Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 451–525

773 questions total · 11pages · All types, answers revealed

Page 6

Page 7 of 11

Page 8
451
MCQeasy

Which statement about the implicit deny policy on a FortiGate is true?

A.It is a user-configurable policy that can be deleted
B.It allows traffic that matches no other policy
C.It can be moved to a different position in the policy list
D.It is always at the bottom of the policy list and denies all unmatched traffic
AnswerD

This is the correct statement. In FortiOS, the implicit deny is always located at the very end of the policy list, after every user-created policy, and serves as the final catch-all rule. During sequential policy lookup, if no explicit policy matches the traffic parameters, the implicit deny matches all remaining sessions and blocks them by discarding the packets, thereby enforcing a strict default-deny posture.

Why this answer

The implicit deny policy is a built-in, non-configurable security policy that resides at the very bottom of the FortiGate policy list. It automatically denies all traffic that does not match any explicit user-defined policy, ensuring that only explicitly permitted traffic is allowed through the firewall.

Exam trap

The trap here is that candidates often think the implicit deny can be modified or moved, confusing it with a regular policy, but FortiGate enforces it as an unchangeable last-resort rule that cannot be deleted, reordered, or altered.

How to eliminate wrong answers

Option A is wrong because the implicit deny policy is not user-configurable and cannot be deleted; it is a hardcoded default rule. Option B is wrong because the implicit deny policy denies, not allows, traffic that matches no other policy. Option C is wrong because the implicit deny policy is fixed at the bottom of the policy list and cannot be moved to a different position.

452
MCQeasy

An administrator needs to back up the FortiGate configuration to a TFTP server at 10.0.0.10. Which command should be used?

A.tftp -p -l mybackup.conf 10.0.0.10
B.execute backup config tftp mybackup.conf 10.0.0.10
C.execute backup config ftp mybackup.conf 10.0.0.10
D.copy config tftp://10.0.0.10/mybackup.conf
AnswerB

This is the correct FortiGate CLI command for backing up the configuration to a TFTP server. The command 'execute backup config' specifies the backup operation, 'tftp' selects the protocol, 'mybackup.conf' is the destination filename on the server, and '10.0.0.10' is the server IP. On FortiGate, this initiates a TFTP put from the unit, and it is the exact syntax required to meet the administrator's need.

Why this answer

The correct command to back up a FortiGate configuration to a TFTP server is 'execute backup config tftp <filename> <server-ip>'. This is a standard FortiOS CLI command that uses TFTP (Trivial File Transfer Protocol) to transfer the configuration file to the specified server at 10.0.0.10. Option B matches this syntax exactly.

Exam trap

The trap here is that candidates may confuse the FortiGate CLI syntax with a standard TFTP client command (Option A) or mistakenly use 'ftp' (Option C) instead of 'tftp', overlooking the specific protocol required by the server.

How to eliminate wrong answers

Option A is wrong because 'tftp -p -l mybackup.conf 10.0.0.10' is a client-side TFTP command used on a Linux/Windows host, not a FortiGate CLI command; FortiGate does not support raw TFTP client commands. Option C is wrong because it specifies 'ftp' instead of 'tftp', which would attempt an FTP transfer, not TFTP, and the server at 10.0.0.10 is a TFTP server, not an FTP server. Option D is wrong because 'copy config tftp://10.0.0.10/mybackup.conf' is not a valid FortiOS CLI command; FortiGate uses 'execute backup' for configuration backups, not a 'copy' command with a URI.

453
MCQhard

A FortiGate administrator is troubleshooting a high CPU usage issue. The 'get system performance status' command shows that the CPU usage is consistently above 80% with no traffic. Which of the following is the most likely cause?

A.An interface is in error-disable state causing CPU interrupts.
B.The firewall policy is misconfigured, causing packet drops.
C.A DDoS attack is overwhelming the CPU.
D.A process such as the IPS engine is stuck in an infinite loop.
AnswerD

A stuck process like the IPS engine can enter an infinite loop or deadlock in user space, consuming an entire CPU core even when no traffic is passing through the device. This is a well-known software defect scenario; the process runs continuously, executing instructions without yielding, causing high CPU while traffic counters remain low. Administrators can confirm this with `diag sys top` to identify the process ID, then restart the engine or the FortiGate, and also check for crash logs to identify the underlying bug.

Why this answer

When CPU usage remains high (above 80%) with no traffic, the most likely cause is a process stuck in an infinite loop, such as the IPS engine. This is a known software bug or process hang that consumes CPU cycles even without network traffic, and it can be verified using 'diagnose sys top' to identify the offending process.

Exam trap

The trap here is that candidates often associate high CPU with external attacks or configuration errors, but the key clue 'with no traffic' eliminates those options, pointing instead to an internal process malfunction.

How to eliminate wrong answers

Option A is wrong because an interface in error-disable state would cause link flaps or port shutdown, generating CPU interrupts only when traffic is present, not with no traffic. Option B is wrong because a misconfigured firewall policy causing packet drops would only consume CPU when packets are being processed, not when there is zero traffic. Option C is wrong because a DDoS attack requires incoming traffic to overwhelm the CPU; with no traffic, there is no attack vector to cause high CPU usage.

454
MCQeasy

Which FortiGate feature allows you to block access to specific URL categories such as 'Social Media' or 'Gambling'?

A.Web Filtering
B.Antivirus
C.Intrusion Prevention System (IPS)
D.Application Control
AnswerA

Web Filtering on FortiGate leverages the FortiGuard web filtering database to classify URLs into categories (e.g., social media, malware, phishing) and enforce per-policy allow, block, or warn actions based on those categories or a custom URL list. This directly controls which websites users can access, making it the correct feature for blocking specific sites. It can also be combined with local overrides and wildcard FQDN entries to fine-tune granular access control.

Why this answer

FortiGate's Web Filtering feature uses URL rating and category databases (e.g., FortiGuard) to block access to entire categories like 'Social Media' or 'Gambling' based on the destination URL. This is distinct from content inspection; it operates at the HTTP/HTTPS request level by matching the requested URL against predefined or custom category lists.

Exam trap

The trap here is confusing Application Control with Web Filtering, as both can block 'Social Media' but Application Control blocks based on application signatures (e.g., Facebook app traffic) while Web Filtering blocks based on URL categories, and candidates often overlook that Application Control cannot block a website accessed via a browser if the URL category is not explicitly blocked.

How to eliminate wrong answers

Option B (Antivirus) is wrong because it scans file content for malware signatures, not URL categories. Option C (IPS) is wrong because it detects and blocks network-based attacks using signatures, not URL categorization. Option D (Application Control) is wrong because it identifies and controls applications based on traffic patterns (e.g., Facebook app), not URL categories, and can be bypassed if the app uses different protocols or ports.

455
Multi-Selectmedium

A FortiGate administrator is configuring a dial-up IPsec VPN for remote users. The users will connect from various locations with dynamic public IP addresses. The administrator wants to ensure that the VPN is secure and that only authorized users can connect. Which two Phase 1 configuration settings are required to support this scenario? (Choose two.)

Select 2 answers
A.Set the 'Remote Gateway' to 'Dialup User'.
B.Set the 'Remote Gateway' to the specific IP address of each user.
C.Enable 'XAUTH' for extended authentication.
D.Configure 'Aggressive' mode for Phase 1.
E.Enable 'NAT Traversal' in Phase 1 settings.
AnswersA, C

Setting the remote gateway to 'Dialup User' allows the FortiGate to accept connections from any IP address, which is necessary for users with dynamic public IPs. This mode is designed for dial-up VPNs where the remote peer's IP is not known in advance. Without this, the FortiGate would only accept connections from a specific IP.

Why this answer

For a dial-up IPsec VPN with dynamic user IPs, the remote gateway must be set to 'Dialup User' to accept connections from any IP. To authenticate individual users, XAUTH must be enabled, which prompts for username and password after the tunnel is established. These two settings ensure that the VPN can handle dynamic IPs and enforce user authentication.

Other settings like Aggressive mode or NAT Traversal may be used but are not required for all scenarios.

Exam trap

The trap here is assuming that Aggressive mode or NAT Traversal are mandatory for dial-up VPNs, when the essential requirements are Dialup User and XAUTH for dynamic IPs and user authentication.

456
Multi-Selecthard

A FortiGate administrator is configuring ZTNA for a web application. Which TWO components are required for a ZTNA configuration to function?

Select 2 answers
A.SSL VPN
B.IPsec VPN
C.ZTNA rules
D.ZTNA tags
E.Firewall policy
AnswersC, D

ZTNA rules are the central policy object in FortiOS that define which users and devices—identified by ZTNA tags—may access a specific protected application, and what action to take. When a client makes an HTTPS request through the ZTNA access proxy, the proxy evaluates matching ZTNA rules to allow or deny the session, making this the correct answer. These rules replace traditional firewall policies for application-level access control, not SSL VPN or IPsec.

Why this answer

ZTNA rules are the core policy mechanism that defines access control for ZTNA applications, specifying which users and devices can access which resources based on identity and device posture. Without ZTNA rules, the FortiGate cannot enforce the granular, identity-based access decisions that ZTNA requires.

Exam trap

The trap here is that candidates often confuse ZTNA with traditional VPN technologies (SSL VPN or IPsec VPN) or assume a standard firewall policy is mandatory, when in fact ZTNA operates as a separate, identity-centric access control layer that requires ZTNA rules and tags as its fundamental building blocks.

457
MCQmedium

An admin needs to configure an SSL VPN for remote users that only provides access to specific internal applications, not full network access. What feature should be configured?

A.Full tunneling
B.Client certificate authentication
C.Split tunneling
D.Web mode portal
AnswerC

Split tunneling is correct because it enables the administrator to define specific destination subnets that are routed through the SSL VPN tunnel, while all other traffic goes directly to the client's local network or Internet. This allows remote users to reach only the intended internal applications without exposing the entire corporate network. Split tunneling is configured via destination-based routing on the FortiGate, making it the precise access-control method for this scenario.

Why this answer

Split tunneling (Option C) is the correct feature because it allows the SSL VPN to route only traffic destined for specific internal applications through the encrypted tunnel, while all other traffic goes directly to the internet. This meets the requirement of providing access to specific internal applications without granting full network access, as split tunneling uses routing policies to selectively forward traffic based on destination IP addresses or application ports.

Exam trap

The trap here is that candidates often confuse 'web mode portal' (Option D) with application-specific access, but web mode only provides a browser-based gateway and does not inherently restrict network-layer access without additional split tunneling or firewall policies.

How to eliminate wrong answers

Option A is wrong because full tunneling routes all client traffic through the VPN tunnel, including internet-bound traffic, which would provide full network access and is the opposite of the requirement to limit access to specific internal applications. Option B is wrong because client certificate authentication is an authentication method that verifies the user's identity, not a mechanism to control which applications or network resources are accessible after authentication. Option D is wrong because a web mode portal provides a browser-based interface for accessing specific web applications, but it does not inherently restrict network-level access; it still requires split tunneling or other routing controls to prevent full network access.

458
Multi-Selecthard

An admin is configuring a policy-based NAT (central SNAT) to translate internal users to a pool of public IPs using overload. The admin wants to ensure that specific applications using non-standard ports are not affected by NAT. Which THREE steps should the admin consider?

Select 3 answers
A.Disable NAT for those applications by adding a policy before the NAT policy with 'set nat disable'
B.Configure a separate IP pool dedicated to those applications
C.Use a fixed port range in the IP pool configuration
D.Use central SNAT with a VIP for source NAT
E.Enable 'set nat enable' on the policy
AnswersA, B, C

Adding a policy before the central SNAT policy with 'set nat disable' creates a deterministic exception: traffic matching that earlier policy is evaluated and its NAT disabled, so it is never processed by the subsequent central SNAT rule. Due to FortiOS policy ordering, the first match wins, meaning this exempt policy must be placed ahead of the NAT policy. This selectively preserves the original source address/port for those applications while other traffic continues through central SNAT.

Why this answer

Adding a policy before the central SNAT policy with `set nat disable` explicitly exempts specific traffic from NAT translation, ensuring that applications using non-standard ports are not affected by the overload behavior. Option B is correct because configuring a separate IP pool dedicated to those applications allows you to control the NAT behavior independently, such as using a pool without PAT or with a fixed port range, thereby avoiding port remapping issues. Option C is correct because using a fixed port range in the IP pool confines source port allocation to a specified range, accommodating applications that expect particular ports.

Option D is incorrect because a VIP is for destination NAT, not source NAT, and does not address source port modification. Option E is incorrect because enabling NAT on the policy would translate all traffic, not protect specific applications.

Exam trap

The trap is that candidates may believe only disabling NAT (Option A) can protect applications, overlooking that a dedicated IP pool with a fixed port range (Options B and C) can also preserve application behavior by controlling source port allocation. Additionally, some might incorrectly assume that a VIP (Option D) or simply enabling NAT (Option E) would address the issue.

459
MCQeasy

A network administrator is configuring a FortiGate for the first time and needs to enable administrative access via HTTPS from the internal network. Which configuration step is required?

A.Set the administrative access to HTTPS on the internal interface
B.Enable HTTPS on the system global settings
C.Create a firewall policy allowing inbound HTTPS from internal to the FortiGate
D.Configure a static route for the management subnet
AnswerA

To manage a FortiGate via HTTPS on a specific interface, you must explicitly enable HTTPS in the interface's administrative access settings. This is done with `config system interface` and `set allowaccess https` (or `set allowaccess ping https ...`), which tells the control plane to accept HTTPS sessions destined to that interface's IP address. Without this setting, even if the interface has a valid IP and the firewall permits HTTP(S) traffic, the FortiGate will drop management connection attempts.

Why this answer

Administrative access to a FortiGate interface is controlled per-interface under the interface configuration. By default, HTTPS access is disabled on all interfaces. To enable administrative HTTPS access from the internal network, you must set the administrative access to HTTPS on the specific internal interface.

This allows the FortiGate to listen for HTTPS management traffic on that interface's IP address.

Exam trap

The trap here is that candidates confuse firewall policies (which control traffic passing through the FortiGate) with local-in policies (which control traffic destined to the FortiGate), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option B is wrong because HTTPS is not enabled globally; it is enabled per-interface under config system interface. The global settings only control the HTTPS port (default 443) and certificate, not the interface-level access. Option C is wrong because firewall policies control traffic passing through the FortiGate, not traffic destined to the FortiGate itself.

Administrative access is governed by the local-in policy, which is implicitly controlled by the interface's administrative access settings. Option D is wrong because a static route is only needed if the management subnet is not directly connected; for the internal network, the FortiGate already has a directly connected route, so no static route is required.

460
MCQhard

A user reports that a legitimate website is being blocked by FortiGate web filtering. The administrator checks and finds that the URL category is 'Unrated'. What is the most likely cause?

A.The DNS server is not resolving the domain.
B.The website is new and not yet categorized by FortiGuard.
C.The web filter is configured to block all unrated sites.
D.The website is in the 'Blocked' category.
AnswerB

FortiGuard classifies websites by continuously crawling and categorizing the public internet, but a brand-new domain or newly launched website may not yet have an entry in the FortiGuard rating database. When FortiGate receives a request for such a site, it returns a rating of 'Unrated', and the security policy's handling of the Unrated category determines whether the URL is allowed or blocked. Since no category has been assigned, the site is blocked not because it is malicious or inappropriate, but simply because it has not yet been reviewed — this is the well-known false-positive scenario for newly registered domains.

Why this answer

When a website is categorized as 'Unrated' in FortiGate web filtering, it means FortiGuard's web filtering database has not yet assigned a category to that URL. This commonly occurs for newly registered or recently launched websites that have not been crawled and classified by FortiGuard's rating infrastructure. The correct answer is B because the 'Unrated' status directly indicates the site is new and not yet categorized.

Exam trap

The trap here is that candidates may confuse the 'Unrated' category with a configuration setting (like blocking unrated sites) or a network issue (like DNS failure), rather than recognizing it as a FortiGuard rating status indicating the site has not yet been classified.

How to eliminate wrong answers

Option A is wrong because DNS resolution is unrelated to URL categorization; a DNS failure would result in a connection error, not an 'Unrated' category. Option C is wrong because while a web filter policy can be configured to block unrated sites, the question asks for the most likely cause of the 'Unrated' category itself, not the blocking action. Option D is wrong because if the website were in the 'Blocked' category, it would show that specific category in the logs, not 'Unrated'.

461
MCQhard

A FortiGate administrator is upgrading firmware from version 6.0 to 7.0. The upgrade path requires multiple steps. Which of the following is the recommended method to ensure a successful upgrade?

A.Upgrade to 6.2, then to 6.4, then to 7.0, following the official upgrade path
B.Perform a factory reset after upgrading to 7.0
C.Use the 'execute upgrade-version' command to automatically determine the path
D.Upload and install the 7.0 firmware directly, then restore configuration from backup
AnswerA

Fortinet firmware upgrades must follow the documented sequential path because configuration syntax and daemon behaviour change between major releases; jumping directly from 6.0 to 7.0 risks an unsupported conversion. Stepping through 6.2 and 6.4 lets each release migrate the configuration incrementally, satisfying the multi-step upgrade constraint in the stem.

Why this answer

FortiGate firmware upgrades must follow a specific path to ensure compatibility of the firmware image, configuration database, and bootloader. Skipping intermediate versions (e.g., 6.2 and 6.4) can cause configuration corruption or boot failure because each major version may change the internal data structures or require a specific bootloader version. The official upgrade path from 6.0 to 7.0 is 6.0 → 6.2 → 6.4 → 7.0, as documented in Fortinet's release notes.

Exam trap

The trap here is that candidates may think a direct upgrade is acceptable because they assume firmware is backward-compatible, or they confuse the 'execute update-now' command with an automatic path resolver, when in fact Fortinet requires strict adherence to the documented upgrade path to prevent bootloader and configuration schema mismatches.

How to eliminate wrong answers

Option B is wrong because performing a factory reset after upgrading to 7.0 does not address the need for a correct upgrade path; it only resets the configuration, but the firmware itself must still be upgraded in the correct sequence to avoid bootloader or database incompatibilities. Option C is wrong because the 'execute upgrade-version' command does not exist; FortiGate uses 'execute update-now' for firmware updates, but there is no automatic path determination command—the administrator must manually follow the documented upgrade path. Option D is wrong because directly uploading and installing 7.0 firmware from 6.0 is not supported; it can result in a failed upgrade or a non-booting unit due to incompatible firmware structures, and restoring a configuration from backup after a direct upgrade may also fail if the configuration format has changed.

462
MCQmedium

A network admin runs 'diag sys session filter proto 6' and 'diag sys session list' and sees many sessions with state 'SYN_SENT' to a public web server. The firewall policy allows TCP/443. What is the MOST likely cause?

A.The web server is overloaded and dropping connections
B.The policy is in proxy mode but should be flow mode
C.The destination NAT (VIP) for the web server is not configured
D.The firewall policy has session TTL set too low
AnswerC

The destination NAT (VIP) is the critical missing element in this scenario. When a client sends a TCP SYN to the web server's public IP, the FortiGate must use a matching VIP to translate that destination to the server's private IP address; without it, the firewall has no next hop or internal server to forward the packet to. As a result, the SYN is dropped or consumed by the firewall itself, the server never receives the request, and the client's session stays in SYN_SENT.

Why this answer

The 'diag sys session filter proto 6' command filters for TCP sessions (protocol 6). Seeing many sessions stuck in 'SYN_SENT' state indicates that the FortiGate is sending SYN packets to the destination but never receiving a SYN-ACK reply. Since the firewall policy allows TCP/443, the most likely cause is that the destination NAT (VIP) for the public web server is not configured.

Without a VIP, the FortiGate forwards the packet with the original destination IP (the public IP), which may not be routable or may not exist on the internal network, causing the SYN to be sent into a black hole.

Exam trap

The trap here is that candidates assume 'SYN_SENT' always indicates a server-side issue (like overload or firewall blocking), but in FortiGate diagnostics, it specifically points to a missing or misconfigured destination NAT when the destination is a public IP that must be translated to an internal server.

How to eliminate wrong answers

Option A is wrong because an overloaded web server would typically respond with a SYN-ACK or RST, not cause the FortiGate to see endless 'SYN_SENT' states; the server would still complete the TCP handshake or reject the connection. Option B is wrong because proxy mode vs. flow mode affects how the firewall processes traffic (e.g., deep inspection), but it does not cause sessions to remain in 'SYN_SENT' state; that state indicates a failure in the TCP handshake at the network layer. Option D is wrong because a low session TTL would cause sessions to expire prematurely, not prevent the initial SYN-ACK from being received; 'SYN_SENT' means the handshake never completed, not that it was terminated early.

463
Multi-Selectmedium

A FortiGate in NAT/Route mode has multiple internal networks. The administrator wants to configure a loopback interface for management access. Which THREE statements about loopback interfaces are correct? (Choose three.)

Select 3 answers
A.The loopback interface must be assigned to a physical port
B.The loopback interface is always up regardless of physical link status
C.The loopback interface can be used as a source IP for management traffic
D.The loopback interface cannot be used for firewall policies
E.The loopback interface participates in routing protocols
AnswersB, C, E

Because a loopback interface has no physical hardware behind it, its link status is always administratively and operationally up as long as the FortiGate unit itself is powered on and running. This is a key advantage over physical interfaces, which may go down due to cable disconnection, switch failure, or negotiated link loss. The persistent up state makes loopback interfaces ideal for dynamic routing protocols and management sources that need a stable endpoint.

Why this answer

Option B is correct because a FortiGate loopback interface is a logical interface with no dependency on any physical link, so its operational state remains up even if physical ports go down. Option C is correct because the loopback's stable IP address is commonly configured as the source-ip for management protocols such as HTTPS, SSH, SNMP, and syslog, ensuring consistent management reachability. Option E is correct because loopback interfaces can be included in routing protocol configurations (for example, OSPF or BGP) and advertised as a stable router ID or network, which is a standard design practice.

Option A is wrong because a loopback is a logical interface that is not bound to a physical port. Option D is wrong because loopback interfaces can absolutely be referenced in firewall policies as source or destination interfaces.

Exam trap

The trap here is that candidates often assume loopback interfaces cannot be used in firewall policies or must be tied to a physical port, but FortiGate treats them as fully functional interfaces for both routing and policy enforcement.

464
MCQeasy

Which FortiGate log type records user authentication events, such as successful logins and failed login attempts?

A.ZTNA logs
B.Event logs
C.Traffic logs
D.Security logs
AnswerB

Event logs are the correct log type for user authentication events. They record auditable system events, including successful and failed login attempts for administrators, VPN users, and other service accounts, as well as authentication failures and lockouts. Event logs are specifically designed to capture user authentication and accounting information for security auditing.

Why this answer

Event logs on a FortiGate record system-level activities including user authentication events such as successful logins, failed login attempts, and administrative actions. These logs are specifically designed to capture events that are not traffic-related, making them the correct choice for authentication events.

Exam trap

NSE4 often tests the confusion between log types, especially event vs. security logs; candidates may incorrectly assume that authentication events are part of security logs because they relate to security, but FortiGate classifies them as event logs.

How to eliminate wrong answers

Option A is wrong because ZTNA logs focus on Zero Trust Network Access events, such as proxy access and device posture checks, not general user authentication. Option C is wrong because traffic logs record network traffic flows (source/destination IP, ports, bytes) and do not include authentication events. Option D is wrong because security logs capture security profile events like IPS, antivirus, and web filtering, not user login activities.

465
Multi-Selectmedium

A company has two internet connections (WAN1 and WAN2). The administrator wants to route HTTP traffic from the internal network through WAN1, and all other traffic through WAN2. Which TWO configurations are needed?

Select 2 answers
A.Define an SD-WAN rule that matches HTTP and sets WAN1 as preferred
B.Apply NAT with IP pool on the firewall policy
C.Add a static route with a lower priority to WAN1
D.Create a policy-based routing rule to send HTTP traffic to WAN1
E.Configure load balancing between WAN1 and WAN2
AnswersA, D

An SD-WAN rule is the correct, centralized mechanism in FortiOS to steer traffic based on application or service. By creating a rule that matches HTTP and setting WAN1 as the preferred member, you explicitly route that protocol out of WAN1 while optionally maintaining failover to WAN2 if WAN1 goes down. This approach leverages SD-WAN health-check and load-balancing logic, making it the most robust and policy-driven solution.

Why this answer

SD-WAN rules allow you to define application-based routing policies. By creating an SD-WAN rule that matches HTTP traffic and sets WAN1 as the preferred interface, the FortiGate will automatically steer HTTP sessions out through WAN1 while using the default routing table (which points to WAN2) for all other traffic. This leverages the SD-WAN feature's ability to perform per-application load balancing and failover without requiring policy-based routing.

Exam trap

The trap here is that candidates often confuse policy-based routing (Option D) with SD-WAN rules (Option A), not realizing that both are valid methods for application-based routing on FortiGate, and the question asks for TWO configurations needed, so both A and D are correct.

466
MCQeasy

Which of the following is a characteristic of policy-based NAT on a FortiGate?

A.NAT is configured directly in the firewall policy using the 'set nat' option
B.NAT is configured separately from firewall policies using Central NAT rules
C.NAT is applied to all traffic regardless of policy
D.NAT can only be used with IP pools
AnswerA

In policy-based NAT, the translation is an integral part of the firewall policy itself. The administrator enables NAT by setting the `nat` option to `enable` within that specific policy, optionally choosing an IP pool for source translation. This binds the translation rule directly to the policy's matching criteria, providing per-policy granularity, which is the defining characteristic of this approach.

Why this answer

Policy-based NAT on a FortiGate is configured directly within a firewall policy using the 'set nat' command. This allows NAT to be applied selectively based on the policy's matching criteria (source, destination, service, etc.), rather than being defined as a separate rule. This approach is the traditional method on FortiGate and is distinct from Central NAT, which decouples NAT rules from firewall policies.

Exam trap

The trap here is that candidates often confuse policy-based NAT with Central NAT (Option B), mistakenly thinking NAT must always be configured separately, but FortiGate supports both methods and the question specifically asks about policy-based NAT.

How to eliminate wrong answers

Option B is wrong because Central NAT rules are a separate feature where NAT is configured independently from firewall policies, which is the opposite of policy-based NAT. Option C is wrong because policy-based NAT is not applied to all traffic; it only applies to traffic that matches the specific firewall policy where NAT is enabled. Option D is wrong because policy-based NAT can use either IP pools or the interface IP address (via 'set nat' without an IP pool), so it is not limited to IP pools.

467
MCQeasy

An administrator is configuring a firewall policy on a FortiGate to allow internal users to access a web server on the internet. The administrator wants to log all traffic that matches this policy. Which logging option should be enabled on the policy to log traffic at the session start and end?

A.Log Allowed Traffic - All Sessions
B.Generate Logs when Session Starts
C.Log Allowed Traffic - Security Events
D.Capture Packets
AnswerA

This is correct because selecting 'All Sessions' under 'Log Allowed Traffic' causes the FortiGate to log every session that matches the policy, including the start and end of the session. This provides a complete record of allowed traffic. It is the appropriate setting when the administrator wants to log all traffic for auditing or troubleshooting purposes.

Why this answer

To log all allowed traffic including session start and end, the administrator should enable 'Log Allowed Traffic' and select 'All Sessions'. This setting ensures that every session matching the policy is logged, providing comprehensive visibility. Other options like logging only security events or only session start do not meet the requirement.

Capture Packets is for troubleshooting, not logging. This configuration is essential for auditing and monitoring network activity.

Exam trap

The trap here is confusing 'Log Allowed Traffic - All Sessions' with 'Generate Logs when Session Starts', which only logs the beginning of a session.

468
Multi-Selecthard

Which THREE factors should be considered when tuning IPS to reduce false positives?

Select 3 answers
A.Excluding trusted source IP addresses from certain signatures.
B.Enabling hardware acceleration for IPS processing.
C.Increasing the sensitivity of signatures to catch more attacks.
D.Adjusting the severity threshold for which signatures generate alerts.
E.Creating IPS filters to whitelist specific traffic patterns.
AnswersA, D, E

By creating a source-IP exemption list for specific signatures, known-good hosts such as domain controllers or admin workstations are skipped during detection. This reduces false positives without weakening protection for untrusted endpoints, since traffic from other sources still hits the full signature set. This is a targeted, address-based tuning measure that preserves detection efficacy where it matters.

Why this answer

Excluding trusted source IP addresses from certain signatures prevents the IPS from generating alerts for traffic that is known to be legitimate, directly reducing false positives. This is a common tuning technique in FortiGate IPS where you can create exceptions for specific sources or destinations to avoid unnecessary alerts from benign traffic.

Exam trap

The trap here is that candidates often confuse performance optimization (hardware acceleration) with accuracy tuning, or mistakenly think that increasing sensitivity reduces false positives, when in fact it does the opposite.

469
MCQhard

You run 'diagnose debug application ike -1' and see the following output: 'Initiator: no acceptable proposal'. What is the MOST likely cause of this error?

A.The pre-shared key is incorrect
B.The Phase 1 encryption or hash algorithm is mismatched
C.The remote gateway is not reachable
D.The firewall policy is blocking UDP port 500
AnswerB

A mismatched Phase 1 encryption or hash algorithm directly causes the exact error seen in the ike debug. When the initiator sends a proposal list and the responder cannot find an identical SA transform (same encryption, hash, DH group, lifetime), the responder returns a NO_PROPOSAL_CHOSEN notify and the debug prints something like "no acceptable proposal" or "proposal mismatched". Correcting the FortiGate's Phase 1 algorithm set to match the peer resolves this.

Why this answer

The error 'no acceptable proposal' indicates that the IKE Phase 1 negotiation failed because the two VPN peers could not agree on a common set of security parameters. This is most commonly caused by a mismatch in the encryption algorithm (e.g., AES128 vs AES256) or the hash algorithm (e.g., SHA1 vs SHA256) configured on the FortiGate versus the remote peer. The pre-shared key is not checked until after Phase 1 completes, so it would not cause this specific error.

Exam trap

The trap here is that candidates often confuse Phase 1 proposal mismatches with pre-shared key errors, but the PSK is only checked after the proposal is accepted, so the 'no acceptable proposal' error points exclusively to encryption/hash/DH group mismatches.

How to eliminate wrong answers

Option A is wrong because the pre-shared key is verified during Phase 1 authentication, after the proposal is accepted; an incorrect PSK would result in a different error such as 'no suitable proposal found' or authentication failure. Option C is wrong because if the remote gateway were unreachable, the debug output would show 'no response' or 'timeout', not 'no acceptable proposal'. Option D is wrong because if UDP port 500 were blocked, the IKE packets would never reach the peer, resulting in a timeout or 'no response' error, not a proposal mismatch.

470
MCQeasy

Which statement best describes the 'implicit deny' policy on a FortiGate?

A.It can be moved to a different position in the policy list
B.It is automatically applied to all traffic that does not match any explicit policy
C.It is a configurable policy that denies all traffic
D.It logs all denied traffic by default
AnswerB

FortiGate evaluates traffic against explicit firewall policies in sequence; anything matching none of them is dropped by the implicit deny, which sits at the end of the policy list. It is not configured manually and applies automatically to all unmatched traffic.

Why this answer

The 'implicit deny' policy on a FortiGate is a built-in, last-resort rule that automatically denies any traffic not matching an explicit firewall policy. It is not visible in the policy list and cannot be moved, modified, or deleted; it is always applied as the final rule to ensure that only explicitly permitted traffic is allowed through the FortiGate.

Exam trap

The trap here is that candidates often confuse the implicit deny with a configurable policy, thinking it can be moved, logged, or modified, when in fact it is a fixed, non-configurable default rule that is always present and never logs traffic by default.

How to eliminate wrong answers

Option A is wrong because the implicit deny policy is not a movable entry in the policy list; it is a fixed, invisible rule that always resides at the bottom of the policy evaluation order. Option C is wrong because the implicit deny is not configurable — it is a hardcoded default behavior that cannot be edited or removed. Option D is wrong because the implicit deny does not log denied traffic by default; logging must be explicitly enabled on an explicit deny policy or via global logging settings.

471
MCQmedium

An administrator has configured an SSL deep inspection profile with 'certificate inspection' for a firewall policy. Users report that they receive certificate errors when accessing HTTPS sites. What is the MOST likely reason?

A.The certificate installed on the FortiGate for SSL inspection is expired
B.The web server uses a self-signed certificate which is blocked by the inspection profile
C.The users' browsers do not trust the FortiGate's CA certificate
D.The FortiGate is not configured to re-sign certificates with its own CA certificate
AnswerB

In certificate inspection mode, the FortiGate does not decrypt the SSL stream but still inspects the server certificate during the handshake. A self-signed certificate is inherently untrusted because it is not issued by a recognized CA, so the inspection profile blocks the connection. This block prevents the browser from completing the handshake, resulting in certificate error messages being displayed to the user.

Why this answer

With 'certificate inspection' mode, the FortiGate does not decrypt traffic or present its own certificate to clients. It only inspects the server certificate during the SSL handshake. If the inspection profile is configured to block invalid certificates (e.g., self-signed, expired, untrusted CA), and the web server uses a self-signed certificate, the FortiGate will drop the connection.

Users may then see a certificate error or connection failure in their browsers. Option C is incorrect because certificate inspection never involves the FortiGate's CA certificate; that is only used in full SSL inspection when re-signing certificates.

472
MCQmedium

A FortiGate is configured with FSSO for firewall authentication. Users report they are prompted for credentials every time they access the internet, even though they are logged into the domain. What is the most likely cause?

A.The users are not members of the FSSO group.
B.The firewall policy uses 'All Users' instead of a specific group.
C.The FSSO collector agent service is not running.
D.The FortiGate's LDAP server is unreachable.
AnswerC

The FSSO collector agent is the critical component that gathers logon events from Active Directory (either through NetAPI polling or by reading Windows security event logs) and forwards them to the FortiGate. If the collector agent service is stopped or not running, the FortiGate has no source of domain user logon information, so it treats all traffic as unauthenticated and triggers local firewall authentication prompts. This is the most direct cause of the symptom described, because the entire FSSO identity pipeline is broken.

Why this answer

If the FSSO collector agent service is not running, the FortiGate cannot receive the logon events from the domain controllers. Without these events, the FortiGate has no way to know which users are authenticated, so it falls back to prompting for credentials on every new session, even though users are already logged into the domain.

Exam trap

The trap here is that candidates often confuse FSSO with LDAP authentication, assuming an LDAP connectivity issue is the cause, when in fact FSSO relies on a separate collector agent and domain controller event polling, not direct LDAP queries.

How to eliminate wrong answers

Option A is wrong because users not being members of the FSSO group would cause them to be denied access or not matched to the policy, not repeatedly prompted for credentials. Option B is wrong because using 'All Users' in the firewall policy would actually bypass FSSO authentication entirely, allowing traffic without any credential prompt. Option D is wrong because the FortiGate's LDAP server being unreachable affects LDAP-based authentication or directory lookups, not the FSSO polling mechanism which relies on the collector agent and domain controller events, not direct LDAP queries.

473
MCQeasy

An administrator wants to use Active Directory credentials to authenticate firewall administrators. Which authentication server type should be configured on the FortiGate?

A.TACACS+
B.FSSO
C.LDAP
D.RADIUS
AnswerC

LDAP is the directory protocol Microsoft Entra ID and Active Directory expose for credential queries. Configuring an LDAP server on the FortiGate lets administrator logins be validated against Active Directory, satisfying the requirement to reuse those credentials.

Why this answer

LDAP (Lightweight Directory Access Protocol) is the correct choice because it directly integrates with Microsoft Active Directory to authenticate firewall administrators using their existing AD credentials. FortiGate can bind to an LDAP server to verify username and password pairs, making it the native protocol for AD authentication without requiring additional services or translation layers.

Exam trap

The trap here is that candidates often confuse FSSO (used for transparent network authentication) with direct admin authentication, or assume RADIUS is the only way to integrate with AD, but FortiGate's native LDAP support is the simplest and most direct method for admin authentication against Active Directory.

How to eliminate wrong answers

Option A is wrong because TACACS+ is a Cisco-proprietary protocol that separates authentication, authorization, and accounting (AAA) and is not natively used by Active Directory; it requires a separate TACACS+ server to bridge to AD. Option B is wrong because FSSO (Fortinet Single Sign-On) is designed for transparent user identification on the network, not for authenticating firewall administrators; it polls AD for login events but does not perform direct password validation. Option D is wrong because RADIUS is a generic AAA protocol that can authenticate against AD only if a RADIUS server (like NPS) is configured as an intermediary; it is not a direct AD authentication method and adds unnecessary complexity for admin authentication.

474
MCQeasy

A network administrator wants to prevent users from downloading files with .exe extensions via HTTP and HTTPS. Which security profile feature should be used?

A.Web filter profile with URL filter to block .exe sites
B.Application control profile to block file transfer applications
C.Antivirus profile with 'block' action for file pattern matching .exe
D.IPS profile to block executable file transfers
AnswerC

The antivirus profile in FortiOS includes a file filter (or file pattern) capability that can match filenames, file extensions, or MIME types during protocol decoding. By configuring a file pattern for '.exe' and setting the action to 'block', FortiGate inspects the file's extension as it passes through HTTP (or HTTPS when deep inspection is enabled) and discards the file before it reaches the user. This is the correct method because the antivirus engine works at the content layer, not at the URL or application layer, and can enforce file-type blocking regardless of the website hosting the file.

Why this answer

The Antivirus profile in FortiGate can be configured with a file pattern matching rule to block files based on their extension, such as .exe. This feature operates at the application layer, inspecting HTTP and HTTPS traffic (via SSL inspection) to identify and block executable files before they reach the user. Option C is correct because it directly uses the antivirus engine's file pattern matching capability to enforce this policy.

Exam trap

The trap here is that candidates confuse URL filtering (which blocks sites) with file extension filtering (which blocks specific file types within allowed sites), leading them to choose the web filter profile option instead of the antivirus profile.

How to eliminate wrong answers

Option A is wrong because a web filter profile with URL filtering blocks access to entire websites or URL categories, not specific file extensions within HTTP/HTTPS downloads; it cannot inspect file content or extensions. Option B is wrong because an application control profile is designed to identify and control network applications (e.g., Skype, BitTorrent), not to block file transfers based on file extension; it does not inspect file payloads. Option D is wrong because an IPS profile is used to detect and prevent network-based attacks and vulnerabilities, not to block specific file types; it focuses on exploit signatures, not file extensions.

475
MCQmedium

A network admin has configured a firewall policy allowing HTTPS traffic from the internal network to a DMZ web server. Users report that the web pages load slowly. The admin checks the policy and notices traffic shaping is not applied. What is the BEST action to ensure fair bandwidth distribution for HTTPS traffic?

A.Create a traffic shaping policy and apply it to the firewall policy
B.Increase the bandwidth of the internet link
C.Configure policy-based routing for HTTPS traffic
D.Enable QoS on the outgoing interface
AnswerA

In FortiGate, bandwidth control is enforced through traffic shaping policies that are directly referenced by a firewall policy. You can assign a shared or per-IP traffic shaper with guaranteed and maximum bandwidth values, plus a priority level, so matching HTTPS sessions get explicit bandwidth limits and fair distribution. This is the only option that applies per-policy rate limiting, allowing the administrator to cap and prioritize traffic without affecting other policies.

Why this answer

Traffic shaping is the correct mechanism to enforce fair bandwidth distribution for HTTPS traffic. By creating a traffic shaping policy and applying it to the firewall policy, the admin can allocate a specific bandwidth guarantee or limit for HTTPS sessions, preventing them from starving other traffic. Without shaping, HTTPS traffic can consume all available bandwidth, causing slow performance for other users.

Exam trap

The trap here is that candidates often confuse QoS (which prioritizes packets) with traffic shaping (which controls bandwidth allocation), leading them to select option D, but QoS alone does not enforce fair distribution of bandwidth across multiple sessions.

How to eliminate wrong answers

Option B is wrong because increasing the internet link bandwidth does not enforce fair distribution; it only adds more capacity, which can still be monopolized by aggressive HTTPS traffic. Option C is wrong because policy-based routing controls the path traffic takes, not bandwidth allocation; it does not shape or limit traffic. Option D is wrong because QoS on the outgoing interface is a lower-level mechanism that typically prioritizes packets based on DSCP or CoS values, but it does not provide the per-policy bandwidth control that traffic shaping offers in FortiGate.

476
MCQhard

You run the command 'diagnose vpn ike log filter name vpn1' and then 'diagnose vpn ike log filter type phase1'. The log shows: 'IKEv1 exchange:f4470f07:00000000: responder: main mode: received IKE_SA_INIT (aggressive mode not allowed)'. What is the problem?

A.The initiator is using IKEv2 while the responder uses IKEv1
B.The responder is configured for main mode only, but the initiator is sending aggressive mode
C.The pre-shared key is wrong
D.The phase1 proposal is incompatible
AnswerB

In IKEv1, an aggressive-mode initiator sends its SA proposal, key-exchange material, nonce, and identity in a single packet, while a main-mode-only responder expects the two-round-trip Main Mode sequence (SA exchange first, then KE/nonce). When the responder's phase 1 configuration is set to 'main mode only,' it immediately discards the incoming aggressive-mode packet and logs a mode mismatch such as 'aggressive mode is not supported.' This rejection occurs before any proposal comparison or PSK authentication, so the log indicates a configuration mismatch rather than a cryptographic or proposal failure.

Why this answer

The log message 'aggressive mode not allowed' indicates the responder (FortiGate) is configured to accept only main mode IKE phase1 negotiations, but the initiator sent an aggressive mode request. This mismatch causes the responder to reject the IKE_SA_INIT message, as aggressive mode is disabled by default or explicitly set to main mode only in the phase1 configuration.

Exam trap

The trap here is that candidates may confuse the 'aggressive mode not allowed' message with a proposal mismatch or authentication failure, but the log explicitly states the mode is the issue, not the cryptographic parameters or keys.

How to eliminate wrong answers

Option A is wrong because the log explicitly shows 'IKEv1 exchange', so both sides are using IKEv1, not IKEv2. Option C is wrong because a pre-shared key mismatch would cause a different error, such as 'invalid payload' or 'authentication failed', not a mode rejection message. Option D is wrong because an incompatible phase1 proposal would generate a 'no acceptable proposal' or 'proposal mismatch' error, not a message about aggressive mode not being allowed.

477
MCQeasy

A FortiGate administrator configures a firewall policy to allow HTTP traffic from internal users to the internet. The policy uses source address 'internal_subnet', destination address 'all', and service 'HTTP'. After applying the policy, users report they cannot access websites. What is the most likely cause?

A.The source interface is misconfigured
B.The destination address object 'all' is incorrect
C.The policy order is incorrect and a deny policy above is blocking the traffic
D.The policy only allows HTTP (port 80), but users are likely accessing HTTPS (port 443)
AnswerD

The service object restricts the policy to TCP port 80 only, so browser sessions to port 443 match no permit rule and are dropped. Widening the service to HTTPS or ALL resolves the failure, since modern sites default to TLS.

Why this answer

The policy explicitly allows HTTP (TCP port 80), but modern web traffic predominantly uses HTTPS (TCP port 443). Since the service object does not include HTTPS, the firewall will drop HTTPS packets by default unless a separate policy or rule permits them. This is the most likely reason users cannot access websites, as most sites redirect HTTP to HTTPS or require HTTPS for secure connections.

Exam trap

The trap here is that candidates assume 'HTTP' covers all web traffic, but FortiGate treats HTTP and HTTPS as distinct services based on port numbers, and the implicit deny will block any unmatched traffic.

How to eliminate wrong answers

Option A is wrong because the source interface misconfiguration would typically cause a complete lack of connectivity for all traffic from that interface, not just web browsing, and the policy would not match at all. Option B is wrong because the destination address object 'all' is a valid FortiGate object that represents any destination IP address, and it is correct for allowing traffic to the internet. Option C is wrong because while policy order can affect traffic matching, the question states the policy was applied and there is no indication of a deny policy above; the most direct and common cause is the service mismatch.

478
MCQmedium

An administrator wants to ensure that search engine results from Google, Bing, and Yahoo are filtered to exclude explicit content when users perform searches. Which feature should the administrator configure in the web filter profile?

A.FortiGuard category filter
B.URL filter
C.Safe search
D.DNS filter
AnswerC

Safe search: Safe search enforcement is a specific FortiGate feature that inserts the appropriate safe search cookies or query parameters (e.g., 'safe=active' for Google) into outbound requests to supported search engines. It also integrates with DNS-based and HTTPS inspection to prevent users from disabling this setting. Unlike category or URL filters, it actively modifies the request so the search engine itself returns filtered results, which is the only way to guarantee content-level safe search on the SERP.

Why this answer

Safe search is a feature within FortiGate's web filter profile that enforces search engine providers (Google, Bing, Yahoo) to filter explicit content from search results. It works by appending specific parameters to search URLs or using HTTPS inspection to inject the safe search cookie, ensuring compliance with content filtering policies.

Exam trap

The trap here is that candidates confuse category filtering (which blocks entire sites) with safe search (which filters content within allowed sites), leading them to select FortiGuard category filter instead of Safe search.

How to eliminate wrong answers

Option A is wrong because FortiGuard category filter blocks or allows entire categories of websites (e.g., 'Adult/Mature Content'), but it does not control the search results within allowed search engines. Option B is wrong because URL filter matches specific URLs or patterns, not the dynamic search result content from search engines. Option D is wrong because DNS filter blocks or redirects DNS queries to domains, but it cannot modify the content of search results returned by a search engine.

479
Multi-Selectmedium

A FortiGate administrator is configuring FSSO to authenticate users transparently. The FSSO collector agent is installed on a Windows server in the domain. Which TWO requirements must be met for FSSO to work correctly?

Select 2 answers
A.The FortiGate must be a member of the Active Directory domain
B.The users must authenticate via captive portal at least once
C.The FortiGate must be able to reach the FSSO collector agent on TCP port 8000 (or the configured port)
D.The firewall policies must use FSSO groups directly without any user objects
E.The FSSO collector agent must have network access to the Active Directory domain controllers
AnswersC, E

The FortiGate must be able to reach the FSSO collector agent on TCP port 8000 (or the port specified under FSSO settings). This is the connection over which the collector agent sends login and logout events; if the port is firewalled, the FortiGate will not receive authentication updates and FSSO policies will fail to match. The default port is 8000, but it must match exactly on both the agent and the FortiGate.

Why this answer

The FortiGate must communicate with the FSSO collector agent over TCP port 8000 (or a custom port) to receive real-time user login/logoff events. This connection is essential for the FortiGate to map IP addresses to authenticated domain users and enforce identity-based firewall policies. Without this reachability, the FortiGate cannot obtain the necessary user-to-IP mappings from the collector agent.

Exam trap

The trap here is that candidates assume the FortiGate must join the Active Directory domain (Option A), but FSSO only requires network connectivity to the collector agent, not domain membership.

480
MCQhard

A FortiGate is configured with IPsec VPN using IKEv2 and a policy-based tunnel. The remote subnet is 10.0.2.0/24, and the local subnet is 192.168.1.0/24. The tunnel is up, but traffic from 192.168.1.0/24 to 10.0.2.0/24 fails. The administrator checks the firewall policy and sees a policy allowing traffic from the local interface (port1) to the remote interface (virtual ipsec interface) with the action set to IPSEC. What is the most likely missing configuration?

A.IKEv2 does not support policy-based VPNs
B.The tunnel interface is not assigned to the correct VDOM
C.The Phase 2 proposal does not match the remote subnet
D.The firewall policy's source or destination addresses are not correctly set to the local and remote subnets
AnswerD

In a policy-based IPsec VPN, the firewall policy itself defines the local and remote subnets through its source and destination address objects, effectively acting as the Phase 2 proxy-IDs. If those address objects do not exactly match the subnets to be protected, the tunnel remains up but traffic is not matched by the policy, so the FortiGate drops or fails to forward it. Additionally, using only 'all' as the destination may send a proxy-ID of 0.0.0.0/0, which many remote peers reject, causing a negotiation mismatch even though the policy itself is permissive.

Why this answer

In a policy-based IPsec VPN on FortiGate, the firewall policy must explicitly specify the local and remote subnets as the source and destination addresses. Even if the tunnel is up, traffic will fail if the policy's source/destination address objects do not match the actual subnets (192.168.1.0/24 and 10.0.2.0/24). The action set to IPSEC only enables VPN encapsulation; it does not override incorrect address matching.

Exam trap

The trap here is that candidates assume a tunnel being up means all traffic will pass, but FortiGate policy-based VPNs require the firewall policy's address objects to precisely match the protected subnets, not just the tunnel interface.

How to eliminate wrong answers

Option A is wrong because IKEv2 fully supports policy-based VPNs on FortiGate; the issue is not protocol version compatibility. Option B is wrong because VDOM assignment affects interface visibility, but the tunnel is up and the policy references the virtual IPsec interface, indicating correct VDOM placement. Option C is wrong because a Phase 2 proposal mismatch would prevent the tunnel from establishing or cause it to fail during negotiation, but the tunnel is already up, so the Phase 2 selectors must match the remote subnet.

481
Multi-Selectmedium

A FortiGate administrator needs to allow SMTP traffic (TCP port 25) from the internal network (10.0.0.0/8) to a mail server in the DMZ (172.16.0.10). The administrator wants to apply an antivirus profile and log all sessions. Which THREE configuration steps are required?

Select 3 answers
A.Create a schedule object and apply it to the policy
B.Create a firewall policy with source: 10.0.0.0/8, destination: 172.16.0.10, service: SMTP, action: ACCEPT
C.Create an antivirus profile and apply it to the policy
D.Configure NAT on the policy to translate source IPs
E.Enable logging on the firewall policy
AnswersB, C, E

A firewall policy with source 10.0.0.0/8, destination 172.16.0.10, service SMTP, and action ACCEPT is the fundamental permit rule needed to allow the SMTP traffic. FortiGate evaluates policies from top to bottom, and this tuple uniquely identifies the SMTP session directed to the mail server. Without such an explicit ACCEPT policy, the implicit deny rule would silently drop the traffic, so this is the correct baseline configuration.

Why this answer

A firewall policy must be created to allow SMTP traffic from the internal network (10.0.0.0/8) to the DMZ mail server (172.16.0.10) on TCP port 25. The policy must specify the source, destination, service (SMTP), and action (ACCEPT) to permit the traffic. Without this policy, the traffic would be blocked by default.

Exam trap

The trap here is that candidates often assume NAT is required for any traffic leaving a private network, but in FortiGate, NAT is only needed when the destination is on a different network segment that requires source address translation, such as the internet, not for internal-to-DMZ traffic.

482
MCQhard

A FortiGate is configured with two WAN links (port1 and port2) and uses ECMP routing. The administrator wants to ensure that traffic from a specific internal subnet (192.168.10.0/24) always uses port1, while all other traffic uses ECMP. Which configuration should be applied?

A.Create a separate VDOM for 192.168.10.0/24 and route it through port1
B.Create two static routes with equal distances to use ECMP, and add a policy route for 192.168.10.0/24 with outgoing interface port1
C.Configure a VIP to translate 192.168.10.0/24 to an IP on port1
D.Use a firewall policy to change the route based on source
AnswerB

Equal-distance static routes create an ECMP group that load-balances traffic across port1 and port2, but this balances based on destination and may not honor source-based preferences. Adding a policy route for 192.168.10.0/24 with outgoing interface port1 forces all traffic originating from that source subnet to egress via port1, overriding the ECMP decision for that specific source. This combination gives you both the high-availability/load-balancing benefit of ECMP and the required source-specific egress control.

Why this answer

Policy routes override the routing table for matching traffic, allowing you to force traffic from 192.168.10.0/24 out port1 while ECMP handles all other traffic. ECMP distributes traffic across multiple equal-cost routes, but a policy route takes precedence over the routing table for specified traffic. This meets the requirement without disrupting ECMP for other traffic.

Exam trap

The trap here is confusing firewall policies with routing decisions; candidates often think a firewall policy can change the outgoing interface, but it only controls access, not the path traffic takes through the network.

How to eliminate wrong answers

Option A is wrong because creating a separate VDOM for a single subnet is overkill and introduces administrative overhead; VDOMs are for multi-tenant isolation, not simple source-based routing. Option C is wrong because a VIP translates destination IPs, not source subnets, and does not control outbound interface selection. Option D is wrong because firewall policies do not change routes; they match traffic and apply actions like allow/deny, but routing decisions are made by the routing table or policy routes.

483
Multi-Selectmedium

A site-to-site IPsec VPN is configured with IKEv2. The tunnel establishes but traffic does not pass. Which two troubleshooting steps should the administrator perform first?

Select 2 answers
A.Check the Phase 2 selectors.
B.Verify that the Phase 1 proposal matches.
C.Check the firewall policies allowing traffic through the tunnel.
D.Check the routing table for routes pointing to the remote networks.
AnswersC, D

In Fortinet's policy-based VPN model, firewall policies are the gatekeepers that decide which traffic is allowed to traverse the tunnel interface. Even with Phase 1 and Phase 2 both up, packets are dropped unless there is an explicit policy permitting traffic between the local and remote zones (e.g., from 'internal' to 'tunnel'). This is a frequent point of failure because the tunnel status itself is independent of the policy configuration.

Why this answer

Even if the IPsec tunnel is established, traffic will not pass unless firewall policies explicitly permit it. In FortiGate, a Phase 2 tunnel being up does not imply that traffic is allowed; you must have a policy that matches the source/destination and enables the action to forward traffic through the tunnel interface.

Exam trap

The trap here is that candidates assume a 'tunnel up' status guarantees traffic flow, but FortiGate separates tunnel negotiation from firewall policy enforcement, so both a policy and a route are required for traffic to pass.

484
MCQmedium

An administrator wants to back up the FortiGate configuration to a remote FTP server. Which command should be used?

A.execute restore config ftp <filename> <server>
B.copy running-config startup-config
C.execute backup system ftp <filename> <server>
D.execute backup config ftp <filename> <server>
AnswerD

`execute backup config ftp <filename> <server>` is the correct FortiGate CLI command to export the current configuration to a remote FTP server. The command specifies the object type `config` (the device configuration), the protocol `ftp`, the destination filename, and the server's hostname or IP address. FortiOS will prompt for FTP credentials if they are not provided, and the resulting backup file can later be restored with the corresponding `execute restore config ftp` command. This is the standard, supported method for a configuration backup via FTP.

Why this answer

The `execute backup config ftp` command is the specific FortiGate CLI command designed to back up the configuration file to a remote FTP server. This command directly initiates an FTP transfer of the current system configuration, ensuring the backup is stored externally for disaster recovery.

Exam trap

The trap here is confusing the `backup` and `restore` commands, or using a Cisco-style command like `copy running-config startup-config`, which is not valid on FortiGate devices.

How to eliminate wrong answers

Option A is wrong because `execute restore config ftp` is used to restore a configuration from an FTP server, not to back up. Option B is wrong because `copy running-config startup-config` is a Cisco IOS command for saving the running configuration to NVRAM, not a FortiGate command for backing up to an FTP server. Option C is wrong because `execute backup system ftp` is not a valid FortiGate command; the correct syntax uses `config` to specify the configuration file, not `system`.

485
Multi-Selectmedium

A FortiGate administrator needs to allow SNMP monitoring from a management station at 10.10.10.50. Which TWO configuration steps are required? (Choose two.)

Select 2 answers
A.Enable SNMP agent globally
B.Configure an SNMP community with read-only access and restrict access to 10.10.10.50
C.Configure an SNMP trap to send alerts to 10.10.10.50
D.Enable SNMP on the interface connected to the management station
E.Configure a firewall policy allowing SNMP from the management station
AnswersA, B

The FortiGate's SNMP agent is disabled by default; without enabling it globally under System > SNMP, the device will not respond to any SNMP get/set requests regardless of other configuration. Enabling the agent is the mandatory first step to allow a management station to poll MIB objects such as interface utilization, CPU, and memory. This is a global toggle, not per-interface, and once enabled the agent listens on port 161 for all configured SNMP communities.

Why this answer

The SNMP agent must be globally enabled on the FortiGate before any SNMP queries can be processed. Option B is correct because an SNMP community with read-only access defines the authentication and access control parameters, and restricting it to 10.10.10.50 ensures only that management station can poll the device.

Exam trap

The trap here is that candidates often confuse SNMP monitoring (polling) with SNMP traps, or mistakenly think a firewall policy is needed for local management traffic, when in fact SNMP agent access is controlled entirely by the community configuration and the global enable setting.

486
MCQhard

A FortiGate administrator runs 'diagnose vpn tunnel list' and sees the following output for an IPsec tunnel: 'status: up', 'incoming: 0 packets', 'outgoing: 100 packets'. Phase 1 and Phase 2 both show state 'up'. What is the MOST likely cause of zero incoming packets?

A.The remote gateway is using aggressive mode
B.The FortiGate has a static route pointing to the VPN interface
C.The VPN is configured in policy-based mode
D.The Phase 2 proposal includes a mismatched proxy ID
AnswerD

During Phase 2 negotiation, both peers exchange proxy IDs (traffic selectors) that define which source and destination subnets are encrypted. If the local proxy ID does not exactly match the remote peer's expected subnets, the IPsec SA is established with mismatched selectors. The remote gateway may then drop incoming packets that fall outside its configured selectors, or it may not respond at all, causing the tunnel to appear up but traffic to fail in one or both directions.

Why this answer

The output shows the VPN tunnel is up with outgoing packets but zero incoming packets. This indicates a Phase 2 mismatch, most commonly due to mismatched proxy IDs (local/remote subnets). When proxy IDs do not match between peers, the tunnel establishes but traffic is not correctly matched, causing the remote gateway to drop or not send traffic to the FortiGate, resulting in zero incoming packets.

Exam trap

The trap here is that candidates see 'status: up' and assume the tunnel is fully functional, overlooking that Phase 2 proxy ID mismatches can leave the tunnel up but unable to pass traffic in one direction.

How to eliminate wrong answers

Option A is wrong because aggressive mode affects Phase 1 authentication (using fewer exchanges and sending the ID in plaintext) but does not cause zero incoming packets once the tunnel is up; it would prevent Phase 1 from completing if mismatched. Option B is wrong because a static route pointing to the VPN interface is necessary for routing traffic into the tunnel; its presence would not cause zero incoming packets—it would actually help traffic flow. Option C is wrong because policy-based mode (vs. route-based) does not inherently cause zero incoming packets; both modes can work correctly if proxy IDs match.

The issue is specifically a Phase 2 proxy ID mismatch, which prevents the remote peer from associating incoming traffic with the correct SA.

487
MCQmedium

A FortiGate is configured with two VDOMs: root and vdom1. The administrator wants to allow a server in vdom1 to be accessible from the internet via a virtual IP (VIP) configured in the root VDOM. Which configuration is required to achieve this?

A.Enable asymmetric routing on both VDOMs and disable session helpers.
B.Assign the same interface to both VDOMs and enable VDOM sharing.
C.Configure a static route in vdom1 pointing to the root VDOM's VIP as the gateway.
D.Create inter-VDOM links between root and vdom1, and configure firewall policies to allow traffic.
AnswerD

Inter-VDOM links are required to route traffic between VDOMs. The VIP in the root VDOM will translate the destination IP to the server's IP in vdom1. Firewall policies on both VDOMs must allow the traffic. This setup enables the server in vdom1 to be reachable from the internet through the root VDOM's VIP.

Why this answer

To allow a server in one VDOM to be accessible via a VIP in another VDOM, inter-VDOM links must be configured to route traffic between them. Firewall policies on both VDOMs are also required to permit the traffic. This ensures that the VIP in the root VDOM can forward traffic to the server in vdom1, and return traffic can flow back.

Exam trap

The trap here is thinking that a static route to a VIP or sharing interfaces can bridge VDOMs, when the correct method is inter-VDOM links with firewall policies.

488
MCQmedium

An administrator needs to apply traffic shaping to limit bandwidth for video streaming traffic on a firewall policy. Which configuration step is required?

A.Use an application control profile to restrict video streaming
B.Configure policy-based routing to shape traffic
C.Enable QoS on the interface and set the bandwidth limit
D.Create a traffic shaper and reference it in the firewall policy
AnswerD

Creating a traffic shaper defines the guaranteed and maximum bandwidth thresholds, then referencing it directly in the firewall policy applies those limits to matched video streaming traffic. This satisfies the requirement to shape bandwidth per policy, since FortiGate shapers only take effect once bound to the policy handling that traffic.

Why this answer

Traffic shaping in FortiGate is applied by creating a traffic shaper (either per-IP or shared) and then referencing that shaper in the firewall policy that matches the video streaming traffic. This allows the administrator to control bandwidth usage for specific traffic flows without affecting other traffic. Option D is correct because it directly describes this required configuration step.

Exam trap

The trap here is that candidates often confuse QoS interface settings (which limit all traffic on an interface) with traffic shapers (which limit specific traffic in a policy), leading them to select Option C instead of D.

How to eliminate wrong answers

Option A is wrong because an application control profile is used to identify and optionally block or allow applications, not to shape or limit bandwidth; it does not provide traffic shaping capabilities. Option B is wrong because policy-based routing (PBR) is used to route traffic based on source/destination or other attributes, not to shape or limit bandwidth; shaping is applied via traffic shapers in policies, not via routing decisions. Option C is wrong because enabling QoS on an interface sets a bandwidth limit for the entire interface, not for specific traffic types like video streaming; traffic shaping for specific applications requires a traffic shaper referenced in a firewall policy.

489
Multi-Selecthard

You are troubleshooting a FortiGate HA cluster that is not failing over correctly. The cluster has two units in active-passive mode. You check the HA status and see both units are in 'standalone' mode. Which THREE configurations could cause this? (Choose three.)

Select 3 answers
A.The FortiGate is configured in transparent mode
B.The HA group ID is different on each unit
C.The firmware versions are different but both are 7.0.x
D.The HA heartbeat interface is down on one unit
E.The HA password is different on each unit
AnswersB, D, E

The HA group ID is a mandatory matching parameter for cluster membership; each heartbeat packet carries the group ID, and a FortiGate only processes heartbeats from units with the same group ID. If the two units are configured with different group IDs, they will silently discard each other's heartbeat messages, so neither ever sees a peer and both remain in standalone mode. This is a classic misconfiguration when units are pre-staged separately or when a configuration template is not synchronized. Setting both units to the same group ID (0 through 255) is required before they can form an HA cluster.

Why this answer

The HA group ID must match on all cluster members for them to recognize each other as part of the same cluster. If the group IDs differ, each unit will operate independently in standalone mode, as they cannot form a common HA session.

Exam trap

The trap here is that candidates often overlook the HA password requirement or assume transparent mode disables HA, but FortiGate supports HA in all operational modes, and password mismatches are a common misconfiguration.

490
Multi-Selectmedium

An administrator is configuring ECMP (Equal-Cost Multi-Path) on a FortiGate. Which TWO conditions are required for ECMP to load balance traffic across multiple routes?

Select 2 answers
A.Routes must use different next-hop IP addresses
B.Routes must have the same priority setting
C.Routes must have the same administrative distance
D.Routes must be static routes only
E.Routes must be through different interfaces
AnswersB, C

The route priority setting, also known as the metric, must be identical for all routes to be eligible for ECMP in FortiGate. FortiGate evaluates routes by administrative distance first, then priority, and only when both values match are the routes considered equal cost and installed simultaneously. If one route has a lower priority, it will always be preferred, and the higher-priority route will be ignored, preventing load balancing. Therefore, ensuring the same priority is a correct and essential condition for ECMP.

Why this answer

ECMP requires that multiple routes have the same priority (also known as 'distance' in some contexts) to be considered equal-cost. In FortiGate, priority is a metric that determines route preference; only routes with identical priority can be used simultaneously for load balancing. Option C is also correct because administrative distance must be the same for routes to be considered equal; if administrative distances differ, the route with the lower distance is preferred, and ECMP will not apply.

Exam trap

The trap here is that candidates often confuse 'priority' with 'administrative distance' or assume ECMP requires different next-hop IPs, but FortiGate actually requires both priority and administrative distance to be identical, and next-hop IPs can be the same if interfaces differ.

491
MCQmedium

An administrator configures a DLP sensor to detect credit card numbers in traffic. However, the sensor is not detecting any credit card numbers even though they are present in emails. What could be the reason?

A.Email traffic is encrypted and SSL deep inspection is not enabled
B.The DLP sensor is applied to the wrong policy
C.The credit card regular expression is incorrect
D.The DLP sensor is in 'Monitor' mode
AnswerA

This is correct because DLP sensors operate on cleartext payloads. When email traffic is protected by TLS/SSL and SSL deep inspection is not enabled, the sensor sees only ciphertext, so any regex pattern or data-identifier match is impossible. You must enable deep inspection on the applicable firewall policy so the FortiGate can decrypt the email and feed the plaintext to the DLP sensor.

Why this answer

If a DLP sensor is configured to detect credit card numbers in emails but is not detecting them, a likely reason is that the email traffic is encrypted (e.g., via TLS) and SSL deep inspection is not enabled on the FortiGate. Without SSL deep inspection, the FortiGate cannot see the contents of encrypted emails, so the DLP sensor cannot inspect the payload for credit card numbers. Therefore, enabling SSL deep inspection would allow the DLP sensor to detect the patterns.

Exam trap

NSE4 often tests the impact of encryption on inspection; candidates may overlook that without SSL deep inspection, DLP and IPS cannot see encrypted payloads, leading to false negatives.

How to eliminate wrong answers

Option B is wrong because if the DLP sensor were applied to the wrong policy, it would not detect any traffic, but the question states that credit card numbers are present in emails and the sensor is not detecting them; while possible, it is less likely than encryption, and the question asks for the reason 'could be' — but the most common and likely reason is encryption. Option C is wrong because if the credit card regular expression were incorrect, it would not detect, but the question implies the sensor is configured to detect credit card numbers; again, less likely than encryption. Option D is wrong because 'Monitor' mode would still detect and log, but not block; the question says 'not detecting any', so monitor mode would still detect.

492
MCQeasy

An administrator wants to restrict access to a web server from only specific countries. The FortiGate is located at the network edge. Which address object type should be used in the source field of the firewall policy?

A.FQDN address object
B.Wildcard FQDN address object
C.Geography address object
D.Subnet address object
AnswerC

A geography address object in FortiOS is explicitly designed for geo-IP filtering. It references a country or region (e.g., China or Europe) by leveraging FortiGuard's geolocation database to map an IP address to a country. When used in a firewall policy's source or destination, it allows or denies traffic based on the client's geographic location, making it the correct and direct approach for restricting web server access by country.

Why this answer

A Geography address object allows the FortiGate to match traffic based on the source IP's country of origin, using the built-in GeoIP database. This is the only address object type that can restrict access by country without requiring manual IP range updates.

Exam trap

The trap here is that candidates may confuse Geography address objects with FQDN or Subnet objects, mistakenly thinking that a wildcard or domain-based object can filter by geographic location, when in fact only the Geography object leverages the FortiGate's GeoIP database for country-level matching.

How to eliminate wrong answers

Option A is wrong because an FQDN address object resolves to a specific IP address or set of IP addresses, not to a country or geographic region. Option B is wrong because a Wildcard FQDN address object matches domain names with wildcards (e.g., *.example.com) and is used for web filtering or DNS-based policies, not for geographic restrictions. Option D is wrong because a Subnet address object defines a specific IP range or network segment, which cannot dynamically represent all IPs from a particular country.

493
MCQhard

A FortiGate in flow-based mode is configured with an antivirus profile to block infected files. A user downloads a .zip file containing a known virus, but the download is allowed and the file is not quarantined. What is the MOST likely reason?

A.The antivirus profile is not set to 'block' for virus outbreaks
B.The virus definition database is outdated
C.Flow-based inspection does not support antivirus for .zip archives
D.Flow-based inspection does not decompress archives by default
AnswerD

In flow-based inspection mode, the FortiGate processes files in a streaming fashion, reading data as it flows through and not buffering the whole file, which means it cannot decompress archive files like .zip before scanning their contents. Because the virus is hidden inside the .zip, the scanner never actually sees it, so the file passes through undetected even if signatures are current. Proxy-based inspection, in contrast, buffers the entire file and can decompress archives to scan each contained file, which is why flow mode fails in this situation. The default behavior in flow mode is not to decompress archives, making this the correct explanation.

Why this answer

In flow-based inspection mode, FortiGate does not decompress archive files (such as .zip) by default. This means the antivirus engine cannot inspect the contents of the compressed file, so even if a known virus is inside, it will not be detected or blocked. To inspect archives in flow-based mode, you must enable 'deep archive inspection' in the antivirus profile.

Exam trap

The trap here is that candidates assume flow-based and proxy-based modes behave identically regarding archive scanning, but FortiGate's flow-based mode requires explicit configuration to decompress archives, whereas proxy-based mode does it by default.

How to eliminate wrong answers

Option A is wrong because the antivirus profile's 'block' action for virus outbreaks is a separate setting for outbreak prevention, not for standard virus detection; the issue here is that the file inside the archive was never inspected. Option B is wrong because an outdated virus definition database would cause missed detection of new viruses, but the scenario specifies a 'known virus', implying the signature exists; the core problem is the lack of archive decompression, not signature age. Option C is wrong because flow-based inspection does support antivirus for .zip archives, but only if archive decompression is explicitly enabled; the statement that it does not support it at all is incorrect.

494
MCQeasy

Which of the following is a prerequisite for SSL deep inspection to work correctly on FortiGate?

A.A dedicated HTTPS firewall policy.
B.A firewall policy that has SSL inspection enabled.
C.The FortiGate must be operating in proxy mode.
D.An active FortiCare license.
AnswerB

The correct prerequisite is that the firewall policy permitting the HTTPS traffic must have SSL inspection enabled, meaning an SSL/SSH inspection profile is applied to that policy. This profile instructs the FortiGate to decrypt the traffic, apply security controls, and re-encrypt it, which is the essence of deep inspection. Without this profile attached, the policy merely forwards the encrypted traffic without any visibility.

Why this answer

SSL deep inspection requires a firewall policy with SSL inspection enabled to intercept and decrypt HTTPS traffic. Without such a policy, the FortiGate cannot apply the CA certificate to re-encrypt traffic for inspection, making deep inspection non-functional.

Exam trap

The trap here is that candidates often confuse the need for a firewall policy with SSL inspection enabled with the misconception that a separate HTTPS-only policy or proxy mode is mandatory, when in fact any policy matching HTTPS traffic can be configured for deep inspection.

How to eliminate wrong answers

Option A is wrong because a dedicated HTTPS firewall policy is not required; any firewall policy with the appropriate SSL inspection profile can handle HTTPS traffic. Option C is wrong because FortiGate supports SSL inspection in both proxy-based and flow-based modes, not exclusively proxy mode. Option D is wrong because an active FortiCare license is not a prerequisite for SSL deep inspection; it is required for FortiGuard services like web filtering but not for the inspection mechanism itself.

495
Multi-Selectmedium

A FortiGate administrator is implementing a policy to allow outbound traffic from the internal network to the internet. The requirements are: (1) all traffic from internal users must be source NATed to the external interface IP, (2) traffic from a specific server must use a different public IP, (3) HTTP traffic must be shaped to 10 Mbps. Which THREE configuration elements should the administrator create? (Choose three.)

Select 3 answers
A.A traffic shaper for HTTP traffic
B.A VIP for the server
C.A firewall policy with NAT enabled and the IP pool referenced
D.An IP Pool for the specific server's public IP
E.A policy-based routing rule for the server
AnswersA, C, D

Traffic shapers are used to control bandwidth usage and prioritize traffic. In this scenario, to allow HTTP traffic while ensuring it doesn't saturate the link, a traffic shaper can be applied to the firewall policy to guarantee or limit bandwidth for HTTP. It doesn't affect the destination or source IP translation; it's a QoS mechanism.

Why this answer

A traffic shaper is required to enforce bandwidth limits on HTTP traffic. In FortiGate, traffic shaping policies allow you to define per-policy bandwidth constraints, such as capping HTTP traffic to 10 Mbps, by applying a shaper to the firewall policy that matches HTTP traffic.

Exam trap

The trap here is confusing VIP (destination NAT) with IP pool (source NAT), leading candidates to incorrectly select VIP for source IP translation requirements.

496
MCQeasy

Which FortiGate feature allows administrators to verify if a specific IP address is being blocked by a security policy?

A.diagnose sys session list
B.get system ha status
C.diagnose debug flow
D.diagnose sniffer packet
AnswerC

This command runs a trace of a specific user-selected packet or flow through the FortiGate's processing pipeline, displaying each stage including policy lookup, routing decisions, and the final action (accept or drop). It captures the exact policy ID matched and the reason for any drop, such as implicit deny or traffic-shaping constraints. As a debug utility, it is the proper tool for verifying the policy decision for a given flow, making it the correct answer.

Why this answer

The 'diagnose debug flow' command allows administrators to trace the path of a packet through the FortiGate, showing which security policy, routing, and other checks it matches. By filtering on a specific IP address, administrators can see if traffic from that IP is being blocked by a policy and the reason for the block.

Exam trap

NSE4 often tests the confusion between session listing and flow tracing, leading candidates to choose 'diagnose sys session list' when they need to see policy enforcement details.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys session list' displays existing sessions but does not show policy evaluation or blocking reasons. Option B is wrong because 'get system ha status' shows high availability status, unrelated to policy blocking. Option D is wrong because 'diagnose sniffer packet' captures packets but does not indicate whether they are blocked by a security policy; it only shows if packets are present on the interface.

497
MCQmedium

An administrator needs to forward logs from a FortiGate to a FortiAnalyzer for centralized logging. The FortiAnalyzer IP is 10.10.10.10. Which configuration is required on the FortiGate?

A.config system central-management set type fortianalyzer set ip 10.10.10.10 end
B.config log setting set fortianalyzer ip 10.10.10.10 end
C.config log syslogd setting set server 10.10.10.10 end
D.config log fortianalyzer setting set status enable set server 10.10.10.10 end
AnswerD

This is the correct FortiOS CLI branch for enabling FortiAnalyzer log forwarding. 'set status enable' activates the FortiAnalyzer connection, and 'set server 10.10.10.10' defines the destination FortiAnalyzer appliance's IP address; optional settings like 'set upload enable' control exactly how logs are pushed. Once committed, the FortiGate establishes a dedicated logging channel to FortiAnalyzer, which is the intended method for collecting logs on that platform.

Why this answer

The FortiGate uses the `config log fortianalyzer setting` command to configure direct logging to a FortiAnalyzer. This command enables the log forwarding feature (`set status enable`) and specifies the FortiAnalyzer's IP address (`set server 10.10.10.10`). The other options either use incorrect command paths or are intended for different logging destinations (e.g., syslog or central management).

Exam trap

The trap here is that candidates confuse the `config log fortianalyzer setting` command with the `config system central-management` command (used for FortiManager) or the syslog configuration, leading them to select options that configure the wrong service or miss the required `set status enable` step.

How to eliminate wrong answers

Option A is wrong because `config system central-management` is used for centralized management (e.g., FortiManager), not for log forwarding to FortiAnalyzer. Option B is wrong because `config log setting` is a global log configuration context, but the correct subcommand for FortiAnalyzer is `config log fortianalyzer setting`, not a direct `set fortianalyzer ip` syntax. Option C is wrong because `config log syslogd setting` configures syslog forwarding, which uses a different protocol (UDP/TCP syslog) and is not the native FortiAnalyzer logging method.

498
MCQeasy

A FortiGate administrator wants to authenticate VPN users against an existing LDAP server. The administrator creates an LDAP user group on the FortiGate. What additional configuration is REQUIRED to use this group for IPsec VPN authentication?

A.In the IPsec Phase 1 configuration, set the peer type to 'dialup' and specify the user group under authentication
B.Enable LDAP over TLS (LDAPS) on the FortiGate
C.Assign the LDAP user group to a firewall policy
D.Configure a RADIUS server as an intermediate proxy between FortiGate and LDAP
AnswerA

Dialup peer type makes the FortiGate accept multiple dynamic peers rather than one fixed remote gateway, and the authentication setting binds the LDAP user group to Phase 1. Without both, the group cannot authenticate VPN users, so this satisfies the requirement to use the LDAP group for IPsec authentication.

Why this answer

For IPsec VPN authentication, the FortiGate must know which users are allowed to connect. Setting the peer type to 'dialup' in Phase 1 enables the FortiGate to accept connections from remote users rather than another gateway. Specifying the LDAP user group under authentication tells the FortiGate to validate the VPN user's credentials against that group's members, which are resolved via the LDAP server.

Without this configuration, the FortiGate has no way to associate the LDAP group with the VPN tunnel.

Exam trap

The trap here is that candidates often confuse the authentication configuration (Phase 1) with the authorization configuration (firewall policies), leading them to select Option C, thinking that assigning the group to a policy is sufficient for VPN authentication.

How to eliminate wrong answers

Option B is wrong because LDAPS (LDAP over TLS) is a transport security measure for the LDAP connection, but it is not required for IPsec VPN authentication; the FortiGate can authenticate using plain LDAP or LDAPS, and the question asks for what is required. Option C is wrong because firewall policies control traffic flow after authentication, not the authentication process itself; assigning the LDAP user group to a firewall policy is needed for authorization and access control, but it does not enable the VPN to authenticate users. Option D is wrong because a RADIUS server is not required; the FortiGate can directly query the LDAP server for authentication without an intermediate proxy, and using RADIUS would be an additional, optional configuration.

499
Multi-Selectmedium

A network admin wants to block all traffic from the BitTorrent application. The admin has enabled application control on the firewall policy. Which step is necessary to achieve this?

Select 1 answer
A.Add a DNS filter profile to block BitTorrent tracker domains
B.Add the BitTorrent application signature to the application control profile and set action to block
C.Set the application control inspection mode to proxy-based
D.Enable 'deep inspection' in the application control profile
E.Enable SSL deep inspection on the firewall policy
AnswersB

Application control profiles act on traffic only when the relevant application signature is present and its action is set to block. Adding the BitTorrent signature with a block action is therefore the necessary step to drop that application's traffic.

Why this answer

To block BitTorrent traffic, the admin must add the BitTorrent application signature to the application control profile and set the action to block (option B). Application control can detect BitTorrent even though it uses proprietary encryption—FortiGate uses protocol decoders and signature matching on unencrypted handshake data. SSL deep inspection (option E) is not required because BitTorrent does not use SSL/TLS encryption; enabling deep inspection would not help and would add unnecessary overhead.

Options A, C, and D are also unnecessary: DNS filter does not block the application itself, proxy-based inspection is not mandatory, and deep inspection (in the profile) is not the correct setting.

Exam trap

The trap is assuming that all encrypted applications require SSL deep inspection. BitTorrent uses proprietary protocol encryption, not SSL/TLS. Application control can identify BitTorrent without decryption by analyzing unencrypted portions of the traffic, so deep inspection is not needed.

500
Multi-Selectmedium

An admin needs to configure a FortiGate to send logs to a FortiAnalyzer. Which TWO steps must be performed? (Choose two.)

Select 2 answers
A.Set the log aggregation interval
B.Configure SNMP trap destinations
C.Create a firewall policy to allow traffic to FortiAnalyzer
D.Configure the FortiAnalyzer IP under config system log-fortianalyzer
E.Enable logging to FortiAnalyzer using the 'set status enable' command under the same configuration
AnswersD, E

The command `config system log-fortianalyzer` enters the FortiAnalyzer configuration mode, where the `set server <ip>` command specifies the IPv4 address of the FortiAnalyzer device that will receive logs. This is the mandatory first step in the CLI to point the FortiGate at its log collector. Without this address, the FortiGate has no destination for its syslog-like log streams to FortiAnalyzer. Optionally, parameters like `set upload-option` and `set source-ip` can also be set here, but the server IP is essential.

Why this answer

The FortiGate must be configured with the FortiAnalyzer IP address under the `config system log-fortianalyzer` hierarchy to establish the logging destination. Option E is correct because after setting the IP, the `set status enable` command must be issued to activate log forwarding to that FortiAnalyzer; without this, no logs are sent even if the IP is configured.

Exam trap

The trap here is that candidates often think a firewall policy is required to allow outbound log traffic, but FortiGate management traffic (including logs to FortiAnalyzer) bypasses the firewall policy engine and is controlled solely by the management VDOM or system settings.

501
MCQeasy

An administrator has configured two FortiGate units in an active-passive HA cluster. The primary unit fails. How does the secondary unit become active?

A.The secondary unit detects loss of heartbeat from the primary and takes over
B.The administrator must manually reboot the secondary unit
C.The secondary unit becomes active only if the heartbeat link is also down
D.The secondary unit waits for a configuration change before becoming active
AnswerA

FortiGate HA uses heartbeat packets over the HA link; when the secondary stops receiving them within the configured thresholds, it assumes the primary has failed and transitions to active, taking over the cluster's IP addresses and sessions.

Why this answer

In an active-passive HA cluster, the secondary unit monitors the primary unit's health via heartbeat messages. When the primary fails and stops sending heartbeats, the secondary unit detects the loss of heartbeat and initiates a failover, transitioning to the active role. This is the default behavior in FortiGate HA, where the secondary unit does not require manual intervention or additional conditions to become active.

Exam trap

The trap here is that candidates may think the secondary unit requires the heartbeat link to be down or manual intervention to become active, but FortiGate HA automatically promotes the secondary unit upon detecting the primary's failure via heartbeat loss.

How to eliminate wrong answers

Option B is wrong because FortiGate HA is designed for automatic failover; the administrator does not need to manually reboot the secondary unit, as that would defeat the purpose of high availability. Option C is wrong because the secondary unit becomes active when the primary fails, regardless of whether the heartbeat link is also down; the heartbeat link being down alone would not trigger a failover if the primary is still active. Option D is wrong because the secondary unit does not wait for a configuration change; it becomes active based on the failure detection, and configuration synchronization occurs after the failover.

502
Multi-Selecthard

A FortiGate administrator is troubleshooting why traffic from a specific source IP is not being logged. The traffic is allowed by a firewall policy with logging enabled. Which TWO commands could the administrator use to verify if the traffic is hitting the expected policy? (Choose two.)

Select 2 answers
A.get system performance status
B.diagnose debug flow
C.diagnose sniffer packet any 'host 10.0.0.1'
D.diagnose sys session filter src 10.0.0.1
E.diagnose debug application fnbamd
AnswersB, D

The 'diagnose debug flow' command is the definitive real-time tracing tool for FortiGate traffic. It allows you to apply filters (e.g., by source IP, destination IP, port, or VLAN) and then traces each packet through the entire data path, showing the exact policy ID matched, the action taken (accept or drop), and any profile-based processing or session errors. This output directly answers the question of 'which policy did this traffic match?' making it the correct troubleshooting method.

Why this answer

Option B (diagnose debug flow) is correct because it traces a packet through the FortiGate's inspection path, showing which firewall policy matches the traffic and whether it is allowed or denied, which directly verifies if the source IP hits the expected policy. Option D (diagnose sys session filter src 10.0.0.1) is correct because it filters the session table by the source IP so the administrator can run 'diagnose sys session list' and confirm the session was created and which policy ID it matched. Option A (get system performance status) only shows CPU, memory, and uptime statistics and provides no policy-matching information.

Option C (diagnose sniffer packet any 'host 10.0.0.1') captures raw packets but does not reveal which firewall policy processed them. Option E (diagnose debug application fnbamd) debugs the Fortinet non-blocking authentication daemon, which is unrelated to firewall policy matching for this traffic.

Exam trap

NSE4 often tests the difference between packet capture (sniffer) and policy-lookup tracing (debug flow), causing candidates to choose sniffer when the question asks which policy the traffic hits.

503
MCQeasy

Which of the following is a characteristic of route-based IPsec VPN compared to policy-based IPsec VPN?

A.Route-based VPN is only supported in IKEv1
B.Route-based VPN requires Phase 2 selectors to match both local and remote subnets
C.Route-based VPN can use dynamic routing protocols like OSPF
D.Route-based VPN uses firewall policies with IPsec action
AnswerC

Because route-based VPNs present the IPsec tunnel as a virtual interface, that interface can participate in dynamic routing protocols such as OSPF, BGP, or RIP. This allows the VPN to exchange routing information automatically, so remote subnets are learned dynamically rather than requiring static routes for each destination. This is a major operational advantage over policy-based VPNs, which cannot run routing protocols across the tunnel in a straightforward manner.

Why this answer

Route-based IPsec VPNs create a virtual tunnel interface (e.g., ipsec0 or tunnel) that acts as a logical routing point, allowing dynamic routing protocols such as OSPF to exchange routes over the encrypted tunnel. This is a key advantage over policy-based VPNs, which rely on static security policies and cannot support dynamic routing.

Exam trap

The trap here is that candidates often confuse route-based VPNs with policy-based VPNs, assuming both require Phase 2 selectors to match subnets, but route-based VPNs use a tunnel interface with any-to-any selectors and rely on routing instead.

How to eliminate wrong answers

Option A is wrong because route-based VPNs are supported in both IKEv1 and IKEv2; IKEv2 is actually more common for route-based deployments. Option B is wrong because route-based VPNs do not require Phase 2 selectors to match subnets; the tunnel interface handles all traffic, and selectors are typically set to 0.0.0.0/0 to allow any traffic. Option D is wrong because route-based VPNs use the tunnel interface directly, not firewall policies with an IPsec action; policy-based VPNs are the ones that require firewall policies with an IPsec action to trigger encryption.

504
Multi-Selecthard

An organization uses FortiMail for email filtering and FortiGate for web filtering. The administrator wants to ensure that email traffic is filtered for spam and malware before reaching the internal mail server. Which TWO steps should be taken? (Choose two.)

Select 2 answers
A.Configure FortiMail to scan incoming emails and then forward them to the internal mail server.
B.Apply an antivirus profile to the firewall policy that handles SMTP traffic.
C.Apply an email filter profile to the firewall policy that handles SMTP traffic.
D.Configure the FortiGate to route SMTP traffic through FortiMail using a policy-based routing or VIP.
E.Disable SMTP inspection on the FortiGate to avoid double scanning.
AnswersA, D

FortiMail must be configured as the mail gateway in inline mode, receiving incoming SMTP messages before any other mail server. It performs comprehensive email security functions—spam filtering, antivirus, phishing protection, and content inspection—using its own message-specific heuristics and reputation databases. Once a message is deemed clean, FortiMail relays it to the internal mail server, ensuring that only sanitized mail reaches the user's inbox.

Why this answer

Option A is correct because FortiMail is the dedicated email security appliance that must actually perform the spam and malware scanning of inbound messages before relaying them to the internal mail server. Option D is correct because the FortiGate must be configured to direct SMTP traffic to FortiMail first, typically via a policy route or a VIP/port-forwarding rule, so that mail is inspected before it reaches the internal mail server. Option B is not correct because an antivirus profile on the FortiGate only scans traffic passing through the firewall and does not provide the full email spam/malware filtering that FortiMail delivers.

Option C is not correct because FortiGate email filter profiles are not the mechanism used to filter SMTP for spam and malware in this FortiMail-based design. Option E is not correct because disabling SMTP inspection on the FortiGate would remove an additional layer of protection and does not accomplish the goal of filtering email through FortiMail.

Exam trap

The trap here is that candidates may think FortiGate's security profiles (antivirus, web filter) can replace FortiMail's dedicated email filtering, but FortiGate lacks the specialized spam and email malware detection engines that FortiMail provides.

505
MCQmedium

In a FortiGate HA cluster, the administrator needs to perform a firmware upgrade without causing a full service outage. Which procedure should be followed?

A.Upgrade the primary unit first, then the secondary unit
B.Upgrade the secondary unit first, then perform a failover, then upgrade the primary unit
C.Disable HA and upgrade each unit separately
D.Upgrade both units simultaneously
AnswerB

The correct procedure is to upgrade the standby unit first, verify it has booted and joined the cluster with a healthy synchronization, then manually fail over so that the upgraded unit becomes primary and handles traffic. After that, upgrade the former primary (now standby) to the same version, ensuring both units finally run identical firmware. This rolling upgrade preserves a live unit for every step, avoiding an outage and keeping the HA pair in a supported configuration throughout.

Why this answer

In a FortiGate HA cluster, the correct upgrade procedure is to upgrade the secondary (subordinate) unit first, then trigger a failover so it becomes primary, then upgrade the former primary. This maintains service continuity because at least one unit is always running the stable firmware and passing traffic. Upgrading the primary first would cause an outage during the upgrade window.

Exam trap

NSE4 often tests the order of HA firmware upgrades — candidates incorrectly assume upgrading the primary first is fine because it 'leads' the cluster, missing that it causes an outage.

How to eliminate wrong answers

Option A is wrong because upgrading the primary first takes the active traffic-handling unit offline, causing a full outage until the upgrade completes and the cluster reconverges. Option C is wrong because disabling HA removes redundancy and requires manual reconfiguration, and it does not preserve seamless failover during the upgrade. Option D is wrong because upgrading both units simultaneously causes a complete cluster outage and can also cause HA heartbeat/firmware mismatch issues during the process.

506
MCQeasy

An administrator wants to apply a safe search policy to enforce strict search results on Google, Bing, and Yahoo. Which security profile feature should be used?

A.Web filter safe search enforcement
B.Application control to block search engines
C.DNS filter to block search engine domains
D.Web filter URL filter with keyword blocking
AnswerA

Safe search enforcement is a built-in Web Filter profile setting that forces supported search engines (Google, Bing, YouTube) to apply strict content filtering by automatically modifying search request URLs (e.g., appending 'safe=active' for Google and 'adlt=strict' for Bing) or by redirecting to a forced-search endpoint. Unlike blocking features, it does not deny access to the search engine; it preserves search capability while scrubbing explicit results, which directly satisfies the administrator's goal. It typically requires HTTPS inspection to rewrite embedded search URLs inside encrypted traffic.

Why this answer

Web filter safe search enforcement is the correct feature because it directly integrates with search engines (Google, Bing, Yahoo) to force the use of their built-in safe search parameters (e.g., Google's 'safe=active' parameter appended to URLs). This ensures that explicit content is filtered at the source, regardless of the user's browser settings or search engine choice.

Exam trap

The trap here is that candidates may confuse 'blocking search engines' (application control or DNS filter) with 'enforcing safe search within search engines' (web filter safe search enforcement), leading them to select an option that prevents access rather than controlling content.

How to eliminate wrong answers

Option B is wrong because application control blocks or allows applications (e.g., blocking all search engine traffic), but it cannot enforce safe search parameters within allowed search engines. Option C is wrong because a DNS filter blocks entire domains (e.g., blocking google.com), which would prevent access to search engines entirely, not enforce safe search. Option D is wrong because a URL filter with keyword blocking can block specific URLs or keywords in the URL, but it cannot dynamically inject safe search parameters into search engine queries, which is required for strict safe search enforcement.

507
MCQeasy

An organization wants to use FortiToken for two-factor authentication on SSL VPN logins. Which authentication method must be enabled on the FortiGate to support this?

A.Two-factor authentication with FortiToken
B.RADIUS authentication
C.PKI authentication
D.LDAP authentication
AnswerA

The 'Two-factor authentication with FortiToken' setting on a FortiGate enables the native token-based OTP mechanism, where users must provide both their primary password and a one-time passcode generated by a FortiToken device or mobile token. This is the correct option because it directly activates the FortiToken two-factor authentication feature within FortiOS, ensuring that the token OTP is validated as part of the authentication process. It is distinct from external protocols or directory services, as it is built-in and specifically designed for FortiToken integration.

Why this answer

FortiToken is a hardware or software token that generates one-time passwords (OTPs) for two-factor authentication (2FA). To use FortiToken with SSL VPN logins, the FortiGate must have 'Two-factor authentication with FortiToken' enabled in the user or user group configuration. This setting tells the FortiGate to prompt for both the user's regular password and the current FortiToken OTP during the SSL VPN authentication process.

Exam trap

The trap here is that candidates often confuse the authentication method required for FortiToken with external servers like RADIUS or LDAP, not realizing that FortiToken is a Fortinet-proprietary two-factor solution that must be explicitly enabled as a two-factor method on the FortiGate itself.

How to eliminate wrong answers

Option B (RADIUS authentication) is wrong because RADIUS is an external authentication protocol that can be used for 2FA, but it does not directly enable FortiToken support; FortiToken is a Fortinet-specific token that requires the built-in two-factor method. Option C (PKI authentication) is wrong because PKI uses digital certificates for authentication, not token-based OTPs, and is typically used for client certificate authentication rather than two-factor with FortiToken. Option D (LDAP authentication) is wrong because LDAP is a directory service protocol for retrieving user credentials, but it does not natively support FortiToken OTPs; FortiToken requires the FortiGate's internal two-factor mechanism to validate the token.

508
Drag & Dropmedium

Drag and drop the steps to upgrade FortiGate firmware via the web interface into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Firmware upgrade requires uploading the image and confirming; the device reboots automatically.

509
MCQmedium

A FortiGate administrator wants to ensure that traffic from the 192.168.1.0/24 network to the internet is translated to a single public IP address using overload (PAT). Which NAT configuration should be used?

A.Policy-based NAT with a fixed port range
B.One-to-one NAT IP Pool
C.Virtual IP (VIP) with port forwarding
D.Central SNAT with a dynamic IP pool using overload
AnswerD

Central SNAT with a dynamic IP pool using overload is the correct approach because it implements many-to-one Source NAT: the FortiGate dynamically selects a public IP from the pool and rewrites each internal source IP to that public IP while also changing the source port to a unique value, enabling thousands of internal connections to share a single public address. Central NAT is the recommended method for outbound internet traffic because it cleanly separates NAT configuration from firewall policies and directly supports overload/PAT, matching the requirement for general internet egress.

Why this answer

Central SNAT with a dynamic IP pool using overload (PAT) is the correct method to translate all traffic from the 192.168.1.0/24 network to a single public IP address. The 'overload' option enables port address translation (PAT), allowing multiple internal hosts to share one public IP by using unique source port numbers, which is exactly what the administrator needs for internet-bound traffic.

Exam trap

The trap here is that candidates often confuse 'one-to-one NAT' (Option B) with PAT, thinking it can overload a single IP, but one-to-one NAT requires a dedicated public IP per internal host and does not perform port translation.

How to eliminate wrong answers

Option A is wrong because policy-based NAT with a fixed port range restricts the number of concurrent translations to the size of the port range, which would not allow all hosts in the /24 network to share a single IP efficiently and could exhaust ports quickly. Option B is wrong because one-to-one NAT IP Pool maps each internal IP to a unique public IP, requiring multiple public IPs and not supporting overload (PAT) to share a single IP. Option C is wrong because Virtual IP (VIP) with port forwarding is used for inbound destination NAT (port forwarding) to internal servers, not for outbound source NAT with overload to a single public IP.

510
MCQmedium

Given the exhibit, a user in the internal network tries to SSH to a public server (203.0.113.10). What will happen and why?

A.The SSH connection will succeed because policy 1 allows all services before policy 2 is evaluated.
B.The SSH connection will succeed because policy 2 is evaluated first.
C.The SSH connection will be blocked because policy 2 explicitly denies SSH.
D.The SSH connection will be blocked because policy 1 does not include SSH service specifically.
AnswerA

In FortiGate, firewall policies are evaluated sequentially from the top of the policy list downward. Because policy 1 matches all traffic from the internal interface to wan1 with service set to ALL, it includes SSH (TCP port 22). Since this allow policy is encountered first, it takes effect and the SSH session is permitted. Policy 2, even though it explicitly denies SSH, is never reached because the first match already decided the traffic's fate.

Why this answer

Policy 1 is an implicit allow-all rule that matches all traffic before policy 2 is evaluated. Since FortiGate processes policies in sequential order from top to bottom, the SSH connection to 203.0.113.10 matches policy 1 first, which permits all services, including SSH. Therefore, the connection succeeds without ever reaching policy 2.

Exam trap

The trap here is that candidates assume a deny rule later in the policy list will block traffic, forgetting that FortiGate uses first-match logic, so an earlier allow-all rule takes precedence.

How to eliminate wrong answers

Option B is wrong because policy 2 is not evaluated first; FortiGate evaluates policies in sequential order from top to bottom, so policy 1 is checked before policy 2. Option C is wrong because although policy 2 explicitly denies SSH, it is never reached due to the earlier match with policy 1. Option D is wrong because policy 1 does not need to include SSH specifically; it allows all services, which inherently includes SSH.

511
Multi-Selectmedium

An administrator wants to configure a DNS filter to block access to known malicious domains and also enforce safe search on search engines. Which THREE settings are required in the DNS filter profile? (Choose three.)

Select 3 answers
A.Add entries to the static domain blocklist
B.Select 'Redirect to safe search' for search engines
C.Configure a DNS sinkhole IP address
D.Specify external DNS servers for resolution
E.Enable DNS filtering based on FortiGuard categories
AnswersA, B, E

Adding entries to the static domain blocklist within a DNS filter profile is correct because it allows you to manually specify exact domain names to always block, independent of FortiGuard categorization. This is useful for domains that are known threats or unwanted but may not yet be classified by FortiGuard, or for enforcing custom corporate policy. The blocklist takes precedence over category-based filtering, ensuring these domains are always denied.

Why this answer

Adding entries to the static domain blocklist allows the administrator to manually specify known malicious domains that should be blocked regardless of FortiGuard category ratings. This provides a hard-coded block for domains that may not yet be categorized or that the administrator wants to ensure are always blocked.

Exam trap

The trap here is that candidates often confuse the DNS sinkhole IP address (a response action) with a required setting for blocking, or they think external DNS servers must be specified in the profile, when in fact the DNS filter profile uses the FortiGate's system DNS settings by default.

512
MCQhard

An administrator configures a policy route to send all traffic from a specific subnet to a different next-hop. However, traffic from that subnet is still using the default route. Which configuration could be causing this?

A.The firewall policy denies the traffic before policy routing
B.The policy route is applied to the wrong incoming interface
C.The default route has a higher administrative distance
D.The policy route destination is set to all
AnswerB

Policy routes are tied to a specific incoming interface, so if the traffic arrives on a different interface than the one specified in the policy route, the route will never be evaluated. The administrator must confirm that the policy route's incoming interface matches the physical port where the traffic actually enters the FortiGate. Since the policy route is not applied on the wrong interface, the traffic follows the normal routing table, and the intended policy behavior is not observed.

Why this answer

Policy routes are evaluated based on the incoming interface of the traffic. If the policy route is applied to the wrong incoming interface, traffic from the specified subnet arriving on a different interface will not match the policy and will instead follow the default route. This is a common misconfiguration where the administrator assumes the policy applies globally rather than per-interface.

Exam trap

The trap here is that candidates often assume policy routes apply globally to all traffic matching the source/destination, forgetting that FortiGate requires the incoming interface to be explicitly specified for policy routes to be evaluated.

How to eliminate wrong answers

Option A is wrong because firewall policies are evaluated after policy routing in FortiGate's processing order; if policy routing matches, the traffic is forwarded to the policy route's next-hop before any firewall policy is checked, so a deny firewall policy would not cause the traffic to use the default route. Option C is wrong because a higher administrative distance makes a route less preferred, so if the default route had a higher administrative distance, it would be less likely to be used, not more; the issue is that the policy route is not being matched at all. Option D is wrong because setting the policy route destination to 'all' would match all destinations, which would actually increase the likelihood of the policy route being applied, not cause it to be ignored; the problem is the interface mismatch, not the destination setting.

513
MCQmedium

An administrator runs the following CLI command and sees the output: 'diagnose sys session list | grep -A 5 10.1.1.100' and finds a session with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the session?

A.The session is about to expire
B.The session has been active for approximately 1 second
C.The session has been active for 3600 seconds
D.The session is using UDP protocol
AnswerC

The 'duration' field in Fortinet's session output records the age of the session in seconds, counting upward from the moment the connection was first seen. In this output, duration=3600 directly indicates the session has been active for exactly 3600 seconds (one hour). This is the only option that matches the literal value in the CLI output.

Why this answer

The 'duration' field in Fortinet session output indicates the actual time the session has been alive (session age), while 'expire' indicates the remaining time before timeout. Here, duration=3600 means the session has been active for 3600 seconds (1 hour). expire=3599 is just slightly less than the duration, but the key is that duration is the age. Therefore, option C is correct.

Exam trap

Common mistake: Candidates think 'duration' is the timeout value, but in Fortinet's 'diagnose sys session list', 'duration' is the elapsed time since the session started, and 'expire' is the remaining time. The timeout is the sum of duration and expire (if not zero), but here duration is directly the age.

How to eliminate wrong answers

Option A is wrong because 'expire=3599' indicates the session still has 3599 seconds left, so it is not about to expire; it is nearly full duration. Option C is wrong because 'duration=3600' is the total session timeout value, not the actual time the session has been active; the active time is duration minus expire (1 second). Option D is wrong because 'proto=6' indicates TCP protocol (protocol number 6), not UDP (which is protocol 17).

514
MCQhard

An administrator runs 'diagnose ips anomaly list' and sees the following output: List of anomaly events: ID: 1, Type: tcp_syn_flood, Status: triggered, Count: 1500, Threshold: 1000 What does this indicate?

A.The IPS anomaly sensor is configured to block all TCP traffic.
B.The FortiGate has detected a single TCP SYN packet and is logging it.
C.The FortiGate is experiencing a TCP SYN flood attack and has triggered rate-based detection.
D.The FortiGate is performing a TCP SYN flood attack.
AnswerC

The output displays an anomaly event of type 'tcp_syn_flood' in the triggered state, which means the FortiGate has detected that the number of incompleted TCP SYN packets has exceeded the configured threshold for the anomaly sensor. This is rate-based detection because the sensor continuously monitors the rate of SYN packets and compares it against a threshold; when the rate shoots up, the anomaly is considered triggered and the configured action (such as dropping subsequent packets or sending an alert) is executed. Therefore, the FortiGate is correctly interpreting a TCP SYN flood attack targeting itself or a protected host.

Why this answer

The output from 'diagnose ips anomaly list' shows a tcp_syn_flood anomaly with a count of 1500 exceeding the threshold of 1000, and the status is 'triggered'. This indicates that the FortiGate's IPS anomaly sensor has detected a rate-based anomaly — specifically, the number of TCP SYN packets received per second has surpassed the configured threshold, which is a classic sign of a TCP SYN flood attack. The FortiGate has triggered its rate-based detection mechanism, which can then take configured actions such as alerting or blocking, confirming option C as correct.

Exam trap

The trap here is that candidates may confuse a triggered anomaly with a permanent block action or misinterpret the count as a single packet, when in fact the output clearly shows a rate-based threshold exceedance indicating an ongoing flood attack.

How to eliminate wrong answers

Option A is wrong because the IPS anomaly sensor does not block all TCP traffic; it only monitors and optionally blocks traffic that exceeds a specific rate threshold for a defined anomaly type, such as tcp_syn_flood. Option B is wrong because the output shows a count of 1500 and a threshold of 1000, indicating multiple packets have been detected over a rate interval, not a single packet, and the anomaly is triggered, not just logged. Option D is wrong because the FortiGate is the victim or detection point, not the attacker; the output indicates it is receiving an excessive number of SYN packets, not generating them.

515
MCQmedium

A FortiGate administrator wants to ensure that traffic from the internal network to an external FTP server uses a specific source IP address (203.0.113.10). The internal network uses RFC 1918 addresses. Which NAT configuration should be used?

A.Policy-based NAT using an IP pool set to 'Fixed Port Range'
B.Virtual IP (VIP) mapping the internal server to 203.0.113.10
C.Central SNAT with dynamic IP pool
D.Policy-based NAT using an IP pool with type 'Overload' and the IP address 203.0.113.10
AnswerD

Policy-based NAT with an IP pool of type Overload performs source NAT by translating the source address of all matching sessions to the single IP defined in the pool. Since the pool contains only 203.0.113.10, every outbound session from the internal server will appear to originate from that exact IP using PAT (port address translation). This directly meets the requirement of ensuring all traffic from the server uses 203.0.113.10 as the source IP.

Why this answer

Policy-based NAT with an IP pool type 'Overload' (PAT) allows multiple internal hosts to share the single public IP 203.0.113.10 for outbound traffic. This meets the requirement to translate RFC 1918 source addresses to a specific source IP when accessing an external FTP server, while preserving port multiplexing.

Exam trap

The trap here is confusing VIP (inbound destination NAT) with source NAT (SNAT), leading candidates to select Option B, even though the requirement is for outbound traffic from internal clients to use a specific source IP.

How to eliminate wrong answers

Option A is wrong because 'Fixed Port Range' IP pools are used for static port allocation, typically for protocols that require predictable ports (e.g., SIP), not for general outbound source NAT with a single IP. Option B is wrong because a Virtual IP (VIP) is used for inbound destination NAT (port forwarding) to map an external IP to an internal server, not for outbound source NAT from internal clients. Option C is wrong because Central SNAT with a dynamic IP pool would select from a range of IPs, not guarantee the specific source IP 203.0.113.10.

516
MCQeasy

An administrator wants to restrict SSL VPN access to only users who have a valid client certificate issued by the company's internal CA. Which setting should be configured?

A.Configure a firewall policy with identity-based authentication
B.Enable 'certificate-based authentication' in the user group
C.Enable 'require client certificate' in the SSL VPN settings
D.Import the users' public keys into the FortiGate
AnswerC

Setting 'Require Client Certificate' in the SSL VPN settings makes the FortiGate demand a client certificate during the SSL/TLS handshake, and only a certificate signed by a configured trusted CA will be accepted. This ensures that every SSL VPN session is cryptographically tied to a credential that is bound to a specific US user, so users without a valid certificate cannot even initiate the handshake. This is the direct control that physically enforces certificate-based access.

Why this answer

The 'require client certificate' setting in the SSL VPN portal or interface configuration enforces mutual TLS (mTLS), where the FortiGate requests and validates a client certificate against the configured CA. This ensures that only users presenting a valid certificate issued by the company's internal CA can establish the SSL VPN tunnel, regardless of their authentication credentials.

Exam trap

The trap here is that candidates confuse 'certificate-based authentication' with a user group setting, when in fact the enforcement point is the SSL VPN portal or interface configuration, not the user group definition.

How to eliminate wrong answers

Option A is wrong because identity-based firewall policies control access based on user/group authentication (e.g., LDAP or local users), not client certificate validation; they do not enforce certificate-based client identity at the SSL VPN tunnel level. Option B is wrong because 'certificate-based authentication' in a user group is not a valid FortiGate setting; user groups support authentication methods like LDAP, RADIUS, or PKI, but the group itself does not have a toggle for certificate-based authentication—this must be configured in the SSL VPN settings. Option D is wrong because importing users' public keys into the FortiGate is not a standard method for client certificate validation; the FortiGate validates client certificates by trusting the issuing CA's certificate, not by importing individual user public keys.

517
MCQmedium

An administrator creates a firewall policy with a traffic shaper to limit bandwidth for guest wireless users. After applying the policy, users can still consume high bandwidth. The administrator confirms the policy is matching. What is the MOST likely reason the traffic shaper is not effective?

A.The traffic shaper's maximum bandwidth is set too high
B.The traffic shaper is applied to the wrong direction (egress vs ingress)
C.The traffic shaper is configured but not applied to the policy's 'Traffic Shaper' field
D.The traffic shaper is a per-IP shaper but the policy applies to a subnet
AnswerC

FortiGate traffic shapers are objects that must be explicitly referenced in a firewall policy; simply creating a shaper under Traffic Shaping does not cause any policy to use it. The firewall policy's 'Traffic Shaper' field and 'Per-IP Shaper' field both default to 'None', which means traffic matching the policy is forwarded with no bandwidth limitation. To enforce a shaping rule, the administrator must select the desired shaper in that drop-down field. When the shaper is left unassigned, the policy passes traffic at full interface speed, perfectly explaining the 'high bandwidth consumption' symptom.

Why this answer

In FortiGate, a traffic shaper must be explicitly selected in the 'Traffic Shaper' field of the firewall policy to be applied. Simply creating a shaper and configuring it is insufficient; the policy's shaper field links the shaper to the traffic. Without this link, the shaper is not enforced, even if the policy matches.

Exam trap

The trap here is that candidates assume creating a traffic shaper automatically applies it to all matching traffic, but FortiGate requires explicit assignment in the firewall policy's shaper field to enforce the limit.

How to eliminate wrong answers

Option A is wrong because setting the maximum bandwidth too high would still limit bandwidth, just at a higher threshold; it would not cause the shaper to be completely ineffective. Option B is wrong because traffic shapers in FortiGate are applied per policy and control both ingress and egress directions based on the shaper type (e.g., per-policy shaper applies to both directions); direction misconfiguration would not render the shaper entirely ineffective. Option D is wrong because a per-IP shaper applied to a subnet is valid and would limit each individual IP's bandwidth; it would not cause the shaper to be ineffective.

518
MCQmedium

Which of the following best describes the difference between flow-based and proxy-based inspection for antivirus scanning?

A.Flow-based inspection reassembles the entire file before scanning, while proxy-based scans packets on the fly
B.Flow-based inspection scans first packet and allows, while proxy-based buffers the entire session
C.Flow-based inspection requires SSL deep inspection, while proxy-based does not
D.Flow-based inspection uses pattern matching and anomaly detection with low latency, while proxy-based provides full content reassembly and higher detection rates
AnswerD

This correctly captures the core trade-off. Flow-based inspection processes packets in a streaming fashion using pattern matching, protocol anomaly detection, and flow-level heuristics, keeping latency low and throughput high. Proxy-based inspection buffers and reassembles the entire payload, which allows for detecting complex evasions and embedded malware, but at the cost of higher latency and resource usage.

Why this answer

Flow-based inspection uses pattern matching and anomaly detection to scan traffic with low latency, while proxy-based inspection fully reassembles files and content, enabling deeper analysis and higher detection rates. In Fortinet's FortiOS, flow-based mode is optimized for performance, whereas proxy-based mode provides more thorough inspection by buffering and reconstructing the entire data stream before scanning.

Exam trap

The trap here is that candidates often confuse the performance characteristics, mistakenly thinking flow-based is 'less secure' or that proxy-based always requires SSL inspection, when in fact both modes can be applied to different inspection needs and SSL inspection is a separate configuration.

How to eliminate wrong answers

Option A is wrong because it reverses the roles: flow-based inspection scans packets on the fly without full reassembly, while proxy-based inspection buffers and reassembles the entire file before scanning. Option B is wrong because flow-based inspection does not simply 'scan first packet and allow'; it performs real-time pattern matching and anomaly detection on the flow, and proxy-based inspection buffers the entire session, not just the session but the content for full reassembly. Option C is wrong because SSL deep inspection is a separate feature that can be used with both flow-based and proxy-based inspection; it is not a defining difference between the two modes.

519
MCQeasy

A network administrator wants to prevent users from accessing known malicious websites using FortiGate. Which security profile should be applied to the firewall policy to achieve this goal?

A.Antivirus profile
B.Application control profile
C.IPS profile
D.Web filtering profile
AnswerD

A web filtering profile is purpose-built to control web access by evaluating each requested URL against FortiGuard's real-time web category database, which includes categories like gambling, adult, and malicious sites. It can block or allow entire categories, apply URL or DNS filtering, and log or warn users based on policy. This is the exact tool to prevent users from accessing inappropriate content, as it can be assigned to a firewall policy to filter both HTTP and HTTPS traffic.

Why this answer

Web filtering profile. FortiGate's web filtering profile uses URL rating and category-based filtering to block access to known malicious websites by leveraging FortiGuard's real-time threat intelligence. This is the specific security profile designed to control web access based on URL reputation, including blocking malicious URLs.

Exam trap

The trap here is that candidates often confuse web filtering with application control or IPS, mistakenly thinking that blocking malicious websites requires signature-based detection or application-layer control, rather than URL reputation-based filtering.

How to eliminate wrong answers

Option A is wrong because an Antivirus profile scans files for malware but does not block access to websites based on URL reputation or category. Option B is wrong because an Application control profile identifies and controls network applications (e.g., social media, streaming) but does not filter web URLs or block malicious websites. Option C is wrong because an IPS profile detects and prevents network-based attacks using signatures, but it is not designed to block access to known malicious websites based on URL filtering.

520
MCQmedium

An organization needs to restrict internet access for employees to business hours only (Monday to Friday, 8:00 to 18:00). Which object should the admin use in the firewall policy?

A.A schedule object with recurring time
B.A time-range object
C.An on-time schedule
D.A calendar object
AnswerA

A schedule object with recurring time is the standard FortiGate construct for defining repeating time periods. The 'recurring' type allows you to specify days of the week and a start/end time, and it remains active indefinitely. This precisely matches the requirement to restrict internet access for employees on a continuous, repeating basis. In a firewall policy, this object controls when the rule is enforced, enabling automated time-based access control.

Why this answer

A schedule object with recurring time is the correct choice because FortiGate firewall policies use schedule objects to define time-based access control. A recurring schedule allows you to specify days of the week and a time range (e.g., Monday to Friday, 8:00-18:00) that repeats weekly, which perfectly matches the requirement for business hours only.

Exam trap

The trap here is that candidates familiar with Cisco devices might confuse 'time-range object' (Cisco) with FortiGate's 'recurring schedule', leading them to select option B, which is not a valid FortiGate object.

How to eliminate wrong answers

Option B (a time-range object) is wrong because FortiGate does not use a 'time-range object'; that term is specific to Cisco IOS ACLs, not FortiGate. Option C (an on-time schedule) is wrong because FortiGate has no such object type; the correct term is 'recurring schedule' for repeating patterns. Option D (a calendar object) is wrong because FortiGate does not have a 'calendar object'; schedules are either one-time or recurring, and a calendar object is not a valid FortiGate object.

521
MCQmedium

A FortiGate is operating in transparent mode. The administrator needs to configure a new VLAN interface for segmenting traffic. Which statement about VLAN interfaces in transparent mode is correct?

A.VLAN interfaces require IP addresses and act as routed interfaces in transparent mode.
B.VLAN interfaces can be created on physical interfaces and are layer-2 only, requiring no IP addresses for traffic forwarding.
C.VLAN interfaces can only be created on physical interfaces, and each VLAN requires a separate IP address in the management VDOM.
D.VLAN interfaces are not supported in transparent mode; the administrator must switch to NAT/Route mode.
AnswerB

Correct: In transparent mode, you can create VLAN subinterfaces on physical ports to segment the Layer-2 network. These interfaces operate purely at Layer 2, bridging frames between 802.1Q-tagged segments without any IP configuration for forwarding. A management IP is optional and only for administrative access, not for the VLAN interface's traffic path. This design lets the firewall apply security policies to VLAN traffic while remaining invisible to Layer 3 routing.

Why this answer

In transparent mode, FortiGate acts as a layer-2 bridge, forwarding traffic based on MAC addresses. VLAN interfaces can be created on physical interfaces to segment traffic at layer 2, and they do not require IP addresses for forwarding; IP addresses are only needed for management access if desired.

Exam trap

The trap here is that candidates often assume VLAN interfaces always require IP addresses for operation, confusing transparent mode's layer-2 behavior with NAT/Route mode's layer-3 routing requirements.

How to eliminate wrong answers

Option A is wrong because VLAN interfaces in transparent mode are layer-2 only and do not require IP addresses for traffic forwarding; they are not routed interfaces. Option C is wrong because VLAN interfaces do not require a separate IP address in the management VDOM; IP addresses are optional and only for management. Option D is wrong because VLAN interfaces are fully supported in transparent mode; the administrator does not need to switch to NAT/Route mode.

522
MCQeasy

A FortiGate administrator wants to configure a captive portal to authenticate users before granting network access. Which authentication method is used by the captive portal?

A.Form-based authentication
B.IPsec pre-shared key authentication
C.X.509 certificate authentication
D.NTLM authentication
AnswerA

Form-based authentication is the standard method for a FortiGate captive portal. When a user without an existing authenticated session attempts to access a web resource, the FortiGate redirects the browser to a login page containing an HTML form. The user submits a username and password, which the FortiGate then validates against a configured authentication server (e.g., LDAP, RADIUS, or local user database). Upon successful validation, the FortiGate creates an authentication session and permits the traffic, making this the correct interactive method for captive portal.

Why this answer

FortiGate captive portals use form-based authentication by default, presenting a web page where users enter credentials (username/password) that are verified against a configured authentication server (e.g., LDAP, RADIUS, or local user database). This method is designed for HTTP/HTTPS interception and does not rely on network-layer or certificate-based mechanisms.

Exam trap

The trap here is that candidates may confuse captive portal authentication with other FortiGate authentication methods like NTLM or certificate-based authentication, assuming the portal can use any of them, but the default and primary method is form-based authentication.

How to eliminate wrong answers

Option B is wrong because IPsec pre-shared key authentication is used for VPN tunnel establishment, not for web-based captive portal user login. Option C is wrong because X.509 certificate authentication is typically used for client certificate validation in SSL VPN or 802.1X, not for the form-based login page of a captive portal. Option D is wrong because NTLM authentication is a Windows-specific challenge-response protocol used for integrated Windows authentication (e.g., in Active Directory environments), not the default or primary method for FortiGate captive portals.

523
MCQmedium

An administrator wants to block upload of files containing credit card numbers via web forms. Which security profile should be used?

A.Antivirus profile
B.Web filter profile
C.Application control profile
D.Data leak prevention (DLP) profile
AnswerD

A Data Leak Prevention (DLP) profile is expressly designed to detect and prevent the transmission of sensitive information, including credit card numbers, by applying content inspection, regex pattern matching, and file fingerprinting to data in motion. On FortiGate, a DLP profile can be attached to a security policy to inspect HTTP, FTP, SMTP, and other protocols, and it can block, log, or allow based on predefined or custom data classifiers. This precisely matches the administrator's requirement to block uploads of files containing credit card data, making it the correct choice.

Why this answer

Data Leak Prevention (DLP) profiles on FortiGate are specifically designed to inspect traffic content for sensitive data patterns such as credit card numbers, SSNs, and custom regex patterns, and to block or log based on those matches. Blocking uploads of files containing credit card numbers via web forms is a classic DLP use case because DLP can scan HTTP POST bodies and file contents. The DLP profile is applied to a firewall policy, where it inspects the matching traffic.

Exam trap

NSE4 often tests the difference between content inspection (DLP, antivirus) and metadata/behavior inspection (web filter, app control), and candidates who pick 'web filter' because the traffic is web-based miss that DLP is the only profile that reads the actual data pattern.

How to eliminate wrong answers

Option A is wrong because antivirus profiles detect malware signatures and known malicious files, not sensitive data patterns like credit card numbers. Option B is wrong because web filter profiles categorize and block URLs or domains based on reputation and category, not the content of uploaded files. Option C is wrong because application control profiles identify and control applications by signature (e.g., Facebook, BitTorrent) but do not inspect payload content for data patterns.

524
Multi-Selecteasy

A FortiGate admin is creating a firewall policy to allow outbound HTTP and HTTPS traffic from the internal network. The admin wants to ensure that traffic is inspected by security profiles (antivirus, web filter). Which THREE of the following must be configured on the firewall policy to achieve this?

Select 3 answers
A.Set the action to ACCEPT
B.Set the schedule to always
C.Apply an antivirus profile and a web filter profile to the policy
D.Configure the service to include HTTP and HTTPS
E.Enable NAT on the policy
AnswersA, C, D

The action parameter is the core permit or deny decision in a FortiOS firewall policy. Only when set to ACCEPT will the FortiGate allow the session to be established and forward traffic; DENY immediately drops packets and prevents any further processing. Security profiles can only operate on traffic that has passed this initial action check, so ACCEPT is the non-negotiable foundation for allowing outbound web traffic.

Why this answer

Setting the action to ACCEPT is mandatory for the firewall policy to allow traffic through. Without ACCEPT, the policy would deny traffic by default, preventing any inspection by security profiles. The ACCEPT action enables the FortiGate to process the traffic through the configured security profiles.

Exam trap

The trap here is that candidates often think NAT is required for outbound traffic inspection, but NAT is only for address translation and does not enable security profile processing; the key is the ACCEPT action and proper service/profile configuration.

525
MCQeasy

Which of the following FortiGate features allows users to authenticate using a one-time password generated by a mobile app?

A.FSSO
B.LDAP
C.FortiToken
D.Captive portal
AnswerC

FortiToken generates time-based one-time passwords (TOTP) in a mobile app, satisfying the stem's requirement for app-generated OTP authentication on FortiGate. Unlike SMS or email tokens, FortiToken Mobile runs locally on the device, producing rolling codes that FortiGate validates against its shared secret during firewall or SSL VPN login.

Why this answer

FortiToken is Fortinet's two-factor authentication solution that generates one-time passwords (OTPs) via a mobile app (FortiToken Mobile) or hardware token. When a user authenticates, they must provide both their regular password and the current OTP from the FortiToken app, which is validated by the FortiGate against the token's seed record. This directly matches the question's requirement for OTP generation by a mobile app.

Exam trap

The trap here is that candidates often confuse FortiToken with FSSO or LDAP because all three involve authentication, but only FortiToken specifically generates and validates one-time passwords via a mobile app.

How to eliminate wrong answers

Option A (FSSO) is wrong because FSSO (Fortinet Single Sign-On) collects user login events from domain controllers to map users to IP addresses for policy enforcement, but it does not generate or validate one-time passwords. Option B (LDAP) is wrong because LDAP is a directory service protocol used for storing and retrieving user credentials and attributes; it does not generate OTPs or provide two-factor authentication. Option D (Captive portal) is wrong because a captive portal is a web-based authentication interface that redirects users to a login page, but it does not generate OTPs; it can be used with external authentication methods but is not itself an OTP generator.

Page 6

Page 7 of 11

Page 8

All pages