Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 301–375

773 questions total · 11pages · All types, answers revealed

Page 4

Page 5 of 11

Page 6
301
MCQhard

A FortiGate administrator is configuring a route-based IPsec VPN between two FortiGate devices. After setting up the tunnel and firewall policies, traffic does not flow. The administrator runs 'diagnose vpn tunnel list' and sees the tunnel is up. 'get router info routing-table all' shows routes on both sides. However, pings from the local network to the remote network fail. What is the MOST likely cause?

A.The pre-shared key is incorrect
B.The firewall policy allowing traffic to the remote subnet has the source and destination interfaces reversed
C.The remote FortiGate's static route points to the wrong local subnet
D.The Phase 2 proposal uses different encryption algorithms on each side
AnswerB

In a route-based VPN, the policy must be configured with the VPN interface as the destination interface (if traffic flows from internal to VPN) or source interface (if from VPN to internal). Misconfiguration here causes traffic to be dropped.

Why this answer

The tunnel is up and routes are present, indicating Phase 1 and Phase 2 negotiations succeeded. The most likely cause is that the firewall policy allowing traffic to the remote subnet has the source and destination interfaces reversed. In a route-based VPN, the policy must have the incoming interface as the source (e.g., internal) and the outgoing interface as the destination (e.g., the VPN tunnel interface).

Reversing these prevents traffic from being matched, even though the tunnel is established.

Exam trap

The trap here is that candidates assume a tunnel being up and routes present guarantees traffic flow, overlooking that the firewall policy's interface direction must match the traffic flow, not the tunnel's logical direction.

How to eliminate wrong answers

Option A is wrong because an incorrect pre-shared key would prevent Phase 1 from completing, causing the tunnel to show as down, not up. Option C is wrong because the remote FortiGate's static route pointing to the wrong local subnet would cause asymmetric routing or unreachability, but the local side's routes are correct per the scenario; the issue is on the local firewall policy, not the remote route. Option D is wrong because mismatched Phase 2 proposals would cause the tunnel to fail to establish or show as up with no traffic, but 'diagnose vpn tunnel list' would typically show a down or error state, not 'up'.

302
MCQhard

An administrator enables deep inspection for HTTPS traffic. Users report that they cannot access some websites because of certificate errors. The administrator wants to override these errors and allow access. What should be configured?

A.Disable certificate verification in the deep inspection profile
B.Add the websites to the 'FortiGuard category' allow list
C.Configure the web filter to allow these websites
D.Add the websites to the 'SSL/SSH exemption' list in the deep inspection profile
AnswerD

Adding the websites to the SSL/SSH exemption list in the deep inspection profile is the correct method because it instructs the FortiGate to skip decryption for those exact destinations. The FortiGate then forwards the TLS handshake untouched, so the browser sees the original site certificate and no certificate validation error occurs. All other HTTPS traffic continues to be deeply inspected, preserving overall security while solving the compatibility problem.

Why this answer

In FortiOS, deep inspection can generate certificate errors for sites with self-signed or mismatched certificates. To allow access despite errors, the administrator can add the affected domains to the 'SSL/SSH exemption' list in the deep inspection profile. This exempts those sites from deep inspection, avoiding the certificate error.

303
MCQeasy

A FortiGate administrator wants to authenticate VPN users against an existing Active Directory server. The administrator creates a user group referencing a remote LDAP server and configures the firewall policy to authenticate using that group. However, users report authentication failures. What is the FIRST step to troubleshoot?

A.Run 'diag test authserver ldap <server> <username> <password>'
B.Verify the user group configuration
C.Restart the FortiGate
D.Check the LDAP server's firewall rules
AnswerA

Running the diagnostic command `diag test authserver ldap <server> <username> <password>` forces the FortiGate to initiate a live LDAP bind operation against the configured server object using the exact credentials provided. This single command validates the LDAP server's network reachability (TCP and TLS if LDAPS is enabled) and the correctness of the bind password in one step. Because it bypasses the VPN tunnel and user-group mapping layers, any failure here pinpoints a core LDAP authentication issue, making it the most efficient first troubleshooting action for VPN user login failures.

Why this answer

The `diag test authserver ldap` command directly tests LDAP authentication against the specified server, username, and password, isolating whether the FortiGate can successfully bind and authenticate the user. This is the fastest way to determine if the issue lies with the LDAP server connectivity, credentials, or configuration, rather than with the user group or policy. Since the administrator has already created the group and policy, the first logical step is to verify the fundamental authentication path before examining higher-level configurations.

Exam trap

The trap here is that candidates often jump to checking the user group or policy configuration (Option B) because they assume the LDAP server is reachable, but the NSE4 exam emphasizes using diagnostic commands first to isolate the problem at the authentication source.

How to eliminate wrong answers

Option B is wrong because verifying the user group configuration assumes the authentication itself works, but the core issue may be that the FortiGate cannot reach or bind to the LDAP server at all. Option C is wrong because restarting the FortiGate is a blunt, non-diagnostic step that does not address the root cause and may temporarily mask the problem without providing insight. Option D is wrong because checking the LDAP server's firewall rules is a network-level check that should be performed only after confirming the FortiGate's own LDAP test fails, as the test command will reveal connectivity or authentication errors first.

304
MCQmedium

A client connects to a FortiGate SSL VPN in web mode. The user can access internal web applications but cannot ping or RDP to servers. The administrator wants to allow these services. What must be changed?

A.Enable split tunneling on the SSL VPN portal
B.Change the SSL VPN type from web mode to tunnel mode
C.Add the server IP addresses to the portal's bookmarks
D.Configure a firewall policy allowing the client's IP to the servers
AnswerB

Web mode proxies only HTTP and HTTPS through the browser, so ICMP and RDP cannot traverse it. Tunnel mode installs a virtual adapter and routes arbitrary IP traffic, enabling ping and RDP to internal servers.

Why this answer

Web mode SSL VPN only provides application-layer access through a web portal, typically using HTTP/HTTPS. It does not create a virtual network interface on the client, so lower-layer protocols like ICMP (ping) and RDP (TCP/3389) cannot be routed through the VPN. To support these services, the VPN must operate in tunnel mode, which assigns a virtual IP to the client and creates a full Layer 3 tunnel, allowing all IP-based traffic to traverse the FortiGate.

Exam trap

The trap here is that candidates assume adding a firewall policy or enabling split tunneling will magically allow non-web traffic in web mode, not realizing that web mode fundamentally lacks the Layer 3 virtual interface required to route protocols other than HTTP/HTTPS.

How to eliminate wrong answers

Option A is wrong because split tunneling controls which destinations are routed through the VPN tunnel versus the internet, but it does not change the fundamental limitation of web mode—web mode cannot pass non-HTTP traffic regardless of split tunneling settings. Option C is wrong because bookmarks in the SSL VPN portal are only shortcuts for web-based applications; they do not enable protocol-level forwarding for ICMP or RDP. Option D is wrong because firewall policies are necessary for traffic to be permitted, but without tunnel mode, the client's traffic never reaches the FortiGate as routable IP packets—web mode only proxies HTTP/HTTPS requests, so a firewall policy alone cannot allow ping or RDP.

305
MCQeasy

What is the purpose of enabling 'DNS filter' in a security profile?

A.To cache DNS responses for faster browsing
B.To prevent DNS tunneling attacks
C.To enforce safe search on search engines
D.To block DNS queries to known malicious domains
AnswerD

A DNS filter enforces a security policy by matching DNS queries against a real-time feed of malicious domains, including those used for malware, ransomware, phishing, and botnet C2 infrastructure. When a client attempts to resolve such a domain, the filter returns a denial (either a block page IP or a sinkhole IP) instead of the real record, preventing the connection before it is established. This proactive approach stops threats at the earliest stage of the communication chain, even if the client has no other security controls.

Why this answer

FortiGate's DNS filter security profile inspects DNS queries and blocks those destined for domains categorized as malicious (botnets, phishing, malware C2) using FortiGuard's DNS threat intelligence. This prevents clients from resolving and reaching known-bad domains, cutting off the first step of many attacks.

Exam trap

NSE4 often tests the difference between the DNS filter profile's core purpose (blocking malicious domain resolution) and its optional sub-features (safe search, caching) — candidates pick 'safe search' or 'DNS tunneling' because those appear in the profile's settings, missing the primary intent.

How to eliminate wrong answers

Option A is wrong because DNS caching is a resolver/performance function, not the purpose of the DNS filter security profile. Option B is wrong because while DNS filtering can disrupt some DNS tunneling by blocking malicious domains, preventing DNS tunneling specifically is not its stated purpose — that is better addressed by DNS inspection/DoS policies and anomaly detection. Option C is wrong because safe search enforcement is a separate DNS filter option (safe search for Google/Bing/YouTube) within the profile, not the profile's overall purpose.

306
MCQeasy

Which IPsec VPN mode is typically used for site-to-site VPNs and is more secure because it negotiates Phase 1 in six messages?

A.Quick mode
B.Aggressive mode
C.IKEv2
D.Main mode
AnswerD

Main Mode is the default IKEv1 Phase 1 mode for site-to-site VPNs because it uses six messages to negotiate the IKE SA while protecting each side's identity. It performs the Diffie-Hellman exchange before sending identities, and all identity information is encrypted once the SA is established, which mitigates packet sniffing on untrusted links. FortiGate's phase 1 settings allow selecting Main to enforce this more robust exchange, making it the recommended choice for fixed, site-to-site peers.

Why this answer

Main mode is the correct answer because it is the IPsec VPN mode typically used for site-to-site VPNs and is considered more secure due to its use of six messages during Phase 1 (IKE) negotiation. This mode protects the identities of both peers by encrypting the identity payloads after the Diffie-Hellman exchange, making it resistant to man-in-the-middle attacks and identity disclosure.

Exam trap

The trap here is that candidates often confuse Main mode with Aggressive mode, mistakenly thinking Aggressive mode is more secure because it is faster, but in reality, Aggressive mode sacrifices identity protection for speed, making it less secure for site-to-site VPNs.

How to eliminate wrong answers

Option A is wrong because Quick mode is a Phase 2 exchange that negotiates IPsec security associations (SAs) for data traffic, not a Phase 1 mode, and it uses only three messages, not six. Option B is wrong because Aggressive mode uses only three messages in Phase 1, which reduces security by transmitting identities in cleartext before the Diffie-Hellman exchange is completed, making it vulnerable to identity theft. Option C is wrong because IKEv2 is a separate protocol that uses a four-message exchange (two request/response pairs) for initial SA setup, not six messages, and while it is secure, it is not the mode described in the question.

307
MCQhard

An admin configures a Central SNAT rule to translate internal 192.168.1.0/24 to 203.0.113.10 when accessing the internet. However, traffic from 192.168.1.100 to 8.8.8.8 shows source IP 192.168.1.100 in logs. What is the MOST likely cause?

A.The Central SNAT rule is disabled
B.The Central SNAT rule is applied to the wrong outgoing interface
C.The firewall policy has an IP pool configured, overriding Central SNAT
D.The destination address in the Central SNAT rule is incorrect
AnswerB

Central SNAT rules specify an outgoing interface, and if the interface does not match the actual egress interface used by the traffic, the rule is skipped and no translation occurs. However, in a typical policy-based NAT deployment, the firewall policy's IP pool takes precedence over any central SNAT rule, regardless of interface matching. This makes an interface mismatch a possible but less likely explanation, because the override would still mask the central rule even if the interface were correct.

Why this answer

The Central SNAT rule is not being applied to the traffic. The most likely cause is that the rule specifies an outgoing interface different from the one used to reach 8.8.8.8, so the rule does not match and no source translation occurs.

Exam trap

Candidates may confuse IP pool override with Central SNAT, but if an IP pool were active, the source would be changed to the pool IP. Here, the source remains the original internal IP, indicating the Central SNAT rule itself is not matching.

How to eliminate wrong answers

Option A is wrong because if the Central SNAT rule were disabled, no SNAT translation would occur, but the traffic would still be logged with the original source IP; however, the question states the admin configured the rule, and a disabled rule would not cause the observed behavior unless explicitly verified. Option B is wrong because Central SNAT rules are not interface-specific; they are applied globally based on source/destination criteria, so applying to the wrong outgoing interface would not cause the rule to be ignored entirely—it would simply not match the traffic. Option D is wrong because the destination address in the Central SNAT rule is used to match traffic (e.g., to the internet), and an incorrect destination would prevent the rule from matching, but the traffic would still be subject to other SNAT mechanisms like IP pools on the policy; the question specifically describes a scenario where the rule is configured but overridden, not a mismatch.

308
MCQmedium

A company has a web server in the DMZ that must be accessible from the internet on both HTTP and HTTPS. The admin configures a VIP to map the public IP to the server's private IP. However, external users can only reach HTTP. What is the MOST likely cause?

A.The VIP is configured for port forwarding only for HTTP (port 80)
B.The web server is not listening on HTTPS
C.The VIP is using overload mode instead of one-to-one
D.The firewall policy allowing traffic to the VIP only permits HTTP
AnswerA

The virtual IP (VIP) object on a FortiGate is responsible for destination NAT, mapping an external address and port to an internal server. When a VIP is defined with only the HTTP service (port 80), the FortiGate will only translate traffic destined to that external IP:port pair. Incoming HTTPS connections to port 443 are not matched by the VIP, so they are dropped or not forwarded, precisely matching the symptom that external users cannot reach the web server over HTTPS.

Why this answer

The VIP (Virtual IP) configuration on a FortiGate maps a public IP and port to a private IP and port. If the VIP is configured only for port forwarding on TCP 80 (HTTP), it will not translate traffic for TCP 443 (HTTPS). This is the most likely cause because external users can reach HTTP but not HTTPS, indicating the VIP itself is not handling HTTPS traffic.

Exam trap

The trap here is that candidates often assume the firewall policy is the issue, but the VIP itself must be configured to forward the specific ports; a policy allowing all traffic is useless if the VIP does not translate the destination port for HTTPS.

How to eliminate wrong answers

Option B is wrong because if the web server were not listening on HTTPS, the connection would still be attempted and fail at the server level, but the symptom is that external users cannot reach HTTPS at all, which points to a VIP or policy issue, not server configuration. Option C is wrong because overload mode (PAT) and one-to-one mode (DNAT) both can handle multiple ports; the mode does not restrict which ports are forwarded. Option D is wrong because the firewall policy allowing traffic to the VIP only permits HTTP would block HTTPS, but the question states the VIP is configured for port forwarding only for HTTP, making the VIP itself the root cause; a policy issue would be secondary and less likely given the VIP configuration.

309
Multi-Selecthard

Which TWO are best practices for configuring IPsec VPN on FortiGate to ensure high availability and security?

Select 2 answers
A.Disable DPD on the phase1 interface to reduce overhead.
B.Enable perfect forward secrecy (PFS) for phase2 to ensure session keys are not compromised if a private key is stolen.
C.Use aggressive mode for faster IKE negotiation.
D.Configure a dead peer detection (DPD) interval to detect tunnel failures.
E.Disable PFS to reduce CPU load on the firewall.
AnswersB, D

Enabling PFS for phase2 is a best practice because it forces a new Diffie-Hellman exchange for each Quick Mode, generating fresh session keys independent of the IKE SA's shared secret. If the firewall's private key or pre-shared secret is later stolen, an attacker cannot use it to derive previous or subsequent phase2 keys, limiting data exposure to the current session. PFS adds a small computational cost but is strongly recommended for environments handling sensitive data.

Why this answer

Perfect Forward Secrecy (PFS) ensures that if an attacker compromises the private key used during IKE phase1, they cannot derive the session keys used in phase2. By requiring a new Diffie-Hellman exchange for each phase2 rekey, PFS isolates the compromise to only the current session, protecting past and future encrypted traffic. This is a critical security best practice for IPsec VPNs on FortiGate.

Exam trap

The trap here is that candidates often confuse DPD with a performance overhead feature and disable it, or they mistakenly believe aggressive mode is faster and therefore better, overlooking the severe security implications of sending identities in cleartext.

310
MCQeasy

Which FortiGate log type records information about firewall policy matches and traffic statistics?

A.Event logs
B.Traffic logs
C.Audit logs
D.Security logs
AnswerB

Traffic logs are written by the FortiGate session table when a flow matches an explicit or implicit firewall policy. Each entry records the policy ID, session ID, source and destination IP/port, interfaces, NAT translations, and byte/packet counts for both directions. They also indicate the action taken, such as accept, deny, or SSL-negotiation failure. This is the dedicated log type for reviewing which firewall policies allowed or blocked specific sessions and how much bandwidth they consumed.

Why this answer

FortiGate traffic logs record information about firewall policy matches, including source and destination IP addresses, ports, protocols, and the action taken (allow/deny). They also include traffic statistics such as bytes sent and received. Therefore, traffic logs are the correct log type for this information.

Exam trap

NSE4 often tests the distinction between log types, and candidates may confuse traffic logs with event or security logs, especially when the question mentions 'firewall policy matches' which could be misconstrued as security events.

How to eliminate wrong answers

Option A is wrong because event logs record system events such as administrator logins, configuration changes, and HA events, not traffic details. Option C is wrong because audit logs are a subset of event logs that specifically record administrative actions and configuration changes. Option D is wrong because security logs are not a standard FortiGate log type; security-related events are typically found in event logs or specific security logs like IPS or antivirus logs, but they do not record general traffic statistics.

311
MCQmedium

A FortiGate is configured in an active-passive HA cluster. The administrator wants to verify which unit is currently the primary and also see the HA uptime and priority of each unit. Which command should the administrator use?

A.get system ha status
B.diagnose sys ha status
C.show system ha
D.diagnose sys ha dump
AnswerA

This command displays the HA cluster status, including which unit is primary, the HA uptime, and the priority of each member. It provides a concise summary directly from the CLI, making it ideal for quickly verifying the active unit and its attributes in an active-passive setup.

Why this answer

The command 'get system ha status' is the correct way to view the current HA status on a FortiGate. It shows which unit is the primary, the HA uptime, and the priority of each cluster member. This directly answers the administrator's need to verify the active unit and its attributes in an active-passive cluster.

Exam trap

The trap here is confusing configuration display commands like 'show system ha' with operational status commands like 'get system ha status'.

312
MCQeasy

A FortiGate administrator is configuring a new SSL VPN portal for employees. The requirement is that employees must authenticate using their Active Directory credentials, and after authentication, they should only be able to access a specific internal web server via a bookmarked link. Which SSL VPN configuration should the administrator use to meet these requirements?

A.Configure the SSL VPN settings to use 'Web Mode' and add a bookmark to the portal for the internal web server.
B.Configure the SSL VPN settings to use 'Web Mode' and enable 'Client Certificate' authentication.
C.Configure the SSL VPN settings to use 'Tunnel Mode' with split tunneling and add a static route for the web server.
D.Configure the SSL VPN settings to use 'Tunnel Mode' and create a firewall policy allowing all internal subnets.
AnswerA

Web mode allows users to access specific web-based applications through a portal without a full tunnel. By adding a bookmark to the internal web server, users can click the link to access it. Authentication can be set to use Active Directory. This meets the requirements of AD authentication and limited access to a specific web server via a bookmark.

Why this answer

Web mode is designed for browser-based access to specific applications, and bookmarks provide easy links to internal web servers. Authentication can be configured to use Active Directory, satisfying the credential requirement. Tunnel mode would provide broader network access than needed and does not use bookmarks for specific applications.

Therefore, web mode with a bookmark and AD authentication is the correct solution.

Exam trap

The trap here is assuming that tunnel mode is always required for internal access, when web mode with bookmarks is sufficient and more secure for specific web applications.

313
MCQmedium

An administrator needs to ensure that in an active-passive HA cluster, the primary unit always remains the preferred master unless it fails, regardless of other factors. The administrator sets the primary's HA priority to 200 and the secondary to 100. However, after a reboot of the primary, the secondary becomes the primary. What additional step is required?

A.Set 'set ha-mgmt-status enable' on the primary
B.Reduce the secondary priority to 0
C.Increase the primary priority to 255
D.Set 'set override enable' under config system ha
AnswerD

Enabling 'override' in the HA configuration is the correct way to allow a higher-priority unit to preempt and become primary again after it recovers from a failure. When 'override' is enabled, the cluster continuously compares the priority of all units, and if a unit with a higher priority comes back online, it will actively take over the primary role. This ensures that in an active-passive setup, the preferred primary unit will regain mastership after a failover, instead of letting the secondary remain as primary indefinitely. The command is configured under 'config system ha' and is essential for automatic failback.

Why this answer

In HA, the 'override' setting (or 'set override enable') ensures that when the primary recovers, it will preempt the current primary and become active again. Without override, the cluster uses a non-preemptive mode: once a unit becomes primary, it stays primary even if a higher-priority unit comes back online.

314
MCQmedium

A network admin has configured a firewall policy allowing traffic from the 'internal' zone to the 'external' zone. The policy uses a service object 'HTTP' (TCP/80). Users report they can access HTTP websites but not HTTPS. The admin confirms no other policies block HTTPS. What is the most likely cause?

A.The FortiGate needs to perform SSL inspection on HTTPS traffic
B.There is a policy ordering issue; a later policy might block HTTPS
C.HTTPS traffic is being dropped by implicit deny because no policy matches it
D.The service object 'HTTP' also includes TCP/443 by default
AnswerC

This is the correct explanation. In FortiOS, every firewall policy list ends with an implicit deny rule that silently drops any traffic that does not match an explicit allow policy. The administrator's policy only allows the HTTP service (TCP/80), so HTTPS traffic (TCP/443) has no matching allow entry and is consequently dropped by the implicit deny rule. This is a classic failure point when administrators assume that allowing HTTP also covers HTTPS, or forget to add a separate policy for HTTPS.

Why this answer

The firewall policy explicitly allows only HTTP (TCP/80) traffic from the internal zone to the external zone. HTTPS uses TCP/443, which is not included in the service object 'HTTP'. Since no other policy permits HTTPS, the traffic hits the implicit deny rule at the end of the policy list, which drops all unmatched traffic.

This is the default behavior on FortiGate firewalls.

Exam trap

The trap here is that candidates assume a policy allowing HTTP will also allow HTTPS because both are web traffic, but FortiGate treats them as distinct services based on TCP port numbers, and implicit deny will block any unmatched traffic.

How to eliminate wrong answers

Option A is wrong because SSL inspection is not required for HTTPS traffic to pass through a firewall; it is only needed for deep packet inspection or decryption, not for basic connectivity. Option B is wrong because the admin confirmed no other policies block HTTPS, and a later policy would only block traffic if it explicitly denied it; the issue is that no policy permits HTTPS at all. Option D is wrong because the service object 'HTTP' is predefined as TCP/80 only and does not include TCP/443 by default; TCP/443 is part of the 'HTTPS' service object.

315
MCQeasy

What is the purpose of the 'DNS Filter' feature on a FortiGate?

A.To block DNS queries to malicious domains based on FortiGuard category and allow/block lists.
B.To cache DNS queries for faster resolution.
C.To encrypt DNS traffic to prevent eavesdropping.
D.To filter the content of DNS responses from legitimate servers.
AnswerA

DNS Filter on FortiGate intercepts DNS queries and evaluates the requested domain against FortiGuard's threat intelligence categories, as well as administrator-defined allow and block lists. If the domain is categorized as malicious or prohibited, the FortiGate drops the query or returns a spoofed response, preventing the client from resolving the domain to an IP address. This is a proactive security control because it stops the connection before any traffic reaches the malicious server, even if the client already knows the IP via DNS pinning or a hosts file.

316
MCQeasy

What is the purpose of configuring a loopback interface on a FortiGate?

A.To create a logical interface that remains up regardless of physical link status
B.To provide a virtual IP address for NAT
C.To connect to a VLAN
D.To aggregate multiple physical interfaces for increased bandwidth
AnswerA

A loopback interface is a virtual interface that is always administratively up once created, independent of any physical link state. This guarantees a stable IP address for management access, routing protocol peering (e.g., OSPF, BGP), and device identification, even if all physical interfaces fail. Only a manual shutdown or system-wide outage can bring it down.

Why this answer

A loopback interface is a logical interface that is not tied to any physical port, so it remains operational (up/up) as long as the FortiGate itself is running. This makes it ideal for management access, BGP peering, and other services that require a stable IP address independent of physical link failures.

Exam trap

The trap here is that candidates confuse a loopback interface with a virtual IP (VIP) for NAT or with a VLAN sub-interface, because both are 'virtual' constructs, but they serve entirely different purposes in the FortiGate architecture.

How to eliminate wrong answers

Option B is wrong because a loopback interface is not used for NAT; virtual IPs (VIPs) or IP pools are used for NAT purposes. Option C is wrong because VLANs are created as sub-interfaces on physical or aggregate interfaces, not on a loopback interface. Option D is wrong because aggregating multiple physical interfaces for increased bandwidth is achieved via Link Aggregation (LAG) or 802.3ad, not a loopback interface.

317
MCQhard

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is an ICMP session with state 01 and expires in 1 second.
B.The session is a UDP session to port 443 and has been active for 3600 seconds.
C.The session is a TCP session to port 443 that has been active for 3600 seconds and will expire in 3599 seconds.
D.The session is a TCP session that has timed out and will be removed in 3599 seconds.
AnswerC

Protocol 6 is TCP, and the filter dport=443 confirms destination port 443. The duration field shows 3600 seconds elapsed, while expire=3599 indicates the session will time out in 3599 seconds, matching the stated interpretation precisely.

Why this answer

The output shows 'proto=6', which is the protocol number for TCP, and 'dport=443' indicates the destination port is HTTPS. The 'duration=3600' means the session has been active for 3600 seconds, and 'expire=3599' means it will expire in 3599 seconds. The 'proto_state=01' is a TCP state code, confirming this is a TCP session.

Exam trap

The trap here is that candidates often confuse protocol numbers (e.g., thinking '6' is UDP or ICMP) or misinterpret 'expire' as the time since expiration rather than the remaining time until expiration.

How to eliminate wrong answers

Option A is wrong because 'proto=6' is TCP, not ICMP (which uses protocol number 1), and 'dport=443' specifies a port, which is not applicable to ICMP. Option B is wrong because 'proto=6' is TCP, not UDP (which uses protocol number 17), and the session is to port 443, not from it. Option D is wrong because the session has not timed out; 'expire=3599' indicates it is still active and will expire in 3599 seconds, not that it has already timed out.

318
MCQeasy

What is the PRIMARY purpose of enabling 'Safe Search' in a web filter profile?

A.To block all search engines
B.To prevent users from using HTTPS search engines
C.To enforce safe search settings on supported search engines like Google and Bing
D.To log all search queries
AnswerC

The core purpose of safe search is to enforce content filtering on supported search engines such as Google and Bing by appending safe search parameters or using DNS-based enforcement. This compels the search engine to omit adult or explicit material from result pages, aligning with an organization's acceptable use policy. FortiGate applies this through firewall policy profiles, ensuring users cannot disable it client-side.

Why this answer

Safe Search enforces the safe search feature of popular search engines (e.g., Google, Bing) to filter explicit content from search results. It does not block search engines or HTTPS.

319
MCQmedium

An admin wants to apply different QoS markings to traffic from two different departments. The admin creates two firewall policies: one for Sales (policy ID 1) and one for Engineering (policy ID 2). Both policies have traffic shaping enabled. However, traffic from both departments receives the same QoS marking. What is the MOST likely mistake?

A.The policies are in the wrong order
B.QoS marking is only applied at the interface level
C.The traffic shaping policy is applied globally
D.The admin applied the same traffic shaper to both policies
AnswerD

When both firewall policies reference the identical traffic-shaper object, the QoS markings and bandwidth parameters applied by that shaper are the same for every matching session. To apply different QoS markings, the administrator must create at least two distinct traffic shapers, or configure separate diffserv/ToS values, and attach the appropriate shaper to each policy. If the shaper is the same in both rules, no amount of policy reordering or interface tweaking will produce separate markings. The correct solution is to give each traffic class its own shaper object so bandwidth allocation and diffserv markings can differ.

Why this answer

If the same traffic shaper is applied to both firewall policies, the QoS marking defined in that shaper will be identical for all matched traffic, regardless of the policy. Each policy must reference a distinct traffic shaper with the desired DSCP or 802.1p marking to differentiate the departments.

Exam trap

The trap here is that candidates assume creating separate firewall policies automatically results in different QoS markings, but they overlook that the traffic shaper itself must be unique and configured with the correct DSCP value for each policy.

How to eliminate wrong answers

Option A is wrong because policy order affects which policy matches first, but both policies are already matching traffic from different departments (Sales and Engineering), so order does not cause identical QoS markings. Option B is wrong because QoS marking in FortiOS can be applied at the firewall policy level via traffic shapers, not only at the interface level; interface-level QoS is for egress queuing, not marking. Option C is wrong because a global traffic shaping policy would apply to all traffic, but the question states both policies have traffic shaping enabled, implying per-policy shapers are used, not a global one.

320
MCQmedium

A network admin configures a firewall policy allowing HTTP traffic from internal users to an external web server. The policy uses a service object 'HTTP' defined as TCP/80. However, users cannot reach the server. What is the MOST likely cause?

A.The external web server is using HTTPS (TCP/443) instead of HTTP
B.The source address object does not include the users' subnet
C.The policy order is wrong; the policy is placed after a deny-all policy
D.The interface is set to the wrong zone
AnswerA

The service object in this policy explicitly allows only TCP port 80 (HTTP). An external web server listening on TCP/443 (HTTPS) will not match this policy; FortiGate implicitly denies all traffic that does not match any explicit policy, so the client's HTTPS request is silently dropped. To permit the traffic, the admin must either change the service object to HTTPS (TCP/443) or create a separate policy with the correct service.

Why this answer

The firewall policy explicitly allows TCP/80 (HTTP), but the external web server is using TCP/443 (HTTPS). Since the service object does not match the actual traffic, the firewall will drop or reject the packets, preventing connectivity. This is a classic service mismatch issue in FortiGate firewall policies.

Exam trap

The trap here is that candidates assume HTTP traffic is always on port 80, but the question deliberately sets up a scenario where the server uses HTTPS (port 443), testing the understanding that firewall policies are port-specific and service objects must match the actual application protocol.

How to eliminate wrong answers

Option B is wrong because the source address object not including the users' subnet would cause a different symptom—traffic from those users would not match the policy at all, but the question states the policy is configured for internal users, implying the source is correct. Option C is wrong because if the policy were placed after a deny-all policy, the traffic would be blocked by the deny-all rule, but the question does not indicate any policy order issue; the problem is specifically about service mismatch. Option D is wrong because an interface set to the wrong zone would prevent the policy from being matched due to zone mismatch, but the question focuses on the service definition, not interface/zone configuration.

321
Multi-Selectmedium

A FortiGate administrator needs to ensure that a specific traffic flow is fully inspected by the antivirus and IPS profiles. The traffic is HTTPS. Which THREE configuration items are required? (Select three.)

Select 3 answers
A.Enable flow-based inspection mode globally
B.Apply an IPS profile to the firewall policy
C.Apply an antivirus profile to the firewall policy
D.Enable SSL/TSL deep inspection on the firewall policy
E.Configure a DNS filter profile
AnswersB, C, D

An IPS profile contains signatures and anomaly detection rules that inspect traffic for known vulnerabilities, exploits, and attack patterns. By applying this profile to the firewall policy, the FortiGate can block malicious packets in real time, which directly addresses the requirement to secure the specific traffic flow. Without the profile, even with flow-based inspection enabled, the device would not have the rulebase to identify intrusion attempts.

Why this answer

Option B is correct because an IPS profile must be attached to the firewall policy for the FortiGate to inspect the traffic flow for intrusions and exploits. Option C is correct because an antivirus profile must also be applied to the firewall policy so that the same traffic is scanned for malware and viruses. Option D is correct because the traffic is HTTPS, so SSL/TLS deep inspection must be enabled on the firewall policy to decrypt the traffic and allow the antivirus and IPS engines to inspect the payload.

Option A is not required because flow-based inspection mode is a global inspection setting and is not a mandatory item for applying antivirus and IPS profiles to a specific HTTPS policy. Option E is not required because a DNS filter profile is used for DNS security filtering and does not enable antivirus or IPS inspection of HTTPS traffic.

Exam trap

NSE4 often tests the misconception that simply applying antivirus and IPS profiles to a policy is enough to inspect HTTPS traffic, but without SSL deep inspection, the FortiGate cannot see inside the encrypted tunnel, so the profiles are ineffective.

322
MCQeasy

A company uses Fortinet Single Sign-On (FSSO) to authenticate users for firewall policies. The FSSO collector agent is installed on a Windows server and configured with Active Directory polling. What does the collector agent do?

A.It acts as a RADIUS proxy between FortiGate and AD
B.It monitors AD logon events and sends user-IP mappings to the FortiGate
C.It polls the FortiGate for user information
D.It directly authenticates users to the FortiGate
AnswerB

The FSSO collector agent polls Active Directory domain controllers for logon events, then forwards the resulting user-to-IP mappings to the FortiGate. This lets firewall policies identify users by IP without requiring them to authenticate directly against the FortiGate.

Why this answer

The FSSO collector agent polls Active Directory for security event logs to detect user logon events. It then maps the logged-on user to their IP address and sends this user-IP mapping to the FortiGate via the FSSO protocol (port 8000). This allows the FortiGate to enforce firewall policies based on user identity without requiring the user to authenticate directly to the FortiGate.

Exam trap

The trap here is that candidates often confuse the collector agent's role with that of a RADIUS server or a direct authentication proxy, but FSSO is purely a passive monitoring mechanism that does not perform authentication itself.

How to eliminate wrong answers

Option A is wrong because the FSSO collector agent does not act as a RADIUS proxy; RADIUS-based authentication is handled by a separate FortiAuthenticator or RADIUS server, not by the collector agent. Option C is wrong because the collector agent does not poll the FortiGate for user information; instead, it pushes user-IP mappings to the FortiGate. Option D is wrong because the collector agent does not directly authenticate users to the FortiGate; it only monitors existing AD logon events and relays the mapping information.

323
MCQeasy

What is the purpose of configuring an NTP server on a FortiGate?

A.To enable time-based firewall policies.
B.To synchronize the FortiGate's system clock with a reliable time source.
C.To allow the FortiGate to act as an NTP server for the network.
D.To authenticate with FortiGuard services.
AnswerB

This is the correct purpose. Configuring an NTP server on a FortiGate makes the firewall synchronize its internal hardware clock with an authoritative time source, ensuring accurate timestamps for logs, VPN certificates, and protocol operations that depend on consistent time. Without reliable synchronization, the system clock can drift, leading to issues such as expired certificates or misleading security logs. NTP is specifically designed to maintain that accuracy automatically and continuously.

Why this answer

Configuring an NTP server on a FortiGate synchronizes the system clock with a reliable time source, which is essential for accurate logging, certificate validation, and time-based operations. While time-based firewall policies depend on an accurate clock, NTP itself is the mechanism to achieve that accuracy, not the policy feature itself.

Exam trap

The trap here is that candidates confuse the purpose of NTP (time synchronization) with the features that depend on accurate time, such as time-based policies or FortiGuard authentication, leading them to select those as the primary purpose.

How to eliminate wrong answers

Option A is wrong because time-based firewall policies are a feature that uses the system clock, but the purpose of NTP configuration is to synchronize that clock, not to directly enable the policies. Option C is wrong because while a FortiGate can be configured as an NTP server for the network, that is an optional role, not the primary purpose of configuring an NTP server on the device. Option D is wrong because FortiGuard services use the system clock for authentication and license validation, but NTP configuration is not a direct authentication method; it merely ensures the clock is accurate for those services.

324
MCQmedium

An administrator needs to upgrade the firmware on a FortiGate from version 6.4.10 to 7.0.1. The device currently runs FortiOS 6.4.10. Which upgrade path should be followed?

A.Downgrade to 6.2.0 then upgrade to 7.0.1
B.Upgrade to 7.0.0 first, then to 7.0.1
C.Upgrade directly from 6.4.10 to 7.0.1 via the GUI
D.Upgrade to 6.4.99 (if exists) then to 7.0.1
AnswerB

FortiGate requires that you first upgrade to the initial release of the target major branch, in this case 7.0.0, before applying the latest patch 7.0.1. The 6.4.x branch and the 7.0.x branch use different configuration database schemas, and 7.0.0 is the only version that performs the required schema migration. Without this intermediate step, the upgrade to 7.0.1 would be rejected by the firmware validation process.

Why this answer

Fortinet requires a sequential upgrade path for major version jumps. FortiOS 6.4.10 can upgrade directly to 7.0.0, and then to 7.0.1, because 7.0.0 is the first release in the 7.0 branch. Upgrading directly from 6.4.10 to 7.0.1 is not supported as it skips the required intermediate version.

Exam trap

The trap here is that candidates assume GUI or direct upgrades are always safe, but Fortinet strictly enforces sequential version upgrades to prevent configuration and system incompatibilities.

How to eliminate wrong answers

Option A is wrong because downgrading to 6.2.0 is unnecessary and not a valid upgrade path; Fortinet does not support downgrading as a step to upgrade. Option C is wrong because upgrading directly from 6.4.10 to 7.0.1 via the GUI is not supported; the upgrade must go through 7.0.0 first. Option D is wrong because 6.4.99 does not exist as a release; Fortinet uses specific build numbers, not arbitrary patch versions, and the correct intermediate is 7.0.0.

325
Multi-Selectmedium

A FortiGate administrator is troubleshooting a traffic issue where users cannot access a specific website. The administrator runs 'diagnose debug flow' and sees the output indicating that traffic is being denied by a firewall policy. Which two actions should the administrator take to identify the specific policy denying the traffic? (Choose two.)

Select 2 answers
A.Run 'diagnose debug enable' and then reproduce the issue
B.Use 'diagnose sys session list' to find the policy ID
C.Review the policy list and look for the policy ID shown in the debug output
D.Check the traffic log for the session to see the policy ID
E.Disable all firewall policies temporarily
AnswersC, D

When you run 'diagnose debug flow', the output includes a log line that states the matching policy ID, for example "op=... policyid=..." for each packet. By reviewing the firewall policy list and looking up that specific policy ID, the administrator can directly inspect the action, schedule, source/destination addresses, and services configured on that policy to determine why it is handling the traffic unexpectedly.

Why this answer

Option C is correct because the 'diagnose debug flow' output explicitly prints the policy ID (e.g., 'matched policy 5') that denied the traffic, so reviewing the firewall policy list for that ID pinpoints the exact offending policy. Option D is correct because FortiGate traffic logs record the policy ID (policyid) for each session, so checking the log entry for the denied session reveals the same policy identifier and confirms which rule blocked the traffic. Option A is not the right action because 'diagnose debug enable' only turns on debug output; it does not itself identify the policy, and the administrator has already captured the flow output.

Option B is incorrect because 'diagnose sys session list' shows session details such as source/destination and state, but it does not reliably surface the denying policy ID for a denied flow. Option E is incorrect and dangerous because disabling all firewall policies would remove security enforcement and is not a valid troubleshooting step.

Exam trap

NSE4 often tests whether candidates know that debug flow output itself contains the policy ID, so they waste time on session list or disabling policies instead of reading the trace and correlating with logs.

326
MCQmedium

An administrator wants to send FortiGate logs to a FortiAnalyzer for centralized logging and reporting. Which configuration step is required on the FortiGate?

A.Enable SNMP traps to the FortiAnalyzer
B.Create a firewall policy to allow traffic to the FortiAnalyzer
C.Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding
D.Configure a syslog server under System > Settings
AnswerC

This is the correct action because FortiGate has dedicated integration settings for FortiAnalyzer under the Log & Report menu (often System > Log & Report > FortiAnalyzer). Here, you enter the FortiAnalyzer IP/FQDN and serial number, and then enable log sending/archiving for specific log types (e.g., traffic, event). Once configured, FortiGate uses the FGFM (FortiGate-to-FortiAnalyzer) protocol to securely and reliably forward logs, including buffering and retransmission. This is the intended mechanism for centralized logging on FortiAnalyzer, so this option precisely addresses the administrator's goal.

Why this answer

FortiGate uses the Log & Report section to configure FortiAnalyzer settings, specifically under 'Log Settings' or 'Log Forwarding'. This enables the FortiGate to forward logs to a FortiAnalyzer device for centralized logging and reporting, using the FortiGate-FortiAnalyzer protocol (based on syslog over TCP with Fortinet extensions).

Exam trap

The trap here is that candidates often confuse the generic syslog server configuration (Option D) with the FortiAnalyzer-specific log forwarding setup, or they mistakenly think a firewall policy (Option B) is the primary step rather than the log forwarding configuration itself.

How to eliminate wrong answers

Option A is wrong because SNMP traps are used for sending network management alerts (e.g., interface down) to an SNMP manager, not for forwarding logs to FortiAnalyzer. Option B is wrong because while a firewall policy may be needed to allow outbound traffic to the FortiAnalyzer IP, it is not the primary configuration step for log forwarding; the log forwarding settings themselves are configured under Log & Report. Option D is wrong because configuring a syslog server under System > Settings is for sending logs to a generic syslog server, not for the FortiAnalyzer-specific integration which requires the dedicated FortiAnalyzer configuration under Log & Report.

327
MCQmedium

An administrator creates a firewall policy to allow outbound HTTP and HTTPS traffic from the internal network to the internet. The policy uses a dynamic IP pool for SNAT. Users report that some websites load slowly or fail to load intermittently. The administrator checks the firewall logs and sees 'session helper' warnings. What is the most likely cause?

A.The policy has traffic shaping enabled that is throttling the bandwidth
B.The firewall policy is configured for proxy-based inspection, causing high latency
C.The IP pool is configured with fixed port range, limiting the number of available ports
D.The DNS server on the internal network is misconfigured
AnswerC

A fixed port range in an IP pool restricts the translated source ports to a narrow set, such as 1024–2048, drastically capping the number of concurrent NAT sessions per pool address. Once those ports are exhausted, new outbound connections fail intermittently until old sessions time out, exactly matching the reported symptoms. Session helper warnings, such as for FTP or ICMP, appear because the helper cannot allocate a NAT port for the associated data channel, confirming that the IP pool port configuration is the root cause.

Why this answer

The 'session helper' warnings indicate that the firewall is struggling to allocate NAT sessions for the dynamic IP pool. When the IP pool uses a fixed port range, the number of available source ports per IP is limited, leading to port exhaustion under heavy HTTP/HTTPS traffic. This causes intermittent failures and slow loads as new connections are dropped or queued.

Exam trap

The trap here is that candidates confuse 'session helper' warnings with application-layer issues (like proxy latency or DNS) instead of recognizing it as a NAT resource exhaustion symptom tied to port range limitations in the IP pool configuration.

How to eliminate wrong answers

Option A is wrong because traffic shaping throttles bandwidth but does not generate 'session helper' warnings; those are related to NAT resource exhaustion, not rate limiting. Option B is wrong because proxy-based inspection can add latency but would not cause intermittent failures tied to port availability; 'session helper' warnings are specific to NAT session allocation, not inspection mode. Option D is wrong because a misconfigured DNS server would cause consistent name resolution failures, not intermittent loading issues with 'session helper' warnings in the firewall logs.

328
MCQmedium

An administrator notices that the FortiGate HA cluster has two units, but only one is shown as 'primary' and the other as 'standby'. The administrator did not configure any load balancing. Which HA mode is in use?

A.Active-passive
B.Load-balanced cluster
C.Standalone
D.Active-active
AnswerA

Active-passive is the standard FortiGate HA mode in which one cluster unit holds the primary/active role and processes all production traffic, while the second unit remains in standby, synchronizing configuration and (if session pickup is enabled) session state via the dedicated HA heartbeat link. When the active unit fails or loses heartbeats, the standby unit is promoted to active and takes over the virtual cluster interfaces, providing transparent failover with minimal disruption.

Why this answer

In active-passive HA mode, one FortiGate unit is the primary (active) and the other is the standby (passive), with no traffic load balancing between them. The scenario describes exactly one primary and one standby with no load balancing configured, which matches active-passive. Active-active would show both units processing traffic, and load-balanced cluster is not a FortiGate HA mode.

Exam trap

NSE4 often tests the visual signature of HA modes — one primary plus one standby equals active-passive — so candidates confuse it with active-active or invent a 'load-balanced' mode that does not exist.

How to eliminate wrong answers

Option B is wrong because 'load-balanced cluster' is not a valid FortiGate HA mode; FortiGate HA modes are active-passive and active-active. Option C is wrong because standalone means a single FortiGate with no HA cluster at all, which contradicts the presence of two units in a cluster. Option D is wrong because active-active HA would show both units actively processing traffic (often with session distribution), not one primary and one standby.

329
Multi-Selectmedium

A network administrator is configuring SNMP on a FortiGate for monitoring. Which three pieces of information are required to complete the SNMPv2c configuration? (Choose THREE.)

Select 3 answers
A.SNMPv3 authentication protocol (MD5/SHA)
B.SNMP manager IP address (allowed hosts)
C.SNMP trap receiver IP and community
D.SNMP community string
E.SNMP interface (the interface that will respond to SNMP queries)
AnswersB, D, E

The SNMP manager IP address (allowed hosts) is a mandatory access-control parameter in FortiGate's SNMP configuration. Without it, the SNMP agent will not accept queries from any network management station, effectively disabling polling. Specifying the NMS IP restricts SNMP access to authorized management systems, ensuring that only the intended server can read the device's MIB data.

Why this answer

SNMPv2c uses community-based security, so the SNMP community string (Option D) is required for authentication. The SNMP manager IP address (Option B) is needed to define which hosts are allowed to query the FortiGate. The SNMP interface (Option E) specifies which network interface will listen for and respond to SNMP queries.

These three pieces are mandatory for SNMPv2c configuration on a FortiGate.

Exam trap

The trap here is that candidates often confuse SNMPv2c requirements with SNMPv3 requirements, selecting authentication protocols (Option A) which are irrelevant for v2c, or they assume trap configuration is mandatory for basic monitoring, when it is actually optional.

330
MCQeasy

Which IPS detection method uses a baseline of normal traffic and alerts when deviations exceed a threshold?

A.Anomaly detection
B.Rate-based detection
C.Signature-based detection
D.Protocol decode-based detection
AnswerA

Anomaly detection is the IPS technique that builds a statistical or machine-learning baseline of 'normal' network behavior by observing traffic patterns over time, including metrics like packet sizes, protocols, and session flows. Once the baseline is established, any significant deviation from that learned profile is flagged as an anomaly, potentially indicating a zero-day exploit or insider threat. This is the only method listed that fundamentally depends on a baseline of normal traffic to operate.

Why this answer

Anomaly detection establishes a baseline of normal network traffic patterns and triggers alerts when observed traffic deviates significantly from that baseline. This method is effective for identifying unknown or zero-day attacks that do not match predefined signatures, as it relies on statistical or behavioral analysis rather than fixed patterns.

Exam trap

The trap here is that candidates often confuse rate-based detection with anomaly detection, but rate-based detection uses fixed or adaptive thresholds on event counts (e.g., SYN flood rate) rather than a learned baseline of normal traffic behavior.

How to eliminate wrong answers

Option B (Rate-based detection) is wrong because it monitors the frequency of specific events (e.g., connection attempts per second) and triggers when a threshold is exceeded, but it does not establish a baseline of normal traffic; it uses static or dynamic rate limits. Option C (Signature-based detection) is wrong because it compares traffic against predefined patterns or signatures of known attacks, not against a baseline of normal behavior. Option D (Protocol decode-based detection) is wrong because it analyzes protocol compliance and anomalies within protocol fields (e.g., malformed packets), but it does not learn normal traffic patterns over time.

331
MCQeasy

A FortiGate administrator needs to check the current HA status of a two-unit cluster. The administrator wants to see which unit is the primary, the HA mode, and the uptime of each unit. Which command should the administrator use?

A.diagnose sys ha status
B.show system ha
C.diagnose sys ha checksum
D.get system ha status
AnswerA

The 'diagnose sys ha status' command displays detailed HA status information, including the current primary unit, HA mode, cluster uptime, and the status of each member. It is the correct command to quickly assess the HA cluster's health and roles. This command is commonly used for troubleshooting and verification.

Why this answer

To view the current HA status, including which unit is primary, the HA mode, and uptime, the administrator should use 'diagnose sys ha status'. This command provides a comprehensive overview of the cluster's operational state and is the standard tool for HA monitoring and troubleshooting.

Exam trap

The trap here is confusing configuration commands like 'show system ha' with status commands; 'show' displays settings, while 'diagnose sys ha status' reveals real-time operational status.

332
MCQmedium

An administrator wants to upgrade the FortiGate firmware from version 6.4.9 to 7.0.1. What is the most important consideration before proceeding?

A.Verify the upgrade path and check for any required intermediate versions
B.Upgrade to the latest 7.0.x directly without intermediate steps
C.Disable all firewall policies before upgrading
D.Ensure the configuration is backed up
AnswerA

Fortinet only guarantees a clean upgrade when you follow the documented firmware upgrade path from your current version to the target release. Intermediate versions are often mandatory because each major release can change the configuration schema, firewall object syntax, and internal database structure; skipping them can cause the upgrade to abort or produce corrupt settings. The correct first step is always to consult the FortiOS Upgrade Path tool and the release notes to identify any required stepping stones before attempting the move.

Why this answer

FortiGate firmware upgrades must follow a validated upgrade path to avoid configuration incompatibilities or boot failures. Version 6.4.9 to 7.0.1 requires an intermediate upgrade to 7.0.0 first, as direct jumps across major versions or skipping required intermediate releases can corrupt the firmware image or render the device unbootable. Fortinet publishes explicit upgrade paths in the release notes, and ignoring them is the most common cause of failed upgrades.

Exam trap

The trap here is that candidates assume a configuration backup is the most critical step, but Fortinet specifically tests that verifying the upgrade path is the primary consideration to prevent a non-bootable device.

How to eliminate wrong answers

Option B is wrong because upgrading directly to the latest 7.0.x without intermediate steps violates Fortinet's required upgrade path; 6.4.9 must first go to 7.0.0 before reaching 7.0.1. Option C is wrong because disabling firewall policies is not a prerequisite for firmware upgrades; the upgrade process preserves the configuration, and policies remain intact. Option D is wrong because while backing up the configuration is a best practice, it is not the most important consideration; the upgrade path is critical to avoid a bricked device, whereas a backup only protects against data loss after a failure.

333
MCQeasy

Which of the following best describes the function of FortiGuard web filtering categories?

A.They are used to quarantine infected files
B.They block specific IP addresses known for hosting malware
C.They provide a list of allowed websites only
D.They categorize websites to allow granular control over access based on content type
AnswerD

FortiGuard web-filtering categories assign websites to taxonomy classes, such as 'Social Networking', 'Video/Audio', and 'Webmail', based on the site's actual content. This allows FortiGate administrators to construct IPv4/IPv6 firewall policies and proxy policies that permit or deny entire content categories, optionally with per-user or per-time overrides. Because the categorization is content-driven, it enables fine-grained access control that adapts to the constantly changing web rather than relying on a simple list of URLs.

Why this answer

FortiGuard web filtering categories are pre-classified buckets (e.g., Social Networking, Malware, Phishing, Streaming Media) that map URLs/domains to content types. Administrators use these categories in web filter profiles to allow, block, monitor, or warn on entire classes of sites, giving granular, policy-driven control without maintaining manual URL lists. This is the core function of the FortiGuard category database.

Exam trap

The trap is conflating web filtering categories with other security profiles — candidates often pick 'block specific IPs' or 'quarantine files' because those sound like security functions, but categories are strictly about content classification for access control.

How to eliminate wrong answers

Option A is wrong because quarantining infected files is the job of the antivirus profile (or sandboxing), not web filtering categories. Option B is wrong because blocking specific malicious IPs is handled by IP reputation/blocklists or DNS filter, not by URL content categories. Option C is wrong because FortiGuard categories classify both allowed and blocked content — they are not an allow-list-only mechanism; the admin decides the action per category.

334
Matchingmedium

Match each Fortinet product to its primary role.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Next-generation firewall

Security information and event management

Centralized logging and analytics

Centralized management and policy orchestration

Advanced threat detection and analysis

Why these pairings

FortiGate is the NGFW, FortiManager handles centralized management, FortiAnalyzer provides logging/reporting, and FortiSandbox performs advanced threat detection. Common confusions include swapping management with firewall roles or logging with threat detection.

335
MCQhard

An administrator runs 'diagnose vpn ssl stat' and sees 'tun-num: 5, clients: 0'. Users are unable to connect to the SSL VPN. The SSL VPN settings are correct and the certificate is valid. What could be the cause?

A.The FortiGate has reached the maximum number of SSL VPN users allowed by the license
B.The SSL VPN is listening on a non-default port and users are connecting to the default port
C.The SSL VPN certificate is not trusted by the client browsers
D.The SSL VPN portal is configured with 'limit-scan' scanning
AnswerB

The FortiGate's SSL VPN listening port is configured under `config vpn ssl settings` and defaults to 443. If it has been changed to a non-standard port like 10443, client connections attempting to reach 443 will not be accepted by the SSL VPN service, resulting in no established sessions. Thus `diagnose vpn ssl stat` correctly displays zero active tunnels because the clients are connecting to the wrong port and never complete the handshake.

Why this answer

The 'tun-num: 5, clients: 0' output indicates that the SSL VPN tunnel interface is up but no clients are connected. If the SSL VPN settings and certificate are correct, the most likely cause is a port mismatch: the FortiGate is configured to listen on a non-default port (e.g., 10443), but users are attempting to connect to the default SSL VPN port (443). This prevents the SSL handshake from completing, resulting in zero active clients.

Exam trap

The trap here is that candidates assume 'tun-num: 5, clients: 0' indicates a licensing or certificate issue, but the key diagnostic clue is that the tunnel interface exists (meaning the service is running) yet no clients are connected, pointing to a connectivity or port mismatch rather than a resource or authentication problem.

How to eliminate wrong answers

Option A is wrong because if the license limit were reached, 'clients: 0' would not appear; instead, the output would show a count equal to the maximum allowed, and users would receive a license limit error. Option C is wrong because an untrusted certificate would still allow a connection attempt (with a browser warning), and the 'clients' count would increment as the SSL handshake begins; the issue here is zero clients, not a certificate trust problem. Option D is wrong because 'limit-scan' is a web filtering feature that controls scanning of web content, not a parameter that blocks SSL VPN connections; it has no effect on the SSL VPN tunnel establishment.

336
Multi-Selectmedium

An administrator wants to implement ZTNA (Zero Trust Network Access) on a FortiGate to secure access to an internal application. Which TWO components are essential for a ZTNA configuration?

Select 2 answers
A.A firewall policy using IPsec VPN
B.A FortiGate in transparent mode
C.A policy-based IPsec tunnel
D.A proxy-based firewall policy
E.A ZTNA rule that verifies endpoint identity and posture
AnswersD, E

ZTNA on FortiGate requires a proxy-based firewall policy, because the FortiGate must terminate and inspect the session to enforce per-application access rather than forwarding packets at layer 3/4. This satisfies the scenario's need to secure access to a specific internal application.

Why this answer

Option D is correct because ZTNA on FortiGate requires a proxy-based firewall policy, which enables full inspection of the traffic and allows the FortiGate to enforce ZTNA access control for the internal application. Option E is correct because the ZTNA rule is the core enforcement component that verifies the endpoint's identity and posture (via FortiClient EMS tags) before granting access to the protected resource. Options A and C are incorrect because ZTNA does not rely on IPsec VPN or policy-based IPsec tunnels; it uses a client-based access proxy model instead of traditional tunnel-based remote access.

Option B is incorrect because transparent mode is not an essential requirement for ZTNA; ZTNA can be deployed on a FortiGate in NAT/route mode as well.

Exam trap

The trap here is confusing ZTNA's proxy-based architecture with VPN-based access, leading candidates to incorrectly select IPsec or policy-based tunnel options, when ZTNA actually requires a proxy firewall policy and a separate ZTNA rule for endpoint verification.

337
Multi-Selecthard

An administrator receives alerts about a possible data breach. Sensitive data (credit card numbers) might be leaving the network via email. The admin wants to detect and block such emails. Which THREE security profiles should be combined?

Select 3 answers
A.Web filter profile
B.SSL deep inspection profile
C.Email filter profile
D.Data leak prevention (DLP) profile
E.Antivirus profile
AnswersB, C, D

The SSL deep inspection profile performs full TLS/SSL decryption and re-encryption, using a FortiGate-issued CA certificate to terminate the client connection and then open a new secure connection to the server. This decrypted traffic is then fed to other UTM profiles—email filter, DLP, antivirus—so they can see the actual payload. Without this profile, any encrypted SMTP/IMAPS/webmail traffic remains opaque, and data exfiltration could pass undetected. In the context of an email-related breach alert, this is the enabling profile that makes content inspection possible.

Why this answer

B is correct because SSL deep inspection is required to decrypt SSL/TLS-encrypted email traffic (e.g., SMTP over TLS) so that the FortiGate can inspect the content for sensitive data like credit card numbers. Without decryption, the DLP and email filter profiles cannot see the payload of encrypted emails, rendering them ineffective.

Exam trap

The trap here is that candidates often forget that encrypted email traffic (e.g., Gmail, Office 365) requires SSL deep inspection to be decrypted before DLP and email filtering can work, leading them to incorrectly omit the SSL deep inspection profile.

338
MCQmedium

An administrator wants to block users from uploading sensitive documents through webmail. Which security profile should be configured on the FortiGate to achieve this goal?

A.Data Leak Prevention (DLP)
B.Antivirus
C.Application control
D.Web filter
AnswerA

DLP (Data Leak Prevention) profiles in FortiOS inspect traffic content, not just metadata. It can match file content against predefined or custom sensitive data patterns (e.g., credit card numbers or confidential labels like 'INTERNAL ONLY') using full-content scanning. When a match occurs, the firewall can block the upload, log it, and optionally send a notification. Unlike antivirus or web filter, DLP operates at the content-inspection layer of the proxy and can be applied to HTTP/HTTPS, FTP, and email protocols, making it the appropriate choice for preventing sensitive-data exfiltration via uploads.

Why this answer

Data Leak Prevention (DLP) is the correct security profile because it is specifically designed to inspect content (e.g., file names, patterns, or keywords) in traffic such as webmail uploads and block sensitive data from leaving the network. DLP sensors can be configured with rules to match patterns like credit card numbers, social security numbers, or custom keywords, and then take action such as blocking or logging the session.

Exam trap

The trap here is that candidates may confuse the function of DLP with web filtering or application control, thinking that blocking the webmail application entirely is equivalent to preventing data leaks, when in fact DLP is the only profile that inspects the actual content being transmitted.

How to eliminate wrong answers

Option B (Antivirus) is wrong because it focuses on detecting and blocking malware based on signatures, not on inspecting content for sensitive data patterns. Option C (Application control) is wrong because it identifies and controls applications (e.g., blocking webmail entirely) but does not inspect the actual data payload for sensitive content. Option D (Web filter) is wrong because it controls access to websites based on categories or URLs, not the content within uploaded files or messages.

339
Multi-Selecthard

An admin wants to ensure that traffic between two internal subnets (10.0.1.0/24 and 10.0.2.0/24) is inspected by the FortiGate but does not have its source IP translated. Which THREE configuration elements are required? (Choose three.)

Select 3 answers
A.NAT disabled on that policy
B.A static route for each subnet on the FortiGate
C.An IP pool for source NAT
D.A firewall policy allowing traffic between the two subnets
E.Security profiles (e.g., antivirus, IPS) applied to the policy
AnswersA, D, E

To preserve the original source IP of internal hosts when routing between subnets, the firewall policy must have NAT explicitly disabled. With NAT enabled, FortiGate would translate the source address to its own egress interface IP, which breaks end-to-end visibility, compromises logging, and can break return routing when the destination subnet has specifically crafted routes back to the real host address.

Why this answer

When traffic between two internal subnets does not require source IP translation, NAT must be explicitly disabled on the firewall policy. By default, FortiGate policies may have NAT enabled (especially on outbound interfaces), so disabling NAT ensures the original source IP (10.0.1.x) is preserved when communicating with 10.0.2.x. This is configured by setting the 'set nat enable' option to 'disable' in the policy or unchecking NAT in the GUI.

Exam trap

The trap here is that candidates often assume static routes are always needed for inter-subnet routing, but FortiGate automatically creates connected routes for directly attached subnets, making static routes unnecessary in this scenario.

340
MCQeasy

Which address object type allows you to match traffic based on the domain name in the HTTPS SNI field?

A.Geography
B.Wildcard FQDN
C.Subnet
D.FQDN
AnswerB

A Wildcard FQDN object, such as *.example.com, matches domain names using a pattern and can be compared against the Server Name Indication (SNI) field in TLS handshakes. This allows FortiGate to filter traffic based on the domain name a client requests before the connection is decrypted. It is the only address object type among these options that natively supports SNI matching, making it the correct answer when domain-based traffic identification is needed.

Why this answer

The Wildcard FQDN address object type in FortiGate allows you to match traffic based on the domain name in the HTTPS Server Name Indication (SNI) field. Unlike a standard FQDN, which matches the exact domain, the Wildcard FQDN supports patterns like *.example.com, enabling policy enforcement for subdomains and dynamic hostnames within a domain.

Exam trap

The trap here is that candidates often confuse Wildcard FQDN with standard FQDN, assuming both can match subdomains, but only Wildcard FQDN supports the asterisk (*) wildcard for pattern matching in the SNI field.

How to eliminate wrong answers

Option A (Geography) is wrong because Geography objects match traffic based on the source or destination IP address's geolocation, not the domain name in the SNI field. Option C (Subnet) is wrong because Subnet objects match traffic based on IP address ranges, not domain names or SNI fields. Option D (FQDN) is wrong because a standard FQDN object matches the exact domain name in the SNI field but does not support wildcard patterns, making it unsuitable for matching subdomains or variable hostnames.

341
MCQeasy

What is the order of evaluation for firewall policies on a FortiGate?

A.Random order
B.From bottom to top
C.From top to bottom, first match
D.By policy ID in ascending order
AnswerC

FortiGate evaluates policies sequentially from the first entry in the policy table downwards, applying the first policy whose source, destination, service and schedule criteria match the packet; subsequent policies are never consulted once a match occurs.

Why this answer

FortiGate firewall policies are evaluated sequentially from the top of the policy list downward. The first policy that matches the traffic's source, destination, service, and schedule is applied, and no further policies are checked. This top-down, first-match behavior ensures deterministic traffic handling and is fundamental to FortiGate's policy-based architecture.

Exam trap

The trap here is that candidates often confuse policy ID with evaluation order, assuming policies are processed by ascending ID, but FortiGate evaluates based on the visual list order, which can be manually rearranged independently of the ID numbers.

How to eliminate wrong answers

Option A is wrong because FortiGate does not evaluate policies in random order; it uses a deterministic sequential evaluation from top to bottom. Option B is wrong because policies are evaluated from top to bottom, not bottom to top; a bottom-to-top order would reverse the intended priority and is not how FortiGate processes policies. Option D is wrong because while policy IDs are assigned sequentially, evaluation order is determined by the policy's position in the list (which can be rearranged), not by the numeric ID; reordering policies changes evaluation order independently of their IDs.

342
MCQeasy

A FortiGate policy allows traffic from the internal network to a DMZ server. The admin wants to limit access to only specific hours. Which object type should be used in the policy?

A.Address group
B.Schedule
C.Service group
D.Traffic shaper
AnswerB

Schedule is correct because FortiGate uses schedule objects (one-time or recurring) to define when a policy is permitted to match traffic. The policy's schedule field is evaluated during the lookup process; if the current time is outside the defined start/end and day-of-week parameters, the policy is skipped and traffic is compared against subsequent rules. This provides precise control over business hours, maintenance windows, or one-off events.

Why this answer

A schedule object is the correct choice because it defines time-based conditions (e.g., specific hours, days, or recurring intervals) that FortiGate applies to firewall policies. By attaching a schedule to a policy, the admin can restrict traffic to the DMZ server only during the permitted hours, such as business hours or maintenance windows.

Exam trap

The trap here is that candidates often confuse a schedule with a service group, thinking they can restrict time by limiting port availability, but FortiGate requires a dedicated schedule object for time-based policy enforcement.

How to eliminate wrong answers

Option A is wrong because an address group groups multiple IP addresses or subnets for source/destination matching, not time-based access control. Option C is wrong because a service group aggregates protocols and ports (e.g., TCP/80, UDP/53) for application filtering, not time restrictions. Option D is wrong because a traffic shaper controls bandwidth allocation and QoS, not temporal access limits.

343
MCQeasy

Which of the following best describes the purpose of a captive portal on a FortiGate?

A.To provide secure remote access to internal resources
B.To authenticate users before granting network access
C.To encrypt traffic between sites
D.To block malware from entering the network
AnswerB

A captive portal intercepts HTTP/HTTPS sessions and redirects unauthenticated clients to a login page, so credentials are verified before any traffic is permitted through the FortiGate. This enforces the pre-access authentication constraint in the stem rather than merely logging or filtering traffic.

Why this answer

A captive portal on a FortiGate intercepts HTTP/HTTPS traffic from unauthenticated users and redirects them to a web-based login page. Once the user provides valid credentials (e.g., via local database, LDAP, or RADIUS), the FortiGate creates an authenticated session, allowing network access. This is a core mechanism for guest Wi-Fi or BYOD onboarding, not for remote access or encryption.

Exam trap

The trap here is that candidates confuse captive portal with SSL VPN or IPsec VPN, thinking it provides remote access or encryption, when in fact it only performs local network access authentication and does not create a secure tunnel.

How to eliminate wrong answers

Option A is wrong because secure remote access to internal resources is provided by IPsec VPN or SSL VPN (e.g., FortiClient), not by a captive portal which only authenticates users at the network edge. Option C is wrong because encrypting traffic between sites is the function of IPsec VPN tunnels or ADVPN, not a captive portal which does not perform any encryption. Option D is wrong because blocking malware is handled by FortiGate's antivirus, IPS, and web filtering engines, not by a captive portal which focuses solely on user authentication before granting network access.

344
MCQmedium

A FortiGate administrator notices that the device's disk usage is critically high, causing logging failures. The administrator wants to free up space without losing important logs. Which action should be taken first?

A.Delete all existing log files
B.Configure log compression
C.Disable logging to the local disk
D.Increase the disk retention period
AnswerB

Configuring log compression on a FortiGate (typically using gzip) reduces the on-disk footprint of stored logs without removing any data, preserving full log fidelity for later analysis. This non-destructive approach directly addresses disk-full pressure by shrinking existing and future log files, and it can be combined with retention policies to keep more history within the same space.

Why this answer

Log compression reduces the size of existing log files on the disk without deleting any data, directly addressing the critically high disk usage while preserving all important logs. This is the safest first step because it reclaims space immediately without risking data loss or altering logging behavior.

Exam trap

The trap here is that candidates may confuse 'increasing retention period' (which makes the problem worse) with 'decreasing retention period' (which would free space but delete logs), or they may think disabling logging is a quick fix without realizing it stops all logging activity.

How to eliminate wrong answers

Option A is wrong because deleting all existing log files would permanently remove important logs, which contradicts the requirement to not lose them. Option C is wrong because disabling logging to the local disk would stop all future logging to the device, potentially losing critical security events, and does not free up space already used. Option D is wrong because increasing the disk retention period would actually cause logs to be kept longer, worsening the disk usage problem rather than solving it.

345
MCQeasy

Refer to the exhibit. An administrator has created an IPS sensor with two entries. The first entry sets severity 'medium' and action 'block'. The second entry sets severity 'critical' and action 'block'. What will happen when a packet triggers an IPS signature with severity 'low'?

A.The packet will be allowed (pass).
B.The packet will be logged and a session will be created.
C.The packet will be blocked if the signature severity is 'low' or 'high'.
D.The packet will be blocked because the sensor is enabled.
AnswerA

Because this packet triggers no signature that has been explicitly configured with a drop, reset, or reject action, the IPS sensor applies its default pass behavior. The configured sensor only overrides the default for the specific signatures listed; all other traffic, including this packet, is allowed to proceed unmodified. IPS inspection does not preemptively block traffic; blocking requires a matching signature entry with a destructive action.

Why this answer

The IPS sensor in the exhibit defines rules only for severity 'medium' and 'critical', both with action 'block'. When a packet triggers a signature with severity 'low', it does not match any entry in the sensor. Therefore, the default action for unmatched signatures is to allow (pass) the traffic.

FortiGate IPS sensors apply actions only to explicitly configured severity levels; unlisted severities are not affected.

Exam trap

The trap here is that candidates assume an enabled IPS sensor blocks all traffic by default, but FortiGate IPS sensors only apply actions to signatures whose severity is explicitly listed in the sensor entries.

How to eliminate wrong answers

Option B is wrong because logging and session creation are not automatic for unmatched severity levels; they only occur if the sensor entry specifies 'log' or if the signature action is triggered. Option C is wrong because the sensor does not block 'low' severity signatures, and 'high' severity is not even listed in the sensor entries. Option D is wrong because simply enabling the sensor does not block all traffic; blocking only happens for signatures that match an entry with a 'block' action.

346
MCQhard

A FortiGate is configured with an IPS profile that includes a signature with a 'Pass' action. The firewall policy uses this IPS profile. What will happen when traffic matching that signature is detected?

A.The traffic is allowed, but the session is reset
B.The traffic is allowed without logging
C.The traffic is blocked and logged
D.The traffic is blocked and the session is reset
AnswerB

With the 'pass' action, the packet is allowed to continue to its destination and, by default, no log message is generated for the signature match. In FortiOS, logging for a pass action requires explicitly enabling the 'Log' toggle on the IPS rule or profile; otherwise the event is silently permitted. This makes 'allowed without logging' the correct outcome for a pass-only IPS profile.

Why this answer

When a signature with a 'Pass' action is triggered in an IPS profile applied to a firewall policy, FortiGate allows the traffic to pass through without any further inspection or logging for that specific signature. The 'Pass' action explicitly overrides the default IPS behavior, meaning the traffic is permitted and no log entry is generated for that signature match, as logging is only performed when the action is set to 'Block' or 'Reset'.

Exam trap

The trap here is that candidates often assume any IPS signature match will always generate a log entry or block traffic, but the 'Pass' action explicitly allows traffic and suppresses logging unless configured otherwise.

How to eliminate wrong answers

Option A is wrong because the 'Pass' action does not reset the session; resetting the session is associated with the 'Reset' action, not 'Pass'. Option C is wrong because the 'Pass' action allows traffic, not blocks it, and logging is not performed for 'Pass' actions unless explicitly configured with a separate log setting. Option D is wrong because the 'Pass' action neither blocks traffic nor resets the session; blocking and resetting are behaviors of 'Block' or 'Reset' actions.

347
MCQhard

An administrator configures a FortiGate in transparent mode to be deployed between a router and a switch. After installation, traffic passes through but the administrator cannot access the FortiGate's management IP from the management network. What is the MOST likely reason?

A.The management IP is not in the same subnet as the management network.
B.Transparent mode does not support management access; only NAT/Route mode does.
C.The FortiGate's firewall policy blocks management traffic even in transparent mode.
D.The administrator must configure a management VLAN interface to access the FortiGate.
AnswerA

In transparent mode, the FortiGate operates as a layer 2 bridge and uses a dedicated management IP for administrative access. This management IP must belong to the same subnet as the directly connected management network, because the FortiGate resolves the management destination via ARP and does not route management traffic without a routed interface. If the management IP is in a different subnet, the FortiGate cannot respond to ARP requests or forward management packets, making it unreachable. Therefore, the administrator's incorrect subnet selection prevents any management connection.

Why this answer

In transparent mode, the FortiGate acts as a Layer 2 bridge, and its management IP must belong to the same subnet as the management network to be reachable. If the management IP is on a different subnet, the FortiGate will not respond to management traffic because it does not route between subnets in transparent mode; it only forwards traffic at Layer 2.

Exam trap

The trap here is that candidates often assume transparent mode disables all management access or requires special VLANs, when the real issue is simply a subnet mismatch between the management IP and the management network.

How to eliminate wrong answers

Option B is wrong because transparent mode fully supports management access via a dedicated management IP, just like NAT/Route mode, though the IP is used for management only and not for routing. Option C is wrong because by default in transparent mode, there is no firewall policy blocking management traffic; management access is controlled by administrative access settings (e.g., HTTPS, SSH) on the management interface, not by firewall policies. Option D is wrong because a management VLAN interface is not required; the administrator can assign a management IP directly to the FortiGate's management interface (e.g., the internal interface) as long as it is on the same subnet as the management network.

348
MCQmedium

A company uses FSSO (Fortinet Single Sign-On) with a domain controller. Users authenticate to the domain, and the FortiGate retrieves the login events. The firewall policy uses the FSSO group. Some users report that after logging in, they cannot access resources that require authentication. The administrator checks the FSSO status and sees that the FortiGate is receiving login events. What is the most likely cause?

A.The user is not a member of the FSSO group
B.The FSSO collector agent is not running
C.The user's IP address is not in the source address range of the policy
D.The FortiGate is not polling the domain controller
AnswerC

FSSO authenticates the user and populates the group, but the firewall policy still matches on source address; if the workstation's IP falls outside that range, the policy never applies and traffic is denied. This satisfies the stem's symptom of successful login events yet blocked access.

Why this answer

Even though the FortiGate is receiving FSSO login events, the firewall policy also includes a source address restriction. If the user's IP address falls outside the defined source address range, the policy will not match, and the user will be denied access despite being authenticated via FSSO. The FSSO group membership is only one condition; the source IP must also satisfy the policy's source address criteria.

Exam trap

The trap here is that candidates assume receiving FSSO login events guarantees policy match, ignoring that the source address condition in the firewall policy is a separate, independent requirement that must also be satisfied.

How to eliminate wrong answers

Option A is wrong because if the user were not a member of the FSSO group, the FortiGate would not show the user as authenticated, and the administrator would not see the user's login events in the FSSO status. Option B is wrong because the FSSO collector agent is confirmed to be running since the FortiGate is receiving login events; a stopped collector agent would prevent event reception. Option D is wrong because the FortiGate is already receiving login events, which proves it is successfully polling or receiving data from the domain controller; if polling were failing, no events would appear.

349
MCQhard

An administrator has configured a firewall policy with a destination NAT (DNAT) VIP to map public IP 203.0.113.5 to internal server 10.10.10.20 on port 443. The policy allows HTTPS traffic from the internet to the VIP. However, when testing from an internal client on the same subnet as the server, the connection to 203.0.113.5 fails. What is the most likely cause?

A.Hairpin NAT (NAT loopback) is not configured, so internal clients cannot reach the public IP and be redirected to the internal server.
B.The firewall policy does not have NAT enabled for the outbound direction.
C.The firewall policy does not include the internal client's subnet as a source address.
D.The VIP does not have the 'port-forward' option enabled.
AnswerA

When an internal client tries to access the public IP of a VIP that points to an internal server on the same subnet, the traffic goes to the FortiGate, which performs DNAT, but the return traffic from the server goes directly to the client, bypassing the FortiGate. This asymmetric routing breaks the connection. Hairpin NAT (or NAT loopback) is required to ensure return traffic also goes through the FortiGate, allowing proper translation.

Why this answer

Hairpin NAT is required when internal clients access a public IP that is DNATed to an internal server. Without it, the server's return traffic bypasses the FortiGate, causing asymmetric routing and connection failure. Configuring hairpin NAT involves adding a firewall policy that allows the internal subnet to access the VIP and enabling NAT on that policy, ensuring return traffic is translated correctly.

Exam trap

The trap here is overlooking the need for hairpin NAT when internal clients access the public IP of a VIP that maps to an internal server.

350
Multi-Selecthard

A FortiGate administrator is configuring a policy-based routing (PBR) rule to send all traffic from the 'Engineering' VLAN (10.1.0.0/16) to a dedicated internet link through gateway 203.0.113.1. The administrator also wants to apply a traffic shaper to limit bandwidth. Which THREE configuration tasks must be performed?

Select 3 answers
A.Define a traffic shaper object with the desired bandwidth limits
B.Enable SD-WAN on the FortiGate
C.Configure Central NAT to translate the source IP
D.Create a policy-based route with source 10.1.0.0/16 and gateway 203.0.113.1
E.Create a firewall policy allowing traffic from Engineering VLAN to internet and apply the traffic shaper
AnswersA, D, E

The shaper must exist before it can be applied in a firewall policy.

Why this answer

A traffic shaper object must first be defined with the desired bandwidth limits (e.g., maximum rate, burst size) before it can be applied to a firewall policy. Without this object, the shaper cannot be referenced or enforced.

Exam trap

The trap here is that candidates often think SD-WAN is required for PBR or that Central NAT is mandatory, when in fact PBR and traffic shaping are independent features that can be configured without SD-WAN or Central NAT.

351
MCQhard

You receive an alert that a user's FortiToken synchronization is off. You need to resynchronize the token. Which CLI command achieves this?

A.diagnose user fortitoken resync <token-serial>
B.config user fortitoken edit <token-serial> set status activate
C.execute fortitoken-update <token-serial>
D.execute fortitoken-resync <token-serial>
AnswerD

"execute fortitoken-resync <token-serial>" is the correct command to resynchronize a FortiToken's OTP sequence with the FortiGate. It re-aligns the token's counter value with the server's expected counter, which is necessary when the token has been pressed multiple times without authentication, causing drift. This command is executed from the "execute" CLI level and takes the token serial number as its only argument.

Why this answer

The correct command to resynchronize a FortiToken on a FortiGate is `execute fortitoken-resync <token-serial>`. This CLI command triggers the token to synchronize its time-based one-time password (TOTP) seed with the FortiGate, correcting drift caused by clock skew or battery depletion. Options A, B, and C either use incorrect syntax, perform a different function, or do not exist in the FortiOS CLI.

Exam trap

The trap here is that candidates confuse the `execute` level command for resynchronization with the `diagnose` level command used for viewing token status, or they mistakenly think that editing the token configuration (Option B) can fix synchronization issues.

How to eliminate wrong answers

Option A is wrong because `diagnose user fortitoken resync` is not a valid FortiOS command; the correct diagnose command for token troubleshooting is `diagnose user fortitoken list` or `diagnose user fortitoken info`, but resynchronization is an execute-level operation. Option B is wrong because `config user fortitoken` is used to edit token attributes (like status or activation), not to trigger a resynchronization; setting `status activate` only enables the token, it does not fix synchronization drift. Option C is wrong because `execute fortitoken-update` is not a valid FortiOS command; the correct command for updating token firmware or seed is `execute fortitoken-update` does not exist, and the actual update process uses `execute fortitoken-import` or `execute fortitoken-resync`.

352
MCQmedium

An administrator wants to integrate FortiSandbox with a FortiGate to analyze suspicious files. Which security profile must be configured to send files to FortiSandbox?

A.Application Control profile with FortiSandbox enabled
B.Antivirus profile with FortiSandbox enabled
C.IPS profile with FortiSandbox enabled
D.Web Filter profile with FortiSandbox enabled
AnswerB

An Antivirus profile is the correct integration point because FortiGate's antivirus inspection can forward suspicious files to FortiSandbox for dynamic, sandbox-based analysis. During traffic inspection, the AV engine can detect unknown or low-confidence threats and send the associated file to FortiSandbox to identify zero-day malware. This provides an additional layer of protection beyond standard signature-based antivirus scanning.

Why this answer

FortiSandbox integration with FortiGate requires the Antivirus profile to be configured with FortiSandbox enabled. This is because FortiSandbox is designed to analyze suspicious files that are typically detected by the antivirus engine, and the Antivirus profile is the only security profile that can forward files to FortiSandbox for advanced threat detection. The Antivirus profile uses the 'fortisandbox' option under 'scan-mode' to send files that cannot be conclusively determined as clean or malicious.

Exam trap

The trap here is that candidates often assume FortiSandbox can be integrated with multiple security profiles (like IPS or Web Filter) for file analysis, but only the Antivirus profile supports the file-forwarding mechanism to FortiSandbox.

How to eliminate wrong answers

Option A is wrong because Application Control profiles are used to identify and control network applications, not to send files to FortiSandbox; they lack the file-scanning and forwarding mechanism required for sandbox analysis. Option C is wrong because IPS profiles focus on intrusion prevention by inspecting network traffic for attack signatures, not on file-level analysis or forwarding files to external sandboxes. Option D is wrong because Web Filter profiles control web access based on URL categories and content filtering, and they do not have the capability to send files to FortiSandbox for analysis.

353
MCQmedium

A FortiGate has multiple firewall policies. Policy ID 1 allows HTTP from LAN to WAN. Policy ID 2 allows all traffic from DMZ to WAN. A packet arrives from the DMZ interface destined to a web server on the internet using HTTPS. Which policy is matched?

A.Policy ID 1, because it is first in order
B.Policy ID 2, but only if it has a service allowing HTTPS
C.Implicit deny, because no policy matches HTTPS traffic
D.Policy ID 2, because it matches the source interface and destination
AnswerD

Policy ID 2 is the correct match because it is the first policy whose source interface (DMZ) and destination interface (WAN) exactly correspond to the HTTPS traffic's ingress and egress. Its service is set to 'ALL', which encompasses HTTPS port 443, and its action is 'ACCEPT', meaning the firewall is explicitly configured to forward this session. Unlike Policy ID 1, which has mismatched interfaces, Policy ID 2 satisfies every required attribute for this traffic. Thus, it is the effective policy that permits the HTTPS traffic.

Why this answer

Policy ID 2 is matched because it allows all traffic from the DMZ interface to the WAN destination interface without any service restriction. The packet originates from the DMZ interface and is destined to the internet (WAN), so the source and destination interfaces match Policy ID 2. Since Policy ID 2 does not specify a service, it implicitly permits all protocols, including HTTPS.

Exam trap

The trap here is that candidates assume a policy must explicitly list a service (like HTTPS) to match HTTPS traffic, but FortiGate policies with no service defined match all traffic, and the order of policies only matters when multiple policies match the same source and destination interfaces.

How to eliminate wrong answers

Option A is wrong because Policy ID 1 specifies the source interface as LAN, not DMZ, so the packet from DMZ cannot match it regardless of order. Option B is wrong because Policy ID 2 allows all traffic without a service restriction, so it does not require an explicit HTTPS service to match. Option C is wrong because Policy ID 2 explicitly matches the source and destination interfaces and permits all traffic, so the implicit deny is not reached.

354
Multi-Selecthard

An administrator notices that VoIP traffic (SIP) is not being inspected by the IPS profile applied to the firewall policy. The administrator suspects the traffic is being accelerated by NPU offloading. Which TWO actions can prevent NPU offloading for SIP traffic to ensure IPS inspection? (Choose two.)

Select 2 answers
A.Change the policy inspection mode to 'Proxy-Based'
B.Disable 'Allow Offload' in the policy advanced options
C.Enable 'Set SNAT' on the policy
D.Enable 'Deep Inspection' on the policy
E.Create a separate VIP for SIP
AnswersA, B

Switching the policy inspection mode from Flow-Based to Proxy-Based forces all traffic in that policy to be processed by the FortiGate CPU rather than being offloaded to the CP/ASIC hardware. SIP ALG functionality, which handles call setup, NAT traversal, and opening pinholes for RTP media, is only fully executed when packets pass through the proxy engine. Because proxy-based inspection never offloads, this ensures the SIP ALG sees every packet, making it the most direct and reliable fix for SIP traffic not being inspected correctly.

Why this answer

Changing the inspection mode to 'Proxy-Based' forces the firewall to reassemble and inspect the entire SIP session in software, bypassing NPU offloading. NPU offloading accelerates traffic by processing packets in hardware, which skips deep inspection like IPS. Proxy-based inspection ensures the firewall acts as a proxy for the SIP traffic, allowing IPS to inspect the payload.

Exam trap

The trap here is that candidates often confuse 'Deep Inspection' with a generic inspection mode, not realizing it is specific to SSL/TLS traffic and does not affect NPU offloading for SIP.

355
Multi-Selecthard

An administrator needs to configure destination NAT for multiple internal servers using a single public IP address by differentiating based on destination port. The public IP 203.0.113.10 should map to: (A) 10.0.0.1:80 for HTTP, (B) 10.0.0.2:443 for HTTPS. Which TWO configuration steps are required? (Choose two.)

Select 2 answers
A.Create a VIP for HTTP mapping port 80 to 10.0.0.1
B.Create an IP pool for the public IP
C.Create a VIP for HTTPS mapping port 443 to 10.0.0.2
D.Configure policy-based routing for each server
E.Use Central SNAT with port forwarding
AnswersA, C

A Virtual IP (VIP) in FortiOS is the standard object for destination NAT, translating an incoming public IP:port pair to a private destination. By mapping the external address's TCP port 80 to 10.0.0.1:80, the administrator configures the DNAT rule that redirects inbound HTTP traffic to the first internal server. This VIP must then be referenced in a firewall policy that allows the traffic and performs the translation.

Why this answer

A Virtual IP (VIP) is required to map the public IP 203.0.113.10 and destination port 80 to the internal server 10.0.0.1:80. This is the standard FortiGate method for destination NAT (port forwarding) when multiple internal servers share a single public IP, differentiated by destination port.

Exam trap

The trap here is confusing IP pools (used for source NAT) with VIPs (used for destination NAT), leading candidates to incorrectly select IP pool or Central SNAT options for port forwarding scenarios.

356
MCQmedium

An administrator is configuring a FortiGate HA cluster and wants to ensure that the primary unit is always preferred based on its configuration priority. Which setting should be enabled to allow the primary unit to resume its role after a failover if it regains connectivity?

A.set ha-inherit-priority enable
B.set override enable
C.set session-pickup enable
D.set ha-priority 255
AnswerB

Setting 'override enable' is the correct way to make a higher-priority FortiGate unit reclaim the primary role in a cluster. When enabled, a unit that becomes healthy and has a higher configured priority than the current primary will preempt the role back, ensuring the preferred unit resumes active control. This is essential for deterministic failback after maintenance or an outage, because without override the lower-priority unit would stay primary until it fails.

Why this answer

The 'set override enable' setting allows the primary unit to resume its role after a failover if it regains connectivity, based on its configured priority. Without override, the cluster does not preempt; the current primary remains primary even if a higher-priority unit rejoins. Enabling override ensures the primary unit always takes back its role when available.

Exam trap

The trap is confusing priority setting with override; candidates might think setting a high priority alone ensures preemption, but override must be enabled for the priority to take effect after failover.

How to eliminate wrong answers

Option A is wrong because 'set ha-inherit-priority enable' is not a valid FortiGate command; HA priority inheritance is not a standard feature. Option C is wrong because 'set session-pickup enable' enables session failover, not priority-based preemption. Option D is wrong because 'set ha-priority 255' sets the priority value but does not enable override; without override, the priority is not used for preemption.

357
MCQeasy

When configuring a route-based IPsec VPN, which of the following must be created to allow traffic to flow through the tunnel?

A.A static route to the remote subnet via the IPsec interface
B.A firewall policy with the VPN interface as source
C.A NAT rule to translate the private IPs
D.A security profile for VPN traffic
AnswerA

The static route is the core requirement in route-based IPsec VPN because the IPsec tunnel is bound to a virtual interface (e.g., s2s_ike). Without a route directing the remote subnet's destination IPs to that interface, the FortiGate has no next-hop to forward traffic into the tunnel, so packets are dropped by the routing decision. While a firewall policy must also exist to permit the traffic, it is the route that actually enforces the "remote subnet via IPsec interface" path, and traffic that doesn't follow this route remains unencrypted and may be routed incorrectly.

Why this answer

In a route-based IPsec VPN, the tunnel is represented as a virtual IPsec interface. To route traffic from the local network to the remote subnet through this tunnel, a static route must be configured with the remote subnet as the destination and the IPsec interface as the next-hop or outgoing interface. Without this route, the FortiGate has no forwarding information to send traffic into the tunnel, even if the IPsec phase 1 and phase 2 settings are correctly established.

Exam trap

The trap here is that candidates often confuse route-based VPNs with policy-based VPNs, mistakenly thinking that a firewall policy alone is sufficient to direct traffic into the tunnel, when in fact the route is the critical component that enables the forwarding decision in a route-based design.

How to eliminate wrong answers

Option B is wrong because a firewall policy with the VPN interface as source is not required; the policy must have the VPN interface as the destination (or as both source and destination in a bidirectional policy) to allow traffic exiting the tunnel, but the question specifically asks what must be created to allow traffic to flow through the tunnel, and the fundamental requirement is the route. Option C is wrong because NAT is not mandatory for route-based IPsec VPNs; in fact, site-to-site VPNs typically avoid NAT to preserve the original source IP, and NAT rules are only added if address translation is explicitly needed. Option D is wrong because a security profile (such as antivirus or web filter) is optional and applied to firewall policies for inspection, but it is not a prerequisite for traffic to flow through the tunnel.

358
MCQhard

A company with 500 employees uses FortiGate as their internet gateway. They recently enabled SSL deep inspection using the built-in CA certificate. After deployment, many users report that they cannot access their online banking websites. The error message in the browser says 'The certificate is not trusted'. The administrator has already pushed the FortiGate CA certificate to all domain-joined computers via Group Policy. However, the problem persists for banking sites. The administrator also notices that banking sites load fine on mobile devices that do not have the CA certificate installed. What is the most likely cause and solution?

A.Disable SSL inspection entirely to avoid certificate issues.
B.The CA certificate is not properly installed on all computers. Re-deploy via Group Policy.
C.Use certificate inspection instead of deep inspection for all traffic.
D.Banking websites use certificate pinning. Exempt them from deep inspection using an SSL inspection exemption list.
AnswerD

Banking platforms frequently implement certificate pinning by hard-coding the expected public key or certificate fingerprint in the client or browser. When FortiGate performs deep inspection, it replaces the original server certificate with its own re-signed copy, causing the pin validation to fail and the connection to be blocked. The recommended fix is to add these banking domains to the SSL exemption list so the FortiGate passes the original certificate untouched, preserving deep inspection for all other domains.

Why this answer

Banking websites often use HTTP Public Key Pinning (HPKP) or certificate pinning, where the browser expects a specific certificate or public key from the server. When FortiGate performs SSL deep inspection, it re-signs the server's certificate with its own CA, breaking the pinning validation. This causes the 'certificate not trusted' error even when the FortiGate CA is trusted, because the browser detects that the presented certificate does not match the pinned certificate.

The correct solution is to exempt banking sites from deep inspection using an SSL inspection exemption list, allowing the original server certificate to pass through.

Exam trap

The trap here is that candidates assume the issue is always a missing CA certificate deployment, but the real problem is certificate pinning, which causes trust failures even when the CA is trusted, because the browser checks the pinned certificate hash against the presented certificate.

How to eliminate wrong answers

Option A is wrong because disabling SSL inspection entirely would remove security visibility for all HTTPS traffic, which is an overreaction and not necessary; the issue is specific to pinned certificates. Option B is wrong because the problem persists despite the CA certificate being properly deployed via Group Policy, and the error is not due to missing CA trust but due to certificate pinning validation failure. Option C is wrong because certificate inspection (which only inspects the certificate metadata, not the content) would still present the original server certificate to the browser, but it does not address the root cause of pinning; however, the question states deep inspection is enabled, and switching to certificate inspection would not resolve the pinning issue because the browser still sees the original certificate, which is actually correct for pinned sites—but the real fix is exemption, not a global change to certificate inspection.

359
MCQeasy

Which of the following is NOT a valid address object type in FortiGate?

A.Subnet
B.Wildcard FQDN
C.Geography
D.MAC address
AnswerD

MAC addresses are not a valid address object type in FortiGate firewall policies because policy matching is based on IP addresses, ports, and interfaces, not Layer 2 hardware addresses. While FortiOS can track MAC addresses for DHCP reservations, device inventory, and wireless user identification, those contexts use separate mechanisms rather than the address object list. Since the question asks for something that cannot be defined as a policy address object, MAC address is the correct choice.

Why this answer

FortiGate address objects support Subnet, Wildcard FQDN, and Geography types, but MAC addresses are not a valid address object type. MAC addresses are used in other contexts like static ARP entries or DHCP reservations, not as firewall address objects.

Exam trap

The trap here is that candidates may confuse MAC address filtering (available in some security features like device identification) with a valid firewall address object type, leading them to incorrectly select a wrong answer.

How to eliminate wrong answers

Option A is wrong because Subnet is a standard address object type in FortiGate, used to define IPv4 or IPv6 network ranges. Option B is wrong because Wildcard FQDN is a valid address object type that matches multiple FQDNs using wildcard patterns (e.g., *.example.com). Option C is wrong because Geography is a valid address object type that allows matching traffic based on source or destination country using GeoIP databases.

360
MCQeasy

An administrator is troubleshooting an SSL VPN connection issue. Users can authenticate but receive 'No available tunnel' error. What is the most likely cause?

A.Split tunneling is misconfigured.
B.The firewall policy does not allow traffic from the SSL VPN interface.
C.The SSL VPN port is blocked on the firewall.
D.The SSL VPN IP pool has run out of addresses.
AnswerD

When the SSL VPN IP pool is exhausted, the FortiGate cannot assign an IP address to the connecting client after successful authentication, so the tunnel cannot be completed. This often manifests as the client connecting and authenticating but then being unable to establish the tunnel or receive a virtual IP. In FortiOS, this condition can be verified with 'get vpn ssl monitor' or by checking the configured IP pool's usage.

Why this answer

The 'No available tunnel' error after successful authentication indicates that the SSL VPN daemon cannot assign an IP address to the client. The most likely cause is that the SSL VPN IP pool has exhausted its available addresses, preventing the creation of a virtual tunnel interface. This is a common issue when the pool size is smaller than the number of concurrent users.

Exam trap

The trap here is that candidates often confuse post-authentication issues (like IP pool exhaustion) with pre-authentication issues (like port blocking) or traffic-routing issues (like split tunneling or firewall policies), leading them to select options that would prevent authentication entirely rather than the specific error message given.

How to eliminate wrong answers

Option A is wrong because split tunneling controls which subnets are routed through the VPN tunnel versus the client's local network; it does not affect the ability to establish the tunnel itself. Option B is wrong because the firewall policy on the SSL VPN interface controls traffic forwarding after the tunnel is established, not the tunnel creation process. Option C is wrong because if the SSL VPN port were blocked, users would not be able to authenticate at all; the error occurs after successful authentication.

361
Drag & Dropmedium

Drag and drop the steps to perform a factory reset on FortiGate via CLI into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Factory reset is done with execute factoryreset, then confirm; device reboots to defaults.

362
MCQmedium

A FortiGate is configured with two equal-cost static default routes via two ISPs. The administrator wants to use both links simultaneously for outbound traffic, distributing sessions per source-destination pair. Which ECMP load balancing method should be configured under config system settings?

A.weighted-round-robin
B.vip-inbound-grpc
C.spillover
D.source-destination-ip
AnswerD

Configuring source-destination-ip hashes each session's source and destination IP pair, so distinct flows spread across both ISP links while a single flow stays pinned to one route. This satisfies the stem's requirement to use both links simultaneously, distributing sessions per source-destination pair rather than per packet.

Why this answer

The source-destination-ip method under ECMP load balancing distributes sessions based on both source and destination IP addresses, ensuring that all packets belonging to the same session (same source-destination pair) are forwarded via the same path. This meets the requirement of using both links simultaneously for outbound traffic while maintaining per-session consistency.

Exam trap

The trap here is that candidates often confuse ECMP load balancing methods with general load balancing techniques, mistakenly selecting weighted-round-robin because it sounds like a standard load balancing algorithm, but it does not guarantee per-source-destination pair distribution in FortiGate's ECMP context.

How to eliminate wrong answers

Option A (weighted-round-robin) is wrong because it distributes sessions in a round-robin fashion based on weights, not per source-destination pair, which can cause session asymmetry. Option B (vip-inbound-grpc) is wrong because it is not an ECMP load balancing method; it relates to gRPC-based VIP configuration for inbound traffic. Option C (spillover) is wrong because it forwards traffic to a secondary link only when the primary link's bandwidth threshold is exceeded, not for simultaneous use of both links.

363
MCQhard

Given the above IPS sensor configuration, what will happen when traffic matching a high-severity IPS signature is detected?

A.The traffic will be logged but not blocked.
B.The traffic will be blocked only if the signature is enabled globally.
C.The traffic will be blocked because the sensor has a block action.
D.The traffic will be allowed because no entry exists for high severity.
AnswerD

This is correct because the IPS sensor contains no entry for high-severity signatures, and an unmatched signature in FortiGate IPS results in an implicit pass. The sensor only applies actions (block, reset, or log) to traffic that matches a defined signature or severity override. With no high-severity rule in the sensor, the traffic is allowed and forwarded without inspection-based action.

Why this answer

The IPS sensor configuration shown does not include an entry for high-severity signatures. Without a specific action defined for high severity, the sensor defaults to allowing the traffic while still generating a log entry. This is a common behavior in FortiGate IPS where only explicitly configured severity levels have defined actions.

Exam trap

The trap here is that candidates assume high-severity signatures are automatically blocked by default, but FortiGate requires explicit action configuration per severity level, and the default action is to allow.

How to eliminate wrong answers

Option A is wrong because logging without blocking would require a 'monitor' or 'pass' action explicitly configured for high severity, which is absent. Option B is wrong because global signature enablement does not override the per-severity action configuration; the sensor's action table determines blocking, not global status. Option C is wrong because the sensor does not have a block action for high severity; the block action is only defined for critical and medium severity levels in the provided configuration.

364
MCQmedium

An admin configures a firewall policy to allow SMTP traffic from a mail server to the internet with NAT enabled. External recipients report that the email source IP is the FortiGate's external interface IP. The admin wants the source to be a specific IP from a pool. What should the admin configure?

A.Create a central SNAT policy with the source as the mail server and the translated IP as the desired address
B.Use a VIP with port forwarding to translate the source
C.In the firewall policy, enable NAT and specify the IP pool as a fixed port range or overload
D.Enable NAT on the policy and set the IP pool configuration to use a dynamic IP pool
AnswerC

In the firewall policy, enabling NAT and referencing an IP pool is the proper method for policy-based source NAT. An IP pool configured as overload (PAT) allows multiple internal sessions to share a single translated IP, while a fixed port range pool also uses a single IP but constrains the source port range; both can satisfy the requirement for a single public address for the mail server. This is exactly what the admin needs for SMTP traffic, ensuring all outbound mail appears from the same IP. Thus it is the correct choice.

Why this answer

The admin wants the source IP of outbound SMTP traffic to be a specific IP from a pool rather than the FortiGate's external interface IP. In a firewall policy with NAT enabled, you can specify an IP pool to override the default source NAT behavior. The IP pool can be configured as Fixed Port Range or Overload (PAT) to translate the mail server's source IP to a desired address from the pool, ensuring external recipients see that specific IP.

Exam trap

The trap here is that candidates often confuse IP pools with VIPs or central SNAT, mistakenly thinking VIPs can modify source IPs or that central SNAT is required, when in fact the IP pool directly attached to the firewall policy is the correct and simplest solution for overriding the source NAT address.

How to eliminate wrong answers

Option A is wrong because a central SNAT policy is used for source NAT but does not allow specifying an IP pool directly within a firewall policy; it requires separate configuration and is not the standard method for overriding the translated IP in a policy-based NAT scenario. Option B is wrong because a Virtual IP (VIP) is used for destination NAT (port forwarding), not source NAT; it translates incoming traffic to an internal server, not outbound source IPs. Option D is wrong because a dynamic IP pool is used for load-balancing or rotating source IPs, not for pinning the source to a specific IP from a pool; the admin needs a fixed translation, which requires Fixed Port Range or Overload mode.

365
MCQhard

An administrator has configured an IPS sensor to block critical-severity attacks. However, after a week, they notice that a known exploit (CVE-2021-44228) is still getting through. Which configuration change should be made to improve detection?

A.Set the IPS sensor severity filter to 'low' and above.
B.Change the IPS sensor action from 'default' to 'block' for all signatures.
C.Create a custom IPS signature for the exploit.
D.Enable the specific IPS signature for the exploit in the sensor.
AnswerD

Enabling the specific signature for CVE-2021-44228 closes the detection gap, since severity-based blocking only acts on signatures already enabled and rated critical. If that signature is disabled or absent from the sensor's active set, traffic matching the exploit passes uninspected regardless of the critical-severity policy.

Why this answer

The IPS sensor must have the specific signature for CVE-2021-44228 (Log4Shell) enabled to detect and block it. Even if the sensor is set to block critical-severity attacks, the signature for this exploit may be disabled by default in the sensor's signature database. Enabling the specific signature ensures the sensor inspects traffic for the exploit's unique patterns and applies the configured action.

Exam trap

The trap here is that candidates assume setting the severity filter to 'critical' or changing the action to 'block' globally will catch all critical exploits, but they forget that individual signatures must be explicitly enabled in the sensor to be evaluated.

How to eliminate wrong answers

Option A is wrong because lowering the severity filter to 'low' and above would cause the sensor to process more signatures, but it does not enable a disabled signature; the exploit's signature may still be disabled regardless of severity. Option B is wrong because changing the action from 'default' to 'block' for all signatures would override per-signature actions and could cause false positives or performance issues, but it still does not enable a disabled signature. Option C is wrong because creating a custom IPS signature is unnecessary when the vendor (Fortinet) already provides a signature for CVE-2021-44228; the issue is that the signature is disabled, not missing.

366
MCQeasy

Which FortiGate security feature can be used to block outgoing emails that contain specific keywords, such as confidential information?

A.Email Filter
B.Web Filter
C.Application Control
D.Antivirus
AnswerA

Email Filter is the correct feature because it is specifically designed to inspect SMTP traffic, including outgoing email. It can block outbound spam using anti-spam techniques such as IP reputation, Bayesian filtering, and content analysis. This feature is protocol-aware for email and can enforce policies on both inbound and outbound messages.

Why this answer

Email Filter is the correct answer because it is the FortiGate security profile specifically designed to inspect SMTP, POP3, and IMAP traffic for content violations. It can block outgoing emails based on keyword patterns, such as 'confidential', by matching against defined filter rules in the email filter profile, which operates at the application layer.

Exam trap

The trap here is that candidates often confuse Email Filter with Antivirus or Web Filter, mistakenly thinking that keyword blocking is a general security function rather than a specific email content inspection feature.

How to eliminate wrong answers

Option B (Web Filter) is wrong because it controls HTTP/HTTPS web traffic, not email protocols like SMTP, and cannot inspect email message bodies or headers for keywords. Option C (Application Control) is wrong because it identifies and controls application traffic (e.g., blocking Gmail or Outlook) but does not perform deep content inspection of email bodies for specific keywords. Option D (Antivirus) is wrong because it scans for malware signatures in file attachments and content, not for arbitrary keyword patterns like 'confidential'.

367
MCQhard

An administrator runs the CLI command: 'diagnose sys session list | grep -i dns' and sees sessions with dst port 53. The administrator has configured a DNS filter profile on the firewall policy. However, DNS requests are not being filtered. What is the MOST likely cause?

A.The DNS filter profile is applied to the wrong policy direction
B.DNS filtering requires proxy-based inspection mode on the policy
C.The DNS filter profile has no rules defined
D.The FortiGate is in transparent mode
AnswerB

FortiGate has two inspection modes: flow-based and proxy-based. DNS filtering uses the proxy engine to inspect the DNS query and compare the domain against a FortiGuard category, so the policy controlling the client DNS traffic must be configured for proxy-based inspection mode. If the policy is left in flow mode, the FortiGate performs session-based forwarding and does not decrypt/intercept the DNS protocol payload, so the DNS filter profile is silently ignored. This is the correct reason the DNS filter is ineffective for the administrator's setup.

Why this answer

DNS filtering on FortiGate requires proxy-based inspection mode because it needs to reassemble and inspect the full DNS transaction (request and response) to apply filtering rules. Flow-based inspection only examines individual packets and cannot perform the deep application-layer analysis needed for DNS filtering. Therefore, even if the DNS filter profile is correctly applied to the policy, it will not work unless the policy's inspection mode is set to proxy-based.

Exam trap

The trap here is that candidates often assume DNS filtering works like other security profiles (e.g., web filtering) that can operate in flow-based mode, but DNS filtering specifically requires proxy-based inspection due to the nature of DNS protocol inspection.

How to eliminate wrong answers

Option A is wrong because the DNS filter profile is applied to a firewall policy, which is inherently directional (from source to destination); applying it to the wrong direction would not cause the sessions to appear with dst port 53, and the administrator already sees such sessions, indicating traffic is hitting the policy. Option C is wrong because a DNS filter profile with no rules defined would still allow DNS traffic to pass through (default action is to allow), but the administrator states DNS requests are not being filtered, which implies the profile is not being applied at all, not that it lacks rules. Option D is wrong because transparent mode does not affect the ability to apply DNS filtering; FortiGate can perform DNS filtering in both transparent and NAT modes, so this is not the cause.

368
MCQhard

An administrator runs the command 'diagnose ips anomaly list' and sees many entries for 'tcp_src_session' with high counts. Users report slow internet. What is the most likely issue?

A.The IPS signature database is corrupted
B.The FortiGate has a hardware failure
C.A host on the network is infected with malware that is generating many outbound connections
D.The FortiGate is under a DDoS attack
AnswerC

A single internal host generating a high volume of outbound connections to multiple external destinations is a hallmark of malware infection or P2P activity. FortiOS IPS anomaly detection monitors such behavioral patterns—like excessive half-open connections or a source creating many sessions per second—and flags it as an anomaly. The command output would show this host's source IP with anomaly type and session counts, confirming the botnet-like behavior.

Why this answer

The 'diagnose ips anomaly list' command displays anomalies detected by the IPS engine, and 'tcp_src_session' tracks the number of TCP sessions originating from a single source IP. A high count indicates a single host is initiating an excessive number of outbound TCP connections, which is a classic sign of malware infection (e.g., a botnet client or worm) that is generating numerous outbound connections, consuming bandwidth and causing slow internet for users.

Exam trap

The trap here is that candidates often confuse 'tcp_src_session' (outbound from a source) with 'tcp_dst_session' (inbound to a destination) and incorrectly assume a DDoS attack, but the command specifically shows the source IP, not the destination, pointing to an internal infected host rather than an external attack.

How to eliminate wrong answers

Option A is wrong because a corrupted IPS signature database would typically cause IPS engine errors, not a specific spike in 'tcp_src_session' counts. Option B is wrong because hardware failure would manifest as system crashes, interface errors, or hardware alarms, not as a high count of outbound TCP sessions from a single source. Option D is wrong because a DDoS attack would likely show high counts in 'tcp_dst_session' (many sources to one destination) or 'udp_dst_session', not a single source generating many outbound sessions.

369
MCQmedium

An administrator receives a report that some users cannot authenticate via captive portal on a FortiGate. The captive portal is configured for firewall authentication. The administrator checks the authentication logs and sees 'Authentication failed: invalid credentials'. However, the users confirm they are entering the correct username and password. What is the MOST likely cause?

A.The captive portal interface is not configured with a valid certificate
B.The users are not including the domain name in the username field
C.The FortiGate's clock is out of sync with the LDAP server
D.The LDAP server is not reachable from the FortiGate
AnswerB

When authenticating against an AD or LDAP server, FortiGate often requires the username in a fully qualified format such as DOMAIN\\username or as a User Principal Name (user@domain.com). If users type only their sAMAccountName, the FortiGate constructs a bind DN that does not match any directory entry, so the LDAP server returns error code 49 (invalidCredentials). The passwords may be correct, but the omitted domain prefix makes the bind fail exactly as if the password were wrong.

Why this answer

When FortiGate performs firewall authentication (captive portal) against an LDAP server, the username format must match what the LDAP server expects. If the LDAP server requires a domain-qualified username (e.g., DOMAIN\user or user@domain.com) and users enter only their short username, the bind attempt fails with 'invalid credentials' even though the password is correct. This is the most likely cause given that users confirm their credentials are correct and the logs show authentication failure rather than a connectivity error.

Exam trap

NSE4 often tests the difference between authentication failures caused by wrong username format versus connectivity or certificate issues, and candidates may overlook the domain-qualification requirement for LDAP binds.

How to eliminate wrong answers

Option A is wrong because a missing or invalid certificate on the captive portal interface would cause browser certificate warnings or portal access issues, not an 'invalid credentials' error in the authentication logs. Option C is wrong because clock skew with the LDAP server would typically cause Kerberos authentication failures, not simple LDAP bind failures; LDAP binds do not rely on time synchronization. Option D is wrong because if the LDAP server were unreachable, the logs would show a timeout or connection error, not 'invalid credentials'.

370
MCQhard

An admin runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A.The session is a half-open TCP connection
B.The session is a multicast session
C.The session is a UDP session for DNS over HTTPS
D.The session is an established TCP session for HTTPS traffic
AnswerD

The session is an established TCP session because the output field proto=6 specifies TCP (protocol 6), and proto_state=01 corresponds to the TCP established state, meaning the three-way handshake completed successfully. The destination port 443 is the well-known port for HTTPS, so this session represents active HTTPS traffic traversing the FortiGate. When combined, these values unambiguously identify a normal, established TCP connection for HTTPS, ruling out half-open, multicast, or UDP alternatives.

Why this answer

The output shows `proto=6` (TCP), `proto_state=01` (TCP established), `dport=443` (HTTPS), and a duration/expire indicating an active session. This confirms an established TCP session for HTTPS traffic, making D correct.

Exam trap

The trap here is that candidates may misinterpret `proto_state=01` as a half-open connection (like SYN_SENT) because they confuse the numeric state value with TCP flags, when in fact 01 specifically means ESTABLISHED in FortiGate's session table.

How to eliminate wrong answers

Option A is wrong because `proto_state=01` indicates a fully established TCP connection (state ESTABLISHED), not a half-open connection (which would show state like SYN_SENT or 02). Option B is wrong because multicast sessions use UDP (proto=17) or IGMP, not TCP (proto=6), and the output shows a unicast TCP session. Option C is wrong because DNS over HTTPS uses TCP port 443 but is a UDP-based protocol (DNS itself is UDP, though DoH uses TCP); the output explicitly shows `proto=6` (TCP), not UDP (proto=17), and the session state indicates TCP, not UDP.

371
MCQmedium

A FortiGate administrator manages an active-passive HA cluster of two FGCP units. The administrator needs to upgrade the firmware on the cluster with minimal downtime. The administrator has already uploaded the new firmware image to both units. Which step should the administrator take next to ensure the secondary unit is upgraded first and the cluster remains available?

A.Run 'execute ha manage 1' to access the secondary unit, then run 'execute restore image <firmware_file>' to install the new firmware.
B.Run 'diagnose sys ha upgrade' to trigger the firmware upgrade process on the secondary unit.
C.Run 'execute ha synchronize start' to push the firmware from the primary to the secondary.
D.Run 'execute ha manage 1' to access the secondary unit, then run 'execute reboot' to reboot it into the new firmware.
AnswerA

After uploading the firmware to both units, the administrator should log into the secondary unit via 'execute ha manage 1' and then use 'execute restore image' to install the new firmware. This upgrades the secondary first, then the primary can be upgraded later, minimizing downtime. This is the recommended HA firmware upgrade procedure.

Why this answer

In an active-passive HA cluster, upgrading firmware with minimal downtime involves upgrading the secondary unit first, then triggering a failover so the upgraded secondary becomes primary, and finally upgrading the original primary. Accessing the secondary via 'execute ha manage' and using 'execute restore image' is the correct method. This ensures the cluster remains available during the upgrade process.

Exam trap

The trap here is assuming that simply rebooting the secondary unit or using HA synchronization commands will upgrade its firmware, when in fact firmware must be installed locally on each unit using the restore image command.

372
MCQmedium

A FortiGate admin notices that HTTPS traffic to a web server is not being scanned by the antivirus profile applied to the firewall policy. The admin confirms the policy is correct and antivirus is enabled. What is the MOST likely reason the traffic is not being scanned?

A.The web server's certificate is self-signed and FortiGate is rejecting the connection
B.The antivirus profile is configured for flow-based inspection instead of proxy-based
C.SSL/TLS deep inspection is not enabled on the firewall policy
D.The FortiGuard antivirus subscription has expired
AnswerC

Antivirus inspection requires decrypted payloads, so encrypted HTTPS sessions bypass scanning unless the policy performs SSL/TLS deep inspection. Without it, FortiGate forwards ciphertext untouched, meaning no antivirus profile can examine the traffic regardless of correct policy configuration.

Why this answer

HTTPS traffic is encrypted with SSL/TLS, so an antivirus profile cannot inspect the payload unless the firewall can decrypt the traffic. Even with antivirus enabled in the policy, without SSL/TLS deep inspection (also called SSL inspection or HTTPS decryption), FortiGate only sees encrypted packets and cannot scan for malware. Therefore, the most likely reason is that SSL/TLS deep inspection is not enabled on the firewall policy.

Exam trap

The trap here is that candidates often assume antivirus profiles automatically inspect all traffic, forgetting that encrypted HTTPS requires explicit SSL/TLS decryption before any content inspection can occur.

How to eliminate wrong answers

Option A is wrong because a self-signed certificate does not cause FortiGate to reject the connection by default; it may generate a warning or require an SSL inspection policy to handle untrusted certificates, but the traffic would still be forwarded (and remain unscanned) unless a specific action is configured. Option B is wrong because both flow-based and proxy-based inspection modes support antivirus scanning; the inspection mode affects performance and some features but does not prevent scanning of HTTPS traffic if decryption is configured. Option D is wrong because an expired FortiGuard antivirus subscription would prevent signature updates and might disable real-time scanning, but the traffic would still be inspected (with potentially outdated signatures) unless the license is completely expired and the feature is blocked; the question states antivirus is enabled, so the subscription expiry is not the most likely reason for no scanning at all.

373
MCQmedium

A company recently deployed FortiGate with application control to manage cloud application usage. They want to allow Google Drive for business but block personal Google accounts. Which application control configuration approach is most effective?

A.Use web filtering to block the URL of personal Google Drive.
B.Configure IPS to block personal Google Drive traffic.
C.Use application control with specific signatures for 'Google Drive Business' and 'Google Drive Personal' and apply appropriate actions.
D.Create a rule to block all Google Drive applications.
AnswerC

FortiOS Application Control leverages FortiGuard application signatures that identify Google Drive and its sub-versions, including 'Google Drive Business' and 'Google Drive Personal,' based on flow characteristics and OAuth/authentication context. By applying separate actions—such as block for the Personal signature and allow for the Business signature—the administrator can enforce a granular policy. Each signature is matched to the specific application instance using SSL inspection, enabling precise control that is unavailable with URL or vulnerability-based methods.

Why this answer

FortiGate's application control uses application signatures to distinguish between different versions of the same application, such as 'Google Drive Business' and 'Google Drive Personal'. By configuring specific signatures with appropriate actions (allow for business, block for personal), you can enforce granular control over cloud application usage without affecting legitimate business traffic.

Exam trap

The trap here is that candidates often confuse web filtering (URL-based) with application control (signature-based), assuming that blocking a URL will effectively block personal accounts, but in reality, both account types use the same URL and only differ in application-layer metadata.

How to eliminate wrong answers

Option A is wrong because web filtering blocks URLs, but personal and business Google Drive often share the same base URL (drive.google.com), making URL-based blocking ineffective for distinguishing between account types. Option B is wrong because IPS is designed to detect and prevent network attacks and exploits, not to enforce application-level access policies based on user account type. Option D is wrong because blocking all Google Drive applications would also block the legitimate business use of Google Drive, which contradicts the requirement to allow business accounts.

374
Multi-Selectmedium

An administrator is configuring a FortiGate for ZTNA (Zero Trust Network Access). Which TWO components are essential for ZTNA to function? (Choose two.)

Select 2 answers
A.A firewall policy with ZTNA tags
B.A captive portal
C.FortiClient EMS for endpoint compliance
D.An IPsec VPN tunnel
E.An identity provider (IdP) for user authentication
AnswersC, E

FortiClient EMS for endpoint compliance is indeed a correct and required component of ZTNA. EMS continuously collects telemetry from FortiClient agents—such as OS patching, antivirus status, disk encryption, and overall device posture—and shares this real-time data with the FortiGate. The FortiGate uses this posture information to make per-session access decisions, enforcing that only compliant, healthy devices can reach a ZTNA-protected application. Without EMS, the FortiGate would have no way to verify the trustworthiness of the endpoint, which is central to a zero-trust architecture.

Why this answer

FortiClient EMS is essential for ZTNA because it enforces endpoint compliance by collecting device posture data (e.g., OS version, antivirus status, disk encryption) and communicating this to FortiGate via the FortiTelemetry protocol. Without EMS, the FortiGate cannot verify that endpoints meet security requirements before granting ZTNA access, which is a core principle of Zero Trust.

Exam trap

The trap here is that candidates often confuse ZTNA with VPN technologies (option D) or assume a captive portal (option B) is needed for user authentication, when in fact ZTNA requires an external IdP and EMS for its zero-trust model.

375
MCQeasy

Which FortiGate diagnostic command allows you to capture packets on an interface for troubleshooting network connectivity issues?

A.diagnose debug flow
B.diagnose sniffer packet
C.diagnose sys session list
D.diagnose test application
AnswerB

The `diagnose sniffer packet` command is FortiGate's built-in packet capture utility, equivalent to tcpdump. It allows you to capture raw packets on one or more interfaces with flexible BPF-style filters (e.g., host, port, protocol) and verbosity levels (1 for headers, 2 for headers+payload, 3 for full packet details). This is the canonical command for performing a packet capture on FortiGate, making it the correct answer for capturing packets.

Why this answer

The 'diagnose sniffer packet' command on a FortiGate captures packets on a specified interface, similar to tcpdump. It allows administrators to see live packet data for troubleshooting connectivity, filtering by interface, protocol, host, port, and verbosity level. This is the correct tool for packet-level capture.

Exam trap

NSE4 often tests the distinction between 'diagnose sniffer packet' (packet capture) and 'diagnose debug flow' (flow tracing) — candidates confuse the two when asked about capturing packets on an interface.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug flow' traces the flow of packets through the FortiGate's inspection engine, showing policy lookups and forwarding decisions — it does not capture raw packets on an interface. Option C is wrong because 'diagnose sys session list' displays the session table, not packet captures. Option D is wrong because 'diagnose test application' runs diagnostic tests on FortiGate applications/daemons, not packet capture.

Page 4

Page 5 of 11

Page 6

All pages