THREE components are required?

Select 3 answers
A.A traffic shaper object that defines bandwidth limits
B.A firewall policy that matches YouTube traffic
C.A static route for the YouTube subnet
D.A schedule object to apply the shaper only during business hours
E.Enable traffic shaping on the firewall policy and assign the traffic shaper
AnswersA, B, E

A traffic shaper object is the core definition of a bandwidth profile in Fortinet. It specifies parameters such as guaranteed bandwidth, maximum bandwidth, and traffic priority, enabling controlled allocation of network resources. Without this object, there is no shaping policy to reference, so creating it is an essential first step.

Why this answer

A traffic shaper object is a fundamental component that defines the bandwidth limits (e.g., guaranteed bandwidth, maximum bandwidth, priority) that will be applied to traffic. Without this object, the firewall has no parameters to enforce rate limiting. In FortiGate, the traffic shaper object is created under 'Traffic Shapers' and can be per-policy or per-IP.

Exam trap

The trap here is that candidates mistakenly think a schedule or static route is mandatory, but FortiGate only requires the traffic shaper object, the matching firewall policy, and the shaper assignment on that policy.

267
MCQeasy

What is the purpose of a schedule object in a firewall policy?

A.To specify the time of day when the policy is effective
B.To set the bandwidth limit for the policy
C.To prioritize traffic based on application
D.To limit the number of concurrent sessions
AnswerA

A schedule object defines the time window (such as 09:00–17:00 on weekdays) during which a firewall policy may be enforced. In FortiOS, the schedule condition is evaluated when a new session is being established; if the current time falls outside the schedule, the policy will not match, and the permitted traffic will be denied or evaluated by subsequent policies. This allows administrators to apply time-based access control, such as blocking employee internet access after business hours.

Why this answer

A schedule object in a FortiGate firewall policy defines the time range (e.g., specific hours, days of the week, or recurring intervals) during which the policy is active. When the current time falls outside the schedule, the policy is automatically disabled, allowing administrators to enforce time-based access control without manual intervention. This is distinct from other policy attributes like bandwidth shaping or session limits.

Exam trap

The trap here is that candidates confuse schedule objects with other time-related features like session timeouts or idle timeouts, or assume schedule objects can control bandwidth or application priority, when in fact they only control the policy's active time window.

How to eliminate wrong answers

Option B is wrong because bandwidth limits are configured via traffic shaping policies or per-policy bandwidth limits, not through schedule objects. Option C is wrong because traffic prioritization based on application is handled by application control profiles or QoS policies, not by schedule objects. Option D is wrong because limiting concurrent sessions is a separate policy setting (session limit) or a global session table parameter, not a function of schedule objects.

268
MCQmedium

A FortiGate is configured with an aggregate interface (link aggregation group) consisting of two physical ports. The administrator notices that traffic is not being distributed evenly across the two links. Which configuration setting should be verified to improve load balancing?

A.Check the LACP mode (active vs passive)
B.Increase the MTU on the aggregate interface
C.Verify the load-balancing algorithm for the aggregate interface
D.Ensure the physical ports are in the same VDOM
AnswerC

Aggregate interface traffic distribution is governed by the configured load-balancing algorithm, such as L4 or L3/L4 hashing. Uneven distribution across member links usually means the algorithm's hash inputs, not the physical links, are the constraint.

Why this answer

The aggregate interface uses a load-balancing algorithm to distribute traffic across member links. If traffic is uneven, the algorithm (e.g., source-destination IP, source-destination MAC, or layer 4 port) may not match the traffic pattern, causing hash polarization. Verifying and adjusting this algorithm is the correct step to improve distribution.

Exam trap

The trap here is confusing LACP negotiation settings (active/passive) with the actual traffic distribution mechanism, leading candidates to incorrectly select option A instead of recognizing that the load-balancing algorithm directly controls link utilization.

How to eliminate wrong answers

Option A is wrong because LACP mode (active vs passive) controls link negotiation and aggregation establishment, not traffic distribution across already-aggregated links. Option B is wrong because increasing MTU affects maximum packet size but has no impact on how traffic is hashed or distributed among aggregate members. Option D is wrong because VDOM membership ensures logical separation but does not influence the load-balancing algorithm or per-packet distribution across physical ports in an aggregate.

269
MCQmedium

A company policy requires that all web searches by employees use safe search. Which setting should be configured in the web filtering profile?

A.Enable 'Restrict YouTube Access'
B.Create a URL filter to block URLs with 'safe search'
C.Enable 'Enforce 'Safe Search' on Google, Bing, and Yahoo'
D.Set the 'Action' for FortiGuard categories to 'Warning'
AnswerC

Enabling 'Enforce Safe Search on Google, Bing, and Yahoo' is the correct FortiGate web filtering option because it actively forces these three search engines to use their safe search settings by rewriting URLs, setting cookies, or leveraging FortiGuard's search engine integration. Even if a user attempts to disable safe search in their browser, the FortiGate intercepts the request and ensures the search results are filtered at the network level, thereby meeting the company policy requirement.

Why this answer

The 'Enforce Safe Search' setting in a FortiGate web filtering profile forces Google, Bing, and Yahoo to use their built-in safe search parameters (e.g., &safe=active for Google). This ensures that all web searches from the network comply with the company policy by appending the required query strings to search URLs, blocking explicit content at the search engine level.

Exam trap

The trap here is that candidates often confuse 'Enforce Safe Search' with URL filtering or category blocking, assuming that blocking or warning on categories like 'Search Engines' would achieve the same result, but safe search enforcement is a specific feature that modifies search queries rather than blocking access.

How to eliminate wrong answers

Option A is wrong because 'Restrict YouTube Access' only controls YouTube content (e.g., enforcing strict or moderate mode), not general web search safe search. Option B is wrong because creating a URL filter to block URLs containing 'safe search' would block access to safe search configuration pages, not enforce safe search on search engines. Option D is wrong because setting the 'Action' for FortiGuard categories to 'Warning' only displays a warning page for categorized sites, it does not modify search engine behavior to enforce safe search.

270
MCQeasy

An administrator needs to allow outbound DNS traffic (UDP port 53) from multiple internal subnets to the internet. Which object type should be used to group the subnets into a single source in the firewall policy?

A.VIP group
B.Schedule group
C.Address group
D.Service group
AnswerC

An address group is the correct object because it bundles multiple address objects—such as subnets, IP ranges, and FQDNs—into a single named entity. This address group can then be used as the source field in an outbound policy, effectively allowing all internal subnets to initiate DNS queries. This is exactly what the administrator needs to match the source subnets for outbound UDP port 53 traffic.

Why this answer

An address group is the correct object type to group multiple internal subnets into a single source in a firewall policy. In FortiGate, address groups allow you to combine multiple IP addresses or subnets (IPv4 or IPv6) into a logical group, which can then be referenced as the source in a single firewall policy. This simplifies administration by reducing the number of policies needed to allow outbound DNS traffic from multiple subnets.

Exam trap

The trap here is that candidates often confuse address groups with service groups, mistakenly thinking that grouping subnets is done via service objects, but service groups only define protocols and ports, not IP addresses.

How to eliminate wrong answers

Option A is wrong because a VIP group is used to group multiple virtual IP (VIP) objects for destination NAT (port forwarding) or load balancing, not for grouping source subnets. Option B is wrong because a schedule group is used to group time-based schedules (e.g., daily, weekly) to control when a policy is active, not to define source addresses. Option D is wrong because a service group is used to group multiple service definitions (e.g., DNS, HTTP, HTTPS) by protocol/port, not to group source IP subnets.

271
MCQmedium

An administrator needs to ensure that all traffic from the internal network to the internet goes through a web proxy for content filtering. Which configuration is required on the FortiGate?

A.Enable the proxy feature and set the web proxy port to 80.
B.Enable web proxy in the firewall policy and set action to accept.
C.Configure an explicit web proxy and create a proxy policy.
D.Configure a transparent proxy by using an SSL inspection profile.
AnswerC

An explicit web proxy requires two things: the proxy feature must be enabled and configured on a listening port, and proxy policies must be created to define which users and destinations are allowed, denied, or filtered. This is the correct way to handle 'all traffic' from clients that are configured to use the FortiGate as their proxy. Without a proxy policy, the proxy will accept connections but only return a default or error behavior.

Why this answer

To enforce web proxy-based content filtering for all internal-to-internet traffic, the FortiGate must be configured with an explicit web proxy (which listens on a specific IP and port, typically 8080) and a corresponding proxy policy that defines the traffic matching criteria and action. This setup ensures that client browsers are configured to send requests to the proxy, and the proxy policy applies content filtering rules.

Exam trap

The trap here is that candidates often confuse enabling the web proxy feature in a firewall policy (transparent proxy) with the explicit proxy configuration that requires a separate proxy policy, leading them to select option B.

How to eliminate wrong answers

Option A is wrong because simply enabling the proxy feature and setting the web proxy port to 80 does not create a functional proxy policy; without a proxy policy, no traffic is actually processed through the proxy for content filtering. Option B is wrong because enabling web proxy in a firewall policy with action set to accept does not redirect traffic through the proxy; it only allows the traffic to pass without proxy inspection. Option D is wrong because a transparent proxy uses an SSL inspection profile to intercept traffic transparently, but it does not require an explicit proxy configuration or a proxy policy; instead, it relies on firewall policies with web proxy enabled, which is not the same as the explicit proxy approach needed for the described requirement.

272
Multi-Selectmedium

An administrator wants to block all peer-to-peer (P2P) file sharing applications such as BitTorrent and eMule on the network. Which THREE steps should the administrator take?

Select 3 answers
A.Configure a web filter profile to block P2P websites
B.Enable deep inspection on the firewall policy to detect encrypted P2P traffic
C.Create an application control profile with the P2P category blocked
D.Apply the application control profile to a firewall policy allowing internet access
E.Enable antivirus to block P2P protocols
AnswersB, C, D

Deep inspection is necessary because many P2P applications encrypt their sessions with TLS/SSL, which hides protocol fingerprints from normal flow-based inspection. By acting as a man-in-the-middle and terminating the TLS connection, the FortiGate can re-inspect the decrypted payload with its application control signatures and identify the P2P protocol. Note that deep inspection alone only makes the traffic visible; it must be paired with an application control profile that blocks the P2P category to actually deny it.

Why this answer

Enabling deep inspection on the firewall policy allows the FortiGate to decrypt and inspect encrypted P2P traffic, such as BitTorrent or eMule using TLS/SSL. Without deep inspection, the firewall cannot see inside encrypted packets to identify P2P signatures, making application control ineffective for encrypted flows.

Exam trap

The trap here is that candidates often think web filtering or antivirus can block P2P traffic, but only application control combined with deep inspection can identify and block the actual P2P protocol signatures, especially when encrypted.

273
MCQeasy

An administrator needs to back up the full configuration of a FortiGate, including all system settings, policies, and objects. Which CLI command should be used?

A.diagnose debug config-error-log read
B.execute backup config tftp <filename> <server>
C.show full-configuration
D.execute restore config tftp <filename> <server>
AnswerB

The execute backup config tftp command saves the complete current configuration to a TFTP server as a plain-text file, which can later be used for restoration. It requires the TFTP server IP address and a filename, and the FortiGate will transfer the full configuration to that location. This is the standard CLI method for a full configuration backup and is the correct command to use in this scenario.

Why this answer

The correct command is 'execute backup config tftp <filename> <server>' because it explicitly triggers a full configuration backup (including system settings, policies, and objects) to a TFTP server. This is the standard FortiGate CLI command for exporting the entire running configuration to an external TFTP server, ensuring all configuration elements are captured.

Exam trap

The trap here is confusing the 'backup' and 'restore' commands (options B and D) or mistaking a display-only command like 'show full-configuration' for an actual backup operation.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug config-error-log read' is a diagnostic command used to view configuration error logs, not to perform a backup. Option C is wrong because 'show full-configuration' displays the entire configuration on the console but does not save or transfer it to a backup file or server. Option D is wrong because 'execute restore config tftp <filename> <server>' is used to restore a configuration from a TFTP server, not to back it up.

274
MCQhard

You run the following command on a FortiGate: 'diagnose sys session filter dport 443' and see: proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate?

A.The session is in SYN_SENT state and the three-way handshake is not yet complete
B.The session is using UDP and the duration is 3600 seconds
C.The session is being torn down and will expire in 3599 seconds
D.The session is fully established and has been active for 3600 seconds
AnswerA

In FortiOS session table output, the proto_state field for TCP is shown in hex; a value of 01 corresponds to SYN_SENT (0x01), meaning the initial SYN packet was sent but the SYN-ACK has not yet been received. This indicates the three-way handshake is still in progress and the session is not yet established. Therefore, the correct interpretation is that the connection is incomplete.

Why this answer

The output shows `proto=6`, which indicates TCP, and `proto_state=01`, which corresponds to the TCP state SYN_SENT (0x01). This means the session has sent a SYN but has not yet received a SYN-ACK, so the three-way handshake is incomplete. The `duration=3600` and `expire=3599` indicate the session has been tracked for 3600 seconds and will expire in 3599 seconds, but the state confirms it is not yet established.

Exam trap

The trap here is that candidates see `duration=3600` and `expire=3599` and assume the session is established and about to expire, but the `proto_state=01` (SYN_SENT) clearly indicates the handshake is incomplete, not that the session is active or being torn down.

How to eliminate wrong answers

Option B is wrong because `proto=6` indicates TCP, not UDP (UDP is protocol 17). Option C is wrong because the session is in SYN_SENT state (0x01), not being torn down; a teardown would show states like FIN_WAIT or TIME_WAIT. Option D is wrong because a fully established TCP session would show `proto_state=02` (ESTABLISHED), not `01` (SYN_SENT).

275
Multi-Selecthard

A FortiGate admin is troubleshooting an issue where internal users cannot access a specific external service over TCP/443. The admin confirms that the firewall policy allows HTTP/HTTPS. Which TWO CLI commands should the admin use to diagnose? (Choose two.)

Select 2 answers
A.diagnose firewall iprope list
B.diagnose debug flow
C.diagnose sys session filter dport 443
D.get system performance status
E.execute ping 8.8.8.8
AnswersA, B

The 'diagnose firewall iprope list' command displays the compiled IPv4/IPv6 policy chains exactly as the kernel traverses them during packet evaluation. It is invaluable for verifying the relative ordering of allow and deny policies in the actual dataplane, because a policy buried below a broad deny rule will never be reached. This tool exposes both the explicit policies and the implicit deny at the end, letting you confirm whether a matching allow rule exists before any drop rule in the sequence.

Why this answer

'diagnose firewall iprope list' displays the kernel's internal firewall rule chains, allowing the admin to verify whether the policy lookup is matching the expected rule for TCP/443 traffic. This command helps confirm that the policy is installed and active in the kernel, which is essential for troubleshooting policy-based access issues.

Exam trap

The trap here is that candidates often choose 'diagnose sys session filter dport 443' thinking it directly shows sessions, but they forget that it only sets a filter and requires an additional command to display results, making it incomplete for immediate diagnosis.

276
MCQmedium

An administrator configures a FortiGate HA cluster in active-active mode. After enabling session synchronization, they notice that new sessions are not being synced to the secondary unit. The cluster is using a dedicated heartbeat interface. What could be the reason?

A.The HA mode is set to active-passive
B.The firewall policy does not have session sync enabled
C.The session TTL is too short
D.The heartbeat interface is not configured with an IP address
AnswerB

In FortiGate active-active HA, session synchronization is not automatic — it must be enabled individually on each firewall policy using the 'session sync' option in the policy's advanced settings. Without this setting, each session is tracked only by the specific cluster unit that received its first packet, and if that unit fails or return traffic is load-balanced to a peer, the session is unknown to the other unit. This directly prevents the session table from being shared, which is exactly why the administrator observes no session synchronization.

Why this answer

In active-active HA, session synchronization requires that the session sync flag is enabled on the firewall policy. Without it, sessions are not synced.

277
Drag & Dropmedium

Drag and drop the steps to capture traffic on a FortiGate interface using the CLI into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The sniffer command syntax is diagnose sniffer packet <interface> <filter> <verbose> <count>.

278
MCQmedium

A FortiGate administrator needs to allow remote management from the internet only from a specific IP address. Which configuration achieves this?

A.Create a local-in policy to allow management access only from the trusted host
B.Change the admin port to a non-standard port
C.Enable HTTPS and restrict admin access via admin host
D.Use a firewall policy with source address restriction
AnswerA

A local-in policy is evaluated before any firewall policy and explicitly governs traffic destined to the FortiGate's own IP addresses. By defining a local-in rule that permits management traffic only from the specified trusted host IP, the administrator ensures all other sources are implicitly denied, providing precise source-based access control for the management interface.

Why this answer

A local-in policy is the correct method to restrict remote management access to a FortiGate from the internet because it operates at the control plane level, filtering traffic destined to the FortiGate itself before it reaches the management daemons. By specifying a source IP address in a local-in policy, you can explicitly allow HTTPS or SSH management only from that trusted host, while implicitly denying all other sources. This is more secure than relying on firewall policies, which apply to traffic passing through the FortiGate, not to traffic destined to the FortiGate's own IP addresses.

Exam trap

The trap here is that candidates often confuse firewall policies (which control traffic passing through the FortiGate) with local-in policies (which control traffic destined to the FortiGate), leading them to incorrectly select option D, thinking a standard firewall policy can restrict management access from the internet.

How to eliminate wrong answers

Option B is wrong because changing the admin port to a non-standard port is a form of security through obscurity and does not restrict access to a specific IP address; it only changes the port number, which can still be scanned and accessed from any source. Option C is wrong because enabling HTTPS and restricting admin access via admin host (the 'admin host' setting) is a legacy method that only works for GUI access and does not apply to SSH or other management protocols; it also does not provide the granularity of a local-in policy. Option D is wrong because a firewall policy with source address restriction applies to traffic transiting through the FortiGate (forwarding plane), not to traffic destined to the FortiGate itself (control plane); management traffic is handled by the control plane and must be filtered using local-in policies or the 'trusted host' feature.

279
MCQmedium

An administrator wants to configure SNMPv3 on a FortiGate for secure monitoring. Which configuration is required?

A.Create an SNMPv3 user with authentication and privacy protocols.
B.Enable SNMP agent on the WAN interface only.
C.Configure an access control list for SNMP.
D.Set SNMP community string to 'public' and enable SNMPv1/v2c.
AnswerA

For SNMPv3 on a FortiGate, the administrator must define an SNMPv3 user under the SNMP configuration and assign both an authentication protocol (e.g., SHA or SHA256) and a privacy protocol (e.g., AES or DES) with passphrases. This creates the USM user credentials that provide message authentication and encryption, which is the defining security feature of SNMPv3. Without this user, the FortiGate cannot accept authenticated and encrypted SNMPv3 queries.

Why this answer

SNMPv3 requires a user-based security model (USM) with authentication (e.g., SHA) and privacy (e.g., AES) protocols to provide integrity, authentication, and encryption. Without these, SNMPv3 cannot secure monitoring traffic, making option A the mandatory configuration.

Exam trap

The trap here is that candidates often think enabling SNMP on a specific interface or using ACLs is the primary security requirement, but SNMPv3's security is entirely user-based and requires explicit authentication and privacy protocols.

How to eliminate wrong answers

Option B is wrong because SNMP agent can be enabled on any interface, not only WAN, and the interface selection does not enforce security; SNMPv3 security is user-based, not interface-based. Option C is wrong because while access control lists can restrict SNMP access, they are not required for SNMPv3; the core requirement is the user with authentication and privacy. Option D is wrong because setting the community string to 'public' and enabling SNMPv1/v2c bypasses SNMPv3's security entirely, leaving monitoring unencrypted and unauthenticated.

280
Multi-Selecteasy

An administrator is configuring a dialup IPsec VPN for remote users. Which two settings must be configured on the FortiGate to allow clients to connect?

Select 2 answers
A.Enable XAuth for user authentication.
B.Enable Dead Peer Detection.
C.Enable mode-cfg on the Phase 1 interface.
D.Enable NAT traversal.
E.Create an IP pool for the remote clients.
AnswersC, E

Enabling mode-cfg on the Phase 1 interface is the direct mechanism by which the FortiGate pushes the client configuration back to the dialup peer. This configuration includes the assigned IPv4 address, DNS server, WINS server, and sometimes split-tunnel settings. Without mode-cfg, a remote client has no tunnel IP and cannot route traffic through the VPN, so it is a mandatory component for dialup deployments. In FortiOS, mode-cfg references an IP pool to source the addresses.

Why this answer

Mode-config (mode-cfg) on the Phase 1 interface is required to push network configuration parameters (such as DNS, WINS, and the virtual IP address) to remote IPsec VPN clients. This setting enables the FortiGate to act as a server in a dialup VPN scenario, dynamically assigning IP addresses and other settings to clients without requiring static configuration on each client.

Exam trap

The trap here is that candidates often assume XAuth or NAT traversal are mandatory for dialup IPsec, but the FortiGate specifically requires mode-cfg and an IP pool to dynamically assign client addresses and complete the tunnel setup.

281
MCQmedium

A FortiGate admin is configuring a hub-and-spoke IPsec VPN. The hub has multiple phase 2 configurations for each spoke. The spokes can communicate with the hub but not with each other. The admin wants to allow spoke-to-spoke traffic through the hub. Which configuration change is required on the hub?

A.Change the IPsec mode from policy-based to route-based
B.Modify the Phase 2 selectors on the hub to include both spoke subnets and add firewall policies allowing traffic between the spoke networks
C.Enable 'add-route' on the hub's Phase 1 settings
D.Configure a static route on each spoke pointing to the other spoke's subnet via the tunnel
AnswerB

The correct fix is to ensure the hub's Phase 2 selectors for each spoke tunnel define traffic selectors that include both hub-side and remote-spoke subnets, so the hub can decapsulate traffic from one spoke, match it against the phase2 selectors of the other spoke's tunnel, and re-encapsulate it for forwarding. Additionally, the hub must have firewall policies that explicitly allow traffic between the spoke networks—typically by placing each spoke interface in a zone and permitting the traffic between them or using address objects. Without both the expanded selectors and the inter-spoke firewall policy, packets arriving from one spoke for the other will be dropped, as the hub either lacks the matching phase2 selector or the policy permission to forward the traffic.

Why this answer

In a hub-and-spoke VPN with policy-based IPsec, the hub's Phase 2 selectors define which subnets can communicate through each tunnel. By default, each spoke's Phase 2 selector only includes the hub and that specific spoke's subnets, blocking spoke-to-spoke traffic. Adding both spoke subnets to the hub's Phase 2 selectors and creating firewall policies that permit traffic between those spoke networks allows the hub to route traffic between spokes, effectively enabling spoke-to-spoke communication through the hub.

Exam trap

The trap here is that candidates often assume route-based VPNs are always required for spoke-to-spoke communication, but the real issue is that Phase 2 selectors and firewall policies must be explicitly configured to allow inter-spoke traffic through the hub.

How to eliminate wrong answers

Option A is wrong because changing from policy-based to route-based IPsec is not required; the issue is with Phase 2 selectors and firewall policies, not the IPsec mode. Route-based VPNs use virtual interfaces and routing, but the same selector and policy adjustments would still be needed to allow spoke-to-spoke traffic. Option C is wrong because 'add-route' on Phase 1 settings automatically installs routes for remote networks based on Phase 2 selectors, but it does not modify the selectors themselves or create firewall policies to permit spoke-to-spoke traffic.

Option D is wrong because configuring static routes on each spoke for the other spoke's subnet via the tunnel would only work if the hub already had the correct Phase 2 selectors and firewall policies; without those, the traffic would be dropped at the hub.

282
MCQmedium

A network administrator notices that HTTP traffic is being scanned by the antivirus profile, but HTTPS traffic to the same web server is not being scanned. The firewall policy has the antivirus profile applied and SSL inspection is set to 'certificate-inspection'. What is the most likely reason HTTPS traffic is not being scanned?

A.Certificate inspection does not decrypt the traffic, so the antivirus scanner cannot inspect the payload.
B.The antivirus profile is configured in flow mode, which does not support scanning HTTPS traffic.
C.The web server is not using a cipher supported by the FortiGate.
D.The FortiGate is using proxy-based inspection, which does not support HTTPS scanning.
AnswerA

Certificate inspection only validates the server certificate's identity and trust chain; it does not terminate the TLS session or decrypt the stream. Consequently, the FortiGate forwards the encrypted HTTP payload unchanged, and the antivirus engine sees only ciphertext. Since malware signatures cannot be matched against encrypted bytes, the antivirus profile simply cannot inspect what it cannot see, which is exactly why HTTP traffic appears to bypass scanning.

Why this answer

Certificate inspection only validates the SSL/TLS certificate without decrypting the traffic. Since the antivirus scanner requires access to the plaintext payload to detect threats, it cannot scan HTTPS traffic when only certificate inspection is configured. This is why HTTP traffic is scanned but HTTPS traffic is not.

Exam trap

The trap here is that candidates often assume 'certificate-inspection' implies some level of content scanning, but it only validates the certificate and does not decrypt the traffic for security profile inspection.

How to eliminate wrong answers

Option B is wrong because flow mode does support scanning HTTPS traffic when SSL inspection is configured to decrypt the traffic; the issue here is the lack of decryption, not the inspection mode. Option C is wrong because cipher support is irrelevant when the traffic is not being decrypted at all; the FortiGate never attempts to negotiate a cipher for inspection. Option D is wrong because proxy-based inspection actually supports HTTPS scanning with full SSL decryption; the problem is that certificate inspection does not decrypt, regardless of the inspection mode.

283
MCQmedium

A company has two FortiGate units in an active-active HA cluster. They want to ensure that sessions initiated from the internet through a virtual IP are synchronized to the peer unit in case of failover. Which HA setting is required?

A.Enable 'set ha-mgmt-status enable' on the WAN interface
B.Set 'set schedule' to 'round-robin' for the VIP
C.Configure the same virtual IP on both units
D.Enable 'session-pickup' under config system ha
AnswerD

Enabling session-pickup under the 'config system ha' block instructs the FortiGate to send session table information to the secondary unit on a continuous basis, allowing the standby to have a warm copy of all active connections, including those generated via virtual IPs. When a failover occurs, the backup unit has the necessary state to keep those VIP sessions active, so users do not experience a disruption. This is the central mechanism that makes stateful failover possible in FortiGate HA and is also required for sessions that originate through the VIP to be resumed on the new active device.

Why this answer

In a FortiGate active-active HA cluster, session-pickup (also called session synchronization) must be enabled under 'config system ha' to ensure that sessions — including those initiated through a virtual IP from the internet — are synchronized to the peer unit. Without session-pickup, a failover would drop existing sessions because the new primary has no state for them. This is the specific HA setting that controls whether firewall sessions are mirrored across cluster members.

Exam trap

NSE4 often tests the distinction between HA settings that sound related — candidates pick 'configure the same VIP on both units' because it seems logical, but VIP configuration is automatic in HA; the actual requirement is enabling session-pickup.

How to eliminate wrong answers

Option A is wrong because 'ha-mgmt-status' enables a dedicated HA management interface for out-of-band access, not session synchronization. Option B is wrong because 'schedule' with 'round-robin' is not a valid VIP setting for HA session handling; VIP scheduling is unrelated to session pickup. Option C is wrong because configuring the same VIP on both units is already inherent to HA VIP behavior — it does not by itself synchronize sessions; session-pickup is the required setting.

284
MCQhard

During a failover in an active-passive HA cluster, the newly active unit does not have the same session table as the previous primary, causing all existing sessions to drop. Which setting should the administrator verify?

A.HA override is enabled on both units
B.The heartbeat interface is configured as a dedicated management interface
C.The session pickup setting is enabled
D.The cluster is operating in active-active mode
AnswerC

In an active-passive HA cluster, the session pickup feature continuously synchronizes the session table from the primary unit to the standby unit, so that the standby can take over existing sessions seamlessly on failover. When session pickup is enabled, the secondary unit maintains a fully updated copy of all session entries, and the newly active unit can continue forwarding traffic for those connections without interruption. If this setting were disabled, all sessions would need to be re-established after a failover, causing connection drops for clients.

Why this answer

Session synchronization must be enabled and properly configured to replicate sessions to the standby unit.

285
MCQeasy

What is the primary purpose of the captive portal feature on a FortiGate?

A.To monitor bandwidth usage per user
B.To block all traffic from unknown IP addresses
C.To enable SSL VPN connections
D.To provide a web-based authentication interface for users connecting through a firewall policy
AnswerD

The captive portal feature forces any client that matches a firewall policy with it enabled to authenticate through an HTTP/HTTPS page before its traffic is forwarded. It supports local users, LDAP, RADIUS, and other auth methods, and once the user authenticates, FortiGate adds a session entry that permits subsequent traffic. This enables network administrators to control guest or office internet access without deploying a full VPN or a separate authentication appliance.

Why this answer

The captive portal feature on a FortiGate provides a web-based authentication interface that intercepts HTTP/HTTPS traffic from unauthenticated users and redirects them to a login page. Once the user successfully authenticates (e.g., via local database, LDAP, or RADIUS), the FortiGate dynamically creates a firewall authentication entry, allowing the user's traffic to pass according to the configured firewall policy. This is the primary purpose: to enforce user-based access control through a browser-based authentication mechanism.

Exam trap

The trap here is that candidates often confuse the captive portal with SSL VPN portal or general firewall blocking, but the captive portal is specifically a web-based authentication gateway for local network access, not a VPN endpoint or a blanket traffic blocker.

How to eliminate wrong answers

Option A is wrong because bandwidth monitoring per user is handled by FortiGate's traffic shaping and logging features, not by the captive portal, which focuses on authentication and access control. Option B is wrong because blocking all traffic from unknown IP addresses is a function of firewall policies with default deny rules or IP reputation filtering, not the captive portal, which actually allows unknown users to reach the authentication page before granting access. Option C is wrong because SSL VPN connections are established via the FortiGate's SSL VPN portal (using port 443/tcp with specific VPN settings), not through the captive portal, which is used for local network access authentication.

286
MCQeasy

A FortiGate is configured in NAT/Route mode. Which statement is correct about this mode?

A.Only one interface can be used for traffic.
B.The FortiGate routes traffic between different subnets and can perform NAT.
C.VLAN interfaces are not supported in this mode.
D.The FortiGate acts as a Layer 2 bridge.
AnswerB

This is the correct description of NAT/Route mode, which is the default operating mode of a FortiGate. In this mode, the FortiGate acts as a Layer 3 router and makes forwarding decisions based on IP addresses and routing tables, sending packets from one subnet to another. It can also apply NAT, including source NAT for outbound Internet access and destination NAT for inbound services, as part of its firewall policies.

Why this answer

In NAT/Route mode, the FortiGate operates as a Layer 3 router, forwarding traffic between different subnets while also performing Network Address Translation (NAT) when configured. This is the default operational mode for most FortiGate deployments, enabling both routing and NAT capabilities on the same device.

Exam trap

The trap here is that candidates often confuse NAT/Route mode with Transparent mode, assuming that NAT implies bridging or that only one interface can be used, but FortiGate explicitly supports multiple routed interfaces and VLANs in this mode.

How to eliminate wrong answers

Option A is wrong because NAT/Route mode supports multiple interfaces for traffic forwarding, not just one; each interface can belong to a different subnet. Option C is wrong because VLAN interfaces are fully supported in NAT/Route mode, allowing segmentation of traffic on the same physical port. Option D is wrong because the FortiGate acts as a Layer 3 router in this mode, not a Layer 2 bridge; Layer 2 bridging is associated with Transparent mode.

287
MCQeasy

Which inspection mode in the antivirus profile processes traffic by buffering the entire file before scanning, allowing more thorough detection but potentially increasing latency?

A.Proxy-based inspection
B.Deep inspection
C.DNS inspection
D.Flow-based inspection
AnswerA

Proxy-based inspection is the correct mode because it buffers the entire file in memory before scanning, allowing FortiOS to perform a thorough, full-file signature analysis. This enables detection of threats embedded deep within archives, compressed files, or multi-part executables that could evade streaming methods. As a result, it provides the highest fidelity for antivirus detection, albeit with added latency proportional to file size.

Why this answer

Proxy-based inspection in the antivirus profile buffers the entire file in memory before scanning, enabling thorough detection of threats like polymorphic malware or embedded exploits. This mode reassembles the full data stream, allowing the FortiGate to perform deep content analysis, but it introduces higher latency due to the buffering and reassembly process.

Exam trap

The trap here is that candidates often confuse 'deep inspection' with 'proxy-based inspection' because both involve thorough analysis, but deep inspection specifically refers to SSL/TLS decryption, not the file buffering mechanism in antivirus profiles.

How to eliminate wrong answers

Option B is wrong because deep inspection is a broader security profile feature (e.g., SSL/TLS inspection) that decrypts traffic for scanning, not a specific antivirus inspection mode that buffers files. Option C is wrong because DNS inspection is a separate security profile for filtering DNS queries and responses, not related to file buffering or antivirus scanning. Option D is wrong because flow-based inspection processes packets in real-time without buffering the entire file, reducing latency but sacrificing the thorough detection that proxy-based mode provides.

288
Multi-Selectmedium

A FortiGate administrator wants to block access to Facebook for all internal users. However, the administrator must ensure that the CEO's computer (IP 10.0.0.100) is exempted. Which TWO steps should the administrator take? (Choose two.)

Select 2 answers
A.Add the CEO's IP to the application control profile's 'exempt IP' list.
B.Configure an IP exemption in the application control profile.
C.Create an application control profile with a rule to block 'Facebook' and apply it to the firewall policy for all users.
D.Create a firewall policy above the blocking policy that allows traffic from the CEO's IP to Facebook, with no application control profile.
E.Use a web filter profile with a URL block for 'facebook.com' instead of application control.
AnswersC, D

Creating an application control profile with a rule that blocks the 'Facebook' application signature and assigning that profile to the firewall policy for all users is the correct method. FortiOS application control uses deep packet inspection and regularly updated signatures to identify Facebook traffic even when it uses alternate domains or IP addresses. Because the profile is applied to the policy, every matching session that is detected as Facebook will be blocked for all users.

Why this answer

Option C is correct because the administrator must first create an application control profile containing a rule that blocks the Facebook application (Facebook is recognized as an application signature, not merely a URL), and then apply that profile to the firewall policy covering all internal users so the block is enforced. Option D is correct because FortiGate evaluates firewall policies top-down, so placing a policy above the blocking policy that permits traffic sourced from the CEO's IP 10.0.0.100 and does not reference the application control profile ensures the CEO's traffic is matched and allowed before the blocking policy is reached. Option A is incorrect because application control profiles in FortiOS do not provide an 'exempt IP' list; exemptions are achieved through policy ordering, not profile-level IP exceptions.

Option B is incorrect for the same reason—there is no per-IP exemption setting inside an application control profile. Option E is incorrect because a web filter URL block for facebook.com would not reliably block the Facebook application (which can use multiple domains and non-HTTP traffic) and does not address the CEO exemption requirement.

Exam trap

NSE4 often tests the misconception that application control profiles support IP exemptions, when in fact exemptions are achieved through firewall policy ordering and source IP matching.

289
Multi-Selecteasy

An administrator needs to authenticate users on a FortiGate using RADIUS. Which TWO of the following are required to configure RADIUS authentication?

Select 2 answers
A.A PKI certificate for the RADIUS server
B.A RADIUS server object with IP address and shared secret
C.An FSSO connector
D.A user group that references the RADIUS server
E.A local user account for each RADIUS user
AnswersB, D

RADIUS authentication requires a server object defining the RADIUS host's IP address and the shared secret used to encrypt and authenticate the FortiGate-to-server exchange. Without this object, the FortiGate cannot reach or trust the RADIUS server, so authentication requests fail.

Why this answer

Option B is correct because configuring RADIUS authentication on a FortiGate requires creating a RADIUS server object under User & Authentication > RADIUS Servers, which must include the server's IP address and the shared secret used to encrypt the RADIUS exchange (typically over UDP ports 1812/1813). Option D is correct because the RADIUS server object alone does not enforce authentication; you must create a user group that references the RADIUS server so it can be applied in firewall identity-based policies or SSL-VPN/LDAP-style authentication rules. Option A is not required because PKI certificates are only needed for EAP/TLS-based RADIUS or LDAPS scenarios, not basic RADIUS shared-secret authentication.

Option C is not required because FSSO is a separate agent-based single sign-on mechanism, not a prerequisite for RADIUS. Option E is not required because RADIUS users are authenticated against the external RADIUS database, not against local FortiGate accounts.

Exam trap

The trap here is that candidates often think a local user account is required for each RADIUS user, but RADIUS offloads authentication to an external server, making local accounts unnecessary.

290
Multi-Selectmedium

An administrator needs to allow inbound SSH access from the internet to a specific internal server (10.0.1.10) on port 22. The WAN IP is 203.0.113.10. Which THREE configuration steps are required?

Select 3 answers
A.Ensure the firewall policy allows the SSH service (port 22)
B.Create a firewall policy from WAN to internal interface with destination set to the VIP
C.Configure a source NAT IP pool for outbound traffic
D.Create a Virtual IP (VIP) mapping 203.0.113.10:22 to 10.0.1.10:22
E.Enable SSL inspection on the policy
AnswersA, B, D

Traffic arriving at the FortiGate for the public IP and port 22 must be matched by a firewall policy whose destination is the VIP's mapped address (the private server IP) and whose service includes SSH. Without a policy that explicitly allows port 22/TCP as the service, the FortiGate will drop the session even if the VIP object exists and is correctly configured. Remember that on FortiGate, an inbound DNAT translation (VIP) does not automatically permit traffic; the policy is the only place where the action (accept) is decided.

Why this answer

Option D is correct because a Virtual IP (VIP) performs destination NAT (DNAT), mapping the public WAN address 203.0.113.10 on port 22 to the internal server 10.0.1.10 on port 22, which is the essential first step to make the internal host reachable from the internet. Option B is correct because a firewall policy must be created with the incoming interface as WAN and the outgoing interface as the internal/LAN interface, with the destination set to that VIP object, so the firewall permits and forwards the translated traffic to the server. Option A is correct because the policy must explicitly allow the SSH service on TCP port 22, since inbound traffic is denied by default and the service must be matched in the policy for the connection to be accepted.

Option C is incorrect because a source NAT IP pool applies to outbound traffic (masquerading internal clients behind a public address) and is irrelevant to publishing an internal server for inbound SSH. Option E is incorrect because SSL inspection applies to TLS/HTTPS traffic and cannot inspect SSH, which is not an SSL/TLS protocol, so enabling it would not enable or secure this inbound SSH access.

Exam trap

The trap here is that candidates often assume configuring a VIP alone is sufficient, forgetting that a firewall policy must also be created to permit the translated traffic, and they may confuse source NAT (Option C) with destination NAT required for inbound access.

291
MCQhard

An administrator has configured DLP sensors to detect credit card numbers in outgoing traffic. However, the administrator notices that traffic containing credit card numbers is still passing through undetected. The firewall policy uses flow-based inspection. What is the MOST likely reason DLP is not detecting the data?

A.DLP requires proxy-based inspection to perform data leakage detection.
B.The DLP sensor is not applied to the correct firewall policy.
C.The DLP sensor is configured with the wrong regular expression.
D.The credit card numbers are encrypted by SSL and deep inspection is not enabled.
AnswerA

DLP inspection requires proxy-based inspection because the firewall must reassemble and scan the full payload; flow-based inspection forwards packets without buffering content, so credit card patterns pass undetected. This satisfies the stem's constraint that the policy uses flow-based inspection.

Why this answer

DLP requires proxy-based inspection to buffer and analyze the content. Flow-based inspection does not support DLP.

292
MCQmedium

A FortiGate administrator needs to configure a policy route to send all traffic destined to 10.10.10.0/24 out through interface port3 instead of the default route. Which configuration steps are necessary?

A.Add a firewall policy with source interface any, destination 10.10.10.0/24, and set the egress interface to port3
B.Create a static route for 10.10.10.0/24 with a lower distance pointing to port3
C.Set the default gateway to port3 and remove the existing default route
D.Configure a policy route under 'config router policy' with destination 10.10.10.0/24 and output interface port3
AnswerD

The correct way to route traffic to 10.10.10.0/24 through port3 based on a policy is to configure a policy route in the 'config router policy' section. In FortiOS, policy routes are evaluated before the routing table and can match on source and destination addresses, protocols, and incoming interfaces, then set an explicit output interface. This gives the administrator precise control over traffic engineering without altering the normal routing table or affecting other traffic. Thus, 'config router policy' with destination 10.10.10.0/24 and output interface port3 is the correct implementation.

Why this answer

Policy routes override the routing table for specific traffic based on criteria like source, destination, or protocol. Option D correctly configures a policy route under 'config router policy' to match destination 10.10.10.0/24 and set the output interface to port3, ensuring that traffic is forwarded out port3 regardless of the default route.

Exam trap

The trap here is confusing firewall policies (which control access and NAT) with policy routes (which control forwarding decisions), leading candidates to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because firewall policies control access and NAT, not routing; they cannot override the routing table to force traffic out a specific interface. Option B is wrong because a static route for 10.10.10.0/24 with a lower distance would still be subject to the routing table's longest-match rule and could be overridden by a more specific route or dynamic routing, whereas a policy route takes precedence over the routing table. Option C is wrong because changing the default gateway to port3 would affect all traffic, not just traffic to 10.10.10.0/24, and removing the existing default route would break connectivity for other destinations.

293
MCQeasy

An administrator needs to back up the FortiGate configuration to a remote server using SCP. Which command is correct?

A.execute backup config copy <server> <filename>
B.execute backup config scp <server> <filename>
C.execute backup config tftp <server> <filename>
D.execute backup config ftp <server> <filename>
AnswerB

The command 'execute backup config scp <server> <filename>' is the correct, secure method to back up a FortiGate configuration. SCP (Secure Copy Protocol) runs over SSH, encrypting the entire transfer session, which protects the configuration file and any server credentials from interception. Because the configuration contains sensitive data such as VPN preshared keys, passwords, and certificates, using SCP is strongly recommended, especially when backing up over an untrusted network. The <server> parameter can include a username in user@host format for SSH authentication.

Why this answer

The correct command is 'execute backup config scp <server> <filename>' because SCP (Secure Copy Protocol) is the only option listed that provides encrypted file transfer over SSH, which is required for securely backing up the FortiGate configuration to a remote server. FortiGate uses this CLI command to initiate an SCP session to the specified server and save the configuration file with the given filename.

Exam trap

The trap here is that candidates often confuse 'scp' with 'ftp' or 'tftp' because they all transfer files, but only SCP provides encryption, which is the key requirement for a secure remote backup.

How to eliminate wrong answers

Option A is wrong because 'execute backup config copy' is not a valid FortiGate command; the syntax uses 'copy' incorrectly, and there is no such subcommand for backup operations. Option C is wrong because 'execute backup config tftp' uses TFTP (Trivial File Transfer Protocol), which is unencrypted and lacks authentication, making it unsuitable for secure backups to a remote server. Option D is wrong because 'execute backup config ftp' uses FTP (File Transfer Protocol), which transmits data in cleartext including credentials, and is not the secure method specified in the question (SCP).

294
MCQmedium

A company with 500 users has a FortiGate 1000D running FortiOS 7.2. They have configured full SSL inspection and web filtering to block malware and phishing sites. The administrator receives complaints that some users cannot access a legitimate business website (https://vendor.example.com). The administrator checks the FortiGate logs and sees that the connection is allowed by the firewall policy and web filter. However, the user's browser shows 'ERR_CERT_AUTHORITY_INVALID'. The administrator verifies that the FortiGate's CA certificate is installed on all client machines. Further investigation reveals that the vendor's website uses a certificate signed by a private CA that is not trusted by the FortiGate. The administrator wants to resolve the issue without disabling SSL inspection for the whole website or compromising security. What should the administrator do?

A.Create an SSL exemption for the vendor's domain in the SSL inspection profile.
B.Import the vendor's private CA certificate into the FortiGate's trusted root CA store.
C.Change the SSL inspection profile to certificate inspection only.
D.Install the vendor's CA certificate on the client machines.
AnswerB

Importing the vendor's private CA certificate into the FortiGate's trusted root CA store is the correct fix because the FortiGate acts as a TLS man-in-the-middle and must validate the vendor's server certificate chain before it can generate an on-the-fly session certificate for the client. Once that CA is trusted, the FortiGate successfully validates the vendor's certificate, completes its upstream TLS connection, and issues a client-facing certificate signed by the FortiGate's own CA, restoring full inline inspection without any warning. This centralized approach also avoids needing to touch the 500 client machines.

Why this answer

The FortiGate cannot validate the vendor's certificate because its private CA is not in the FortiGate's trusted root store. By importing that CA certificate into the FortiGate's trusted root CA store, the FortiGate will trust the vendor's certificate chain, allowing full SSL inspection to proceed without errors. This resolves the ERR_CERT_AUTHORITY_INVALID error while maintaining security inspection for the domain.

Exam trap

The trap here is that candidates often assume the client-side CA certificate installation is sufficient, but the FortiGate itself must also trust the server's issuing CA to perform full SSL inspection without errors.

How to eliminate wrong answers

Option A is wrong because creating an SSL exemption bypasses inspection entirely for the domain, which compromises security by allowing encrypted traffic to pass without inspection. Option C is wrong because changing to certificate inspection only would disable deep packet inspection for all traffic, reducing security posture and not specifically addressing the untrusted CA issue. Option D is wrong because the client machines already have the FortiGate's CA certificate installed; the issue is that the FortiGate itself does not trust the vendor's private CA, so installing it on clients does not fix the server-side validation failure.

295
MCQeasy

A FortiGate administrator wants to ensure that traffic from the internal network to the internet is translated to a single public IP address. Which NAT method should be used?

A.Central SNAT
B.One-to-one NAT
C.Fixed port range NAT
D.Overload NAT
AnswerD

Overload NAT, also known as Port Address Translation (PAT), is the correct method for this scenario. It translates the source IP address of all internal hosts to one public IP while dynamically assigning a unique source port for each connection, preserving the host identity through the port mapping. This provides scalable, concurrent internet access for many internal users using a single public address.

Why this answer

Overload NAT (also known as Port Address Translation or PAT) is the correct method because it allows multiple internal hosts to share a single public IP address by mapping each session to a unique source port. This is exactly what the administrator needs: translating all internal-to-internet traffic to one public IP.

Exam trap

The trap here is that candidates often confuse 'Central SNAT' (a FortiGate configuration method) with a specific NAT type, or think 'one-to-one NAT' is suitable for sharing a single IP, when it actually requires a dedicated public IP per internal host.

How to eliminate wrong answers

Option A is wrong because Central SNAT is a policy-based NAT method in FortiGate that can use overload or other modes, but it is not a specific NAT method itself; it is a configuration approach. Option B is wrong because one-to-one NAT maps a single private IP to a single public IP, which would require multiple public IPs for multiple internal hosts, not a single public IP. Option C is wrong because fixed port range NAT allocates a fixed range of ports per internal host, which still requires multiple public IPs or port ranges and does not achieve the goal of using a single public IP for all traffic.

296
MCQmedium

An administrator wants to limit the bandwidth for a specific application (e.g., YouTube) across all users. The administrator creates a traffic shaper and applies it to the firewall policy. What additional configuration is needed to identify YouTube traffic?

A.Enable deep inspection and create a URL filter
B.Create a custom service object for YouTube
C.Use a geography object to block non-local traffic
D.Apply an Application Control profile to the policy
AnswerD

Applying an Application Control profile to the FortiGate policy identifies traffic by application signatures rather than by IP, protocol, or country. Once YouTube is identified, you can attach a traffic shaper to that policy (or use per-application bandwidth limits in the profile) to enforce a maximum bandwidth. This is the correct method because it targets the application while allowing other traffic to remain unaffected.

Why this answer

Application Control profiles are specifically designed to identify and control traffic based on application signatures, such as YouTube. A traffic shaper limits bandwidth, but it requires an Application Control profile to classify the traffic as YouTube before the shaping can be applied. Without this profile, the firewall cannot distinguish YouTube from other web traffic.

Exam trap

The trap here is that candidates often confuse URL filtering (which identifies web domains) with Application Control (which identifies applications by their network behavior), leading them to choose deep inspection and URL filtering instead of the correct Application Control profile.

How to eliminate wrong answers

Option A is wrong because deep inspection and URL filtering inspect HTTPS URLs and content, but they do not identify application traffic like YouTube by its network signatures; URL filtering can block or allow based on domain, but it cannot apply bandwidth shaping to a specific application within a policy. Option B is wrong because a custom service object defines protocols and ports (e.g., TCP/443), but YouTube uses standard HTTPS ports and cannot be uniquely identified by port alone; application identification requires deep packet inspection beyond layer 4. Option C is wrong because geography objects filter traffic based on source or destination IP geolocation, which is unrelated to identifying a specific application like YouTube; this would block or allow entire regions, not shape bandwidth for an application.

297
MCQhard

In an active-active HA cluster, what is the purpose of the 'session sync' configuration?

A.To synchronize configuration changes between cluster members
B.To balance the number of sessions across cluster members
C.To replicate session state so that if one unit fails, another can take over without interruption
D.To synchronize the time between cluster members
AnswerC

Session synchronization replicates the full state of active sessions—including TCP sequence numbers, NAT translations, and timers—from the unit that owns the session to every other member of the cluster. If the owning unit fails, a peer that has an identical session record can immediately resume forwarding traffic without requiring clients to re-establish their connections. This stateful takeover is critical for seamless failover in high-availability clusters.

Why this answer

Session sync ensures that sessions are shared between cluster units so that any unit can handle traffic for a given session.

298
MCQhard

A FortiGate in a hub-and-spoke VPN topology has multiple spoke sites connecting via IPsec. The hub administrator wants to enable direct spoke-to-spoke communication without routing traffic through the hub. What technology should be used?

A.ADVPN (Auto-Discovery VPN)
B.Site-to-site VPN between each spoke pair manually
C.Policy-based VPN with multiple Phase 2 selectors
D.SSL VPN tunnel mode
AnswerA

ADVPN (Auto-Discovery VPN) is the correct dynamic solution. It builds on a standard hub-and-spoke IPsec topology, where the hub acts as a route reflector and triggers short-cut negotiations between spokes via IKE informational exchanges when inter-spoke traffic is detected. This allows spokes to dynamically establish direct IPsec tunnels, eliminating the need for traffic to hairpin through the hub and providing optimal routing and reduced latency.

Why this answer

ADVPN (Auto-Discovery VPN) is the correct technology because it dynamically establishes direct IPsec tunnels between spoke sites in a hub-and-spoke topology, eliminating the need to route inter-spoke traffic through the hub. It uses IKEv2 with short-cut messages (via the hub as a signaling broker) to allow spokes to learn each other's public IP addresses and negotiate a direct tunnel, reducing latency and hub load.

Exam trap

The trap here is that candidates often confuse ADVPN with simply adding more Phase 2 selectors to an existing tunnel, thinking that will magically route traffic directly between spokes, when in fact Phase 2 selectors only control encryption policies, not tunnel establishment.

How to eliminate wrong answers

Option B is wrong because manually configuring site-to-site VPNs between every spoke pair is not scalable and defeats the purpose of a hub-and-spoke design—it requires N*(N-1)/2 tunnels and static configuration, whereas ADVPN automates this. Option C is wrong because policy-based VPNs with multiple Phase 2 selectors only define which traffic is encrypted over an existing tunnel; they do not create new tunnels or enable direct spoke-to-spoke communication without hub involvement. Option D is wrong because SSL VPN tunnel mode provides remote user access to the network, not site-to-site connectivity; it cannot dynamically establish tunnels between spoke sites.

299
MCQhard

An administrator runs 'diagnose sys session filter dport 443' and then 'diagnose sys session list'. The output shows many sessions with 'proto_state=01' and 'expire=3599'. What does 'expire=3599' indicate?

A.The session has 3599 packets
B.The session has been alive for 3599 seconds
C.The session has 3599 bytes of data transferred
D.The session will timeout in 3599 seconds
AnswerD

The expire counter shows the remaining lifetime before FortiGate removes the session from its session table, decrementing each second from the configured timeout. With proto_state=01 confirming an established TCP session, expire=3599 means roughly one hour remains before idle timeout eviction, directly answering what the field indicates.

Why this answer

In FortiGate diagnostics, the 'expire' field in the session list output indicates the remaining time in seconds before the session times out. A value of 3599 seconds means the session will be removed from the session table after that many seconds of inactivity, assuming no further traffic matches the session. This is a key metric for understanding session lifecycle and timeout behavior.

Exam trap

The trap here is confusing 'expire' (remaining time until timeout) with 'duration' (time since session creation), leading candidates to incorrectly select option B.

How to eliminate wrong answers

Option A is wrong because 'expire' does not represent a packet count; packet counts are shown in separate fields like 'packets' or 'pkt_in/pkt_out'. Option B is wrong because 'expire' is the remaining time until timeout, not the elapsed time since the session was created; the 'duration' field tracks how long the session has been alive. Option C is wrong because 'expire' is unrelated to data transfer size; byte counts are displayed in fields such as 'bytes' or 'total_bytes'.

300
MCQeasy

An administrator wants to configure SSL VPN web mode to allow remote users to access a specific internal web application without installing any client software. Which authentication method is required?

A.Certificate-based authentication only
B.No authentication is required for web mode
C.Two-factor authentication with FortiToken is mandatory
D.Any supported authentication method (local, LDAP, RADIUS, certificates)
AnswerD

FortiGate SSL VPN web mode supports multiple authentication backends, including local users, LDAP, RADIUS, and certificate-based authentication. The administrator selects the appropriate method when configuring the SSL VPN portal and corresponding user group. This flexibility allows integration with existing identity sources while maintaining centralized access control, which is why this is the correct answer.

Why this answer

SSL VPN web mode on FortiGate allows remote users to access internal web applications through a browser without client software. FortiGate supports multiple authentication methods for web mode, including local users, LDAP, RADIUS, and certificate-based authentication, so any supported method can be used. There is no requirement for a specific authentication type, making option D correct.

Exam trap

The trap here is that candidates assume SSL VPN web mode requires a specific strong authentication method (like certificates or two-factor), but FortiGate allows any supported method, and the question explicitly asks which is 'required'—not recommended.

How to eliminate wrong answers

Option A is wrong because certificate-based authentication is not mandatory; FortiGate allows other methods like local, LDAP, or RADIUS for SSL VPN web mode. Option B is wrong because SSL VPN web mode always requires authentication to establish the VPN tunnel and access internal resources; no authentication is not supported. Option C is wrong because two-factor authentication with FortiToken is optional, not mandatory; administrators can choose simpler methods if security policies allow.

Page 3

Page 4 of 11

Page 5

All pages