Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 376–450

773 questions total · 11pages · All types, answers revealed

Page 5

Page 6 of 11

Page 7
376
Multi-Selecthard

A FortiGate administrator is troubleshooting an IPsec VPN between two FortiGates. The tunnel is established, but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees the following output: IKE: phase 2 negotiation completed IKE: IPsec SA up What THREE possible causes should the administrator investigate?

Select 3 answers
A.Firewall policies on either FortiGate are not allowing traffic between the local and remote subnets
B.The pre-shared key is incorrect
C.Routing tables on both FortiGates do not have routes pointing to the remote subnets via the VPN interface
D.The IKE mode is set to aggressive mode on one side and main mode on the other
E.NAT is being applied to the VPN traffic before it enters the tunnel, causing IP address mismatch
AnswersA, C, E

Even after an IPsec tunnel reaches Phase 2, traffic is still subject to the firewall policy database on each FortiGate. If no policy with action ACCEPT exists that matches the source/destination subnets and the incoming/outgoing interface (e.g., the IPsec virtual interface), the firewall silently drops the packets. A common misconfiguration is creating a policy for the WAN interface instead of the tunnel interface, or setting the wrong local/remote addresses in the policy.

Why this answer

Even though the IPsec SA is up (phase 2 completed), traffic will not pass unless firewall policies explicitly permit traffic between the local and remote subnets. FortiGate requires a policy that allows the traffic and references the VPN tunnel interface as the outgoing interface.

Exam trap

The trap here is that candidates assume a successful IPsec SA (phase 2 up) guarantees traffic flow, but FortiGate requires separate firewall policies and routing configuration for traffic to traverse the tunnel.

377
MCQmedium

An admin wants to ensure that VoIP traffic (UDP ports 5060-5061) from the internal network to the internet is prioritized over other traffic when the WAN link is congested. Which feature should be configured on the firewall policy?

A.Enable NAT on the policy
B.QoS marking only (DSCP)
C.Traffic shaping policy with a guaranteed bandwidth allocation and high priority
D.Configure a security profile with QoS settings
AnswerC

A traffic shaping policy is the only mechanism in FortiGate that can enforce both bandwidth reservations and queue priority for VoIP. By configuring a shaping profile with guaranteed bandwidth (e.g., 512 kbps) and setting priority to High, you instruct the traffic scheduler to service SIP/RTP UDP packets ahead of lower-priority flows and reserve capacity so that congestion does not starve voice. Guaranteed bandwidth ensures a minimum threshold, while high priority reduces jitter and latency, making this the correct choice for real-time traffic.

Why this answer

A traffic shaping policy with guaranteed bandwidth allocation and high priority ensures that VoIP traffic (UDP ports 5060-5061) receives the necessary bandwidth and is prioritized over other traffic during WAN congestion. Traffic shaping policies on FortiGate allow you to set guaranteed bandwidth, maximum bandwidth, and priority levels, which directly address congestion by reserving resources for critical traffic like VoIP.

Exam trap

The trap here is that candidates confuse DSCP marking (which only tags packets for external QoS) with local traffic shaping that actually enforces bandwidth guarantees and priority on the FortiGate itself, leading them to choose option B instead of C.

How to eliminate wrong answers

Option A is wrong because enabling NAT on the policy translates source IP addresses but does not provide any traffic prioritization or bandwidth guarantees during congestion. Option B is wrong because QoS marking only (DSCP) sets the Differentiated Services Code Point in the IP header for downstream devices, but on FortiGate, DSCP marking alone does not enforce local queuing or bandwidth allocation; it relies on downstream routers to honor the markings, which is insufficient for guaranteed prioritization on the WAN link. Option D is wrong because a security profile with QoS settings does not exist; security profiles (e.g., antivirus, web filtering) inspect content but do not manage bandwidth allocation or traffic priority, and QoS settings are configured separately in traffic shaping policies.

378
Multi-Selectmedium

An administrator is configuring an IPsec VPN between two FortiGates using IKEv1. The tunnel must use main mode and support multiple subnets behind each gate. Which Phase2 settings are required to allow multiple subnets? (Choose two.)

Select 2 answers
A.Set the Phase2 keylife to a higher value
B.Set the Phase2 proposal to include multiple encryption algorithms
C.Create multiple Phase2 selectors, each with different local and remote subnets
D.Enable NAT traversal on the Phase2
E.Use address objects that contain multiple subnets in the Phase2 definition
AnswersC, E

Each Phase2 selector defines exactly one local subnet and one remote subnet pair for a given security association. Creating multiple Phase2 entries under the same Phase1 lets you assign different subnet pairs to the same tunnel, allowing the FortiGate to pick the matching SA for each traffic flow. This is the standard, granular method for supporting multiple subnets across a single IPsec tunnel.

Why this answer

IKEv1 main mode requires that each pair of local and remote subnets be defined in its own Phase2 selector. This allows the VPN to establish separate security associations (SAs) for each subnet pair, enabling multiple subnets behind each FortiGate. Option E is also correct because using address objects that contain multiple subnets (e.g., a subnet group or address range) in a single Phase2 definition is a supported method to negotiate a single SA covering all those subnets, reducing the number of Phase2 selectors needed.

Exam trap

The trap here is that candidates often confuse Phase2 settings (like encryption algorithms or keylife) with the mechanism for defining multiple subnets, leading them to select options that affect security or performance rather than subnet selection.

379
MCQmedium

An administrator is troubleshooting a FortiGate HA cluster that is experiencing frequent failovers. The heartbeat interfaces are configured on port1 and port2. Which diagnostic command should the administrator use to check heartbeat packet loss?

A.diagnose sys ha status
B.get system ha status
C.diagnose sys ha heartbeat
D.diagnose sys session list
AnswerC

This command queries the HA daemon's internal statistics and specifically reports the number of consecutive sent and received heartbeat packets as well as the computed packet loss rate. It is the only command in this list that directly measures the reliability of the heartbeat link, which is essential for diagnosing intermittent failovers or a split-brain condition. A non-zero loss percentage here indicates a degraded heartbeat path, pointing to physical-layer issues such as bad cables, duplex mismatches, or congested interfaces.

Why this answer

The 'diagnose sys ha heartbeat' command is the dedicated diagnostic tool for inspecting HA heartbeat interface statistics, including packet counts, errors, and loss on the configured heartbeat ports (port1 and port2 in this scenario). It shows per-interface heartbeat traffic details that directly reveal whether heartbeats are being dropped, which is the root cause of frequent failovers. This is the only option that targets heartbeat packet-level diagnostics rather than general HA state.

Exam trap

NSE4 often tests the confusion between HA status commands ('get system ha status', 'diagnose sys ha status') and the heartbeat-specific diagnostic, so candidates pick a status command that shows roles but not packet loss.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys ha status' displays HA cluster status information (member roles, priorities, uptime) but does not provide heartbeat packet loss statistics. Option B is wrong because 'get system ha status' is a configuration/status summary command showing HA mode, group name, and member health, not heartbeat packet counters. Option D is wrong because 'diagnose sys session list' shows the session table for traffic flows and has nothing to do with HA heartbeat interface diagnostics.

380
Multi-Selecthard

A FortiGate is configured in an A-P HA cluster. The administrator wants to ensure that session failover occurs for UDP-based voice traffic. Which TWO settings must be enabled?

Select 2 answers
A.Enable UDP session synchronization.
B.Set HA override to enabled.
C.Enable configuration synchronization.
D.Enable session pickup.
E.Set failover hold time to 1 second.
AnswersA, D

Enabling UDP session synchronization directly instructs the FGCP cluster to replicate UDP session table entries from the primary unit to the standby. Because UDP is connectionless, the standby cannot infer active flows from handshake packets, so without this explicit setting, return traffic for existing UDP conversations will be dropped after failover. This setting is protocol-specific and works alongside session pickup to ensure NAT bindings and idle timers are preserved on the new primary.

Why this answer

UDP session synchronization must be enabled to replicate UDP session state between HA cluster members, ensuring that active sessions for voice traffic (which typically uses UDP) are seamlessly taken over by the standby unit during a failover. Without this setting, UDP sessions are not synchronized by default, and voice calls would drop.

Exam trap

The trap here is that candidates often confuse configuration synchronization (which replicates config files) with session synchronization (which replicates dynamic session state), leading them to incorrectly select Option C instead of A.

381
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. Phase 1 is up, but Phase 2 fails to establish. The debug command 'diagnose vpn ike log' shows: 'no suitable proposal found'. What is the most likely cause?

A.Phase 2 encryption or authentication algorithms do not match on both sides.
B.The firewall policy allowing IPsec traffic is missing.
C.The remote gateway IP address is unreachable.
D.The pre-shared key is incorrect.
AnswerA

Phase 2 (Quick Mode) negotiates the IPsec SA parameters, including the encryption algorithm (e.g., AES-256, 3DES) and authentication algorithm (e.g., SHA-1, SHA-256) for the ESP/AH protocol. If the local and remote firewalls do not offer a common proposal for these algorithms and the Diffie-Hellman group, the Phase 2 negotiation will fail with an error such as 'no proposal chosen.' Since Phase 1 has already formed a secure IKE SA, the problem isolates specifically to a Phase 2 proposal mismatch, preventing the tunnel from establishing even though both gateways are reachable and authenticated.

Why this answer

The 'no suitable proposal found' error in Phase 2 of an IPsec VPN tunnel indicates that the Phase 2 parameters (encryption algorithm, authentication algorithm, or PFS settings) do not match between the two FortiGate peers. Since Phase 1 is up, the IKE SA is established, meaning pre-shared keys, remote gateway reachability, and basic firewall policies for IKE traffic are correct. The mismatch specifically occurs in the Phase 2 proposal negotiation, where each side sends its supported transforms and the responder cannot find a common set.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 proposal errors, assuming any 'no suitable proposal found' message relates to Phase 1, but the context of Phase 1 being up explicitly isolates the issue to Phase 2 parameter mismatch.

How to eliminate wrong answers

Option B is wrong because a missing firewall policy for IPsec traffic would prevent Phase 1 from establishing, as IKE packets (UDP 500/4500) would be dropped; Phase 1 being up confirms the firewall policy is in place. Option C is wrong because if the remote gateway IP address were unreachable, Phase 1 would fail to initiate or complete, as IKE negotiation requires bidirectional reachability. Option D is wrong because an incorrect pre-shared key would cause Phase 1 authentication to fail, resulting in a 'no suitable proposal found' error at Phase 1, not Phase 2; Phase 1 being up confirms the pre-shared key is correct.

382
MCQhard

A FortiGate has a policy-based NAT rule that translates source IPs from subnet 192.168.1.0/24 to 203.0.113.10 when accessing the internet. The admin also enables Central SNAT with a rule that translates the same subnet to 203.0.113.20. If both are configured, which translation will be applied to traffic from 192.168.1.0/24 to the internet?

A.Both translations will be applied, causing an error
B.Central SNAT because it is a global setting
C.The FortiGate will use the translation from the policy with the highest ID
D.Policy-based NAT because it is evaluated first
AnswerD

FortiGate's NAT decision pipeline always evaluates policy-based NAT before Central NAT. When a session matches a firewall policy with an explicit NAT translation, that translation is applied immediately; Central SNAT rules are consulted only after no policy-based NAT rule matched. This design makes the more specific, policy-scoped translation authoritative, which is why traffic flows through the policy-based NAT rule.

Why this answer

Policy-based NAT is evaluated before Central SNAT because it is directly tied to the firewall policy that matches the traffic. When a policy-based NAT rule exists for the same traffic, it takes precedence over Central SNAT rules, regardless of any global settings or rule IDs. Therefore, the source IPs from 192.168.1.0/24 will be translated to 203.0.113.10.

Exam trap

The trap here is that candidates often assume Central SNAT, being a centralized feature, overrides all other NAT rules, but FortiGate explicitly gives policy-based NAT higher precedence for traffic matching a firewall policy.

How to eliminate wrong answers

Option A is wrong because FortiGate does not apply both translations simultaneously; it selects one based on precedence, and policy-based NAT is evaluated first, so no error occurs. Option B is wrong because Central SNAT is not a global setting that overrides policy-based NAT; policy-based NAT is tied to a specific firewall policy and takes precedence over Central SNAT for that matched traffic. Option C is wrong because the FortiGate does not use the policy ID to determine NAT precedence between policy-based NAT and Central SNAT; policy-based NAT is always evaluated first regardless of ID.

383
Multi-Selectmedium

Which TWO of the following are required for full SSL inspection to work correctly?

Select 2 answers
A.The private key of each server certificate that will be inspected.
B.The FortiGate's CA certificate installed in the Trusted Root Certification Authorities store on client machines.
C.An intermediate CA certificate imported from the enterprise PKI.
D.A certificate on the FortiGate to generate session certificates.
E.A certificate signed by a public CA installed on the FortiGate.
AnswersB, D

This is a mandatory step because the FortiGate signs every session certificate it sends to clients using its own CA. Without adding that CA certificate to the Trusted Root Certification Authorities store, clients will reject the presented certificate as untrusted and display SSL errors or refuse the connection. This trust installation must be performed on every client that will have its traffic inspected, typically via Group Policy or MDM.

Why this answer

For full SSL inspection, the FortiGate must generate a session certificate on-the-fly for each HTTPS connection after decrypting it. This requires a CA certificate on the FortiGate to sign those session certificates. Additionally, client machines must trust this CA certificate, so it must be installed in their Trusted Root Certification Authorities store; otherwise, browsers will show certificate warnings and block the connection.

Exam trap

The trap here is that candidates often think the FortiGate needs the server's private key (Option A) to decrypt traffic, but in reality, full SSL inspection uses a man-in-the-middle approach where the FortiGate generates its own session certificates, requiring only its own CA certificate and client trust.

384
Multi-Selecthard

An administrator is troubleshooting why an application control profile is not detecting a custom application that uses a non-standard port. The administrator wants to ensure the application is properly identified. Which THREE steps should the administrator take? (Choose three.)

Select 3 answers
A.Set the application control action to 'block' for the application
B.Add a custom application signature based on the traffic pattern
C.Disable flow-based inspection and use proxy-based only
D.Ensure the application control profile is applied to the correct firewall policy
E.Enable SSL deep inspection if the application uses encryption
AnswersB, D, E

If the application is not covered by any built-in FortiGuard signature, the administrator should create a custom application signature based on the traffic's unique pattern. On FortiGate, this is done by defining a custom signature using attributes such as protocol, port, IP, or content-matching criteria in the application control profile. This directly adds detection capability for the unrecognized application, allowing it to be identified and controlled. Without a signature, the application remains invisible to the security inspection.

Why this answer

Option B is correct because application control can only identify a custom application on a non-standard port if a custom application signature is created that matches its traffic pattern, since the default signature database will not recognize it. Option D is correct because an application control profile only takes effect when it is attached to the firewall policy that handles the traffic; if it is applied to the wrong policy, the custom application will never be inspected or detected. Option E is correct because if the custom application's traffic is encrypted with SSL/TLS, the firewall cannot see the application-layer data needed for identification unless SSL deep inspection is enabled to decrypt and inspect it.

Option A is incorrect because setting the action to 'block' only controls what happens after identification and does nothing to help the firewall recognize the application. Option C is incorrect because disabling flow-based inspection and using proxy-based only is not a required step for identifying a custom application and may not even be supported or desirable in all deployments.

Exam trap

The trap is focusing on enforcement actions (like block) or inspection modes instead of the necessary steps for detection: custom signatures, correct policy application, and SSL inspection for encrypted traffic.

385
MCQhard

An admin configures a policy-based NAT rule (central SNAT) to translate source IPs from 10.0.0.0/24 to a dynamic IP pool of 203.0.113.1-203.0.113.10 with overload enabled. Users report that some connections are dropped. What is the MOST likely cause?

A.The port range for each IP in the pool is exhausted
B.The firewall policy has 'set nat enable' disabled
C.The route to the internet is missing
D.The pool does not have enough IPs to cover all users
AnswerA

With overload, each pool IP has a finite port range; once all ports on all ten addresses are consumed by concurrent sessions, new connections cannot be translated and are dropped. Exhaustion of that port range is the likely cause.

Why this answer

With overload enabled (Port Address Translation), the firewall translates multiple internal IPs to a single public IP by using unique source ports. Each public IP can handle up to 65,535 ports, but the actual usable port range is often smaller due to reserved ports and system limits. When all ports on all IPs in the pool are consumed, new connections are dropped because no port can be allocated for the translation.

Exam trap

The trap here is that candidates assume the pool must have enough IPs for each user, but overload (PAT) allows many users to share a single IP, so the real bottleneck is port exhaustion, not IP count.

How to eliminate wrong answers

Option B is wrong because 'set nat enable' is a legacy setting for policy-based NAT; central SNAT rules do not require this option to be enabled on the firewall policy. Option C is wrong because a missing internet route would cause all outbound traffic to fail, not just some connections being dropped. Option D is wrong because dynamic IP pools with overload do not require one IP per user; the issue is port exhaustion, not a lack of IP addresses.

386
MCQmedium

An administrator runs 'diagnose vpn ike config' and sees the output includes 'P2 proposals: aes128-sha256, aes256-sha1'. What does this indicate?

A.The Diffie-Hellman groups for Phase 2
B.The Phase 1 encryption settings
C.The Phase 2 encryption and authentication algorithms
D.The lifetime settings for the VPN tunnel
AnswerC

The 'diagnose vpn ike config' command in FortiOS prints the Phase 2 proposal, which lists the exact ESP (Encapsulating Security Payload) transforms: the encryption algorithm (e.g., AES-GCM, AES-CBC) and the authentication/integrity algorithm (e.g., SHA-256, SHA-1). This is precisely what the administrator sees in the output, making it the correct answer. It reflects the algorithms that will be used for the actual IPsec data tunnel.

Why this answer

The output 'P2 proposals: aes128-sha256, aes256-sha1' from the 'diagnose vpn ike config' command specifically lists the Phase 2 (IPsec) proposals, which define the encryption and authentication algorithms used for protecting data traffic. Option C is correct because these are the Phase 2 encryption (aes128, aes256) and authentication (sha256, sha1) algorithms, not Phase 1 settings or other parameters.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 parameters, assuming 'P2 proposals' includes Diffie-Hellman groups or lifetimes, when in fact it only specifies the encryption and authentication algorithms for the IPsec SA.

How to eliminate wrong answers

Option A is wrong because Diffie-Hellman groups for Phase 2 are not listed in this output; DH groups are typically configured in Phase 1 (IKE) and optionally in Phase 2 for PFS, but the output shows only encryption and authentication algorithms, not DH group identifiers. Option B is wrong because Phase 1 encryption settings are shown under 'P1 proposals' or similar fields in the command output, not under 'P2 proposals', which is explicitly for Phase 2. Option D is wrong because lifetime settings for the VPN tunnel (e.g., 3600 seconds or 100 MB) are displayed separately in the output, often under 'P2 lifetime' or 'IPsec SA lifetime', not in the 'P2 proposals' line.

387
MCQhard

An administrator uses 'diagnose sys session list' and sees the following output for a session: 'proto=6 proto_state=01 duration=3600 expire=3599'. The session is for HTTPS traffic. What does 'proto_state=01' typically indicate in FortiGate?

A.The session is being NATted
B.The session is fully established and active
C.The session is in the initial connection setup phase (SYN_SENT)
D.The session is being inspected by a security profile
AnswerC

The proto_state value 0x01 in the output of 'diagnose sys session list' corresponds to the TCP SYN_SENT state, which occurs during the initial connection setup phase. In this phase, the initiator has transmitted a SYN packet and is awaiting the peer's SYN-ACK response, meaning the three-way handshake is incomplete. This is precisely why the session is not fully established and why this is the correct answer.

Why this answer

In FortiGate, 'proto_state=01' for TCP (proto=6) indicates the session is in the SYN_SENT phase, meaning the initial SYN packet has been sent but the three-way handshake is not yet complete. For HTTPS traffic, this shows the session is still in the connection setup stage, not fully established. The 'duration' and 'expire' values reflect the time since the session was created and the remaining timeout, which is typical for an incomplete handshake.

Exam trap

The trap here is that candidates often confuse 'proto_state=01' with a fully established session because they see 'duration' and 'expire' values and assume the session is active, but the state code explicitly indicates the handshake is incomplete.

How to eliminate wrong answers

Option A is wrong because NAT status is indicated by the 'nat' field in the session list output, not by 'proto_state'; 'proto_state=01' is a TCP state code, not a NAT indicator. Option B is wrong because a fully established and active TCP session would show 'proto_state=02' (ESTABLISHED), not '01' (SYN_SENT). Option D is wrong because security profile inspection is shown by flags like 'ips', 'av', or 'app' in the session output, not by the TCP state field; 'proto_state' only reflects the TCP handshake phase.

388
MCQhard

During a firmware upgrade, the FortiGate reboots and the administrator cannot access the GUI via HTTPS. The CLI shows the system is running the previous firmware. What is the most likely cause?

A.The firmware image was corrupted during upload.
B.The administrator booted from the wrong partition.
C.The administrator did not perform a factory reset before upgrading.
D.The upgrade failed and the system rolled back to the previous firmware.
AnswerD

FortiGate incorporates an automatic rollback mechanism that activates when the newly upgraded firmware fails to boot, fails self-integrity checks, or encounters an incompatible configuration during startup. In such cases, the bootloader automatically falls back to the previously known-good partition and reboots the system using the prior firmware, ensuring availability. The observed reboot followed by a return to the previous version is the textbook signature of this controlled rollback after a failed upgrade attempt.

Why this answer

FortiGate firmware upgrades include an automatic rollback mechanism. If the upgrade fails or the new firmware does not boot successfully, the system automatically reverts to the previous firmware partition during the next reboot. The administrator seeing the previous firmware and being unable to access the GUI indicates the upgrade did not complete successfully, triggering this rollback.

Exam trap

The trap here is that candidates may assume a corrupted image (Option A) is the cause, but FortiGate's automatic rollback mechanism masks the corruption by reverting to the previous firmware, making the symptom appear as if the upgrade never took effect.

How to eliminate wrong answers

Option A is wrong because a corrupted firmware image would typically cause the upgrade process to fail before the reboot, or the system would not boot at all; the rollback mechanism is designed to handle such corruption by reverting to the known good partition. Option B is wrong because FortiGate does not have a manual partition selection during boot; the boot process automatically selects the primary partition, and the rollback mechanism controls which partition is active after a failed upgrade. Option C is wrong because a factory reset is not required before a firmware upgrade; upgrades are performed directly on the running configuration, and a factory reset is only recommended for major version jumps or specific scenarios, not as a prerequisite.

389
MCQeasy

An administrator needs to configure a FortiGate to allow remote management via HTTPS from the internet. Which configuration step is required?

A.Create a firewall policy from WAN to LAN with HTTPS service and set action to ACCEPT.
B.Enable SSH access on the WAN interface instead of HTTPS.
C.Enable HTTPS access on the WAN interface and create a firewall policy allowing inbound HTTPS from any to the FortiGate's IP.
D.Configure a port forwarding rule to redirect HTTPS from WAN to the internal management IP.
AnswerC

HTTPS management requires two things: administrative access enabled on the WAN interface itself, plus an explicit firewall policy permitting inbound TCP 443 to the FortiGate's IP. Without the policy, the implicit deny drops the traffic even when HTTPS access is enabled.

Why this answer

Remote HTTPS management of a FortiGate from the internet requires two steps: enabling HTTPS access on the WAN interface (under config system interface) and creating a firewall policy that allows inbound HTTPS traffic (TCP/443) from any source to the FortiGate's own IP address. Without the explicit policy, the traffic is dropped by the implicit deny rule, even if the interface is configured to listen for HTTPS.

Exam trap

The trap here is that candidates assume enabling HTTPS on the interface alone is sufficient, forgetting that FortiGate still requires an explicit firewall policy to permit inbound traffic to its own IP, as the implicit deny rule blocks all traffic not matched by a policy.

How to eliminate wrong answers

Option A is wrong because a firewall policy from WAN to LAN with HTTPS service would forward management traffic to internal LAN hosts, not to the FortiGate itself, and does not enable the WAN interface to accept HTTPS connections. Option B is wrong because enabling SSH instead of HTTPS does not satisfy the requirement to allow remote management via HTTPS; SSH and HTTPS are separate protocols with different purposes. Option D is wrong because port forwarding is used to redirect traffic to internal servers behind the FortiGate, not to the FortiGate's own management interface; the FortiGate's management IP is directly reachable on the WAN interface when HTTPS access is enabled and a policy is in place.

390
MCQeasy

In Fortinet ZTNA, what is the primary purpose of the ZTNA access proxy component?

A.To act as a forward proxy for web traffic
B.To provide load balancing for multiple FortiGates
C.To proxy connections to internal applications after authentication and device verification
D.To terminate IPsec VPN tunnels
AnswerC

This is the correct function: the ZTNA access proxy acts as a reverse proxy that terminates client requests to internal applications, enforcing authentication (often via SAML/OIDC) and device verification (via FortiClient EMS) before proxying the connection to the actual application server. This creates a zero-trust access model where access is granted per application, per user, and per device, rather than allowing broad network-level connectivity.

Why this answer

The ZTNA access proxy is the core component that mediates user access to internal applications. It intercepts client requests, enforces authentication and device posture checks (via FortiClient telemetry), and then proxies the connection to the protected application. This ensures no direct network access is granted; all traffic must pass through the proxy, which validates trust before forwarding.

Exam trap

The trap here is that candidates confuse the ZTNA access proxy with a forward proxy or VPN concentrator, but Fortinet specifically designed it as a reverse proxy for internal application access, not for general web proxying or tunnel termination.

How to eliminate wrong answers

Option A is wrong because the ZTNA access proxy is a reverse proxy that protects internal applications, not a forward proxy that handles outbound web traffic from clients to the internet. Option B is wrong because load balancing between FortiGates is handled by FortiGate's built-in SD-WAN or external load balancers, not by the ZTNA access proxy component. Option D is wrong because IPsec VPN termination is a separate function of the FortiGate's VPN module, unrelated to the ZTNA access proxy's role in proxying application-layer connections.

391
MCQhard

An administrator configures a dial-up IPsec VPN with IKEv1 main mode. Remote clients can connect successfully, but the administrator notices that the Phase 1 negotiation takes a long time. Which change would most improve the negotiation speed without compromising security?

A.Switch from main mode to aggressive mode
B.Reduce the IKE SA lifetime
C.Increase the number of Phase 1 proposals
D.Enable IKEv2 instead of IKEv1
AnswerD

IKEv2 replaces the 6-message main mode exchange with a compact 4-message exchange by combining SA negotiation and key derivation, and then performing authentication with the same two messages. This halves the round-trip time in the common no-NAT case and also reduces the number of packets that must be processed in parallel. Additionally, IKEv2 supports built-in NAT traversal, and is more resilient to errors because each pair of messages is cryptographically tied together, providing a faster and more robust negotiation than IKEv1 main mode.

Why this answer

IKEv2 reduces Phase 1 negotiation time by using a single exchange of two messages (request/response) instead of IKEv1 main mode's six messages. This eliminates the extra round trips required for identity protection and SA negotiation, speeding up the process without reducing security. The question specifies IKEv1 main mode, so switching to IKEv2 directly addresses the slow negotiation while maintaining strong cryptographic protections.

Exam trap

The trap here is that candidates often choose aggressive mode (Option A) because it reduces round trips, but they overlook that it sends the peer identity in cleartext, which violates the security requirement in the question.

How to eliminate wrong answers

Option A is wrong because aggressive mode reduces round trips but sends the peer's identity in cleartext before the tunnel is established, compromising security by exposing the identity to eavesdroppers. Option B is wrong because reducing the IKE SA lifetime does not speed up initial Phase 1 negotiation; it only causes more frequent rekeying, which can actually increase overall negotiation overhead. Option C is wrong because increasing the number of Phase 1 proposals forces the initiator to attempt more combinations during negotiation, which can slow down the process rather than speed it up.

392
MCQhard

A FortiGate administrator has configured a firewall policy with source NAT using an IP pool that contains two IP addresses: 203.0.113.10 and 203.0.113.11. The pool type is set to 'Overload'. The administrator notices that some outbound connections are failing, and when checking the session table, sees that many sessions are using the same source IP and port. What is the most likely cause of the connection failures?

A.The IP pool is configured with the wrong netmask, causing the FortiGate to incorrectly calculate the available addresses.
B.The FortiGate is running out of available source ports because too many sessions are being translated to the same IP address.
C.The IP pool is configured as 'Overload', which only allows one IP address to be used; the second IP is ignored.
D.The firewall policy is using the wrong outgoing interface, so the NAT pool is not being applied correctly.
AnswerB

This is correct because with an 'Overload' IP pool, multiple sessions can be mapped to the same IP address, but each session requires a unique source port. The FortiGate has a limited number of ports per IP (approximately 64,000). If the number of concurrent sessions exceeds the available ports, new connections will fail. The administrator should consider adding more IP addresses to the pool or using a different NAT type.

Why this answer

An 'Overload' IP pool allows multiple sessions to share the same IP address by using different source ports. However, each IP address has a finite number of ports (about 64,000). If the number of concurrent sessions exceeds this limit, new connections will fail because no ports are available.

The solution is to add more IP addresses to the pool or use a different NAT configuration. This is a common issue in environments with high session counts.

Exam trap

The trap here is assuming that an 'Overload' IP pool with multiple IPs will automatically distribute sessions evenly, when in fact it uses one IP until ports are exhausted before moving to the next.

393
MCQmedium

A network admin configures an IPsec VPN between two FortiGates using IKEv2. Phase 1 completes successfully, but Phase 2 fails to establish. The admin runs 'diagnose vpn ike log' and sees the error 'proposal mismatch'. What is the most likely cause?

A.The IKE version is not compatible
B.The Phase 2 selectors (local and remote subnets) are misconfigured
C.The Phase 2 encryption and authentication algorithms do not match
D.The pre-shared keys do not match
AnswerC

The correct interpretation of the 'proposal mismatch' error is that the Phase 2 encryption and authentication algorithms, or other transform parameters like the PFS Diffie-Hellman group, differ between the two FortiGates. During IKE Phase 2, the initiator sends a list of SA proposals containing encryption algorithms (e.g., AES128/256), integrity algorithms (e.g., SHA1/256), and optionally DH groups for PFS. If none of the responder's configured Phase 2 proposals match any of the initiator's proposals, the responder sends the 'no proposal chosen' or 'proposal mismatch' notification. To resolve this, the Phase 2 transform sets (encryption, authentication, and PFS) must be aligned on both endpoints.

Why this answer

The error 'proposal mismatch' in the 'diagnose vpn ike log' output specifically indicates that the Phase 2 parameters (encryption, authentication, or DH group) do not match between the two FortiGate peers. Since Phase 1 completed successfully, the IKE version (IKEv2) and pre-shared keys are already validated, leaving only the Phase 2 proposal as the cause. Option C correctly identifies that the encryption and authentication algorithms are mismatched, which is the most common reason for this error.

Exam trap

The trap here is that candidates often confuse 'proposal mismatch' with Phase 1 issues or selector mismatches, but the error is specific to cryptographic algorithm negotiation in Phase 2, not to network-layer subnet definitions or authentication credentials.

How to eliminate wrong answers

Option A is wrong because Phase 1 completed successfully, which confirms that both peers are using a compatible IKE version (IKEv2 in this scenario). Option B is wrong because a 'proposal mismatch' error is related to cryptographic parameters, not to the local/remote subnet selectors; a misconfiguration of selectors would typically result in a 'no matching selector' or 'traffic selector mismatch' error, not 'proposal mismatch'. Option D is wrong because pre-shared keys are negotiated during Phase 1 authentication; since Phase 1 succeeded, the PSKs must match, so a PSK mismatch would have prevented Phase 1 from completing.

394
MCQmedium

An administrator wants to view the current session table entries filtered by destination port 443. Which command should be used?

A.diagnose sys session filter dport 443; diagnose sys session list
B.execute session list dport 443
C.diagnose debug flow filter dport 443
D.diagnose sys session list dport 443
AnswerA

The correct workflow in FortiOS for inspecting the session table is to first set a filter with 'diagnose sys session filter dport 443', which configures the current CLI session to show only sessions with a destination port of 443. Then 'diagnose sys session list' prints the matching entries from the kernel session table. This two-step approach lets you combine multiple filter criteria without passing them as command arguments.

Why this answer

FortiGate session table inspection uses the 'diagnose sys session filter' command to set filter criteria (such as dport 443), followed by 'diagnose sys session list' to display matching entries. This two-step filter-then-list pattern is the correct syntax.

Exam trap

NSE4 often tests whether candidates confuse 'diagnose sys session filter/list' (session table inspection) with 'diagnose debug flow filter' (real-time packet debugging), leading them to pick the debug flow command.

How to eliminate wrong answers

Option B is wrong because 'execute session list' is not a valid FortiGate command — session inspection is done via 'diagnose sys session,' not 'execute.' Option C is wrong because 'diagnose debug flow filter' is used for real-time packet flow debugging, not for viewing existing session table entries. Option D is wrong because 'diagnose sys session list dport 443' is invalid syntax — the filter must be set separately with 'diagnose sys session filter' before listing.

395
MCQeasy

Which log severity level indicates that a device is unusable and requires immediate attention?

A.Error
B.Critical
C.Emergency
D.Alert
AnswerC

Emergency (severity 0) is the highest syslog severity level and specifically denotes that the system is unusable. On FortiGate, this log is generated when a fatal condition halts operations, such as a kernel panic or a catastrophic disk failure that prevents booting. Unlike lower severities, Emergency means the device cannot perform its security functions or be administered until it is restarted or repaired.

Why this answer

FortiGate log severity levels are: Emergency (0), Alert (1), Critical (2), Error (3), Warning (4), Notification (5), Information (6), Debug (7). Emergency is the highest severity, indicating the system is unusable.

396
MCQmedium

A FortiGate administrator has enabled central NAT (policy-based NAT) in the VDOM. They need to translate all outbound traffic from the internal subnet 192.168.1.0/24 to the FortiGate's WAN interface IP when it leaves the network. Where must the NAT configuration be referenced in the firewall policy?

A.Enable NAT in the firewall policy and select the central SNAT rule from the NAT dropdown.
B.Create an IP pool with the WAN IP and apply it as the NAT IP in the firewall policy, then disable central NAT.
C.Configure a virtual IP (VIP) for the internal subnet and reference it in the firewall policy as the source.
D.Create a central SNAT rule that matches the source subnet and outgoing interface, and ensure the firewall policy has no NAT configuration.
AnswerD

With central NAT enabled, SNAT is handled by central SNAT rules that are evaluated independently of firewall policies. The firewall policy itself must not have NAT enabled; it simply allows the traffic. The central SNAT rule matches source and destination criteria and performs the translation. This is the correct configuration for policy-based NAT in FortiOS.

Why this answer

When central NAT is enabled, the FortiGate uses central SNAT rules instead of per-policy NAT. The firewall policy references the central SNAT rule implicitly by matching traffic; the policy itself must not have NAT enabled. The central SNAT rule defines the source and destination criteria and the translation.

This separation simplifies management and avoids conflicting NAT configurations.

Exam trap

The trap here is assuming that NAT must still be enabled in the firewall policy even when central NAT is enabled, which is not the case.

397
MCQmedium

An organization uses FortiSandbox to detect advanced threats. The administrator wants to ensure that files downloaded from the internet are sent to FortiSandbox for analysis before being delivered to users. Which Antivirus profile setting should be configured?

A.Enable 'Inline Scan' for FortiSandbox
B.Enable 'FortiSandbox Monitoring'
C.Enable 'FortiSandbox Quarantine'
D.Set 'Scan Mode' to 'Quick'
AnswerA

Inline Scan mode on FortiGate's FortiSandbox integration causes the firewall to submit a file to the sandbox and temporarily buffer the client's request until a verdict is returned. Only a 'clean' verdict releases the file to the end user; malicious or suspicious files are blocked and quarantined. This is the only mode that guarantees the file is not delivered before analysis completes, making it essential for preventing zero-day infections in real time.

Why this answer

To ensure files downloaded from the internet are sent to FortiSandbox for analysis before delivery to users, the 'Inline Scan' option for FortiSandbox must be enabled in the Antivirus profile. This setting causes the FortiGate to hold the file, send it to FortiSandbox, and only deliver it to the user after receiving a verdict (e.g., clean or malicious). Without inline scanning, files are delivered first and scanned asynchronously, which defeats the 'before delivery' requirement.

Exam trap

The trap here is that candidates confuse 'Inline Scan' with 'FortiSandbox Monitoring' or 'Quarantine', thinking any FortiSandbox-related option will send files before delivery, but only 'Inline Scan' enforces the synchronous hold-and-scan behavior required by the question.

How to eliminate wrong answers

Option B is wrong because 'FortiSandbox Monitoring' is not a valid setting in the Antivirus profile; it refers to a feature in the FortiSandbox itself for monitoring submissions, not a FortiGate profile option. Option C is wrong because 'FortiSandbox Quarantine' is not a setting in the Antivirus profile; quarantine actions are configured separately (e.g., in the FortiSandbox or via quarantine policies) and do not control whether files are sent for analysis before delivery. Option D is wrong because setting 'Scan Mode' to 'Quick' only affects the local scanning depth (e.g., file size or archive depth) and has no impact on FortiSandbox submission behavior; it does not enable inline sandboxing.

398
MCQmedium

A network administrator has configured a firewall policy allowing traffic from the internal network (10.0.0.0/8) to the internet. Users report that some websites are not loading. The administrator runs 'diagnose firewall iprope list 100000' and sees the policy listed with a hit count of zero. What is the MOST likely cause?

A.The source interface or destination interface is incorrectly configured
B.The policy has a schedule that does not match the current time
C.The policy is placed below a more specific or broader policy that matches the same traffic
D.The FortiGate has a routing issue preventing traffic from reaching the internet
AnswerC

FortiGate firewall policies are evaluated top-down and the first policy that matches all configured criteria (source, destination, interface, and service) is executed; lower policies are never reached if a higher policy matches the same traffic. This means a broader policy placed above this specific rule—for example, an any-to-any policy—will shadow it, causing this rule's hit count to remain zero. Since FortiGate uses first-match rather than best-match, rule ordering is critical, and moving this rule above the broad policy would restore its visibility and hit count.

Why this answer

A hit count of zero indicates the firewall policy has never matched any traffic. When a more specific or broader policy exists above it in the sequence, the FortiGate processes policies top-down and stops at the first match, so the lower policy never gets evaluated. This is the most likely cause given that the policy is present but unused.

Exam trap

The trap here is that candidates often assume a zero hit count means the policy is not working due to misconfiguration or routing, but the real issue is policy ordering and the top-down match-first behavior of FortiGate firewalls.

How to eliminate wrong answers

Option A is wrong because if the source or destination interface were misconfigured, the traffic would not match any policy at all, but the administrator would likely see hits on other policies or no hits anywhere, not specifically zero on this policy while other policies may have hits. Option B is wrong because a schedule mismatch would prevent the policy from being active, but the policy would still appear in the rule list with a hit count of zero; however, the question states users can reach some websites, implying some traffic is passing, which would not be the case if a schedule were blocking all traffic through this policy. Option D is wrong because a routing issue would prevent traffic from reaching the internet entirely, but users report only some websites are not loading, indicating partial connectivity, and routing issues would affect all internet-bound traffic, not just specific sites.

399
MCQmedium

An organization wants to send FortiGate logs to a central log management system for long-term storage and compliance. Which FortiGate feature is specifically designed for collecting and analyzing logs from multiple FortiGate devices?

A.Disk logging
B.FortiGuard
C.FortiCloud
D.FortiAnalyzer
AnswerD

FortiAnalyzer is Fortinet's dedicated log management and analysis appliance, purpose-built to aggregate logs from FortiGate and other Fortinet devices to a central location. It provides high-capacity storage, real-time search, reporting, and event correlation, making it the standard for enterprise centralized logging. Configuring FortiGate to send logs to FortiAnalyzer via the FortiGate's log settings or Security Fabric fully meets the organization's central log collection need.

Why this answer

FortiAnalyzer is Fortinet's dedicated centralized logging, analysis, and reporting appliance (physical or virtual) designed to collect logs from multiple FortiGate devices, FortiSwitches, FortiAPs, and other Fortinet products. It provides long-term storage, compliance reporting, and advanced analytics such as event correlation and security fabric rating. Unlike local disk logging, FortiAnalyzer aggregates logs from many devices into a single repository, making it the correct choice for centralized log management.

Exam trap

NSE4 often tests the distinction between local logging (disk logging) and centralized logging (FortiAnalyzer), and candidates may confuse FortiCloud with FortiAnalyzer because both offer cloud-based log storage; however, FortiAnalyzer is the dedicated on-prem or virtual appliance for multi-device log collection and analysis.

How to eliminate wrong answers

Option A is wrong because disk logging refers to storing logs locally on the FortiGate's internal disk or a connected USB drive, which is limited to that single device and not designed for central collection from multiple FortiGates. Option B is wrong because FortiGuard is a suite of subscription-based security services (e.g., antivirus, IPS, web filtering) that provide threat intelligence and updates, not a log management system. Option C is wrong because FortiCloud is a cloud-based management and logging service that can collect logs, but it is not specifically designed for multi-device log aggregation and analysis in the same way as FortiAnalyzer; FortiCloud is more focused on management and basic logging for smaller deployments, whereas FortiAnalyzer is the dedicated enterprise-grade solution.

400
Multi-Selecthard

Which THREE steps are necessary when configuring SSL deep inspection on FortiGate? (Choose three.)

Select 3 answers
A.Add a static route to the internet.
B.Create an SSL inspection profile defining the inspection mode.
C.Configure a forward proxy server.
D.Apply the SSL inspection profile to a firewall policy.
E.Generate or import a CA certificate on FortiGate.
AnswersB, D, E

The SSL/SSH inspection profile is where you choose between certificate inspection (which looks only at the server certificate) and full SSL inspection (which decrypts, inspects, and re-encrypts traffic). It also lets you configure actions for invalid certificates, expired ones, and whether to inspect specific protocols like HTTPS or SMTPS. Without creating such a profile, there is no definition of how deep inspection should behave, making it a necessary first step.

Why this answer

An SSL inspection profile defines how FortiGate handles encrypted traffic, including the inspection mode (e.g., full or certificate-inspection). This profile is a mandatory component for deep inspection, as it specifies whether to decrypt, re-encrypt, or simply examine certificates.

Exam trap

The trap here is that candidates often confuse general network configuration steps (like static routes) with SSL inspection-specific steps, or mistakenly think a separate forward proxy server must be configured, when in fact FortiGate handles the proxy role internally.

401
MCQmedium

What is the primary advantage of using IKEv2 over IKEv1 for IPsec VPN?

A.IKEv2 has built-in support for NAT traversal and MOBIKE
B.IKEv2 supports only main mode
C.IKEv2 requires aggressive mode
D.IKEv2 is only for route-based VPN
AnswerA

IKEv2 natively integrates NAT traversal and MOBIKE, letting a tunnel survive IP address changes when a device roams between networks. IKEv1 requires separate NAT-T negotiation and lacks MOBIKE entirely, so sessions break on address change. This directly satisfies the stem's demand for IKEv2's primary advantage over IKEv1.

Why this answer

IKEv2 offers built-in NAT traversal (NAT-T) and MOBIKE (RFC 4555) as core features, not optional extensions. This eliminates the need for separate RFC 3947 NAT-T configuration and allows seamless IP address changes during a VPN session, making it far more robust for mobile users and dynamic environments compared to IKEv1.

Exam trap

The trap here is that candidates often confuse IKEv2's single exchange with 'main mode only' or think it requires aggressive mode, when in fact IKEv2 eliminates both modes and uses a more efficient, secure handshake.

How to eliminate wrong answers

Option B is wrong because IKEv2 does not support only main mode; it uses a single, streamlined exchange (two pairs of messages) that replaces both main and aggressive modes from IKEv1. Option C is wrong because IKEv2 does not require aggressive mode; aggressive mode is an IKEv1 concept that IKEv2 eliminates entirely for security reasons. Option D is wrong because IKEv2 is not limited to route-based VPNs; it supports both policy-based and route-based IPsec VPN configurations in FortiOS.

402
Multi-Selecthard

A company sets up a hub-and-spoke IPsec VPN where all spokes must communicate through the hub. The hub uses policy-based IPsec. Which THREE configurations are required on the hub to allow spoke-to-spoke traffic? (Select three.)

Select 3 answers
A.Configure IKEv2 instead of IKEv1
B.Separate phase2 selectors defining traffic between each pair of spokes
C.Static routes for each spoke's subnet pointing to the respective VPN interface
D.Firewall policies allowing traffic from each spoke's interface to the other spoke's interface
E.Enable NAT on the hub for spoke-to-spoke traffic
AnswersB, C, D

A policy-based IPsec VPN relies on phase2 selectors (proxy IDs) to define exactly which source and destination subnet pairs are protected by a given SA. When the hub receives traffic from Spoke A destined for Spoke B, the hub performs a route lookup and then matches the traffic against its phase2 selectors to determine which IPsec tunnel and SA to use. Without a selector covering the Spoke-A-to-Spoke-B pair—or a broad selector like 0.0.0.0/0 for all subnets—the hub has no matching SA and will drop the traffic or send it unencrypted, depending on the firewall policy. This is the root requirement for hub-and-spoke spoke-to-spoke connectivity.

Why this answer

In a hub-and-spoke policy-based IPsec VPN, the hub must have separate phase2 selectors for each spoke-to-spoke traffic flow because policy-based VPNs define encryption domains per pair of subnets. Without these selectors, the hub cannot match spoke-to-spoke traffic to a specific IPsec SA, and the traffic will be dropped or sent unencrypted.

Exam trap

The trap here is that candidates often think enabling NAT or changing IKE version will solve the routing or encryption issue, but the core requirement is the phase2 selectors and proper routing/firewall policies to allow the hub to forward and encrypt inter-spoke traffic.

403
MCQmedium

An administrator needs to allow SSH access to the FortiGate's management interface from a specific management subnet (10.0.1.0/24). Which configuration achieves this?

A.Set the administrative access profile to allow SSH from any IP
B.Configure a firewall policy to allow SSH from 10.0.1.0/24 to the FortiGate
C.Under system admin settings, set the trusted host for the administrator to 10.0.1.0/24 and enable SSH access
D.Create a local-in policy to allow SSH from 10.0.1.0/24
AnswerC

This is the standard and correct method: in the System > Admin > Administrators settings, define a trusted host as 10.0.1.0/24 for that administrator, and ensure SSH is enabled in the administrative access for the interface the admin connects to. Trusted hosts explicitly allowlist the source IP ranges that can initiate management sessions, so only devices from 10.0.1.0/24 can SSH to the FortiGate. Additionally, SSH administrative access must be enabled on the relevant interface for the login to be accepted.

Why this answer

The trusted host setting under system admin settings restricts administrative access (including SSH) to only the specified source IP or subnet. By setting the trusted host to 10.0.1.0/24 and enabling SSH access, the FortiGate ensures that only SSH connections originating from that management subnet can reach the management interface. This is the standard method for controlling administrative access to the FortiGate's management plane.

Exam trap

The trap here is that candidates often confuse firewall policies (which control transit traffic) with administrative access controls (which control traffic destined to the FortiGate itself), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because setting the administrative access profile to allow SSH from any IP would permit SSH connections from all sources, not just the specific management subnet, violating the requirement. Option B is wrong because firewall policies control traffic passing through the FortiGate between interfaces, not traffic destined to the FortiGate itself; administrative access is governed by administrative access settings and trusted hosts, not firewall policies. Option D is wrong because local-in policies are used to filter traffic destined to the FortiGate's own IP addresses, but they are not the primary or recommended method for restricting administrative access; the trusted host setting is the correct and simpler approach for this purpose.

404
MCQmedium

A FortiGate is operating in transparent mode. The admin needs to allow HTTP traffic from users to a web server. Which type of firewall policy is required?

A.A layer 2 firewall policy
B.A policy-based NAT rule
C.A firewall policy using zone-based security
D.A VIP policy to map the web server's public IP
AnswerA

In transparent mode, the FortiGate acts as a transparent bridge (bump in the wire) and does not route IP traffic, so all traffic control must occur at Layer 2. A layer 2 firewall policy inspects and forwards frames based on MAC addresses, VLANs, and other Layer 2 attributes, making it the only policy type that can effectively filter traffic in this deployment. This policy type is required because there is no Layer 3 routing table or IP-based decision-making in transparent mode.

Why this answer

In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding traffic without routing. To allow HTTP traffic from users to a web server, a Layer 2 firewall policy is required because it filters traffic based on MAC addresses and Layer 2 headers, not IP addresses or routing decisions. This policy type is the only one that works in transparent mode, as it does not involve NAT or routing.

Exam trap

The trap here is that candidates often assume firewall policies always involve IP addresses and routing, but in transparent mode, the FortiGate uses Layer 2 policies that operate at the data link layer, not the network layer.

How to eliminate wrong answers

Option B is wrong because policy-based NAT rules are used in NAT/route mode to translate IP addresses, not in transparent mode where the FortiGate does not perform IP routing or NAT. Option C is wrong because zone-based security policies are applicable in NAT/route mode for grouping interfaces into zones; transparent mode uses Layer 2 policies, not zones. Option D is wrong because VIP policies are used for destination NAT in NAT/route mode to map public IPs to private IPs, which is irrelevant in transparent mode where the FortiGate does not perform IP address translation.

405
MCQhard

An administrator is configuring a FortiGate to authenticate users via LDAP. The LDAP server uses a self-signed certificate. When testing the connection, the FortiGate returns an error about certificate validation. Which action should the administrator take to resolve this issue while maintaining security?

A.Disable certificate validation on the FortiGate for LDAP connections.
B.Set the LDAP server to use port 389 with StartTLS and enable certificate validation.
C.Import the LDAP server's CA certificate into the FortiGate's local certificate store and configure the LDAP server to use LDAPS.
D.Configure the LDAP server to use a public CA-signed certificate instead of a self-signed one.
AnswerC

Importing the CA certificate allows the FortiGate to validate the LDAP server's certificate. Using LDAPS ensures encryption. This maintains security by verifying the server's identity. The FortiGate must trust the CA that signed the LDAP server's certificate. This is the correct approach to resolve certificate validation errors while keeping the connection secure.

Why this answer

The certificate validation error occurs because the FortiGate does not trust the self-signed certificate of the LDAP server. Importing the CA certificate into the FortiGate's local store allows it to validate the server's certificate. Configuring LDAPS ensures the connection is encrypted.

This maintains security without disabling validation.

Exam trap

The trap here is choosing to disable certificate validation for convenience, which compromises security, instead of importing the CA certificate to establish trust.

406
MCQmedium

An administrator is configuring a new FortiGate and wants to allow management access from the internal network via HTTPS. The internal interface is port2 with IP 192.168.1.1/24. Which CLI command correctly enables HTTPS administrative access on port2?

A.config firewall policy edit 1 set allowaccess https end
B.config system interface edit port2 set allowaccess https end
C.config system admin edit admin set https enable end
D.config system global set admin-https enable end
AnswerB

This is the correct method to enable HTTPS administrative access on a specific interface. The `config system interface` block enters the interface configuration context, `edit port2` selects the target interface, and `set allowaccess https` adds HTTPS to the list of management protocols permitted on that interface. Without this setting, even if the HTTPS daemon is globally enabled, FortiGate will ignore HTTPS connection attempts on port2 and the administrator would be locked out of that interface.

Why this answer

The `config system interface` command is the proper context to set the `allowaccess` parameter, which controls the administrative protocols (such as HTTPS) permitted on a specific FortiGate interface. By editing port2 and setting `allowaccess https`, the administrator enables HTTPS management access on that interface, allowing internal users to reach the FortiGate's web GUI via 192.168.1.1.

Exam trap

The trap here is that candidates confuse the `allowaccess` parameter (which is set under `config system interface`) with global settings or firewall policies, mistakenly thinking that enabling HTTPS globally or in a policy will grant interface-specific management access.

How to eliminate wrong answers

Option A is wrong because `config firewall policy` is used to define traffic filtering rules between zones, not to enable administrative access on an interface; the `allowaccess` parameter does not exist in firewall policy configuration. Option C is wrong because `config system admin` manages administrator accounts and their permissions, not interface-level protocol access; the `set https enable` command is invalid in this context. Option D is wrong because `config system global` sets global system parameters, and `set admin-https enable` would enable HTTPS for the entire FortiGate, but it does not restrict or allow access on a specific interface like port2; the correct global command for interface-specific access is `set admin-sport` or similar, but the question requires interface-level control.

407
MCQmedium

A network admin receives an alert that the FortiGate disk logs are no longer being written. The admin checks the disk status and sees that the disk is full. However, the admin needs to preserve the logs for compliance purposes. Which action should the admin take to continue logging while preserving the existing logs?

A.Configure log upload to FortiAnalyzer and manually archive current logs, then clear the local disk
B.Increase the log disk quota to allow more logs
C.Delete all logs from the disk and restart logging
D.Compress the existing log files and set a higher compression level for future logs
AnswerA

Offloading new logs to FortiAnalyzer frees local disk space while retaining compliance evidence, and archiving existing logs before clearing preserves them. This satisfies the stem's dual constraint: continue logging and keep the current logs, which simply deleting or disabling logging would violate.

Why this answer

The correct action is to configure log upload to FortiAnalyzer and manually archive the current logs, then clear the local disk. This preserves the logs for compliance by offloading them to an external server, while freeing up disk space to allow new logging to continue. Other options are incorrect: increasing the disk quota does not solve the full issue, deleting logs loses compliance data, and compression alone may not free enough space immediately.

408
MCQhard

A FortiGate administrator runs 'diagnose sys session filter dport 443' followed by 'diagnose sys session list' and sees the following output for a session: src=10.0.1.10 dst=192.168.2.20 sport=12345 dport=443 proto=6 vrf=0 What does the 'proto=6' indicate about this session?

A.The session is using UDP
B.The session is using ESP
C.The session is using TCP
D.The session is using ICMP
AnswerC

TCP, or Transmission Control Protocol, is indeed assigned IP protocol number 6, which is what the session filter output indicates. This is standard across all IP networks, as defined by the IANA protocol numbers. A FortiGate session for applications such as HTTP, SSH, or SMTP would show 'Proto=6' to represent TCP. Therefore, the correct interpretation of the protocol numeral in the diagnostic output is that the session is using TCP as its transport layer protocol.

Why this answer

In IP protocol numbers, 6 represents TCP. The session output shows proto=6, which means the session is using TCP. This is consistent with dport=443, the standard HTTPS port over TCP.

The FortiGate session table uses IANA protocol numbers to identify the transport protocol.

Exam trap

NSE4 often tests whether candidates know IANA protocol numbers in session output, trapping those who confuse proto=6 with UDP or assume the protocol from the port number alone.

How to eliminate wrong answers

Option A is wrong because UDP is protocol number 17, not 6. Option B is wrong because ESP (Encapsulating Security Payload) is protocol number 50, not 6. Option D is wrong because ICMP is protocol number 1, not 6.

409
Multi-Selectmedium

An administrator is configuring a firewall policy to allow web traffic from the internal network to the internet. They want to apply security profiles and ensure that only HTTP and HTTPS are allowed. Which two actions are required in the firewall policy configuration? (Choose two.)

Select 2 answers
A.Enable NAT in the policy to translate internal IPs to the outgoing interface address.
B.Attach at least one security profile, such as an antivirus or web filter profile.
C.Set the service to HTTP and HTTPS.
D.Attach an application control profile to the policy.
E.Enable logging of all sessions.
AnswersB, C

The administrator wants to apply security profiles. At a minimum, attaching one security profile (e.g., antivirus, web filter, IPS) is necessary to meet that requirement. This ensures that the traffic is inspected and protected according to the organization's security policy. This is a required action.

Why this answer

To allow only HTTP and HTTPS with security profiles, the policy must specify those services and have at least one security profile attached. These two actions ensure the traffic is limited to web protocols and inspected. NAT and logging are optional depending on network design and policy, and application control is a specific profile that may not be required.

Exam trap

The trap here is assuming that NAT or logging are mandatory for a functional outbound web policy, when they are not required to meet the stated goals.

410
MCQmedium

A FortiGate administrator notices that the HA cluster is frequently failing over even though no hardware failure has occurred. The heartbeat link shows some packet loss. What is the best action to reduce unnecessary failovers?

A.Lower the heartbeat interval
B.Change HA mode to active-active
C.Increase the failover threshold
D.Disable session synchronization
AnswerC

The failover threshold (often called the missed-heartbeat threshold) specifies how many consecutive heartbeat packets from the primary must be lost before the secondary unit declares a failover. Increasing this threshold from the default of 3 to a larger value allows the cluster to tolerate small bursts of packet loss or a momentary HA link issue without triggering a failover. This directly reduces spurious failovers while still detecting a true primary outage if the primary remains silent for a longer period, making it the correct corrective action.

Why this answer

The failover threshold (also called heartbeat loss threshold) determines how many consecutive heartbeat packets must be missed before a failover is triggered. By increasing this threshold, the FortiGate will tolerate more packet loss on the heartbeat link before declaring a failure, thus reducing unnecessary failovers caused by transient network issues. This directly addresses the root cause: intermittent packet loss on the heartbeat link.

Lowering the interval would make the problem worse, and changing HA mode or disabling session sync does not affect failover sensitivity.

Exam trap

NSE4 often tests the misconception that lowering the heartbeat interval improves HA responsiveness, but it actually increases sensitivity to packet loss and can cause more failovers.

How to eliminate wrong answers

Option A is wrong because lowering the heartbeat interval increases the frequency of heartbeat packets, which can exacerbate the issue by causing more missed heartbeats in a lossy network, leading to more failovers. Option B is wrong because changing HA mode to active-active does not affect the failover threshold; it only changes how traffic is distributed, and failover still occurs based on heartbeat loss. Option D is wrong because disabling session synchronization does not impact the failover mechanism; it only affects session state sharing between cluster members, which is unrelated to failover triggers.

411
Multi-Selectmedium

A FortiGate is configured with an application control profile to allow only 'business-approved' applications. Users are still able to use Skype for Business. The admin wants to ensure that only Skype for Business is allowed and other Skype variants are blocked. Which THREE steps should the admin take? (Choose three.)

Select 3 answers
A.Identify the exact application signatures for Skype for Business
B.Apply the application control profile to the firewall policy
C.Enable logging for all traffic to verify the application being used
D.Create a custom application signature for Skype for Business
E.Block all other Skype-related application signatures
AnswersA, B, E

To allow Skype for Business while blocking other Skype variants, you must first identify the exact application signatures that match Skype for Business traffic. The FortiGate application control database includes multiple signatures under the 'Skype' family, such as 'Skype.For.Business' and 'Skype.For.Business.Client', each with specific protocol and port definitions. Choosing the wrong signature could result in inadvertently blocking legitimate business traffic or allowing unauthorized peer-to-peer Skype connections. This step is foundational because the subsequent policy rule and blocking actions depend entirely on precisely matching the intended application.

Why this answer

The admin must first identify the exact application signatures for Skype for Business to distinguish it from other Skype variants. FortiGate's application control uses predefined signatures to classify traffic, and without knowing the specific signature IDs (e.g., 'Skype.For.Business'), the admin cannot selectively allow or block applications in the profile.

Exam trap

The trap here is that candidates may think creating a custom signature (Option D) is necessary when FortiGate already includes the required signatures, or they may confuse logging (Option C) as a configuration step rather than a verification tool.

412
MCQhard

A large enterprise is deploying a FortiGate 600F as the perimeter firewall. The security team requires that all administrative access (SSH, HTTPS, and Ping) to the FortiGate must be restricted to a dedicated management network (10.10.10.0/24). Additionally, any failed login attempt from outside the management network should be logged and the source IP should be blocked for 30 minutes. The administrator has configured a local-in policy to deny all administrative access from non-management networks and enabled logging. However, the administrator wants to automatically block the offending IPs. The FortiGate is not connected to any FortiAnalyzer or FortiManager. What should the administrator do to achieve this?

A.Create an automation stitch that triggers on local-in policy logging and adds the source IP to a blocked list via CLI script.
B.Use a FortiAnalyzer to generate alerts and send to SIEM.
C.Configure a firewall policy to block the offending IPs manually based on logs.
D.Enable 'set block-session-ttl' on the local-in policy.
AnswerA

An automation stitch is the correct approach because it creates an event-triggered workflow: a local-in policy log entry (e.g., 'local-in denial') fires an automation trigger, which then executes a CLI script to add the offending source IP to a configured blocked address list. This provides immediate, autonomous enforcement without waiting for human intervention, and it directly addresses the source IP at the device level.

Why this answer

An automation stitch can directly react to local-in policy log events by executing a CLI script that adds the offending source IP to a local banned user list (e.g., via `diagnose user banned-ip add`). This provides automatic, immediate blocking without requiring external devices like FortiAnalyzer, and the 30-minute duration can be set via the ban-time parameter in the script or the local-in policy's block-session-ttl.

Exam trap

The trap here is that candidates confuse 'block-session-ttl' (which only controls session timeout for already-blocked traffic) with automatic IP banning, or assume external devices like FortiAnalyzer are required when the FortiGate's automation stitch can handle the task locally.

How to eliminate wrong answers

Option B is wrong because the FortiGate is not connected to any FortiAnalyzer or FortiManager, so it cannot rely on external devices to generate alerts or forward logs to a SIEM. Option C is wrong because manually blocking IPs based on logs is not automatic and does not meet the requirement for automatic blocking; it also contradicts the need for a real-time response. Option D is wrong because 'set block-session-ttl' on a local-in policy only controls the session timeout for blocked traffic, not the automatic addition of source IPs to a banned list; it does not trigger a dynamic block action.

413
Multi-Selectmedium

A FortiGate administrator is troubleshooting an SSL VPN issue where remote users cannot access internal resources after successful authentication. Which TWO steps should the admin take to resolve the issue? (Select two.)

Select 2 answers
A.Verify that a firewall policy exists allowing traffic from the SSL VPN interface to the internal network
B.Increase the authentication timeout
C.Check the routing table on the FortiGate to ensure return routes are present
D.Restart the FortiGate
E.Disable the SSL VPN portal
AnswersA, C

In FortiOS, SSL VPN traffic is de-encapsulated onto the ssl.root virtual interface, and a firewall policy must explicitly permit traffic from that interface to the internal network with the correct source address (derived from the tunnel IP pool), destination, and service. Without such a policy, even if the tunnel is established and authentication succeeds, packets will be silently dropped by the FortiGate's security engine. Therefore, verifying the existence and correctness of that policy is the first logical step in troubleshooting connectivity.

Why this answer

After successful SSL VPN authentication, traffic from the remote user must be permitted by a firewall policy that allows traffic from the SSL VPN interface (e.g., ssl.root) to the destination internal network interface. Without this policy, packets are dropped even if authentication succeeds. Option C is correct because the FortiGate must have a route back to the SSL VPN client IP pool (or the client's virtual IP) in its routing table; if the return route is missing, the FortiGate cannot forward reply traffic to the remote user, causing asymmetric routing and connectivity failure.

Exam trap

The trap here is that candidates often assume authentication success guarantees full connectivity, overlooking the mandatory firewall policy and routing requirements that are separate from the authentication process.

414
Drag & Dropmedium

Drag and drop the steps to troubleshoot a user unable to access the internet through FortiGate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Troubleshooting follows a logical flow: policy, NAT, routing, packet capture, then logs.

415
MCQeasy

A network administrator needs to configure a FortiGate to allow HTTPS access to the GUI from the internal network. Which two steps must be performed?

A.Create a firewall policy that permits HTTPS traffic from internal to the FortiGate interface IP.
B.Enable HTTPS administrative access on the internal interface.
C.Disable HTTP administrative access on the internal interface.
D.Enable SSH administrative access on the internal interface.
AnswerA, B

FortiGate evaluates interface-to-interface traffic against firewall policies, so a policy permitting HTTPS from the internal subnet to the FortiGate interface IP is required for GUI access. This satisfies the stem's constraint alongside enabling HTTPS administrative access.

Why this answer

To allow HTTPS access to the GUI from the internal network, two actions are required. First, a firewall policy must be created to permit HTTPS traffic (TCP/443) from the internal network to the FortiGate's interface IP. This can be done via CLI with 'config firewall policy' or through the GUI.

Second, HTTPS administrative access must be enabled on the internal interface. This is configured either via CLI with 'config system interface' and 'set allowaccess https' or by checking 'HTTPS' under Administrative Access in the GUI. Without both steps, GUI access will fail.

Exam trap

The trap here is that candidates often think enabling HTTPS access on the interface alone is sufficient, forgetting that a firewall policy is also required to permit the traffic, or they mistakenly believe disabling HTTP is a prerequisite for HTTPS.

How to eliminate wrong answers

Option C is wrong because disabling HTTP administrative access is not a required step for allowing HTTPS GUI access; it is an optional security hardening step. Option D is wrong because SSH administrative access is used for CLI management, not GUI access, and enabling it does not affect HTTPS GUI connectivity.

416
Multi-Selecteasy

A FortiGate administrator wants to send logs to both a local disk and a remote FortiCloud account. Which two conditions must be met for this to work? (Choose two.)

Select 2 answers
A.The FortiGate must be configured to log to both destinations simultaneously
B.The FortiGate must have a valid FortiCloud subscription
C.The FortiGate must be in NAT mode
D.The FortiGate must have a hard disk or SSD installed
E.The FortiGate must have a policy to allow outbound traffic to FortiCloud
AnswersB, D

A valid FortiCloud subscription is mandatory because FortiCloud logging is a licensed cloud service. The FortiGate must authenticate to FortiCloud's servers using the registered account's credentials and entitlement; without an active subscription, log upload attempts will be rejected even if local disk storage is available. This subscription is a hard prerequisite that cannot be bypassed by configuration alone.

Why this answer

The FortiGate must have local storage (disk) to store logs locally. It also must have connectivity to FortiCloud servers, and logging to FortiCloud must be enabled. The local disk logging is a separate configuration.

417
MCQmedium

An administrator wants to allow users to override a blocked category (e.g., Social Networking) by entering an administrator-defined password. Which of the following must be configured?

A.Configure a DNS filter to bypass the block
B.Create a separate firewall policy with a higher priority that permits the traffic
C.Set the web filter profile to 'Monitor' mode instead of 'Block'
D.Enable 'Override' in the Web Filter profile and configure an authentication scheme
AnswerD

To correctly enable user overrides, you must turn on 'Override' in the Web Filter profile and configure an authentication scheme (e.g., local password or LDAP username/password) so the FortiGate can validate the user who submits the override request. You also need to define an authentication rule that lists which users or groups are allowed to override, and you can optionally set a duration for each override session. Once these are in place, users encountering a blocked page are prompted to enter credentials, and a successful authentication creates a temporary, logged exception that is visible in the override history.

Why this answer

To allow users to override a blocked web category by entering an administrator-defined password, you must enable the 'Override' feature within the Web Filter profile and configure an authentication scheme (e.g., using a local user or LDAP group). This allows users to bypass the block temporarily after authenticating with the defined password, rather than permanently changing the policy or filter mode.

Exam trap

The trap here is that candidates often confuse the Web Filter override with creating a separate firewall policy or changing the filter mode, not realizing that the override is a specific feature requiring both the override toggle and an authentication scheme to be configured within the web filter profile itself.

How to eliminate wrong answers

Option A is wrong because a DNS filter bypasses blocking based on DNS queries, not user authentication or password entry; it would allow all traffic to the domain, not a per-user override. Option B is wrong because creating a separate firewall policy with higher priority would permanently permit the traffic for all matching users, not require a password for temporary override. Option C is wrong because setting the web filter profile to 'Monitor' mode only logs the traffic without blocking it, eliminating the need for an override entirely.

418
MCQeasy

A FortiGate administrator needs to configure a static route to reach a remote network 192.168.100.0/24 via next-hop 10.0.0.1. Which CLI command should be used?

A.config network route edit 1 set ip 192.168.100.0 255.255.255.0 set gateway 10.0.0.1 end
B.config router static edit 1 set dst 192.168.100.0 255.255.255.0 set gateway 10.0.0.1 next end
C.config route static edit 1 set destination 192.168.100.0/24 set next-hop 10.0.0.1 end
D.config router static edit 1 set dst 192.168.100.0/24 set next-hop 10.0.0.1 end
AnswerB

This is the exact FortiOS syntax for a static route. 'config router static' enters the static routing table, 'edit 1' creates or edits the route with sequence number 1, and 'set dst' accepts the destination address followed by subnet mask. 'set gateway' defines the next-hop IP, then 'next' commits the entry and 'end' exits configuration mode. This block is valid and works as intended.

Why this answer

It uses the proper FortiGate CLI syntax for configuring a static route. The command 'config router static' enters the static route configuration context, and 'set dst' specifies the destination network with a subnet mask (not CIDR notation), while 'set gateway' defines the next-hop IP address. This matches the FortiGate CLI structure for static routes.

Exam trap

The trap here is that candidates familiar with Cisco IOS may use 'set destination' or 'set next-hop' (similar to Cisco's 'ip route' command) or CIDR notation, but FortiGate requires 'set dst' with a subnet mask and 'set gateway' for the next-hop, testing knowledge of vendor-specific CLI syntax.

How to eliminate wrong answers

Option A is wrong because 'config network route' is not a valid FortiGate CLI command; FortiGate uses 'config router static' for static route configuration. Option C is wrong because 'config route static' is incorrect syntax; the correct command is 'config router static', and 'set destination' and 'set next-hop' are not valid parameters (FortiGate uses 'set dst' and 'set gateway'). Option D is wrong because while it uses the correct 'config router static' command, it incorrectly uses CIDR notation '192.168.100.0/24' with 'set dst'; FortiGate requires a subnet mask in dotted decimal format (e.g., 255.255.255.0) for the destination.

419
MCQeasy

Which of the following FortiGate log types records information about user authentication and administrative access?

A.Event logs
B.Traffic logs
C.System logs
D.Security logs
AnswerA

Event logs are the correct FortiGate log type for authentication records, as they capture administrative login/logout, user authentication attempts, and enforcement of authentication policies. They also log configuration changes and system policy events, making them the central repository for user-access accountability. For example, both successful and failed logins via the web GUI or SSH are written to the event log with timestamps and source IPs.

Why this answer

Event logs on a FortiGate record system-level and administrative activity, including administrator logins, configuration changes, user authentication events, and system operations. This is the log category that captures both user authentication and administrative access events, making it the correct answer. Traffic logs record session-level data (source/destination, bytes, action), while security logs cover UTM events like IPS and antivirus detections.

Exam trap

NSE4 often tests the confusion between Event logs and System logs — candidates assume 'System logs' is a real FortiGate category when system-level events are actually recorded under Event logs.

How to eliminate wrong answers

Option B is wrong because traffic logs record forwarded, denied, or allowed network sessions with Layer 3/4 details — they do not capture authentication or admin access events. Option C is wrong because 'System logs' is not a distinct FortiGate log category in the FortiView/log-type taxonomy; system-level events are folded into Event logs. Option D is wrong because security logs capture UTM inspection results (IPS, antivirus, web filter, app control) rather than authentication or administrative access records.

420
MCQhard

A FortiGate has two internet connections: port1 (ISP1) and port2 (ISP2). An administrator configures two static default routes with equal distance and priority. Traffic to a specific public IP is observed going out port1, but the admin wants it to go out port2. What should be configured?

A.Use ECMP with source-based hashing
B.Configure a policy route to direct the specific destination to port2
C.Increase the administrative distance of the default route on port1
D.Configure a blackhole route
AnswerB

A policy route is evaluated before the routing table, so matching the specific destination and setting the output interface to port2 overrides the default route for only that traffic. You can specify source, destination, and optionally protocol or port criteria, while all other traffic continues to follow the normal administrative-distance-selected default route. This gives exact policy-based control without affecting other destinations.

Why this answer

Policy routes (also called PBR) override the routing table for specific traffic matches. Since both default routes have equal distance and priority, the FortiGate uses ECMP or the route with the lowest cost by default. A policy route can match the specific destination IP and force the traffic out port2, bypassing the routing table lookup.

Exam trap

The trap here is that candidates assume ECMP or route metrics can selectively steer a single destination, but policy routing is the only method that overrides the routing table for specific traffic without affecting other flows.

How to eliminate wrong answers

Option A is wrong because ECMP with source-based hashing distributes traffic across multiple paths based on source IP, not destination; it would not force a specific destination to a single egress. Option C is wrong because increasing the administrative distance of the default route on port1 would make it less preferred for all traffic, not just the specific destination, breaking load balancing. Option D is wrong because a blackhole route discards traffic matching the destination, preventing it from reaching the public IP entirely.

421
Multi-Selecthard

An administrator is troubleshooting an issue where users cannot access an internal web server via the internet through a FortiGate. The FortiGate has a virtual IP (VIP) configured for the web server. The administrator runs 'diagnose debug flow filter daddr <public-ip>' and 'diagnose debug flow trace start 100'. The output shows 'msg: forward to x.x.x.x via intf port2' but then 'msg: policy deny'. Which TWO actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Ensure that a static route exists to the internet via the WAN interface
B.Check if the public DNS resolution for the domain is correct
C.Confirm that the firewall policy's destination is set to the internal web server's IP address (or the VIP's mapped IP)
D.Verify that the firewall policy allowing the traffic has the correct source interface (WAN)
E.Recreate the virtual IP object with a different port
AnswersC, D

After DNAT, the destination IP changes to the internal server. The firewall policy must allow traffic to that internal IP. If the policy's destination is set to the VIP's public IP, it may not match post-DNAT. The correct approach is to set the destination to the mapped IP address.

Why this answer

Option C is correct because when a VIP is used, the firewall policy must reference the VIP object (or its mapped internal IP) as the destination; if the policy destination is left as 'all' or points to the wrong address, the flow trace will show 'policy deny' even though the packet is forwarded toward port2. Option D is correct because the policy permitting inbound access must match the actual ingress interface (the WAN interface where the public IP is reached); if the source interface is set to the internal/LAN interface or 'any' incorrectly, the policy lookup fails and produces 'policy deny'. Option A is not the issue here since the trace already shows the packet being forwarded out via intf port2, meaning routing toward the server exists and the deny occurs at policy evaluation, not at the routing stage.

Option B is irrelevant because DNS resolution only affects name-to-IP mapping and would not cause a FortiGate policy deny for an already-arriving packet. Option E is unnecessary because the VIP is functioning (traffic is being forwarded), and changing the port would not fix a policy-match failure.

Exam trap

NSE4 often tests the interpretation of 'diagnose debug flow' output, and candidates may focus on routing or DNS instead of recognizing that 'policy deny' points directly to a firewall policy mismatch in source interface or destination address.

422
MCQeasy

An admin wants to allow traffic only from specific countries to access a web server. Which type of address object should be used in the firewall policy?

A.Subnet object
B.Geography object
C.FQDN object
D.Wildcard FQDN object
AnswerB

A geography object in FortiGate is the correct mechanism for country-based access control. It references entries in the built-in geolocation database that classifies IP addresses by country, and when used as a source address in a firewall policy, FortiGate extracts the source IP's country and matches it against the object. This enables the admin to create a policy whose source is a specific country object, thereby restricting traffic to that geographic origin.

Why this answer

The Geography object (also known as a GeoIP object) in FortiGate allows firewall policies to permit or deny traffic based on the source or destination country. This is the correct choice because the requirement is to filter traffic by country, which is exactly what Geography objects are designed for, using IP-to-country mappings maintained by FortiGuard.

Exam trap

The trap here is that candidates may confuse Geography objects with FQDN or Subnet objects, thinking they can achieve country filtering by manually listing IP ranges, but FortiGate's GeoIP feature is the only efficient and accurate method for country-based policies.

How to eliminate wrong answers

Option A is wrong because a Subnet object defines a specific IP address range (e.g., 192.168.1.0/24) and cannot represent an entire country's IP space, which is dynamic and not a single contiguous subnet. Option C is wrong because an FQDN object resolves a fully qualified domain name to IP addresses, but it does not provide country-level filtering; it is used for policies based on domain names. Option D is wrong because a Wildcard FQDN object matches multiple subdomains (e.g., *.example.com) and is unrelated to geographic location filtering.

423
MCQeasy

A FortiGate administrator needs to allow SSH management access from a specific IP address 10.0.0.100. Which configuration is required?

A.Enable SSH on the WAN interface and allow all IPs
B.Set the trusted host for the admin account to 10.0.0.100
C.Configure an access list on the upstream router
D.Create a firewall policy allowing SSH from 10.0.0.100 to the FortiGate
AnswerB

Setting the trusted host for the admin account to 10.0.0.100 is the correct method because FortiGate's trusted-host feature restricts administrative logins to traffic originating from that exact source IP address. When configured, the SSH management daemon will reject authentication attempts from any other IP, regardless of which interfaces have SSH enabled. This provides a precise, per-admin source-IP allowlist that directly matches the requirement to permit only one specific management host.

Why this answer

FortiGate uses the 'trusted host' feature to restrict administrative access to specific source IP addresses. By setting the trusted host to 10.0.0.100 for the admin account, only that IP can initiate SSH sessions to the FortiGate management interface, regardless of which interface SSH is enabled on.

Exam trap

The trap here is that candidates often confuse firewall policies (which control transit traffic) with administrative access controls (which control traffic destined to the FortiGate itself), leading them to incorrectly select option D.

How to eliminate wrong answers

Option A is wrong because enabling SSH on the WAN interface and allowing all IPs would permit SSH access from any source, violating the requirement to restrict access to 10.0.0.100 only. Option C is wrong because configuring an access list on the upstream router is an external network control and does not enforce FortiGate's own administrative access restrictions; the FortiGate itself must be configured to limit management access. Option D is wrong because firewall policies control traffic passing through the FortiGate, not traffic destined to the FortiGate itself; management access is governed by administrative access settings and trusted hosts, not by firewall policies.

424
MCQeasy

An admin needs to translate the source IP of traffic from multiple internal hosts to a single public IP when accessing the internet, while keeping track of each session. Which NAT method should be used?

A.Fixed port range NAT
B.One-to-one NAT
C.Central SNAT without overload
D.Overload NAT (Port Address Translation)
AnswerD

Overload NAT, also known as Port Address Translation (PAT), allows many internal hosts to share one public IP by rewriting not only the source IP but also the source port to a unique, dynamically assigned value. The NAT engine maintains a translation table keyed by the public IP and the new source port, so return traffic is correctly forwarded back to the original internal host. This session multiplexing is what makes a single public IP sufficient for the entire internal network, with a theoretical maximum of about 65,536 concurrent sessions per public IP.

Why this answer

Overload NAT, also known as Port Address Translation (PAT), allows multiple internal hosts to share a single public IP address by mapping each session to a unique source port. This is the correct method for translating source IPs from multiple internal hosts to one public IP while maintaining session tracking, as it uses the transport-layer port number to differentiate between concurrent connections.

Exam trap

The trap here is that candidates often confuse 'Central SNAT without overload' with PAT, not realizing that without overload (port translation), the NAT device cannot multiplex multiple internal hosts to a single public IP, leading to session failures.

How to eliminate wrong answers

Option A is wrong because Fixed port range NAT assigns a predefined range of ports to each internal host, which limits the number of concurrent sessions per host and does not efficiently share a single public IP across many hosts. Option B is wrong because One-to-one NAT maps a single internal IP to a single external IP, requiring a public IP for each internal host, which does not conserve public IP addresses. Option C is wrong because Central SNAT without overload translates the source IP without using port multiplexing, meaning it can only handle one session per public IP at a time, causing conflicts when multiple internal hosts try to access the internet simultaneously.

425
MCQeasy

Which FortiGate operating mode allows the device to act as a transparent layer 2 bridge, forwarding traffic without performing NAT or routing?

A.Transparent mode
B.HA mode
C.VDOM mode
D.NAT/Route mode
AnswerA

Transparent mode places the FortiGate as a layer 2 bridge, forwarding frames between interfaces without routing or NAT, so existing IP addressing remains unchanged. NAT/route mode performs routing and address translation, which the scenario explicitly excludes.

Why this answer

Transparent mode is the correct answer because in this mode, FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses without performing Network Address Translation (NAT) or routing. The device does not have an IP address on its interfaces for forwarding decisions, making it invisible to the network at Layer 3.

Exam trap

The trap here is that candidates often confuse 'transparent mode' with 'VDOM mode' because VDOMs can be configured in transparent mode, but VDOM mode itself is a virtualization feature, not the operating mode that defines Layer 2 bridging behavior.

How to eliminate wrong answers

Option B (HA mode) is wrong because High Availability mode is a clustering configuration for redundancy and failover, not an operating mode that changes the device's Layer 2 or Layer 3 forwarding behavior. Option C (VDOM mode) is wrong because Virtual Domain mode is a virtualization feature that allows partitioning a single FortiGate into multiple logical firewalls, each operating in its own mode (transparent or NAT/route), but it does not inherently make the device a transparent bridge. Option D (NAT/Route mode) is wrong because this is the default Layer 3 operating mode where the FortiGate performs routing and NAT, acting as a router with IP addresses on interfaces, which is the opposite of transparent bridging.

426
MCQmedium

You notice that the FortiGate HA cluster is not failing over when the primary unit loses power. The HA configuration shows 'set ha-priority 250' on the primary and 'set ha-priority 200' on the secondary. What is the most likely cause?

A.The secondary unit has a lower priority, so it never takes over
B.The password for HA synchronization is incorrect
C.The session pickup feature is disabled
D.The HA heartbeat interface is not configured correctly or is down
AnswerD

The HA heartbeat interface is the dedicated link used by both units to exchange state and health information. If this interface is not configured correctly or is down, the secondary cannot reliably monitor the primary's heartbeat; in this scenario, the cluster may not even form, or if it did form, the secondary will not detect the primary's failure and will not initiate a failover. In some cases, a failed heartbeat with a still-functioning management plane can lead to split-brain, but a correctly working heartbeat is fundamental to failover detection and to avoid the cluster being stuck with an inactive primary.

Why this answer

The most likely cause is that the HA heartbeat interface is not configured correctly or is down (Option D). FortiGate HA relies on heartbeat packets exchanged over dedicated or VLAN interfaces to monitor peer status. If the heartbeat interface fails, the secondary unit cannot detect the primary's loss of power, so no failover occurs regardless of priority settings.

The HA priority values (250 vs. 200) are valid and would normally cause the primary to be elected as the active unit, but a broken heartbeat link prevents failover detection.

Exam trap

The trap here is that candidates often assume priority values alone determine failover behavior, but FortiGate HA failover requires a working heartbeat link to detect peer failure; without it, even a complete power loss goes unnoticed.

How to eliminate wrong answers

Option A is wrong because the secondary unit's lower priority (200) does not prevent it from taking over; in fact, when the primary fails, the secondary with the next highest priority becomes active. Option B is wrong because an incorrect HA synchronization password would cause configuration sync failures, not a failure to detect a power loss and trigger failover. Option C is wrong because session pickup (or session failover) is a feature for preserving active sessions during failover, not a requirement for the failover itself to occur.

427
MCQmedium

An administrator is troubleshooting an IPsec VPN that uses aggressive mode. The VPN establishes successfully, but the administrator is concerned about security. Which statement is true regarding aggressive mode?

A.Aggressive mode is more secure than main mode
B.Aggressive mode transmits the identification in clear text
C.Aggressive mode provides perfect forward secrecy (PFS) by default
D.Aggressive mode uses six messages instead of three
AnswerB

In aggressive mode, the initiator sends its identification (IDi) along with the Diffie-Hellman values in the first packet, and the responder returns its identification (IDr) in the second packet. Because the shared secret is not yet computed when these packets are exchanged, no encryption keys exist, so the ID payloads are transmitted in plaintext. A passive attacker on the network path can capture these packets and directly read the identities of the VPN peers. This is the primary reason aggressive mode is considered insecure for identity protection.

Why this answer

In aggressive mode, the IKE phase 1 exchange uses three messages instead of six, and the peer's identity (such as the IP address or FQDN) is transmitted in cleartext during the second message before the secure tunnel is established. This exposes the identity to eavesdropping, making it less secure than main mode, which encrypts the identity after the tunnel is set up. The administrator's concern is valid because aggressive mode sacrifices identity protection for faster negotiation.

Exam trap

The trap here is that candidates often confuse aggressive mode's faster negotiation with better security, or mistakenly think the number of messages (three vs. six) implies stronger encryption, when in fact the cleartext identity transmission is the critical security weakness tested on the NSE4 exam.

How to eliminate wrong answers

Option A is wrong because aggressive mode is actually less secure than main mode due to cleartext identity transmission and weaker protection against brute-force attacks. Option C is wrong because perfect forward secrecy (PFS) is not enabled by default in aggressive mode; PFS is a separate configuration option in IKE phase 2 (IPsec SA) and must be explicitly enabled. Option D is wrong because aggressive mode uses three messages (two exchanges) instead of six; main mode uses six messages (three exchanges).

428
Multi-Selectmedium

An administrator is troubleshooting why traffic from a specific subnet (192.168.10.0/24) to the internet is not being matched by the expected firewall policy. The policy list shows an allow policy for this traffic at ID 10, but there is a deny policy at ID 5 for any traffic from 192.168.0.0/16. Which TWO statements are correct?

Select 2 answers
A.The deny policy at ID 5 is matching the traffic before the allow policy at ID 10
B.The allow policy at ID 10 will override the deny policy because it is more specific
C.The traffic will be matched by the implicit deny at the end of the policy list
D.The administrator should enable 'policy override' on the allow policy
E.The administrator should change the deny policy's source to exclude 192.168.10.0/24 or move the allow policy above ID 5
AnswersA, E

Because FortiGate evaluates firewall policies in ascending order of policy ID, the deny at ID 5 is checked before the allow at ID 10. The source 192.168.10.0/24 is entirely within the broader 192.168.0.0/16 object used by the deny policy, so the traffic satisfies all matching criteria of ID 5 and is denied immediately, never reaching ID 10.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom based on their policy ID. Since policy ID 5 (deny for 192.168.0.0/16) appears before policy ID 10 (allow for 192.168.10.0/24), traffic from 192.168.10.0/24 is matched by the broader deny policy first, and the allow policy is never reached. This is a fundamental behavior of FortiGate's policy lookup order.

Exam trap

The trap here is that candidates often assume firewall policies use a 'most specific match' logic like routing, but FortiGate strictly uses sequential first-match based on policy ID order.

429
MCQmedium

An administrator configures an email filter profile to block spam. Despite correct configuration, spam emails still reach users' inboxes. The FortiGate is deployed as a transparent bridge. What is the most likely reason?

A.The FortiGate does not have a valid FortiGuard license
B.The emails are encrypted with TLS and deep inspection is not enabled
C.The email filter profile is set to 'monitor' instead of 'block'
D.The firewall policy is using flow-based inspection, which does not support SMTP proxy
AnswerD

Email filtering for SMTP on FortiGate is performed by the antivirus/email filter proxy engine, which only operates in proxy-based inspection mode. When a firewall policy is set to flow-based inspection, the FortiGate uses a streamlined forwarding path that does not support SMTP proxy functionality, so the email filter profile is silently ignored for that traffic. To enforce email filtering, the policy must use proxy-based inspection (or configure a transparent proxy), allowing the FortiGate to buffer and scan SMTP messages before forwarding them.

Why this answer

In a transparent bridge deployment, FortiGate uses flow-based inspection by default, which does not support SMTP proxy-based email filtering. The email filter profile requires proxy-based inspection to intercept and block spam at the SMTP protocol level. Without enabling proxy-based inspection on the firewall policy, the FortiGate cannot apply the email filter profile effectively, allowing spam to pass through.

Exam trap

The trap here is that candidates often assume email filtering works regardless of inspection mode, but FortiGate specifically requires proxy-based inspection for SMTP proxy features like email filter profiles to function.

How to eliminate wrong answers

Option A is wrong because a valid FortiGuard license is required for real-time spam signature updates, but the email filter profile can still block spam based on local rules or heuristics even without a license; the issue here is that the filter is not being applied at all. Option B is wrong because TLS-encrypted emails would require deep inspection to decrypt and scan, but the question states the configuration is correct and spam still reaches inboxes, implying the filter is not being invoked rather than being bypassed by encryption. Option C is wrong because if the profile were set to 'monitor', it would log spam but not block it, yet the administrator would likely see logs indicating the action; the core problem is that the profile is not being applied due to inspection mode mismatch.

430
Multi-Selectmedium

A FortiGate is configured with a firewall policy that applies an Application Control profile and a Web Filter profile. The administrator wants to log all traffic blocked by the Web Filter profile. Which TWO configurations are required?

Select 2 answers
A.Enable 'Log All Blocked Sites' in the Web Filter profile
B.Set the global 'Logging' setting to 'Verbose'
C.Configure the Application Control profile to log blocked traffic
D.Enable 'Log All Traffic' or 'Log Violation Traffic' on the firewall policy
E.Enable 'Log All Allowed Sites' in the Web Filter profile
AnswersA, D

In the Web Filter profile, 'Log All Blocked Sites' is the switch that generates a log entry whenever the FortiGate denies access to a URL based on a blocked category or explicit URL. This profile-level toggle is required for the blocked request to appear in the traffic log along with the relevant URL filter category and action. Without it, even a matching firewall policy with logging enabled will not create a web-filter-specific blocked-site log record.

Why this answer

The Web Filter profile has a specific setting called 'Log All Blocked Sites' that, when enabled, generates log entries for all traffic that the web filter blocks. This is the direct mechanism to log blocked web traffic at the profile level. Option D is also correct because the firewall policy itself must have logging enabled—either 'Log All Traffic' or 'Log Violation Traffic'—to ensure that the log entries generated by the Web Filter profile are actually recorded and sent to the FortiGate's log system.

Exam trap

The trap here is that candidates often assume enabling logging only in the security profile (Web Filter) is sufficient, forgetting that the firewall policy must also have logging enabled to actually capture and store those log entries.

431
MCQmedium

An administrator configures a route-based IPsec VPN between two FortiGates. The Phase 1 and Phase 2 are up. The administrator adds a static route on each FortiGate pointing to the remote subnet via the virtual tunnel interface (e.g., 'to_remote'). Traffic between the subnets fails. What is the MOST likely missing configuration?

A.NAT must be disabled on the tunnel interface
B.The tunnel interface must be added to a zone
C.The Phase 2 proposal must include the correct local and remote subnets
D.A firewall policy is required to permit traffic between the interfaces
AnswerD

FortiGate processes traffic through firewall policies, not merely routing. Although the static route directs packets to the tunnel interface, no policy permits the subnet-to-subnet flow, so traffic is dropped. Adding a policy allowing the local and remote subnets across the tunnel interfaces satisfies this requirement.

Why this answer

In a route-based IPsec VPN, even when Phase 1 and Phase 2 are up and a static route exists via the virtual tunnel interface, traffic will still be dropped unless a firewall policy explicitly permits it. FortiGate uses a stateful firewall, so a policy must allow traffic from the local interface to the tunnel interface (or vice versa) to forward packets. Without this policy, the FortiGate will not forward traffic between the subnets, even though the tunnel is established.

Exam trap

The trap here is that candidates assume a static route and an established IPsec tunnel are sufficient for traffic flow, overlooking the mandatory firewall policy that FortiGate requires to permit inter-subnet traffic in a route-based VPN.

How to eliminate wrong answers

Option A is wrong because NAT is not required to be disabled on the tunnel interface for route-based VPNs; NAT is typically disabled automatically for IPsec traffic, and disabling it manually is not the missing configuration. Option B is wrong because adding the tunnel interface to a zone is optional and used for grouping interfaces for policy application, but it is not a prerequisite for traffic flow; a firewall policy can be applied directly to the interface without a zone. Option C is wrong because the Phase 2 proposal includes the correct local and remote subnets (0.0.0.0/0 for route-based VPNs), and the question states Phase 2 is up, indicating the proposal is correctly configured; the issue is not with Phase 2 parameters.

432
MCQmedium

A FortiGate administrator has configured a firewall policy allowing HTTP traffic from the internal network (10.0.1.0/24) to the DMZ server (192.168.1.10). The policy is placed after a deny-all policy that blocks traffic from internal to DMZ. Even though the allow policy is more specific, traffic is still being denied. What is the most likely cause?

A.The deny-all policy has a higher policy ID than the allow policy
B.The allow policy is configured with the wrong source interface
C.The allow policy uses a schedule that is not active at the current time
D.The deny-all policy is placed above the allow policy in the policy list
AnswerD

FortiOS performs first-match evaluation, checking rules top-down and enforcing the first rule whose all conditions (source, destination, service, schedule, etc.) are satisfied. If a broad deny-all is positioned above the specific allow policy, every packet that would otherwise match the allow rule hits the deny-all first and is dropped. That is the classic misordering mistake, and it cannot be compensated for by policy IDs or other attributes.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom. The first matching policy is applied, and subsequent policies are ignored. Since the deny-all policy is placed above the more specific allow policy, traffic from 10.0.1.0/24 to 192.168.1.10 matches the deny-all first and is dropped, never reaching the allow rule.

Exam trap

The trap here is that candidates mistakenly believe FortiGate uses a 'best-match' or 'most-specific' logic like routing tables, when in fact it uses strict first-match sequential evaluation, making policy order critical.

How to eliminate wrong answers

Option A is wrong because policy ID order does not determine evaluation priority; FortiGate uses the physical sequence in the policy list, not the ID number. Option B is wrong because if the source interface were incorrect, the traffic would not match the allow policy at all, but the question states the traffic is denied by the deny-all policy, implying the allow policy is otherwise correctly configured. Option C is wrong because a schedule issue would cause the allow policy to be inactive, but the traffic would still be evaluated against the deny-all policy and denied; however, the most likely cause given the policy placement is the order, not a schedule.

433
Multi-Selectmedium

An administrator needs to configure HA on a pair of FortiGates with the following requirements: the cluster must support session failover for TCP, UDP, and ICMP; the management interface should be accessible on both units; and the failover must be triggered if port2 goes down. Which TWO settings must be configured? (Choose two.)

Select 2 answers
A.Enable session pickup
B.Configure a dedicated management interface
C.Add port2 to the monitored interfaces
D.Set the HA mode to active-passive
E.Set the HA override to enabled
AnswersA, C

Enabling session pickup is essential for stateful failover in a FortiGate HA cluster. It synchronizes the session table, including NAT translations, TCP/UDP state, and even application-layer protocol states, between the primary and standby units. This ensures that when a failover occurs, existing connections are not dropped and can continue seamlessly on the new primary. Without session pickup, even if the interface goes down and failover is triggered, all active sessions would be lost, causing disruption to users.

Why this answer

Option A (Enable session pickup) is correct because session pickup is the FortiGate HA setting that synchronizes session state tables across cluster members, which is exactly what enables TCP, UDP, and ICMP sessions to survive a failover to the other unit. Option C (Add port2 to the monitored interfaces) is correct because HA monitors only the interfaces explicitly listed in the monitored-interface configuration; adding port2 ensures that if that link goes down, the unit's HA priority is reduced or it fails over as required. Option B is not required because the requirement is that the management interface be reachable on both units, which is achieved by allowing management access on the HA interfaces or via reserved management interfaces, not by a mandatory dedicated management interface setting.

Option D is not required because session failover and interface monitoring work in both active-passive and active-active modes, so the mode does not have to be active-passive. Option E is not required because override only controls whether a unit with higher priority preempts the primary after it recovers; it is not needed to trigger failover on a link-down event.

Exam trap

NSE4 often tests the misconception that active-passive mode alone provides session failover, when in fact session pickup must be explicitly enabled and monitored interfaces must be configured to trigger failover.

434
MCQmedium

An administrator needs to ensure that users cannot upload files to a specific cloud storage service via HTTPS, while still allowing them to view and download files from the same service. The FortiGate is currently performing SSL deep inspection on all outbound HTTPS traffic. Which security profile should the administrator configure to meet this requirement?

A.Antivirus
B.Data loss prevention (DLP)
C.Application control
D.Web filter
AnswerC

Application control can identify the cloud storage application and apply per-application actions. With SSL deep inspection enabled, it can see inside HTTPS and block only the upload action for that application while allowing download. This meets the requirement precisely without affecting other traffic.

Why this answer

Application control is designed to identify applications and their actions, even within encrypted traffic when SSL deep inspection is active. It can enforce policies that distinguish between upload and download actions for cloud storage apps. This allows the administrator to block uploads while permitting viewing and downloading, exactly as required.

Exam trap

The trap here is assuming that web filtering or DLP can control application-specific actions like upload versus download within an allowed application.

435
MCQmedium

A FortiGate is configured with FSSO (Fortinet Single Sign-On) to authenticate users from Active Directory. Users are logging in to their domain-joined computers, but the FortiGate does not see the user sessions. The polling connector is configured correctly. What is the MOST likely reason?

A.The FSSO agent is not installed on the Domain Controller
B.The user group filter is too restrictive
C.The FortiGate is not in the same subnet as the users
D.DNS resolution for the Domain Controller is failing
AnswerD

DNS resolution for the Domain Controller is failing. In FSSO polling mode, the FortiGate or collector agent must resolve the Domain Controller's fully qualified domain name to an IP address so it can query the DC's security event logs for user logon events. If DNS resolution fails, the polling connection cannot be established, the FortiGate receives no logon information, and thus no FSSO user sessions are generated in the firewall's session table or user list.

Why this answer

The polling connector relies on the FortiGate communicating with the Domain Controller (DC) to retrieve user logon events. If DNS resolution for the DC fails, the FortiGate cannot resolve the DC's hostname to an IP address, preventing the polling connector from establishing the necessary LDAP or NetAPI connections to collect user session data. This is the most likely cause because the polling connector is configured correctly, but network-level name resolution is a prerequisite for any communication.

Exam trap

The trap here is that candidates often assume FSSO requires an agent on the DC (Option A) or that subnet adjacency is mandatory (Option C), overlooking the fundamental dependency on DNS resolution for the polling connector to function.

How to eliminate wrong answers

Option A is wrong because the FSSO agent does not need to be installed on the Domain Controller when using the polling connector; the polling connector collects logon events directly from the DC's security event log without requiring an agent. Option B is wrong because a restrictive user group filter would only limit which users are recognized after successful polling, not prevent the FortiGate from seeing user sessions entirely. Option C is wrong because the FortiGate does not need to be in the same subnet as the users; FSSO polling works across routed networks as long as the FortiGate can reach the DC via IP and DNS.

436
MCQmedium

In an active-active HA cluster, session synchronization is enabled. What is the primary purpose of session synchronization in this mode?

A.To synchronize firewall policies between cluster members
B.To load balance traffic across the cluster
C.To reduce the number of sessions on each unit
D.To ensure that sessions are not lost if a cluster unit fails
AnswerD

Session synchronization's core purpose is to ensure stateful high availability: if one firewall unit fails or is taken out of service, the cluster's other unit(s) already possess the full session information—including NAT mappings, TCP sequence state, and application-level data—required to continue forwarding traffic without resetting connections. This is achieved by continuously transmitting session updates over the HA heartbeat link from the unit that owns each session to its standby or peer units. By doing so, the cluster can fail over in milliseconds, and existing sessions survive the failure. This is fundamental to delivering uninterrupted connectivity in an enterprise network.

Why this answer

Session synchronization in an active-active HA cluster ensures that session state (such as TCP connection state, NAT translations, and sequence numbers) is replicated between cluster members. If one unit fails, the surviving unit already has the session information and can continue forwarding traffic without dropping existing connections.

Exam trap

NSE4 often tests the confusion between session synchronization (runtime session state) and configuration synchronization (policies and objects), leading candidates to pick the policy-related answer.

How to eliminate wrong answers

Option A is wrong because firewall policies are synchronized via configuration synchronization, not session synchronization — session sync deals with runtime session state, not policy definitions. Option B is wrong because load balancing is handled by the HA load-balancing algorithm and virtual MAC/ARP mechanisms, not by session synchronization. Option C is wrong because session synchronization replicates sessions to peers, which can increase the number of sessions on each unit rather than reduce them.

437
MCQeasy

Which FortiGate log severity level indicates that a system is unusable and requires immediate attention?

A.Error
B.Critical
C.Emergency
D.Alert
AnswerC

Emergency (severity 0) is the highest log severity level and is reserved for situations where the FortiGate system is completely unusable, such as a kernel panic, total configuration failure, or unrecoverable hardware fault. This level indicates that the firewall cannot perform any of its security functions, and immediate intervention is required, which is exactly what the question asks to identify.

Why this answer

Emergency is the highest severity level in syslog/FortiGate, indicating a system is unusable. Critical indicates critical conditions but not necessarily unusable.

438
MCQmedium

An administrator wants to block an application named 'Skype' on the network. They create an application control profile and add a rule to block 'Skype'. However, after applying the profile to the policy, users can still use Skype. What is the most likely reason?

A.The application control profile is not enabled on the firewall policy
B.The application signature for Skype is outdated
C.The application control rule is set to 'monitor' instead of 'block'
D.Skype traffic is encrypted and SSL deep inspection is not enabled
AnswerD

Skype uses transport-layer encryption (TLS) to protect its signaling and media traffic. Without SSL deep inspection enabled in the firewall policy, the FortiGate cannot decrypt the SSL/TLS session to read the application-layer payload where the application signature resides. Consequently, the FortiGate sees only encrypted packets that do not match Skype's signature, so the block rule never triggers. To block Skype effectively, the administrator must enable SSL deep inspection with a valid CA certificate, allowing the FortiGate to proxy and inspect the traffic.

Why this answer

Skype uses proprietary encryption and often relies on peer-to-peer connections that bypass traditional port-based inspection. Without SSL deep inspection (also known as HTTPS inspection or certificate-based decryption), the FortiGate cannot decrypt the encrypted Skype traffic to match it against the application control signature. Application control relies on either protocol decoders or deep packet inspection (DPI) to identify applications; if the traffic is encrypted and not decrypted, the FortiGate sees only encrypted payloads and cannot apply the block rule.

Exam trap

The trap here is that candidates often assume application control can block any application by name alone, forgetting that encrypted traffic requires SSL deep inspection to be enabled on the firewall policy for the application signatures to work.

How to eliminate wrong answers

Option A is wrong because if the application control profile were not enabled on the firewall policy, the policy would not apply any application control at all, but the question states the profile was applied, so this is not the most likely reason. Option B is wrong because an outdated signature would cause a failure to detect new variants of Skype, but Skype itself is a well-known, long-standing application with stable signatures; an outdated signature is less likely than the fundamental encryption issue. Option C is wrong because if the rule were set to 'monitor' instead of 'block', the administrator would see log entries indicating the traffic was allowed, not that users could still use Skype without any indication; the question implies the block simply does not work, not that it is silently logging.

439
MCQeasy

Which security profile component is specifically designed to prevent data exfiltration by inspecting outgoing traffic for sensitive data patterns?

A.Application Control
B.Data Leak Prevention (DLP)
C.Antivirus
D.Web Filter
AnswerB

Data Leak Prevention (DLP) is the security profile specifically engineered to detect and prevent the unauthorized transmission of sensitive data. It uses deep content inspection techniques such as exact data matching, regex patterns, and file fingerprinting to identify regulated data elements like PCI-DSS card numbers, HIPAA-protected health records, and PII. DLP also considers contextual factors—source, destination, protocol, and direction—to enforce policies that block, quarantine, or log risky transmissions across SMTP, HTTP, FTP, and cloud apps.

Why this answer

Data Leak Prevention (DLP) is the security profile component specifically designed to inspect outgoing traffic for sensitive data patterns, such as credit card numbers, social security numbers, or custom regex patterns. It uses deep packet inspection (DPI) to analyze content in emails, web uploads, and file transfers, blocking or alerting on matches to prevent unauthorized data exfiltration.

Exam trap

The trap here is that candidates often confuse DLP with Web Filter or Application Control, thinking that blocking web categories or applications inherently prevents data exfiltration, but only DLP inspects the actual content of outgoing traffic for sensitive data patterns.

How to eliminate wrong answers

Option A is wrong because Application Control focuses on identifying and controlling application traffic (e.g., blocking Skype or Facebook) based on signatures, not on inspecting content for sensitive data patterns. Option C is wrong because Antivirus scans for malware signatures and heuristics in files and traffic, not for sensitive data patterns like credit card numbers or PII. Option D is wrong because Web Filter controls access to URLs and web categories (e.g., blocking gambling or adult sites), but does not inspect the content of outgoing traffic for sensitive data patterns.

440
MCQmedium

An administrator wants to view the current session table on a FortiGate. Which command should they use?

A.diagnose debug flow
B.show full-configuration
C.diagnose sys session list
D.get system performance statistics
AnswerC

'diagnose sys session list' is the correct command to view the current session table. It reads the kernel session table and outputs every active connection, including source/destination IP addresses, ports, protocol, session state, and timers. This is the standard tool for troubleshooting NAT, policy, and asymmetric routing because it shows exactly what the firewall is tracking in real time.

Why this answer

The command 'diagnose sys session list' displays the current session table on a FortiGate, showing active sessions with source/destination, protocol, state, and policy information. It is the standard CLI command for inspecting the session table in real time.

Exam trap

NSE4 often tests the confusion between 'diagnose debug flow' (packet tracing) and 'diagnose sys session list' (session table inspection), since both are used in troubleshooting but serve different purposes.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug flow' traces packet flow through the FortiGate for troubleshooting policy and routing decisions, not for listing the session table. Option B is wrong because 'show full-configuration' dumps the entire device configuration, not the runtime session table. Option D is wrong because 'get system performance statistics' displays system performance counters such as CPU and memory, not session entries.

441
Multi-Selectmedium

An administrator is troubleshooting an SSL VPN connection. Users can connect but cannot access internal resources. Which TWO commands would help diagnose the issue?

Select 2 answers
A.get router info routing-table
B.diagnose vpn ssl list
C.diagnose vpn ike status
D.execute ping 8.8.8.8
E.diagnose debug application dnsproxy
AnswersA, B

This command displays the kernel routing table, including the route dynamically inserted for the SSL VPN tunnel interface. By checking it, an administrator can verify that the expected destination routes (or the default route) are present and bound to the SSL-VPN interface, which is essential for diagnosing why client traffic may not be forwarded after a successful SSL VPN handshake.

Why this answer

The 'get router info routing-table' command displays the FortiGate's routing table, which is essential for verifying that the FortiGate has a route to the internal resources the SSL VPN users are trying to access. If the route is missing or incorrect, traffic from the SSL VPN tunnel will not be forwarded to the internal network. Option B is correct because 'diagnose vpn ssl list' shows active SSL VPN sessions, including the assigned virtual IP (VIP) and tunnel interface, which helps confirm that the user is properly connected and has received an IP address from the correct address pool.

Exam trap

The trap here is that candidates often confuse IPsec and SSL VPN troubleshooting commands, selecting 'diagnose vpn ike status' because they associate 'vpn' with IPsec, not realizing SSL VPN uses a completely different set of diagnostic tools.

442
MCQmedium

An organization uses FortiSandbox to analyze suspicious files. The FortiGate is configured to send files to FortiSandbox for analysis when the antivirus scan fails to reach a verdict. Which antivirus inspection mode must be used on the firewall policy for this integration to work?

A.Both flow and proxy modes support FortiSandbox equally
B.Deep inspection
C.Proxy-based inspection
D.Flow-based inspection
AnswerC

Proxy-based inspection is the correct mode because it fully buffers the file, forwards it to FortiSandbox, and pauses the session until a verdict is returned. This allows FortiGate to block the file before it reaches the client if FortiSandbox determines it is malicious. The connection-holding behavior is essential for quarantine and real-time enforcement. In contrast, flow-based inspection lacks this holding capability and therefore cannot provide the same level of blocking.

Why this answer

Proxy-based inspection buffers the file and can hold the connection until FortiSandbox returns a verdict. Flow-based does not support this hold-and-wait mechanism.

443
Multi-Selectmedium

A FortiGate administrator wants to block spam emails sent to the company's mail server. The mail server is behind the FortiGate. Which THREE configurations should be applied?

Select 3 answers
A.Enable DLP to filter spam
B.Configure Application Control to block email applications
C.Enable FortiGuard spam filtering in the Email Filter profile
D.Apply the Email Filter profile to the firewall policy that allows SMTP traffic to the mail server
E.Create an Email Filter profile with spam detection enabled
AnswersC, D, E

Enabling FortiGuard spam filtering within the Email Filter profile activates the cloud-based spam signature and reputation service. This satisfies the requirement to block spam, since the FortiGate must query FortiGuard to classify and reject unsolicited mail before it reaches the protected mail server.

Why this answer

Option C is correct because the FortiGate's Email Filter profile relies on FortiGuard Anti-Spam service to detect and tag/block spam based on FortiGuard's spam signature and IP reputation databases. Option E is correct because an Email Filter profile must first be created and its spam detection (and optionally other checks like banned words, DNSBL, HELO checks) enabled before it can take any action. Option D is correct because an Email Filter profile only takes effect when it is applied to the firewall policy that permits the SMTP traffic destined to the internal mail server.

Option A is not correct because DLP on FortiGate handles data leakage patterns (credit cards, SSNs, file types) rather than spam detection. Option B is not correct because Application Control identifies and blocks applications by signature/behavior, not spam content within SMTP sessions.

Exam trap

The trap here is that candidates confuse DLP or Application Control with email-specific spam filtering, failing to recognize that only the Email Filter profile with FortiGuard antispam can inspect SMTP message bodies and headers for spam content.

444
Multi-Selectmedium

A network administrator has two FortiGate units that need to be configured as an HA cluster. Which TWO of the following are prerequisites for HA formation?

Select 2 answers
A.Both units must have the same FortiOS firmware version.
B.Both units must have the same hostname.
C.The HA heartbeat interface must be on the same Layer 2 network.
D.Both units must be in NAT/Route mode.
E.The HA priority must be set to 0 on both units.
AnswersA, C

Both units in a FortiGate HA cluster must run the exact same FortiOS firmware version and build. Mismatched versions can cause the HA protocol to behave unpredictably, leading to split-brain scenarios or failed failovers. Fortinet only supports HA when all cluster members share identical firmware, so this is a hard prerequisite before configuring HA.

Why this answer

FortiGate HA clusters require all members to run the exact same FortiOS firmware version to ensure protocol compatibility and configuration synchronization. Mismatched firmware versions can cause cluster instability, failover failures, or split-brain scenarios, as the HA heartbeat protocol relies on consistent state machine behavior across units.

Exam trap

The trap here is that candidates often assume hostnames must match (Option B) because they confuse HA synchronization with general network device clustering, but FortiGate actually overwrites hostnames during sync, making mismatched hostnames irrelevant as a prerequisite.

445
Multi-Selecthard

An administrator is troubleshooting why traffic from a specific VLAN (192.168.10.0/24) to the internet is not being NATed correctly. The firewall policy allows the traffic with NAT enabled and uses an IP Pool (overload) for the source translation. The IP Pool is configured with the address 203.0.113.10. However, the traffic still shows the original source IP. Which THREE of the following could cause this issue? (Choose three.)

Select 3 answers
A.There is a Central SNAT rule with higher priority that does not match the traffic
B.The firewall policy does not have the IP Pool selected in the NAT section
C.The IP Pool is configured on the wrong outgoing interface
D.The IP Pool uses one-to-one NAT instead of overload
E.Another firewall policy above the current one matches the traffic and either denies it or does not use NAT
AnswersB, C, E

In FortiGate policy-based NAT, an IP Pool is only applied when the firewall policy explicitly references it via the 'NAT' section and the 'Use IP Pool' dropdown. Merely creating an IP Pool does not cause it to be used; the pool must be tied to the specific policy that binds the source and destination. Without that selection, the firewall falls back to using the outgoing interface address or no NAT, which would leave the original source IP visible.

Why this answer

The IP Pool must be explicitly selected in the NAT section of the firewall policy for the pool to be used for source translation. Without this selection, the firewall will use the default NAT behavior (typically the outgoing interface IP) or no NAT at all, even if NAT is enabled on the policy.

Exam trap

The trap here is that candidates often assume simply enabling NAT on the policy and configuring an IP Pool is sufficient, but they overlook the requirement to explicitly select the IP Pool in the policy's NAT settings.

446
Multi-Selectmedium

An administrator is configuring a loopback interface on a FortiGate for management purposes. Which three statements are true about loopback interfaces? (Choose three.)

Select 3 answers
A.Multiple loopback interfaces can be created.
B.A loopback interface is always up regardless of physical link status.
C.A loopback interface can be used as the source IP for management traffic.
D.Loopback interfaces support VLAN tagging.
E.A loopback interface requires a physical port to be associated.
AnswersA, B, C

FortiGate supports the creation of multiple loopback interfaces, each with its own unique IP address and routing table entries. This allows administrators to deploy several logical endpoints for different services—such as OSPF router IDs, BGP update sources, or management gateways—without consuming physical interface resources. The number of loopbacks is not limited by hardware ports, giving flexibility in network design.

Why this answer

FortiGate allows the creation of multiple loopback interfaces (up to 16, depending on the model) for various purposes such as management, routing, or VPN termination. Each loopback interface is a virtual interface that does not depend on any physical port, providing flexibility in network design.

Exam trap

The trap here is that candidates may confuse loopback interfaces with sub-interfaces or VLAN interfaces, incorrectly assuming they support VLAN tagging or require a physical port, when in fact loopback interfaces are purely logical and independent of hardware.

447
MCQeasy

A network administrator notices that a FortiGate IPS sensor is not detecting any attacks, even though there is known malicious traffic on the network. Which initial troubleshooting step should the administrator take?

A.Ensure the firewall policy is set to flow-based inspection.
B.Disable any DoS policies that might be blocking traffic.
C.Verify that the IPS engine is running and signatures are up to date.
D.Check that the FortiGate is configured in NAT mode.
AnswerC

The IPS engine (ipsengine) is the process that actually inspects packets against the signature database; if it is not running or has crashed, no IPS detection can occur. Additionally, the FortiGuard IPS package must be current, as outdated signatures will fail to match recently disclosed vulnerabilities. Running the command 'get ips status' verifies engine status and signature version, and 'execute update now' forces an update, making this the correct and direct remedy.

Why this answer

The first step in troubleshooting a non-functional IPS sensor is to verify that the IPS engine is running and that the IPS signatures are up to date. If the engine is stopped or signatures are outdated, the sensor cannot detect known malicious traffic regardless of other configurations. This foundational check ensures the detection mechanism itself is operational before investigating policy or mode settings.

Exam trap

The trap here is that candidates often jump to changing inspection modes or firewall policies, forgetting that the IPS engine must be running and signatures current for any detection to occur, which is the most basic and critical prerequisite.

How to eliminate wrong answers

Option A is wrong because flow-based inspection is not required for IPS; IPS can work with both flow-based and proxy-based inspection, and changing the inspection mode is not the initial troubleshooting step when the sensor is not detecting attacks. Option B is wrong because DoS policies are separate from IPS detection and disabling them would not enable IPS to detect attacks; they might block traffic but do not prevent IPS from analyzing it. Option D is wrong because NAT mode is unrelated to IPS detection; FortiGate can run IPS in both NAT and transparent mode, and the mode does not affect the IPS engine's ability to detect attacks.

448
MCQhard

A FortiGate administrator configures SSL deep inspection on a policy using a self-signed CA certificate. Users report that they see a certificate warning in their browsers when accessing HTTPS sites. What is the most effective solution to eliminate these warnings?

A.Use a publicly trusted CA certificate for the FortiGate
B.Disable deep inspection and use certificate inspection only
C.Add the websites to the exemption list in the SSL/SSH profile
D.Install the FortiGate's CA certificate on all client machines in the trusted root store
AnswerD

Installing the FortiGate's CA certificate into the trusted root store of every client establishes the FortiGate as a trusted certificate authority within the organization. When the FortiGate generates a per-session certificate signed by this CA, the client's browser accepts it without warnings because the CA is in its trust store. This directly addresses the root cause of the warning and is the recommended enterprise deployment practice for deep inspection.

Why this answer

The certificate warning occurs because the browser does not trust the FortiGate's self-signed CA certificate. By installing the FortiGate's CA certificate into the trusted root store on each client machine, the browser will trust certificates signed by that CA, eliminating the warning. This is the standard approach for self-signed CA certificates in SSL deep inspection environments.

Exam trap

The trap here is that candidates may think using a publicly trusted CA (Option A) is the solution, not realizing that the FortiGate must hold the private key for that CA, which is impractical and insecure; the correct approach is to trust the FortiGate's own CA internally.

How to eliminate wrong answers

Option A is wrong because using a publicly trusted CA certificate for the FortiGate would require the FortiGate to have the private key for that CA, which is a security risk and not standard practice; the FortiGate's self-signed CA is meant to be distributed internally. Option B is wrong because disabling deep inspection and using certificate inspection only would bypass the need for a trusted CA but would also eliminate the security benefits of inspecting encrypted traffic content. Option C is wrong because adding websites to the exemption list only prevents inspection for those specific sites, not all HTTPS sites, so users would still see warnings for non-exempted sites.

449
MCQhard

A company is implementing SSL/TLS inspection on a FortiGate to monitor encrypted traffic. They want to ensure that traffic to high-risk categories is blocked, while traffic to financial sites is inspected but not blocked. The administrator creates an SSL inspection profile that deep-inspects all traffic except traffic to financial sites. However, users report that they cannot access financial websites. What is the most likely cause?

A.The web filter profile is configured to block financial websites, overriding the SSL inspection exemption.
B.The SSL inspection profile should be set to certificate-inspection instead of deep-inspection for financial sites.
C.The SSL inspection profile must be applied after the web filter profile in the firewall policy.
D.The SSL inspection profile should have deep-inspection disabled for all categories except financial.
AnswerA

The SSL inspection exemption only controls whether the FortiGate decrypts the TLS stream; it does not disable URL/web filtering. FortiGuard can still classify the destination based on the SNI, IP address, or FQDN from the ClientHello, so if the web filter profile blocks the 'Financial Services' category, the session is denied regardless of the decryption bypass. The exemption is the wrong place to expect 'allow' semantics when the web filter policy explicitly says block.

Why this answer

The most likely cause is that the web filter profile applied in the same firewall policy is configured to block financial websites. Even though the SSL inspection profile exempts financial sites from deep inspection, the web filter profile operates independently and can block traffic based on URL category. Since the web filter is evaluated after SSL inspection, it will block the decrypted or even non-decrypted traffic to financial sites if the category is set to block, overriding the SSL inspection exemption.

Exam trap

The trap here is that candidates assume the SSL inspection exemption automatically prevents web filtering from blocking the traffic, but FortiGate applies web filter policies independently, so a block action in the web filter profile overrides any SSL inspection exemption.

How to eliminate wrong answers

Option B is wrong because certificate-inspection only validates the certificate without decrypting the payload, which would not allow the web filter to inspect the content; the issue is not about the inspection type but about the web filter blocking the category. Option C is wrong because the order of profiles within a firewall policy does not affect the evaluation; both SSL inspection and web filter profiles are applied in sequence, but the web filter can still block traffic regardless of the SSL inspection profile's exemption. Option D is wrong because disabling deep-inspection for all categories except financial would still allow the web filter to block financial sites if the web filter profile is configured to block them; the exemption in the SSL inspection profile does not prevent the web filter from blocking.

450
MCQeasy

Which command is used to back up the full FortiGate configuration including all settings and objects?

A.execute backup config
B.execute backup full-config
C.config backup tftp
D.system backup configuration
AnswerA

execute backup config is the correct FortiGate CLI command to back up the full configuration. It captures all system, network, and firewall policy settings into a single plain-text file. This command can be run interactively to save to local disk or with parameters like tftp, ftp, or scp for remote transfer. It is the standard, intended method for creating a complete configuration backup.

Why this answer

The 'execute backup config' command is the correct method to back up the full FortiGate configuration, including all settings and objects, to a TFTP or FTP server. This command exports the entire running configuration in a text format that can be restored later. It is the standard CLI command for a complete configuration backup.

Exam trap

The trap here is that candidates may confuse the correct command with similar-sounding but invalid options like 'execute backup full-config' or 'config backup tftp', or assume a 'system' subcommand exists for backups, when FortiGate uses the 'execute' command structure for operational tasks.

How to eliminate wrong answers

Option B is wrong because 'execute backup full-config' is not a valid FortiGate CLI command; the correct syntax uses 'config' not 'full-config'. Option C is wrong because 'config backup tftp' is not a valid command; the correct command uses 'execute backup config tftp' to specify the protocol. Option D is wrong because 'system backup configuration' is not a valid CLI command; FortiGate uses 'execute backup config' for configuration backups, not a 'system' subcommand.

Page 5

Page 6 of 11

Page 7

All pages