Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 526–600

773 questions total · 11pages · All types, answers revealed

Page 7

Page 8 of 11

Page 9
526
MCQeasy

An administrator wants to upgrade the FortiOS firmware on a FortiGate. Which step is critical before starting the upgrade process?

A.Reboot the FortiGate.
B.Clear all sessions.
C.Back up the configuration file.
D.Disable all firewall policies.
AnswerC

Backing up the configuration file is the correct and mandatory prerequisite before upgrading FortiOS. Use the 'execute backup config' CLI command or the GUI's System > Backup feature to save a copy of the current configuration to a local host or remote server. If the upgrade fails or you need to downgrade to a previous firmware version, this backup allows you to restore the exact pre-upgrade settings, preventing configuration loss or manual re-entry of policies, routes, and objects.

Why this answer

Backing up the configuration file is critical before upgrading FortiOS because the upgrade process may fail or corrupt the configuration, and a backup ensures you can restore the FortiGate to its previous operational state. Without a valid backup, a failed upgrade could result in a complete loss of configuration, requiring manual reconfiguration or a factory reset. Fortinet recommends always backing up the configuration before any firmware upgrade to mitigate risks.

Exam trap

The trap here is that candidates may confuse operational steps (like clearing sessions or disabling policies) with the critical prerequisite of configuration backup, assuming the upgrade process will automatically preserve settings without risk.

How to eliminate wrong answers

Option A is wrong because rebooting the FortiGate before an upgrade is unnecessary and may disrupt current operations; the upgrade process itself handles rebooting as needed. Option B is wrong because clearing all sessions is not a prerequisite for upgrading; the FortiGate will terminate sessions during the reboot phase of the upgrade automatically. Option D is wrong because disabling all firewall policies is not required; the upgrade process preserves policy configurations, and disabling them could cause unintended traffic disruptions if the upgrade fails or is rolled back.

527
MCQeasy

When configuring SSL inspection, which type of inspection decrypts and inspects all HTTPS traffic including applications using non-standard ports?

A.SSL Offloading
B.Certificate Inspection
C.Full SSL Inspection (Deep Inspection)
D.Flow-based Inspection
AnswerC

Full SSL inspection (also called deep inspection) terminates the SSL/TLS connection, decrypts the traffic, applies the full security feature set (IPS, antivirus, web filtering, application control) to the plaintext, and then re-encrypts it for the destination. This gives complete visibility and control over encrypted sessions. It requires installing the FortiGate CA certificate on managed endpoints so the client trusts the re-encrypted connection.

Why this answer

Full SSL Inspection (Deep Inspection) is the correct answer because it performs a man-in-the-middle decryption and re-encryption of all HTTPS traffic, regardless of the port used. This allows the FortiGate to inspect the payload of encrypted sessions, including those on non-standard ports, for threats and policy violations.

Exam trap

The trap here is confusing the processing mode (Flow-based vs. Proxy-based) with the actual SSL inspection method, leading candidates to incorrectly select Flow-based Inspection as a type of SSL decryption.

How to eliminate wrong answers

Option A is wrong because SSL Offloading only decrypts traffic destined to a protected server to reduce server load, not to inspect all HTTPS traffic including non-standard ports. Option B is wrong because Certificate Inspection only checks the SSL certificate validity and does not decrypt the traffic payload, so it cannot inspect the content of HTTPS sessions. Option D is wrong because Flow-based Inspection is a processing mode (flow vs. proxy) that can be used with SSL inspection, but it is not a type of SSL inspection itself.

528
MCQhard

A FortiGate admin configures an IP pool with type 'Fixed Port Range' to translate source IPs from 192.168.1.0/24 to 203.0.113.0/28 using port range 10000-20000. After applying the IP pool to a policy, some users cannot establish connections while others work. What is the MOST likely cause?

A.The internal subnet is using RFC 1918 addresses that cannot be NATed
B.The IP pool's port range is exhausted because the number of internal hosts exceeds the number of available port ranges
C.The IP pool is configured with overload enabled, causing conflicts
D.The firewall policy has NAT disabled
AnswerB

With a fixed-port-range IP pool, the FortiGate reserves a dedicated block of source ports per internal host on the pool's IP address. If you have more internal hosts than available port blocks (e.g., 5,000 hosts with only 4,000 blocks), later hosts receive no port allocation and their sessions are denied. This is a capacity limit caused by the deterministic, non-dynamic port-block allocation of the fixed-range mode.

Why this answer

Fixed Port Range NAT uses a one-to-one mapping of source IPs to unique port ranges. With a /28 pool (16 IPs) and port range 10000-20000 (10,001 ports), each internal host gets a dedicated port block. If more than 16 concurrent internal hosts attempt NAT, the pool is exhausted, causing connection failures for excess hosts.

This matches the symptom where some users work and others do not.

Exam trap

The trap here is confusing Fixed Port Range with Dynamic IP Pool (PAT), where overload allows many internal hosts to share a single external IP; candidates mistakenly think 'overload' is a setting in Fixed Port Range or that the port range itself is the bottleneck, rather than the number of external IPs.

How to eliminate wrong answers

Option A is wrong because RFC 1918 addresses are explicitly designed to be NATed to public IPs, and FortiGate supports NAT for private subnets. Option C is wrong because 'overload' (PAT) is not a configurable parameter for Fixed Port Range; this pool type inherently uses static port ranges without overload. Option D is wrong because the IP pool is applied to a policy, which implies NAT is enabled; if NAT were disabled, no translation would occur for any user.

529
MCQeasy

Which of the following describes the implicit deny action in FortiGate firewall policies?

A.A policy that is automatically created when the first policy is added
B.A policy that denies traffic based on the source IP
C.A policy that denies all traffic and can be moved to any position
D.A default policy that denies all traffic unless explicitly allowed
AnswerD

This is the correct description: the implicit deny is a default, unmodifiable behavior that denies all traffic unless a preceding explicit policy explicitly allows it. The firewall processes policies from top to bottom; when the packet does not match any configured allow or deny rule, it falls through to this built-in default, which silently discards the packet. This enforces a default-deny security posture, ensuring that only traffic explicitly permitted by an administrator can pass through the interface pair.

Why this answer

In FortiGate firewall policies, the implicit deny is a default, system-generated rule that denies all traffic not explicitly permitted by any configured policy. It is always present at the end of the policy list and cannot be moved, modified, or deleted. This ensures that any traffic not matching an explicit 'accept' policy is automatically dropped, enforcing a default-deny security posture.

Exam trap

The trap here is that candidates confuse the implicit deny with a user-created deny policy, thinking it can be moved or customized, when in fact it is a fixed, system-enforced rule that always resides at the end of the policy sequence.

How to eliminate wrong answers

Option A is wrong because the implicit deny is not created when the first policy is added; it exists by default even before any policies are configured. Option B is wrong because the implicit deny denies all traffic regardless of source IP, not just based on source IP. Option C is wrong because the implicit deny is always at the bottom of the policy list and cannot be moved to any position; it is fixed as the last policy.

530
MCQmedium

A FortiGate administrator wants to block outgoing DNS requests to known malware domains. Which security profile should be used?

A.Application control
B.Web filter
C.IPS
D.DNS filter
AnswerD

DNS filter is purpose-built to inspect outgoing DNS queries and compare the requested Fully Qualified Domain Name (FQDN) against FortiGuard DNS categories or an administrator-defined domain list. When a match occurs on a blocked category or domain, the filter can drop the query, return a synthetic NXDOMAIN, or redirect to a sinkhole IP to prevent resolution. This direct interception of the DNS request is why it is the correct feature for this requirement.

Why this answer

DNS Filter is the correct security profile because it is specifically designed to inspect and block DNS queries based on domain names, IP addresses, or categories. By configuring a DNS filter policy with a custom list of known malware domains, the FortiGate can intercept outgoing DNS requests and drop those matching the malicious entries, preventing the resolution of malware domains.

Exam trap

The trap here is that candidates often confuse DNS Filter with Web Filter, assuming that blocking malicious domains is a web filtering function, but DNS Filter operates at the DNS protocol level and is the correct profile for blocking DNS requests to specific domains.

How to eliminate wrong answers

Option A is wrong because Application Control identifies and controls application traffic (e.g., Skype, BitTorrent) based on signatures, not DNS queries to specific domains. Option B is wrong because Web Filter inspects HTTP/HTTPS traffic to block URLs or categories, but it does not inspect DNS requests themselves. Option C is wrong because IPS (Intrusion Prevention System) detects and blocks network-level attacks and exploits using signatures, not DNS queries to specific domain names.

531
MCQeasy

What is the primary function of protocol decoders in the FortiGate IPS engine?

A.They block malicious IP addresses based on reputation.
B.They normalize traffic for specific protocols to enable signature matching.
C.They rate-limit traffic to prevent DoS attacks.
D.They decrypt SSL/TLS traffic for inspection.
AnswerB

Protocol decoders are responsible for taking raw payloads from protocols such as HTTP, SMTP, or SMB and normalizing them into a canonical representation—stripping encoding differences, reassembling fragments, and resolving protocol ambiguities. This normalization is essential because IPS signatures are written against standardized protocol structures; without it, evasion techniques like mixed-case headers, extra whitespace, or chunked encoding would cause signatures to miss malicious content. Thus, the decoder directly enables accurate and reliable signature matching.

Why this answer

Protocol decoders in the FortiGate IPS engine analyze and normalize traffic for specific protocols (e.g., HTTP, DNS, SMTP) by parsing the protocol fields and reconstructing the data stream. This normalization allows IPS signatures to match against a consistent representation of the traffic, regardless of evasion techniques like fragmentation or encoding. Thus, their primary function is to enable accurate signature matching.

Exam trap

NSE4 often tests the role of protocol decoders versus other IPS components, so candidates may confuse decoders with SSL inspection or IP reputation, leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because blocking malicious IP addresses based on reputation is typically handled by IP reputation databases and firewall policies, not by protocol decoders. Option C is wrong because rate-limiting to prevent DoS attacks is a function of DoS policies or traffic shaping, not protocol decoders. Option D is wrong because SSL/TLS decryption for inspection is performed by SSL inspection profiles, which decrypt traffic before it reaches the IPS engine; protocol decoders do not decrypt SSL/TLS.

532
Multi-Selectmedium

A FortiGate administrator is configuring RADIUS authentication for firewall users. Which THREE steps are required to complete the configuration? (Select THREE.)

Select 3 answers
A.Import the RADIUS server certificate into FortiGate
B.Configure a firewall policy with the user group set in 'users/groups'
C.Define the RADIUS server under 'config user radius'
D.Create a user group that uses the RADIUS server as the authentication source
E.Enable 'set auth-type radius' on the interface
AnswersB, C, D

This is the enforcement point of RADIUS-based user authentication. In a firewall policy you set the source to a specific user or user group in the 'users/groups' field, which instructs FortiGate to authenticate any matching traffic against that group's authentication source. Without this policy, the RADIUS server and group are configured but no traffic is ever challenged for credentials, so the authentication is never actually applied.

Why this answer

A firewall policy must reference the user group that uses the RADIUS server as its authentication source. Without this policy configuration, RADIUS-authenticated users cannot match the policy and will be denied access. The 'users/groups' field in the firewall policy is where the user group object is specified to enforce authentication-based access control.

Exam trap

The trap here is that candidates may think importing a server certificate is required for RADIUS (confusing it with LDAPS or EAP), or that an interface-level authentication type command exists, when in fact RADIUS authentication is configured via the server object and user group, not on the interface.

533
MCQmedium

A network admin configures a site-to-site IPsec VPN between two FortiGates using IKEv1 main mode. The tunnel establishes successfully, but no traffic passes. What is the MOST likely cause?

A.Aggressive mode should be used instead of main mode
B.The pre-shared key is incorrect
C.There is no firewall policy allowing traffic through the VPN tunnel
D.The phase2 proposal does not match between peers
AnswerC

Even when the IPsec tunnel interface is up and phase 1/phase 2 SAs are active, FortiGate will not forward any user traffic through the tunnel unless an explicit firewall policy permits it. The policy must be configured with the source address, destination address, and service, and its outgoing interface must be set to the VPN tunnel interface (or the virtual IPsec interface). Without such a policy, packets are dropped at the firewall policy check even though the encrypted tunnel exists and is healthy. This is the classic root cause when the VPN shows connected but users cannot reach remote resources, and the fix is to create the appropriate ACCEPT policy from the local zone to the VPN zone.

Why this answer

The tunnel establishes successfully, meaning IKE phase 1 and phase 2 negotiations completed correctly, which rules out mismatched proposals or incorrect pre-shared keys. However, even with a functional IPsec tunnel, traffic cannot flow unless a firewall policy explicitly permits it between the source and destination zones using the VPN interface. In FortiGate, the VPN tunnel is treated as an interface, and without a policy allowing traffic from the internal network to the VPN interface (or vice versa), packets are dropped by the firewall engine.

Exam trap

The trap here is that candidates assume a successful IPsec tunnel automatically allows traffic, but FortiGate requires an explicit firewall policy to permit traffic through the VPN interface, unlike some other vendors where the tunnel itself implies a permit.

How to eliminate wrong answers

Option A is wrong because aggressive mode is used for faster negotiation with less security (e.g., when peer IP is dynamic), but main mode is fully valid and not the cause of traffic failure after tunnel establishment. Option B is wrong because if the pre-shared key were incorrect, IKE phase 1 authentication would fail and the tunnel would never establish. Option D is wrong because a phase 2 proposal mismatch would cause the IPsec SA negotiation to fail, preventing the tunnel from establishing; since the tunnel is up, the proposals must match.

534
Multi-Selecthard

A FortiGate admin is troubleshooting an issue where traffic from VLAN 10 to the internet is not being NATed even though a policy-based NAT rule is configured. The admin verifies that the firewall policy uses the correct IP Pool. Which THREE steps should the admin take to diagnose the problem? (Choose three.)

Select 3 answers
A.Reboot the FortiGate to clear any session table issues
B.Examine the IP Pool configuration for correct interface binding or port exhaustion
C.Verify that the firewall policy is being hit using 'diagnose firewall fwpolicy list' or logs
D.Check the session table using 'diagnose sys session list' to see if NAT is applied
E.Disable all other firewall policies to isolate the issue
AnswersB, C, D

The IP pool is where FortiGate defines the translated source IP(s) for NAT, so a misconfiguration here directly breaks translation. If the pool is bound to the wrong outgoing interface, traffic egressing the actual interface will not match the pool and will either be untranslated or dropped. Additionally, even with correct binding, an overloaded pool that runs out of available source ports (exhausted port range) will fail to allocate a translation for new sessions, producing a NAT failure that does not appear in policy checks.

Why this answer

Option B is correct because an IP Pool must be bound to the correct egress interface and must have available ports/addresses; if the pool is bound to the wrong interface or its ports are exhausted, NAT translation will not occur even though the policy references the pool. Option C is correct because the admin must confirm the policy is actually matching the traffic, which can be done with 'diagnose firewall fwpolicy list' or by reviewing policy logs; if the policy is not hit, NAT will never be applied. Option D is correct because 'diagnose sys session list' shows the live session table and whether NAT is applied, including the translated source IP and port, which directly reveals if NAT is failing.

Option A is not appropriate because rebooting is disruptive and does not diagnose the root cause of a NAT failure. Option E is not appropriate because disabling all other policies is a risky, non-diagnostic action that could cause an outage and does not isolate the NAT issue in a controlled way.

Exam trap

The trap here is that candidates often assume a firewall policy with NAT enabled will always work, overlooking that the IP Pool itself must be correctly bound to the egress interface and not exhausted, and that rebooting or disabling policies are not valid diagnostic steps.

535
MCQeasy

A FortiGate administrator wants to create a firewall policy that matches traffic based on the destination domain name (e.g., *.example.com). Which type of address object should be used?

A.FQDN object
B.Wildcard FQDN object
C.Subnet object
D.Geography object
AnswerB

A wildcard FQDN object is the correct object type because it supports pattern matching with an asterisk, for example `*.example.com`. This pattern matches both the apex domain and all of its subdomains in FortiGate policies, and the matching is performed against the hostname seen in the traffic, not against a single resolved IP address. It is ideal for allowing an entire domain family regardless of the underlying IP addresses.

Why this answer

A Wildcard FQDN object (option B) is the correct choice because it allows pattern matching with a leading asterisk (e.g., *.example.com) to match any subdomain of example.com. Standard FQDN objects require an exact, fully qualified domain name and do not support wildcard patterns, making them unsuitable for matching traffic based on a domain pattern like *.example.com.

Exam trap

The trap here is that candidates often confuse a standard FQDN object (which requires an exact match) with a Wildcard FQDN object (which supports pattern matching), leading them to incorrectly select option A when the question explicitly asks for a pattern like *.example.com.

How to eliminate wrong answers

Option A is wrong because a standard FQDN object requires an exact domain name (e.g., www.example.com) and does not support wildcard patterns, so it cannot match *.example.com. Option C is wrong because a Subnet object matches traffic based on IP address ranges or CIDR notation, not domain names. Option D is wrong because a Geography object matches traffic based on geographical location (country or region) using IP geolocation, not domain names.

536
Multi-Selecthard

A FortiGate administrator needs to configure a VLAN interface and an aggregate interface. Which THREE statements are correct regarding these interface types?

Select 3 answers
A.Aggregate interfaces require at least one physical member to be up.
B.Aggregate interfaces are only supported in NAT/Route mode.
C.VLAN interfaces cannot be used in transparent mode.
D.VLAN interfaces can be created on aggregate interfaces.
E.VLAN interfaces can have their own IP address and firewall policies.
AnswersA, D, E

For an aggregate interface to pass traffic, FortiOS requires at least one physical member interface to be administratively enabled and have a live link; if every member is down, the aggregate port is marked down. This is the basis of the correct answer because it accurately reflects a physical requirement for aggregate interfaces in FortiOS.

Why this answer

An aggregate interface (LAG) requires at least one physical member port to be administratively and operationally up for the aggregate itself to be considered up. If all member ports are down, the aggregate interface goes down, which is a fundamental behavior of link aggregation groups (LAGs) per IEEE 802.3ad.

Exam trap

The trap here is that candidates often confuse the mode restrictions for VLANs and aggregates, incorrectly assuming VLANs cannot be used in Transparent mode or that aggregates are limited to NAT/Route mode, when in fact both interface types have broader support.

537
Multi-Selectmedium

A FortiGate administrator is configuring a new VLAN interface on a managed FortiSwitch. The FortiGate is the FortiLink parent. The administrator wants to ensure that the VLAN is properly recognized and that traffic can flow between the FortiGate and devices on that VLAN. Which two actions must the administrator perform? (Choose two.)

Select 2 answers
A.Configure the VLAN on the FortiSwitch using the FortiGate GUI or CLI, assigning it to the desired ports.
B.Create a VLAN interface on the FortiGate with the same VLAN ID and assign it to the FortiLink interface.
C.Enable DHCP snooping on the FortiGate for the VLAN to prevent rogue DHCP servers.
D.Set the FortiLink interface to dedicated mode to allow VLAN tagging.
E.Configure a static route on the FortiGate for the VLAN subnet pointing to the FortiLink interface.
AnswersA, B

The FortiSwitch must have the VLAN defined and assigned to the ports where devices will connect. This is typically done via the FortiGate's managed switch configuration, which pushes the VLAN settings to the FortiSwitch. Without this, the VLAN is not present on the switch ports.

Why this answer

For a VLAN to function on a FortiLink-managed FortiSwitch, the FortiGate must have a VLAN interface with the matching VLAN ID bound to the FortiLink interface, and the FortiSwitch must have the VLAN configured on the appropriate ports. These two steps ensure the VLAN is recognized and traffic can flow. Other options are either optional security features or unnecessary configuration steps.

Exam trap

The trap here is assuming that creating the VLAN on the FortiGate alone is sufficient, without also configuring the VLAN on the FortiSwitch ports.

538
MCQmedium

A FortiGate admin runs 'diagnose sys session filter dport 443' and then 'diagnose sys session list'. The output shows a session with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the session?

A.The session is in a half-open state, waiting for SYN-ACK
B.The session is closing with a FIN flag
C.The session is fully established and transferring data
D.The session was blocked by a firewall policy
AnswerA

The session's proto_state value of 01 corresponds to SYN_SENT, indicating the client's SYN has been sent but no SYN-ACK has yet been received from the server. This creates a half-open session that is stuck waiting for the server to respond, often due to packet loss, a misconfigured server, or an intermediate device silently dropping the SYN-ACK. Until that reply arrives, the session cannot transition to the fully established state.

Why this answer

Protocol 6 is TCP, proto_state=01 indicates TCP SYN_SENT state (the first step of the three-way handshake). Duration and expire are in seconds. The session has been open for 3600 seconds (1 hour) and will expire in 3599 seconds, which is unusual for a TCP session that should have completed handshake quickly.

This suggests the session is stuck in SYN_SENT, likely due to no SYN-ACK response.

539
MCQmedium

An administrator needs to configure a firewall policy to allow outbound traffic from the internal network to the internet. The internal network uses private IP addresses, and the FortiGate's WAN interface has a public IP. Which NAT configuration is appropriate to ensure return traffic is routed correctly?

A.Disable NAT and rely on the FortiGate's routing table to forward traffic.
B.Enable NAT and specify a custom IP pool with a private IP address.
C.Enable NAT in the firewall policy and use the outgoing interface address.
D.Create a VIP for the internal subnet and apply it as the source in the policy.
AnswerC

Enabling NAT in the policy and using the outgoing interface address translates the private source IPs to the public IP of the WAN interface. This is the standard configuration for outbound NAT (SNAT) and ensures that return traffic is sent back to the FortiGate, which then translates it back to the internal host. This meets the requirement.

Why this answer

For outbound internet access from a private network, source NAT must be enabled in the firewall policy, typically using the outgoing interface address. This translates private IPs to the public IP of the WAN interface, allowing return traffic to reach the FortiGate and be forwarded back to the internal hosts. Other options either use incorrect NAT types or fail to translate to a routable address.

Exam trap

The trap here is confusing source NAT with destination NAT (VIP) or using a private IP pool for translation.

540
Multi-Selectmedium

A FortiGate admin needs to create a loopback interface for management purposes. Which two statements about loopback interfaces are correct? (Choose two.)

Select 2 answers
A.Loopback interfaces are always up and do not depend on physical links
B.Loopback interfaces can be used to terminate IPSec VPN tunnels
C.Loopback interfaces cannot be assigned an IP address
D.Loopback interfaces are only used for routing protocols
E.Loopback interfaces require a physical port to be up
AnswersA, B

A loopback interface in FortiOS is a virtual interface that has no physical hardware dependency; its operational status is tied to the system's presence and never to any link state. Consequently, the loopback stays up unless the FortiGate itself is rebooted or powered off, even if every physical port is down. This makes it the preferred logical anchor for router IDs, management sessions, and services that need uninterrupted reachability.

Why this answer

Loopback interfaces are virtual interfaces that are always in an up/up state as long as the FortiGate is operational. They do not depend on any physical link or carrier status, making them ideal for management access and stable routing protocol peering.

Exam trap

The trap here is that candidates often assume loopback interfaces are only for routing protocols or that they cannot have an IP address, but FortiGate loopback interfaces fully support IP addressing and are used for multiple purposes including management and VPN termination.

541
MCQmedium

A FortiGate is configured with two equal-cost static routes to the same destination network (0.0.0.0/0) via two different ISPs. The administrator wants to use both links simultaneously for load balancing. What must be enabled?

A.ECMP (Equal Cost Multi-Path) routing
B.SD-WAN
C.Link load balancing
D.Policy routing
AnswerA

FortiGate interprets multiple static routes to the same destination with identical distance and priority as equal-cost paths, installing all of them in the routing table. It then uses a per-destination hash (not per-packet) to select the egress interface for each new session, which preserves session stickiness and enables load sharing across links. This behavior is enabled by default and does not require any additional feature or configuration.

Why this answer

Equal Cost Multi-Path (ECMP) routing is the correct feature to enable because it allows a FortiGate to load-balance traffic across multiple static routes that have the same metric (distance) to the same destination (0.0.0.0/0). By default, FortiGate uses a single best route; enabling ECMP distributes sessions across both ISP links based on a hash algorithm (e.g., source-destination IP), achieving simultaneous utilization without requiring dynamic routing protocols.

Exam trap

The trap here is that candidates confuse ECMP with SD-WAN, assuming SD-WAN is mandatory for any multi-WAN load balancing, when in fact ECMP alone suffices for equal-cost static routes without application-aware steering or link health monitoring.

How to eliminate wrong answers

Option B (SD-WAN) is wrong because SD-WAN is a broader solution for intelligent path control, application steering, and link quality monitoring, but it is not required solely for basic load balancing across equal-cost static routes—ECMP handles that natively. Option C (Link load balancing) is wrong because it is not a specific FortiGate feature; the term is generic and often refers to external hardware or SD-WAN, whereas ECMP is the precise mechanism for equal-cost route load sharing. Option D (Policy routing) is wrong because policy routing (PBR) overrides the routing table based on user-defined policies (e.g., source IP, protocol), which is used for selective traffic steering, not for automatically load-balancing all traffic across equal-cost static routes.

542
MCQeasy

What is the primary purpose of FortiSandbox integration with FortiGate antivirus?

A.To replace the local antivirus scanning engine
B.To perform SSL deep inspection
C.To cache antivirus signatures locally
D.To detect zero-day malware by analyzing file behavior in a sandbox environment
AnswerD

FortiSandbox is purpose-built to detect zero-day malware by detonating suspicious files in an isolated, virtualized environment and observing runtime behaviors such as API calls, registry modifications, and outbound network connections. This dynamic analysis uncovers threats lacking known signatures, complementing FortiGate's signature-based detection. The sandbox returns a risk rating to FortiGate, enabling it to block files that evade traditional antivirus.

Why this answer

FortiSandbox integration with FortiGate antivirus is designed to detect zero-day malware by analyzing file behavior in a sandbox environment. This allows FortiGate to forward suspicious files that evade signature-based detection to FortiSandbox for dynamic analysis, where behavioral patterns are examined to identify unknown threats. The integration enhances the existing antivirus engine rather than replacing it, providing a layered defense against advanced persistent threats.

Exam trap

The trap here is that candidates may confuse the purpose of FortiSandbox with signature-based updates or SSL inspection, mistakenly thinking it replaces or caches signatures, when in fact it provides behavioral detection for unknown threats.

How to eliminate wrong answers

Option A is wrong because FortiSandbox integration does not replace the local antivirus scanning engine; it complements it by handling files that the signature-based engine cannot classify, such as zero-day malware. Option B is wrong because SSL deep inspection is a separate feature of FortiGate that decrypts SSL/TLS traffic for content inspection, and it is not the primary purpose of FortiSandbox integration. Option C is wrong because caching antivirus signatures locally is a function of the FortiGate's antivirus profile and FortiGuard updates, not a purpose of FortiSandbox integration, which focuses on behavioral analysis rather than signature storage.

543
MCQeasy

Which IPsec VPN mode uses IP addresses and ports to define interesting traffic, and requires a separate security policy for each tunnel?

A.Hub-and-spoke VPN
B.Policy-based VPN
C.Dial-up VPN
D.Route-based VPN
AnswerB

Policy-based VPN is the correct IPsec mode because it uses firewall policies to define interesting traffic by matching source/destination IP addresses, protocols, and ports, and then applies action 'IPsec' to encrypt that traffic. In FortiGate, the policy also references the IPsec phase1/phase2 VPN tunnel and security profiles, making the policy the single point of traffic selection. This is exactly how addresses and ports determine which traffic goes over the VPN.

Why this answer

Policy-based VPN (B) is correct because it defines interesting traffic using source/destination IP addresses and ports, and each tunnel requires a separate security policy to specify which traffic should be encrypted. This contrasts with route-based VPNs, which use virtual interfaces and routing tables to determine traffic, allowing a single policy to handle multiple tunnels.

Exam trap

The trap here is that candidates often confuse 'policy-based VPN' with 'route-based VPN', mistakenly thinking that route-based VPNs require separate security policies per tunnel, when in fact route-based VPNs use a single policy tied to the IPsec interface and leverage routing to handle multiple destinations.

How to eliminate wrong answers

Option A is wrong because hub-and-spoke VPN is a topology, not a mode that uses IP addresses and ports to define interesting traffic; it can be implemented with either policy-based or route-based VPNs. Option C is wrong because dial-up VPN is a scenario where remote clients connect to a central gateway, and it typically uses policy-based or route-based modes, but the defining characteristic is dynamic IP assignment, not the use of IP/port-based interesting traffic definitions. Option D is wrong because route-based VPN uses virtual interfaces (e.g., IPsec interfaces) and routing tables to direct traffic into tunnels, not IP addresses and ports in security policies; it does not require a separate security policy per tunnel.

544
MCQmedium

A FortiGate administrator configures a ZTNA rule to protect an internal web server. The rule uses an access proxy. Which component on the FortiGate terminates the incoming ZTNA connection?

A.ZTNA tag
B.SSL inspection profile
C.ZTNA application
D.ZTNA gateway
AnswerD

The ZTNA gateway is the correct answer because it is the network entity that accepts inbound client connections, terminates the TLS session, authenticates the user, validates ZTNA tags, and proxies the session to the configured ZTNA application. In FortiOS, you configure a ZTNA gateway with a virtual host, a port, and an SSL certificate. This is where the client's connection logically ends and the internal connection to the backend application begins.

Why this answer

In FortiGate ZTNA, the access proxy is hosted on the FortiGate itself, and the component that terminates the incoming ZTNA connection from the endpoint is the ZTNA gateway (also called the access proxy gateway). The ZTNA gateway performs the TLS termination and enforces the ZTNA rule, then proxies the traffic to the protected internal server. This is why the FortiGate can inspect and apply zero-trust policy without exposing the server directly.

Exam trap

NSE4 often tests the confusion between the ZTNA application (the protected resource) and the ZTNA gateway (the component that terminates the connection), so candidates pick the resource instead of the terminator.

How to eliminate wrong answers

Option A is wrong because a ZTNA tag is a metadata label applied to endpoints (via EMS or manual tagging) used in policy matching, not a connection terminator. Option B is wrong because an SSL inspection profile decrypts and inspects traffic but does not terminate the ZTNA tunnel or host the access proxy. Option C is wrong because the ZTNA application is the protected resource definition (the internal web server) referenced by the rule, not the component that terminates the client connection.

545
Drag & Dropmedium

Drag and drop the steps to configure a VLAN interface on FortiGate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VLAN interfaces require a physical parent, VLAN ID, IP address, and optional administrative access.

546
MCQeasy

Which of the following is a benefit of using IKEv2 over IKEv1 for IPsec VPN?

A.IKEv2 supports only main mode
B.IKEv2 requires fewer firewall rules
C.IKEv2 uses a single UDP port 500
D.IKEv2 is more robust to network changes and supports MOBIKE
AnswerD

IKEv2 is indeed more robust in mobile and changing network environments, primarily due to MOBIKE (Mobility and Multihoming). MOBIKE allows the VPN peer to update its current IP address to the remote gateway without renegotiating the entire IKE and IPsec SAs, preserving the tunnel across Wi-Fi to cellular handoffs. This feature, specified in RFC 4555 and integrated into RFC 7296, is absent from IKEv1, making IKEv2 superior for dynamic links.

Why this answer

IKEv2 is more robust to network changes because it supports the Mobility and Multihoming (MOBIKE) protocol, which allows an IPsec VPN tunnel to survive IP address changes without re-establishing the entire security association. This is a key advantage over IKEv1, which lacks native support for MOBIKE and requires a full rekey when the endpoint's IP address changes.

Exam trap

The trap here is that candidates often confuse IKEv2's simplified exchange (fewer messages) with requiring fewer firewall rules, but the actual benefit tested is MOBIKE support for network resilience.

How to eliminate wrong answers

Option A is wrong because IKEv2 does not support only main mode; it uses a single exchange (two messages) for initial SA setup, unlike IKEv1 which has main mode and aggressive mode. Option B is wrong because IKEv2 does not inherently require fewer firewall rules; both IKEv1 and IKEv2 typically need UDP ports 500 and 4500 (for NAT traversal) open, so the number of firewall rules is comparable. Option C is wrong because IKEv2 does not use a single UDP port 500; it uses UDP port 500 for initial negotiation and can switch to UDP port 4500 for NAT traversal, similar to IKEv1.

547
MCQhard

A FortiGate is configured with SSL deep inspection using a self-signed CA certificate. Users report that they see a certificate warning in their browser when accessing HTTPS sites. The admin wants to eliminate these warnings. What should the admin do?

A.Install the FortiGate's CA certificate on each client device's trusted root certificate store
B.Disable SSL deep inspection and rely on flow-based antivirus
C.Change the SSL inspection mode to certificate inspection only
D.Configure an SSL certificate exemption for all HTTPS traffic
AnswerA

Installing the FortiGate CA certificate into each client's trusted root store is the only way to make the browser accept the dynamically generated server certificates that FortiGate presents during MITM decryption. Without this trust anchor, every HTTPS session fails the chain validation and triggers a 'certificate not trusted' warning. This step validates the FortiGate as the legitimate signing authority for its intercepted sessions, eliminating warnings and restoring secure, transparent deep inspection.

Why this answer

When FortiGate performs SSL deep inspection, it decrypts HTTPS traffic by acting as a man-in-the-middle, using its own CA certificate to re-encrypt the connection. If the FortiGate's self-signed CA certificate is not trusted by the client, the browser will display a certificate warning because the issuer is not in the client's trusted root store. Installing the FortiGate's CA certificate on each client device's trusted root certificate store establishes trust, eliminating the warnings.

Exam trap

The trap here is that candidates may think disabling or bypassing SSL inspection (options B, C, or D) is a valid way to eliminate warnings, but the correct approach is to establish trust by distributing the FortiGate's CA certificate to clients.

How to eliminate wrong answers

Option B is wrong because disabling SSL deep inspection removes the ability to inspect encrypted traffic for threats, but it does not address the root cause of certificate warnings; it simply avoids the issue. Option C is wrong because certificate inspection only examines the certificate exchange without decrypting the payload, which prevents deep content inspection but still requires a trusted CA to avoid warnings if any interception is performed. Option D is wrong because configuring an SSL certificate exemption for all HTTPS traffic effectively bypasses inspection entirely, leaving the traffic unexamined and defeating the purpose of SSL deep inspection.

548
MCQmedium

An admin wants to block all traffic from a specific geographic region. Which address object type should be used in the firewall policy source?

A.FQDN
B.Subnet
C.IP range
D.Geography
AnswerD

Geography address objects are predefined FortiGuard-maintained collections of IP ranges mapped to countries or regions. Referencing a Geography object in the firewall policy source matches traffic by geolocation, blocking all traffic originating from the specified region without manually enumerating IP addresses.

Why this answer

FortiGate firewalls include a built-in Geography address object type that allows policies to match traffic based on the source or destination IP address's registered country or region. This object uses GeoIP databases to classify IP addresses, enabling administrators to block or allow traffic from entire geographic areas without needing to manually list individual subnets or ranges.

Exam trap

The trap here is that candidates may confuse Geography with IP range or subnet, thinking they can manually compile a list of all IPs for a region, but FortiGate's Geography object automates this via the GeoIP database and is the correct, scalable approach for geographic blocking.

How to eliminate wrong answers

Option A is wrong because FQDN (Fully Qualified Domain Name) objects resolve to IP addresses via DNS and are used for policies based on domain names, not geographic location. Option B is wrong because a Subnet object defines a contiguous block of IP addresses using a network prefix (e.g., 192.168.1.0/24) and cannot represent an entire geographic region. Option C is wrong because an IP range object specifies a start and end IP address (e.g., 10.0.0.1-10.0.0.255) and is intended for arbitrary address ranges, not for geographic classification.

549
MCQmedium

A FortiGate cluster is configured in active-passive HA. The administrator wants to manage the cluster using a single IP address that always points to the current primary unit. Which configuration should be applied?

A.Configure a virtual IP (VIP) for HTTPS management
B.Set the HA management IP as a dedicated interface IP on each unit
C.Enable 'management IP' under HA configuration with the desired IP
D.Use the same IP address on both units and disable ARP
AnswerC

The 'management IP' field under the HA configuration is the correct method because it defines a floating IP (with optional netmask and gateway) that is owned by the primary unit and automatically moves to the failover unit during a failure. This IP is not a regular interface IP; it is added as an alias on the primary unit's management interface, enabling uninterrupted HTTPS management of the cluster via the same address before and after failover. Ensure the management IP is on the same subnet as your management network and that you allow HTTPS on that interface.

Why this answer

The management interface in HA can have a virtual IP that follows the primary unit, accessible via the floating (virtual) management IP.

550
MCQhard

A FortiGate with multiple VDOMs has a policy that allows traffic from VDOM A to VDOM B. The admin notices that traffic from VDOM A to a specific server in VDOM B is being dropped. The session log shows 'deny by forward policy check'. What is the MOST likely cause?

A.The inter-VDOM link is down
B.NAT is required for inter-VDOM traffic
C.The source VDOM has exceeded its session limit
D.The policy in VDOM B to allow traffic from VDOM A is missing or misconfigured
AnswerD

In a multi-VDOM FortiGate, traffic leaving VDOM A and entering VDOM B must match a forward policy in VDOM B that permits the traffic from the inter-VDOM link interface to the destination interface. If that policy is missing, misconfigured (e.g., wrong source/destination addresses, wrong service, or disabled action), the packet is implicitly denied by the firewall's default-deny behavior. The error message would reflect a forward policy check failure, making this the correct explanation for the traffic being blocked.

Why this answer

The session log message 'deny by forward policy check' indicates that the traffic was explicitly denied by a firewall policy rule, not by a routing or resource issue. In a multi-VDOM setup, traffic from VDOM A to VDOM B must be permitted by a policy in VDOM B (the destination VDOM) that allows traffic from the inter-VDOM link or from VDOM A. If that policy is missing or misconfigured, the FortiGate will drop the traffic and log this exact denial.

Exam trap

The trap here is that candidates often assume inter-VDOM traffic is implicitly allowed or that the source VDOM's policy controls the flow, but in reality each VDOM has its own independent policy set and the destination VDOM must have an explicit permit policy for the traffic to be forwarded.

How to eliminate wrong answers

Option A is wrong because an inter-VDOM link being down would cause a routing or connectivity failure, not a 'deny by forward policy check' log entry; the session would show 'no route' or 'link down' instead. Option B is wrong because NAT is not required for inter-VDOM traffic; inter-VDOM communication can be routed without NAT unless explicitly configured for address translation. Option C is wrong because a session limit exceeded would generate a 'session limit reached' or 'resource exhausted' log, not a policy-based deny message.

551
Multi-Selectmedium

An administrator is planning a firmware upgrade from FortiOS 6.0 to 7.2. Which THREE steps should be performed before starting the upgrade process?

Select 3 answers
A.Read the release notes for the target firmware version
B.Remove all static routes to avoid routing issues
C.Verify the upgrade path and ensure intermediate versions are used if needed
D.Perform a full configuration backup
E.Disable all antivirus and IPS sensors
AnswersA, C, D

Release notes are the authoritative source for firmware-specific changes, upgrade caveats, and known issues that can affect the FortiGate during or after the upgrade. They detail critical items such as changes to default behavior, deprecated features, and special instructions for the target version — skipping them can lead to unexpected post-upgrade behavior or service outages.

Why this answer

Reading the release notes for the target firmware version (FortiOS 7.2) is essential because they document critical upgrade-specific information, such as deprecated features, changed default behaviors, known issues, and hardware compatibility requirements. Skipping this step can lead to unexpected service disruptions or feature loss after the upgrade, as the release notes often include mandatory pre-upgrade actions like disabling certain features or adjusting configurations.

Exam trap

The trap here is that candidates may think disabling security features (Option E) is a safe precaution, but Fortinet explicitly advises against disabling security profiles unless a specific release note entry warns of a conflict, making it a distractor that wastes time and reduces security posture.

552
MCQmedium

A company has a web server in the DMZ that needs to be accessible from the internet on port 443 (HTTPS). The administrator configures a Virtual IP (VIP) mapping the public IP 203.0.113.10 to the private IP 10.0.1.10 port 443. Which firewall policy is required to allow inbound traffic?

A.A policy from WAN to DMZ with source any, destination IP of the server (10.0.1.10), and action ACCEPT
B.A policy from WAN to DMZ with source any, destination VIP, and action ACCEPT
C.No firewall policy is needed; the VIP automatically allows traffic
D.A policy from DMZ to WAN with source VIP, destination any, and action ACCEPT
AnswerB

This is the correct way to publish a server. The VIP object defines the public-to-private IP mapping, and the policy uses that VIP as the destination to explicitly allow inbound traffic. After the policy is matched, FortiOS performs destination NAT, replacing the VIP IP with the server's private IP and forwarding the packet to the DMZ. This ensures that all traffic is inspected and controlled by the firewall.

Why this answer

When a Virtual IP (VIP) is configured in FortiGate, the firewall policy must reference the VIP object as the destination, not the actual private IP. The VIP translates the public IP (203.0.113.10) to the private IP (10.0.1.10), and the policy from WAN to DMZ with destination VIP ensures that inbound traffic is matched and permitted before NAT translation occurs. Without this policy, the VIP alone does not allow traffic; it only defines the translation rule.

Exam trap

The trap here is that candidates often assume a VIP automatically permits traffic or that the policy should use the private IP, but FortiGate requires an explicit firewall policy referencing the VIP object to allow inbound traffic through the NAT mapping.

How to eliminate wrong answers

Option A is wrong because the policy must use the VIP object as the destination, not the actual private IP (10.0.1.10); referencing the private IP bypasses the NAT translation and will not match the incoming traffic destined to the public IP. Option C is wrong because a VIP does not automatically allow traffic; it only defines the NAT mapping, and a corresponding firewall policy with action ACCEPT is mandatory to permit the traffic. Option D is wrong because the required policy must be from WAN to DMZ (inbound direction), not from DMZ to WAN; the DMZ-to-WAN policy would control outbound responses, not the initial inbound connection.

553
MCQeasy

A FortiGate administrator wants to see real-time debugging output for traffic matching a specific source IP address. Which command sequence would achieve this?

A.diagnose sys session filter src 10.0.1.10 ; diagnose sys session list
B.diagnose debug flow filter src 10.0.1.10 ; diagnose debug flow show function-name ; diagnose debug enable
C.diagnose sniffer packet any 'host 10.0.1.10' 4
D.diagnose debug reset ; diagnose debug enable ; diagnose debug flow show iprope
AnswerB

This correct sequence first installs a flow trace filter for the source IP, then selects the `function-name` output mode to display the names of kernel functions that process the matching packets, and finally enables debug output. The order is critical because the filter must be active before debugging starts to avoid capturing unrelated traffic, and the `show` option must be set before `enable` takes effect. Once enabled, the FortiGate outputs a step-by-step traversal of the packet through the firewall, including policy lookups, session setup, and any drops, which is exactly what real-time debugging requires.

Why this answer

The 'diagnose debug flow' command sequence is specifically designed for real-time debugging of traffic flows, allowing filtering by source IP with the 'filter src' option. Enabling debug output with 'diagnose debug enable' then shows flow trace information for packets matching the filter, which is the standard method for live traffic debugging on FortiGate.

Exam trap

The trap here is confusing packet sniffing (Option C) with flow debugging (Option B), as both can show traffic for a specific IP, but only debug flow reveals the firewall's internal processing decisions (e.g., policy ID, NAT action) in real time, which is essential for diagnosing policy-related issues.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys session list' shows current session table entries, not real-time debugging output; it provides a static snapshot, not a live trace. Option C is wrong because 'diagnose sniffer packet' captures raw packets but does not provide the flow-level debugging details (e.g., firewall policy decisions, NAT translations) that 'debug flow' offers; it is a packet capture tool, not a flow debugger. Option D is wrong because the command sequence is incomplete and incorrect: 'diagnose debug reset' clears all debug settings, 'diagnose debug enable' enables debug without a filter, and 'diagnose debug flow show iprope' is not a valid command (the correct command is 'diagnose debug flow show function-name' or 'diagnose debug flow show ip-address'); this sequence would either produce no output or show unfiltered debug data.

554
MCQmedium

A FortiGate administrator needs to create a firewall policy that allows traffic from the internal network (10.0.0.0/8) to a public web server (203.0.113.10) on port 443. The policy must also perform source NAT using the FortiGate's external IP (198.51.100.1). Which NAT configuration should be applied?

A.Create an IP pool with the external IP and reference it in the firewall policy
B.Enable NAT on the firewall policy without specifying an IP pool
C.Create a VIP for the web server and reference it in the firewall policy
D.Configure Central SNAT and a matching rule
AnswerB

When you enable NAT on a firewall policy and leave the IP pool field blank, FortiOS performs source NAT using the primary IP address of the egress interface—here, 198.51.100.1. This is the simplest and most common method for enabling internet access from a private network, as it requires no separate NAT objects or additional configuration. The NAT action is directly part of the policy, exactly matching the scenario's request to apply NAT to the policy itself.

Why this answer

When a firewall policy uses source NAT (SNAT) to translate internal source IPs to the FortiGate's own egress interface IP, simply enabling NAT on the policy without specifying an IP pool is sufficient. This is the default behavior: the FortiGate automatically performs source NAT using the IP address of the outgoing interface (in this case, 198.51.100.1). No additional IP pool or central NAT rule is required for this standard outbound NAT scenario.

Exam trap

The trap here is that candidates often confuse source NAT with destination NAT and incorrectly select a VIP (option C), or they overcomplicate the scenario by assuming an IP pool is always required for NAT, when in fact the default interface NAT is sufficient when the goal is to use the FortiGate's own external IP.

How to eliminate wrong answers

Option A is wrong because creating an IP pool is necessary only when you need to translate to a specific IP address that is not the egress interface IP, or when you need to use a range of IPs (e.g., for load balancing or hiding many internal hosts behind a smaller set of public IPs). Here, the requirement is to use the FortiGate's own external IP, which is the default behavior when NAT is enabled without a pool. Option C is wrong because a Virtual IP (VIP) is used for destination NAT (DNAT), i.e., translating an incoming public IP to an internal private IP, not for source NAT.

The question asks for source NAT, so a VIP is irrelevant. Option D is wrong because Central SNAT is an alternative method for configuring source NAT, but it is not required; the question does not specify a need for central NAT management, and the standard policy-based NAT (enabling NAT on the policy) is the simplest and correct approach for this scenario.

555
MCQmedium

A FortiGate is configured with an active-passive HA cluster. The admin notices that when the primary unit fails, the secondary takes over, but after the primary recovers, it does not automatically become active again. What is the most likely reason?

A.The primary has a lower priority than the secondary
B.Override is not enabled
C.Session pickup is disabled
D.The heartbeat interface is down
AnswerB

When override is enabled in FortiGate HA, a device with higher priority can preempt the current primary when it comes back online after a failover. Without override, the cluster maintains the current primary even if a higher-priority unit is available, so the original primary remains active after recovery. This is exactly the observed behavior: the higher-priority unit is primary initially, fails over, and on recovery does not reclaim primary because override is off. The priority is used for initial election and for override-based decisions, but failback requires override enabled.

Why this answer

In FortiGate HA, when the primary unit recovers after a failover, it does not automatically reclaim the primary role unless 'override' is enabled. Without override, the current primary (formerly secondary) retains the active role, and the recovered unit becomes the secondary. Enabling override allows the unit with the higher priority (or lower monitor priority value) to take over as primary when it comes back online.

Exam trap

NSE4 often tests the misconception that the original primary automatically reclaims the active role after recovery — candidates must remember that without override enabled, the current primary retains the role.

How to eliminate wrong answers

Option A is wrong because if the primary had a lower priority than the secondary, the secondary would have been primary from the start — the question states the primary failed and the secondary took over, which is normal behavior. Option C is wrong because session pickup (session synchronization) affects whether sessions survive failover, not whether the original primary reclaims the active role. Option D is wrong because a down heartbeat interface would cause failover, not prevent the recovered primary from becoming active again.

556
MCQeasy

Which of the following best describes the policy lookup order on a FortiGate firewall?

A.Policies are evaluated in the order they appear in the policy list, from top to bottom
B.Policies are evaluated based on the number of hits, least-hit first
C.Policies are evaluated randomly to balance load
D.The policy with the highest priority number is evaluated first
AnswerA

FortiGate firewall policies are stored in a sequential list, and the session engine traverses that list in the exact order the administrator has arranged them, from the topmost entry (index 0) downward. The first policy whose source, destination, service, and other match conditions all align with the session's attributes is immediately applied, and no further policies are consulted for that session. This deterministic top-down approach is why moving a policy to a new position can dramatically change traffic handling, even if the policy's own match fields remain identical.

Why this answer

FortiGate firewalls evaluate firewall policies sequentially from the top of the policy list downward. The first policy that matches the source, destination, service, and other attributes of a packet is applied, and no further policies are checked. This top-down evaluation ensures deterministic traffic handling and is fundamental to FortiGate's stateful inspection engine.

Exam trap

The trap here is that candidates often confuse FortiGate's top-down sequential policy lookup with Cisco ASA's concept of 'first match wins' but may incorrectly assume that hit counts or priority numbers influence the evaluation order, which is not the case on FortiGate.

How to eliminate wrong answers

Option B is wrong because FortiGate does not use hit count to determine policy order; policies are evaluated by their position in the list, not by usage statistics. Option C is wrong because policy evaluation is deterministic and sequential, not random, as random evaluation would break security consistency and is not supported. Option D is wrong because FortiGate uses policy ID order (lower IDs are evaluated first by default) or manual ordering, not a priority number; higher priority numbers do not cause earlier evaluation.

557
MCQhard

An administrator runs 'diagnose vpn ike gateway list' on a FortiGate and sees the following output for a dial-up IPsec VPN: gateway name: 'dialup' version: IKEv1 mode: aggressive local IP: 203.0.113.1 remote IP: 0.0.0.0 state: up peers: 0 What does 'peers: 0' indicate?

A.The remote IP should be set to a specific address
B.The gateway is in a down state
C.No IPsec clients are currently connected
D.The Phase 2 proposals are mismatched
AnswerC

The peers counter shows how many dial-up clients currently have an established IPsec tunnel to this gateway. A value of zero means no clients are connected, even though the gateway itself is up and listening for incoming aggressive-mode connections from remote peers.

Why this answer

In the output of 'diagnose vpn ike gateway list', the 'peers' field shows the number of active IPsec tunnels (Phase 1 SAs) currently established through that gateway. A value of '0' means no remote clients have successfully completed IKE negotiation and are connected. Since the gateway state is 'up', it is ready to accept connections, but no clients are currently associated with it.

Exam trap

The trap here is that candidates see 'state: up' and assume the gateway has active connections, but 'up' only indicates the IKE process is running and listening, not that any peers are actually connected.

How to eliminate wrong answers

Option A is wrong because in a dial-up IPsec VPN, the remote IP is intentionally left as 0.0.0.0 to allow any remote client to initiate a connection; setting a specific address would defeat the purpose of a dial-up configuration. Option B is wrong because the output explicitly shows 'state: up', indicating the IKE gateway process is active and listening, not down. Option D is wrong because Phase 2 proposal mismatches would cause failures during IPsec SA establishment, not affect the Phase 1 peer count; the 'peers' counter specifically tracks Phase 1 SAs, not Phase 2.

558
MCQhard

After upgrading FortiOS, an IPsec VPN tunnel fails to come up. The diagnose output shows 'negotiation failed: no acceptable proposal'. The remote peer is a third-party device. Which step should you take first?

A.Change the IKE version to IKEv2
B.Disable dead peer detection on the FortiGate
C.Reboot the remote peer
D.Check the phase1 and phase2 proposal settings on both ends to ensure they match
AnswerD

The correct first step is to compare the phase1 and phase2 proposal settings on both peers, because after a FortiOS upgrade, default values or accepted algorithms may have changed, causing a mismatch in encryption (e.g., AES128 vs AES256), authentication/hash (e.g., SHA1 vs SHA2), Diffie-Hellman group (e.g., 2 vs 14), or PFS settings. Both IKE security associations (phase1) and IPsec security associations (phase2) require an exact match of all transform sets; if any parameter differs, the tunnel will not come up. Use the "diagnose vpn ike log" or check the FortiGate logs to identify the specific proposal that was rejected, then adjust the FortiGate configuration to match the remote peer's supported algorithms.

Why this answer

The 'no acceptable proposal' error indicates a mismatch in the Internet Key Exchange (IKE) parameters between the FortiGate and the remote peer. Since the remote peer is a third-party device, the most common cause is a misalignment in phase1 (IKE) or phase2 (IPsec) settings such as encryption algorithm, authentication method, Diffie-Hellman group, or lifetime. Option D is correct because verifying and aligning these proposals on both ends is the standard first step to resolve proposal mismatches.

Exam trap

The trap here is that candidates often jump to changing IKE version or disabling DPD, thinking the issue is a protocol incompatibility or a dead peer, when the root cause is almost always a simple proposal mismatch that must be checked first.

How to eliminate wrong answers

Option A is wrong because changing the IKE version (e.g., from IKEv1 to IKEv2) does not fix a proposal mismatch; it only changes the negotiation protocol, and both ends must already support the same version. Option B is wrong because disabling dead peer detection (DPD) does not address proposal negotiation failures; DPD is used to detect peer liveness after the tunnel is established, not during initial IKE negotiation. Option C is wrong because rebooting the remote peer is a disruptive and unnecessary step; it will not correct configuration mismatches and only wastes time when the issue is clearly a proposal mismatch.

559
MCQhard

Refer to the exhibit. A FortiGate SSL VPN user is unable to connect. The debug output shows the above error. What is the most likely cause?

A.The SSL VPN certificate has expired.
B.The CA that issued the SSL VPN certificate is not trusted by the client.
C.The user's password is incorrect.
D.The firewall policy is blocking the SSL VPN port.
AnswerB

During the TLS handshake, FortiGate presents its SSL VPN server certificate to the client, which then attempts to build a trust path to a root CA in its local trust store. If the issuing CA is not installed in the client's trust store, the client aborts with an 'unknown CA' or 'untrusted certificate' error, and the login page is never displayed. This happens because the client cannot verify the server's identity, an essential prerequisite for establishing the encrypted tunnel and preventing man-in-the-middle attacks. The correct remediation is to either replace the self-signed or private certificate with one issued by a publicly trusted CA, or to push the private CA certificate to all client devices.

Why this answer

The debug output indicates an SSL/TLS handshake failure, specifically that the client does not trust the server's certificate. This occurs when the Certificate Authority (CA) that issued the SSL VPN certificate is not in the client's trusted root store. Option B correctly identifies this as the most likely cause because the error is a certificate trust issue, not an expiration or authentication problem.

Exam trap

The trap here is that candidates confuse certificate trust issues (CA not trusted) with certificate expiration, but the debug output clearly shows a trust chain failure, not a validity date error.

How to eliminate wrong answers

Option A is wrong because a certificate expiration error would typically produce a different debug message (e.g., 'certificate has expired') and would be logged as a validity period failure, not a trust chain issue. Option C is wrong because an incorrect password would result in an authentication failure at the login stage, not an SSL/TLS handshake error during the initial connection setup. Option D is wrong because a firewall policy blocking the SSL VPN port would prevent any TCP connection from being established, resulting in a timeout or 'connection refused' error, not an SSL handshake failure with certificate trust messages.

560
MCQhard

An administrator configures an application control profile to block 'Facebook' and 'Twitter' using application signatures. Users can still access Facebook via HTTPS. The firewall policy has application control enabled and SSL deep inspection is not configured. Why is Facebook not blocked?

A.The application signature for Facebook is not updated
B.The application control profile is configured in monitor-only mode
C.HTTPS traffic is encrypted and cannot be inspected without SSL deep inspection
D.Facebook uses a non-standard port that application control does not monitor
AnswerC

Facebook is reached over HTTPS, so the application signature cannot match inside the encrypted TLS payload. Without SSL deep inspection, the firewall sees only encrypted traffic and cannot identify or block the application, satisfying the stem's stated absence of deep inspection.

Why this answer

Without SSL deep inspection, the FortiGate cannot decrypt HTTPS traffic to inspect the application-layer payload. Application control relies on inspecting unencrypted traffic or using SSL inspection to identify applications within encrypted sessions. Since Facebook uses HTTPS, the encrypted traffic passes through without being matched against the application signature, so the block action is not enforced.

Exam trap

The trap here is that candidates assume application control can block any application regardless of encryption, overlooking the fundamental requirement for SSL deep inspection to inspect HTTPS traffic at the application layer.

How to eliminate wrong answers

Option A is wrong because the question states the administrator configured application signatures for Facebook and Twitter, and there is no indication the signatures are outdated; even if they were, the core issue is encryption, not signature version. Option B is wrong because the question says the firewall policy has application control enabled, and there is no mention of monitor-only mode; if it were monitor-only, the traffic would be logged but not blocked, yet the user can still access Facebook, which aligns with the lack of inspection, not a monitor-only setting. Option D is wrong because Facebook uses standard HTTPS ports (443) and application control monitors all ports by default; the issue is encryption, not port selection.

561
MCQhard

An administrator runs the command shown in the exhibit and sees anomalies detected from 10.1.1.100 to 10.2.2.200. The IPS sensor's anomaly settings are configured with the default actions. What will be the default action for the ICMP Flood anomaly?

A.Monitor
B.Block
C.Pass
D.Quarantine
AnswerB

Block is the correct default action for the ICMP flood anomaly in FortiGate. When the configured threshold is exceeded, the FortiGate drops packets from the offending source, protecting both the firewall itself and the downstream network. This reactive mitigation is the default because it immediately stops the flood while still allowing subsequent legitimate traffic once the rate falls below the threshold. Block is the security-first choice for flood anomalies.

Why this answer

By default, FortiGate IPS sensors set the action for ICMP Flood anomalies to 'Block'. This default action is defined in the IPS sensor configuration and is applied when the anomaly threshold is exceeded, as indicated by the detected anomalies from 10.1.1.100 to 10.2.2.200.

Exam trap

The trap here is that candidates often confuse the default action for anomaly-based IPS signatures with the default action for signature-based IPS rules, where 'Monitor' is the default, leading them to incorrectly select 'Monitor' for flood anomalies.

How to eliminate wrong answers

Option A is wrong because 'Monitor' is not the default action for ICMP Flood anomalies; it is a user-configurable action that logs the event without blocking traffic. Option C is wrong because 'Pass' would allow the traffic to bypass inspection, which is not the default behavior for detected anomalies. Option D is wrong because 'Quarantine' is an action typically used for compromised hosts in other security contexts, not the default action for ICMP Flood anomalies in an IPS sensor.

562
MCQmedium

An administrator has configured LDAP authentication on a FortiGate. When testing the LDAP connectivity, the test succeeds. However, users cannot authenticate through the captive portal. What is a possible cause?

A.The captive portal is disabled
B.The user group is not configured to use the LDAP server
C.The LDAP server is not reachable from the captive portal interface
D.The LDAP server's SSL certificate is expired
AnswerB

In FortiGate, an LDAP server object alone is not sufficient for authentication; the user group must explicitly reference that LDAP server as its remote authentication source. When a user tries to authenticate via the captive portal, FortiGate checks the user's group membership and looks at the authentication server assigned to that group. If the LDAP server is not configured in the user group settings, FortiGate has no source to bind against, so the LDAP query is never performed. This is the correct root cause because it explains why connectivity to LDAP succeeds but authentication still fails.

Why this answer

The LDAP connectivity test succeeds, confirming the FortiGate can reach and bind to the LDAP server. However, for captive portal authentication to work, the user group must be explicitly configured to reference the LDAP server as its remote authentication source. Without this mapping, the FortiGate does not know to send authentication requests to the LDAP server, even though the LDAP server connection itself is functional.

Exam trap

The trap here is that candidates assume a successful LDAP connectivity test guarantees full authentication functionality, but FortiGate requires an explicit user group binding to use the LDAP server for captive portal authentication.

How to eliminate wrong answers

Option A is wrong because if the captive portal were disabled, users would not even see the captive portal login page, but the question states users cannot authenticate, implying the portal is active. Option C is wrong because the LDAP connectivity test succeeded, proving the LDAP server is reachable from the FortiGate; the captive portal interface uses the same FortiGate to reach the server. Option D is wrong because an expired SSL certificate would cause the LDAP connectivity test to fail (unless LDAP over TLS is not used), and the test succeeded, so certificate expiry is not the issue.

563
MCQeasy

A FortiGate administrator wants to block access to gambling websites using web filtering. Which FortiGuard category should be blocked?

A.Spam
B.Malware
C.Gambling
D.Pornography
AnswerC

FortiGuard has a dedicated 'Gambling' web filtering category that groups online casinos, sports-betting sites, lotteries, and similar services. To block access, the administrator should create or edit a web filter profile, locate the Gambling category, and set the action to "Block" (or "Monitor" for logging). This category is predefined by FortiGuard and periodically updated, so selecting it directly is the correct and precise method for enforcing a gambling-blocking policy.

Why this answer

FortiGuard web filtering uses pre-defined categories to classify websites. To block gambling sites, the administrator must select the 'Gambling' category in the web filter profile. This category specifically includes domains and URLs related to online betting, casinos, and other gambling activities.

Exam trap

The trap here is that candidates may confuse the 'Gambling' category with other content categories like 'Pornography' or 'Spam', but FortiGuard assigns distinct category IDs for each, and only the correct category will block the intended site type.

How to eliminate wrong answers

Option A is wrong because the 'Spam' category is used to filter unsolicited bulk email or spam-related content, not gambling websites. Option B is wrong because the 'Malware' category blocks sites known to host malicious software or exploits, which is unrelated to gambling content. Option D is wrong because the 'Pornography' category targets adult or explicit sexual content, not gambling sites.

564
MCQmedium

A FortiGate admin runs 'diagnose sys session filter src 10.0.0.10' and gets no output. What does this indicate?

A.The session table is full
B.The source IP 10.0.0.10 is not currently active in any session table
C.The firewall policy is blocking traffic from 10.0.0.10
D.The diagnose command syntax is incorrect
AnswerB

The kernel session table tracks active, stateful connections, and when you apply a source-IP filter, it displays only sessions whose source address matches the filter. If no output is returned, it means the source 10.0.0.10 currently has no session entry — the host is idle, its session expired or was torn down, or it never established one. This is a straightforward observation of the session table state, not a sign of a performance or configuration issue.

Why this answer

The 'diagnose sys session filter' command in FortiGate is used to filter and display active session entries in the session table. When the command 'diagnose sys session filter src 10.0.0.10' returns no output, it means that no session in the session table matches the source IP address 10.0.0.10, indicating that this IP is not currently involved in any active session. This does not imply the session table is full, a policy block, or a syntax error.

Exam trap

The trap here is that candidates may assume no output means a syntax error or a full session table, but FortiGate clearly indicates syntax errors with an error message, and a full table still shows existing sessions; the correct interpretation is that the source IP has no active sessions.

How to eliminate wrong answers

Option A is wrong because a full session table would still show sessions that match the filter, or the command would return an error or warning about table capacity, not simply no output. Option C is wrong because a firewall policy blocking traffic would prevent sessions from being created, but the command only checks the session table; if no session exists, it returns no output regardless of the policy reason. Option D is wrong because the syntax 'diagnose sys session filter src 10.0.0.10' is correct; if the syntax were incorrect, FortiGate would return a syntax error message, not a blank output.

565
MCQhard

An administrator attempts to configure a policy route to route specific traffic from an internal subnet (10.1.1.0/24) to the internet via a different ISP. The policy route is created but traffic is still using the default route. What is the most likely cause?

A.The outgoing interface in the policy route is down.
B.The policy route is not using the correct source interface.
C.The destination address in the policy route is incorrect.
D.The static default route has a lower administrative distance than the policy route.
AnswerA

In FortiGate, policy routes are only considered valid when the specified outgoing interface is in an up state. If that interface is down, the policy route is automatically excluded from the forwarding decision, and packets are instead processed by the normal routing table. This fallback behavior explains why traffic continues to use the default route rather than the intended policy-based path.

Why this answer

Policy routes in FortiGate have a higher priority than static routes, but they are only applied if the specified outgoing interface is operationally up. If the outgoing interface is down, the policy route is skipped, and traffic falls back to the default route. This is the most likely cause because the administrator confirmed the policy route was created but traffic still uses the default route.

Exam trap

The trap here is that candidates often assume policy routes always override static routes, but they forget that FortiGate requires the outgoing interface to be up for the policy route to be active, leading them to incorrectly select administrative distance or source interface issues.

How to eliminate wrong answers

Option B is wrong because the source interface in a policy route is optional; if omitted, the policy matches based on source IP alone, so an incorrect source interface would not cause the policy to be ignored entirely. Option C is wrong because an incorrect destination address would cause the policy to not match the traffic, but the question states the policy route was created and traffic is still using the default route, implying the policy exists but is not being applied. Option D is wrong because policy routes have a higher precedence than static routes regardless of administrative distance; administrative distance only applies to static route selection, not to policy route enforcement.

566
MCQhard

An administrator integrates FortiGate with FortiSandbox for advanced threat detection. The FortiGate is configured to send files to FortiSandbox for analysis. Despite correct configuration, files are not being submitted. The administrator runs 'diagnose debug application fortisandbox -1' and sees 'no server configured'. What is the issue?

A.The FortiSandbox license has expired
B.Firewall policies are blocking communication to the FortiSandbox server
C.The FortiSandbox server IP address is not configured on the FortiGate
D.The antivirus profile is not configured to submit files to FortiSandbox
AnswerC

The debug output "no server configured" directly indicates the FortiGate lacks the FortiSandbox appliance's IP address, so file submission cannot initiate. Without that address, the FortiGate has no destination to send files to, regardless of other settings. Configuring the FortiSandbox server IP under the relevant security fabric or sandbox settings resolves the failure.

Why this answer

The debug output 'no server configured' explicitly indicates that the FortiGate does not have a FortiSandbox server IP address defined in its configuration. Without the server IP configured under 'config system fortisandbox', the FortiGate cannot establish a connection or submit files, regardless of other settings. This is a prerequisite step before any file submission can occur.

Exam trap

The trap here is that candidates often assume the issue is a firewall policy or license problem, but the debug output's exact wording 'no server configured' directly points to a missing server IP configuration, which is a common oversight.

How to eliminate wrong answers

Option A is wrong because an expired FortiSandbox license would generate a license-related error or warning in the debug output, not 'no server configured'. Option B is wrong because firewall policies blocking communication would result in connection timeouts or 'connection refused' errors, not a 'no server configured' message which indicates the server address is missing entirely. Option D is wrong because while the antivirus profile must have 'fortisandbox' enabled for submission, the debug message 'no server configured' points to a missing server IP configuration, not a profile misconfiguration.

567
MCQhard

A FortiGate has a central SNAT policy that translates internal users to a single IP pool address. The admin wants specific traffic (e.g., from a particular subnet) to use a different IP pool. What is the correct approach?

A.Create a new central SNAT policy with the specific subnet as source and place it above the existing policy
B.Create a policy-based NAT rule with the specific subnet and place it above the central SNAT policy
C.Use VIP to translate the source address
D.Modify the existing central SNAT policy to use a dynamic IP pool
AnswerA

Central SNAT policies are evaluated in strict top-down order, and the first policy whose source, destination, and service criteria match the traffic is applied. By creating a new policy with a more specific source subnet (e.g., 10.1.1.0/24) and placing it above the existing broader policy, you guarantee that traffic from that subnet is translated according to the new policy, while all other traffic falls through to the original policy below. This is the standard way to implement selective source translation when central NAT is enabled.

Why this answer

Central SNAT policies are evaluated in sequential order, and the first matching policy is applied. By creating a new policy with the specific subnet as the source and placing it above the existing policy, the FortiGate will match the more specific traffic first and use the different IP pool, while all other traffic continues to match the original policy.

Exam trap

The trap here is that candidates often confuse central SNAT with policy-based NAT or VIP, mistakenly thinking that VIPs can be used for source NAT or that PBNAT rules can be inserted into the central NAT table, when in fact central SNAT policies are a distinct feature with their own ordered list.

How to eliminate wrong answers

Option B is wrong because policy-based NAT (PBNAT) is a legacy feature that operates within firewall policies, not as a separate NAT policy table; placing a PBNAT rule above a central SNAT policy is not a valid configuration as they are different mechanisms. Option C is wrong because a Virtual IP (VIP) is used for destination NAT (DNAT), translating incoming traffic's destination IP, not for source NAT (SNAT) of outbound traffic. Option D is wrong because modifying the existing central SNAT policy to use a dynamic IP pool would apply that pool to all traffic matching the policy, not just the specific subnet, failing to achieve the requirement of using a different IP pool for that subnet.

568
MCQhard

A FortiGate in an HA active-passive cluster is experiencing frequent failovers. The administrator checks the HA statistics and sees that the primary unit's heartbeat interface has a high error rate. What is the most likely cause?

A.The heartbeat cable is faulty or the interface has a duplex mismatch
B.The heartbeat interface is configured as a single link without redundancy
C.The failover threshold is set too low
D.The HA configuration has mismatched passwords
AnswerA

A faulty heartbeat cable or duplex mismatch causes physical-layer errors (CRC, late collisions, high error counts) on the dedicated HA link. Because the FortiGate continuously sends heartbeat packets to verify the peer's liveness, any corruption or drop of those packets is interpreted as a lost heartbeat. This repeated loss of consistency checks makes the cluster flap—each missed heartbeat triggers failover, then the link recovers and the cluster rejoins, causing frequent, disruptive failovers.

Why this answer

A high error rate on the heartbeat interface indicates physical-layer issues such as a faulty cable or duplex mismatch. In an HA active-passive cluster, the heartbeat link must be reliable and low-latency; errors cause packet loss, leading the primary unit to appear unresponsive and triggering a failover to the secondary unit.

Exam trap

The trap here is that candidates often attribute frequent failovers to configuration mismatches (like passwords) or threshold settings, overlooking the physical-layer cause indicated by the high error rate on the heartbeat interface.

How to eliminate wrong answers

Option B is wrong because while a single heartbeat link without redundancy increases risk, it does not directly cause a high error rate on the interface; the error rate is a physical-layer symptom. Option C is wrong because a low failover threshold would cause failovers based on monitored metrics (e.g., link status or ping response), not a high error rate on the heartbeat interface itself. Option D is wrong because mismatched HA passwords prevent the cluster from forming or synchronizing, but they do not cause interface-level errors; the heartbeat link would still show no errors if the cable and duplex settings are correct.

569
MCQhard

A company has two remote sites connected via an SD-WAN overlay. The headquarters uses a FortiGate with two WAN links: Fiber (priority 1) and LTE (priority 2). The SD-WAN rule for business-critical traffic uses the 'best quality' strategy with SLA targets for latency and jitter. The fiber link occasionally experiences high jitter but low latency. The engineer notices that traffic is not failing over to LTE even when jitter exceeds the threshold. What is the most likely reason?

A.The performance SLA for jitter is not configured, only latency.
B.The SD-WAN rule has SLA match set to 'either' instead of 'all'.
C.The LTE link has a higher cost and is not considered for failover.
D.The fiber link has a higher interface weight.
AnswerA

The 'best quality' strategy only fails over when the configured SLA performance criteria are breached. If the performance SLA monitors latency alone, high jitter never triggers a member failure, so traffic stays on the fiber link despite exceeding the jitter threshold.

Why this answer

The SD-WAN rule uses the 'best quality' strategy, which selects the best link based on configured SLA metrics. If only latency is configured in the performance SLA, jitter exceeding the threshold will not trigger a failover, as the SLA only evaluates the configured metrics. The fiber link may still meet the latency SLA, so traffic remains on it despite high jitter.

Exam trap

The trap here is that candidates assume jitter is automatically monitored in SD-WAN SLA, but FortiGate requires explicit configuration of each metric (latency, jitter, packet loss) in the performance SLA; otherwise, unconfigured metrics are ignored for failover decisions.

How to eliminate wrong answers

Option B is wrong because the 'either' vs 'all' setting in SLA match determines whether any or all configured SLA targets must be met for the link to be considered compliant; it does not prevent failover when jitter exceeds the threshold if jitter is not configured. Option C is wrong because SD-WAN failover decisions are based on SLA compliance and strategy, not link cost; cost influences route selection in routing protocols but not SD-WAN rule failover. Option D is wrong because interface weight affects load-balancing ratios in strategies like 'lowest cost' or 'maximize bandwidth', not failover decisions in 'best quality' strategy.

570
MCQmedium

A company has a FortiGate with multiple VDOMs. An admin creates a firewall policy in the root VDOM to allow traffic from a subnet to the internet. The traffic is not matching the policy. What is the most likely cause?

A.The traffic is in a different VDOM than the policy
B.The internet-facing interface is not part of any VDOM
C.The subnet object is defined in the wrong address group
D.The policy is placed at the bottom of the list
AnswerA

Each VDOM on a FortiGate operates as an independent virtual firewall with its own routing table, policy set, and interface associations. A firewall policy configured in the root VDOM only examines traffic whose ingress and egress interfaces belong to that same VDOM. If the traffic flows through interfaces assigned to VDOM2, the root policy is never evaluated, so the traffic is instead subject to VDOM2's own policy list, and the mismatch explains why the policy has no effect.

Why this answer

In a multi-VDOM FortiGate, each VDOM operates as an independent virtual firewall with its own routing table, policies, and interfaces. A firewall policy created in the root VDOM only applies to traffic that enters and exits interfaces assigned to that root VDOM. If the traffic originates from or is destined to an interface belonging to a different VDOM, it will never match the root VDOM policy, causing the traffic to be dropped or handled by the correct VDOM's policies.

Exam trap

The trap here is that candidates assume a policy in the root VDOM applies to all traffic by default, not realizing that VDOMs create strict administrative boundaries where policies are only effective within their own VDOM.

How to eliminate wrong answers

Option B is wrong because an internet-facing interface must be assigned to a VDOM to function; unassigned interfaces are not operational and cannot pass traffic. Option C is wrong because even if the subnet object is in the wrong address group, the policy would still match if the source IP falls within the defined subnet range; the issue is VDOM isolation, not address group membership. Option D is wrong because policy order only matters within the same VDOM; a policy at the bottom of the list in the root VDOM would still match traffic that belongs to the root VDOM, but it cannot match traffic from a different VDOM regardless of its position.

571
MCQhard

You run the following CLI command on a FortiGate: 'diagnose vpn ike config list'. The output includes: 'src 10.0.1.0/24:0 dst 192.168.1.0/24:0'. What does this indicate?

A.The firewall policy is allowing traffic from 10.0.1.0/24 to 192.168.1.0/24
B.The Phase 2 configuration is using 10.0.1.0/24 as local subnet and 192.168.1.0/24 as remote subnet
C.The Phase 1 configuration is using 10.0.1.0/24 as local address
D.The tunnel is in dial-up mode with dynamic remote subnet
AnswerB

This statement correctly interprets the diagnostic output: the phase 2 configuration defines the traffic selectors, specifying which local and remote subnets are allowed to communicate through the VPN. In the output, the local quick mode selector is 10.0.1.0/24 and the remote selector is 192.168.1.0/24, meaning that traffic between these subnets will be encrypted. This is a standard site-to-site VPN setup with explicit proxy IDs.

Why this answer

The 'diagnose vpn ike config list' command displays the Phase 2 configuration for an IPsec VPN tunnel. The output 'src 10.0.1.0/24:0 dst 192.168.1.0/24:0' directly indicates the local and remote subnets defined in the Phase 2 selector, where 'src' is the local subnet and 'dst' is the remote subnet. This confirms that the Phase 2 configuration is using 10.0.1.0/24 as the local subnet and 192.168.1.0/24 as the remote subnet.

Exam trap

The trap here is confusing the 'src' and 'dst' fields in the IKE diagnostic output with firewall policy source/destination, leading candidates to incorrectly select Option A instead of recognizing it as Phase 2 subnet selectors.

How to eliminate wrong answers

Option A is wrong because the 'diagnose vpn ike config list' command shows IKE Phase 2 selectors, not firewall policies; firewall policies are verified with 'diagnose firewall policy list' or 'show firewall policy'. Option C is wrong because Phase 1 configuration uses local and remote IP addresses (not subnets) and is displayed with 'diagnose vpn ike config list' showing 'local' and 'remote' fields, not 'src' and 'dst'. Option D is wrong because the output shows specific subnet masks (/24) for both source and destination, indicating a static, non-dial-up configuration; dial-up mode would show '0.0.0.0/0' for the remote subnet.

572
MCQhard

A FortiGate administrator is troubleshooting a problem where users cannot access the Internet. The FortiGate has a default route pointing to the ISP gateway. The administrator runs 'execute ping 8.8.8.8' from the FortiGate CLI and it succeeds. However, internal users behind NAT are unable to reach external servers. Which is the most likely cause?

A.The default route is incorrectly configured
B.An implicit deny policy is blocking traffic from internal to external
C.No NAT policy is configured for internal users
D.External access profile is set to read-only
AnswerC

If no NAT policy is configured for internal users' traffic, the FortiGate forwards packets with the original private source IP addresses (e.g., 10.0.0.0/8). The external server sends reply packets to that private address, which is not routable across the public internet, causing return traffic to be dropped or blackholed. The FortiGate's own ping works because it uses its interface's public IP as the source, so replies are routable. This mismatch—successful ping from the FortiGate but failures for internal users—is a classic symptom of missing source NAT.

Why this answer

The administrator confirmed that the FortiGate itself can reach the Internet (ping 8.8.8.8 succeeds), so the default route and basic connectivity are working. However, internal users behind NAT cannot reach external servers, which indicates that traffic from internal users is either not being translated or is being blocked. The most likely cause is that no NAT policy (or firewall policy with NAT enabled) exists to perform source NAT for internal users, so their private IP addresses are not translated to the FortiGate's public IP, and the ISP gateway drops the packets because private addresses are not routable on the Internet.

Exam trap

The trap here is that candidates assume a successful ping from the FortiGate CLI proves end-to-end connectivity for all users, but they overlook that NAT translation is required for internal private IPs to reach the Internet.

How to eliminate wrong answers

Option A is wrong because the default route is correctly configured — the 'execute ping 8.8.8.8' succeeded, proving the route works. Option B is wrong because an implicit deny policy would block all traffic, including the ping from the FortiGate itself; since the ping succeeded, there is no implicit deny blocking outbound traffic. Option D is wrong because the external access profile is a GUI/administrative access setting that controls read/write permissions for the web interface, not a factor in NAT or traffic forwarding.

573
MCQeasy

An administrator wants to view real-time debug output for traffic flowing through a FortiGate. Which command should they use to enable flow tracing with a specific source IP filter?

A.diagnose debug enable
B.diagnose debug flow filter src
C.diagnose sys session filter src
D.diagnose sniffer packet filter src
AnswerB

The 'diagnose debug flow filter src' command sets a source IP address filter that restricts the real-time flow debugging output to traffic originating from that specific host. This is the correct first step when you want to trace a particular user's or device's session flow through the FortiGate, because it prevents the console from being flooded with all traffic and makes the output meaningful. After setting this source filter, you must also run 'diagnose debug flow show console enable' and then 'diagnose debug enable' to see the live flow trace messages on the CLI.

Why this answer

The command 'diagnose debug flow filter src <IP>' sets a filter to capture debug flow output for a specific source IP. This is the correct first step to enable flow tracing with a source IP filter. After setting the filter, the administrator would run 'diagnose debug enable' to start the debug output.

The filter command itself is necessary to narrow down the traffic.

Exam trap

The trap is confusing session filters with debug flow filters; candidates might choose 'diagnose sys session filter src' thinking it filters debug output, but it only filters the session table.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug enable' only enables debug output but does not set a filter; without a filter, the output would be overwhelming. Option C is wrong because 'diagnose sys session filter src' filters the session table, not debug flow output. Option D is wrong because 'diagnose sniffer packet filter src' is not a valid command; the sniffer uses different syntax and is for packet capture, not debug flow.

574
MCQeasy

An administrator is configuring a FortiGate to use LDAP for firewall authentication. Users are prompted for their credentials when accessing the internet. After successful authentication, users can access the internet. However, the administrator notices that users are prompted again after 30 minutes of inactivity. Which setting should the administrator adjust to extend the authentication timeout?

A.Increase the 'idle-timeout' in the firewall policy.
B.Modify the 'auth-timeout' in the user settings.
C.Adjust the 'session-ttl' in the firewall policy.
D.Change the 'ldap-timeout' in the LDAP server configuration.
AnswerB

The 'auth-timeout' setting under 'config system global' or per-user group controls how long a user's authentication is valid. By default, it is 30 minutes. Increasing this value will extend the time before users are prompted to re-authenticate. This is the correct setting to adjust for extending the authentication period.

Why this answer

The authentication timeout on a FortiGate is controlled by the 'auth-timeout' setting, which can be configured globally or per user group. This setting determines how long a user remains authenticated after providing credentials. The default is 30 minutes.

To extend this period, the administrator should increase the 'auth-timeout' value. Other timeouts, such as idle-timeout or session-ttl, affect session behavior but not the authentication duration.

Exam trap

The trap here is confusing session timeouts with authentication timeouts, but the re-prompting after 30 minutes is specifically governed by the authentication timeout setting.

575
MCQhard

An administrator is troubleshooting a slow web application. The admin suspects that the FortiGate's session table might be full, causing new sessions to be dropped. Which command should the admin use to check the current session table utilization?

A.get system performance status
B.diagnose sys session list
C.diagnose sys session stat
D.diagnose sys session filter
AnswerC

The 'diagnose sys session stat' command is the correct choice because it directly reports session table statistics, including the current number of sessions, the configured maximum, and the utilization percentage. These metrics allow the administrator to quickly determine whether the FortiGate is approaching its session limit, which can cause new connection failures and slow performance for web applications. This command is purpose-built for assessing session-table pressure and is the most efficient way to diagnose session exhaustion.

Why this answer

The command 'diagnose sys session stat' provides a summary of session table statistics, including the current session count, maximum session count, and utilization percentage. This directly answers whether the session table is full. It is the correct command to quickly assess session table utilization without listing every session.

Exam trap

NSE4 often tests the difference between commands that list sessions versus those that provide summary statistics, causing candidates to choose 'diagnose sys session list' when a quick utilization check is needed.

How to eliminate wrong answers

Option A is wrong because 'get system performance status' displays overall system performance metrics like CPU, memory, and network usage, not session table utilization. Option B is wrong because 'diagnose sys session list' lists all current sessions, which is verbose and does not provide a summary of utilization; it is useful for detailed inspection but not for quick utilization check. Option D is wrong because 'diagnose sys session filter' is used to set filters for session listing, not to display statistics.

576
MCQeasy

A FortiGate admin wants to authenticate VPN users against an existing Microsoft Active Directory. Which authentication method should be configured on the FortiGate?

A.LDAP
B.RADIUS
C.FSSO
D.TACACS+
AnswerA

LDAP is the standard directory access protocol used by Active Directory for querying and binding user credentials. When a FortiGate authenticates VPN users against an LDAP server, it performs an LDAP bind with the user's username and password to verify the credentials directly against the directory. Optionally, it can also retrieve group memberships to enforce access policies, making LDAP the most native and efficient method for integrating with AD.

Why this answer

(LDAP) is correct because Microsoft Active Directory natively supports LDAP (Lightweight Directory Access Protocol) for authentication and directory lookups. FortiGate can directly bind to AD using LDAP to verify VPN user credentials against the AD database without requiring an additional RADIUS server or agent. This method is efficient for direct user authentication in a Windows domain environment.

Exam trap

The trap here is that candidates often confuse FSSO (which is for transparent network access) with direct authentication, or assume RADIUS is always required for AD integration, when LDAP is the simpler and correct method for direct user authentication in VPN scenarios.

How to eliminate wrong answers

Option B (RADIUS) is wrong because RADIUS is a client-server protocol that requires a separate RADIUS server (e.g., NPS on Windows) to proxy authentication to Active Directory; it adds unnecessary complexity when direct LDAP is available. Option C (FSSO) is wrong because FSSO (Fortinet Single Sign-On) is designed for transparent authentication of users on the network based on domain logon events, not for direct VPN user authentication against AD. Option D (TACACS+) is wrong because TACACS+ is a Cisco-proprietary protocol primarily used for device administration (e.g., router/switch login) and is not designed for VPN user authentication against Active Directory.

577
MCQmedium

A FortiGate administrator wants to ensure that all DNS queries to known malware domains are blocked. The firewall policy allows DNS traffic. Which security profile must be applied?

A.Web filter profile
B.DNS filter profile
C.Antivirus profile
D.Application control profile
AnswerB

A DNS filter profile is the correct control because it specifically inspects DNS queries and applies FortiGuard threat intelligence to block malicious, botnet, or phishing domains at the resolution stage. It can also enforce safe search and sinkhole domains, preventing clients from reaching known bad destinations even if they use custom DNS servers. By operating at the DNS layer, it protects all protocols and applications that rely on name resolution, providing comprehensive, early defense.

Why this answer

To block DNS queries to known malware domains, the FortiGate must apply a DNS filter profile to the firewall policy that allows DNS traffic. The DNS filter profile uses FortiGuard's DNS threat database to block or redirect queries to malicious domains, botnets, and phishing sites. This is the purpose-built profile for DNS-layer protection.

Exam trap

The trap is choosing web filter because it also deals with 'domains' — but web filter inspects HTTP URLs, while DNS filter inspects the DNS query itself, which is the correct layer for blocking malware domain lookups.

How to eliminate wrong answers

Option A is wrong because a web filter profile inspects HTTP/HTTPS URL categories, not raw DNS queries — it cannot block a DNS lookup to a malware domain. Option C is wrong because an antivirus profile scans file content for malware signatures, not DNS query destinations. Option D is wrong because application control identifies and controls applications by protocol/behavior, not by DNS domain reputation.

578
MCQeasy

A FortiGate administrator is setting up a new FortiGate in a network that requires the firewall to bridge traffic between two subnets without routing. Which operating mode should the administrator select?

A.Transparent mode
B.NAT/Route mode
C.HA mode
D.VLAN mode
AnswerA

In Transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding Ethernet frames between interfaces based on MAC addresses, much like a wire or switch. It performs no routing or NAT, so existing IP addressing and subnetting remain unchanged, and the device is effectively invisible to the network. This is the correct answer because transparent mode is specifically designed for inline deployment without modifying the Layer 3 topology.

Why this answer

Transparent mode allows the FortiGate to act as a Layer 2 bridge, forwarding traffic between two subnets without performing any routing or NAT. In this mode, the firewall operates like a 'bump in the wire,' inspecting and filtering traffic based on MAC addresses and Layer 2 headers, while the IP addresses of connected devices remain unchanged. This is ideal for scenarios where the FortiGate must be inserted into an existing network without altering the IP topology.

Exam trap

The trap here is that candidates often confuse transparent mode with VLAN mode, thinking VLANs are a separate operating mode, or they assume NAT/Route mode can bridge traffic by disabling NAT, but it still performs routing at Layer 3.

How to eliminate wrong answers

Option B (NAT/Route mode) is wrong because it operates at Layer 3, performing routing and NAT, which changes the IP topology and is not suitable for bridging traffic without routing. Option C (HA mode) is wrong because it is a high-availability configuration for redundancy, not an operating mode for traffic forwarding; it can be used in either transparent or NAT/Route mode. Option D (VLAN mode) is wrong because it is not a standard operating mode on FortiGate; VLANs are configured as interfaces within transparent or NAT/Route mode, not as a separate mode.

579
MCQeasy

Which of the following statements about firewall policy ordering in FortiGate is correct?

A.Policies are evaluated from bottom to top
B.The most specific policy always takes precedence regardless of order
C.Policies are evaluated from top to bottom, and the first match is applied
D.The implicit permit rule at the end allows all traffic not explicitly denied
AnswerC

This is the core behavior of FortiGate's firewall policy engine: policies are read from top to bottom, and the first policy whose all matching criteria (source, destination, service, etc.) match the traffic is applied. Once a match is found, the remaining policies are not evaluated. You control this order by arranging policies, and it is typically visualized as a numbered list in both GUI and CLI.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom in the policy list. The first policy that matches the source, destination, service, and other criteria is applied, and no further policies are evaluated. This is the fundamental 'first-match' behavior that governs traffic processing in FortiGate.

Exam trap

The trap here is that candidates often confuse FortiGate's top-down first-match logic with other firewall platforms that use bottom-up evaluation or automatic specificity-based precedence, leading them to select option A or B.

How to eliminate wrong answers

Option A is wrong because FortiGate evaluates policies from top to bottom, not bottom to top; bottom-to-top evaluation is a common misconception from other firewall platforms. Option B is wrong because FortiGate does not automatically prioritize the most specific policy; order in the policy list determines precedence, and a more specific policy placed lower will never be reached if a less specific policy above matches first. Option D is wrong because the implicit deny rule at the end of the policy list silently drops all traffic that does not match any explicit policy; there is no implicit permit rule in FortiGate.

580
Multi-Selectmedium

A network administrator wants to ensure that all users are blocked from accessing websites categorized as 'Pornography' and 'Hacking' on a FortiGate. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Create a URL filter to block all URLs containing 'pornography' and 'hacking'
B.Enable DNS filter and block the categories there
C.Apply the web filter profile to the firewall policy that governs outbound internet traffic
D.Enable SSL deep inspection to ensure the categories can be identified
E.Create a web filter profile and set the categories 'Pornography' and 'Hacking' to 'block'
AnswersC, E

Applying the web filter profile to the firewall policy that governs outbound internet traffic ensures that HTTP/HTTPS requests from internal users are inspected against the configured URL categories before the traffic is allowed to pass. This satisfies the stem’s constraint that all users must be blocked from accessing 'Pornography' and 'Hacking' sites, as the profile is enforced at the point where traffic exits the internal network to the internet.

Why this answer

A web filter profile must be applied to a firewall policy to enforce web filtering on outbound internet traffic. Without this association, the profile's settings (including category blocks) are not activated. The firewall policy is the enforcement point where security profiles are linked to traffic flows.

Exam trap

The trap here is that candidates often confuse URL filtering (pattern-based) with web filter category blocking (category-based), or assume SSL deep inspection is mandatory for category-based blocking when it is not required for domain-level categorization.

581
MCQmedium

A FortiGate administrator is configuring an SSL VPN web mode portal. The administrator wants users to access only a specific internal web application (https://internal-app.company.local) and nothing else. Which SSL VPN setting should be configured to achieve this?

A.In the SSL VPN portal, set the default bookmark to the application URL
B.Configure a firewall policy that allows traffic only to the application's IP address
C.Enable split tunneling under the SSL VPN settings
D.Under the SSL VPN portal, configure 'URL Access' to allow only https://internal-app.company.local
AnswerD

The URL Access feature under the SSL VPN portal provides a per-portal whitelist of web addresses that users are allowed to access through the reverse proxy. When you specify only https://internal-app.company.local, the FortiGate enforces that rule during proxy processing: any request to a URL that does not match the whitelist is denied with an error. This precisely meets the requirement because it is a proxy-level, application-aware access control, rather than a network-layer rule or a UI shortcut. It effectively prevents users from browsing to any other internal or external web host through the portal while allowing the specific internal application.

Why this answer

The 'URL Access' setting in the SSL VPN web mode portal allows the administrator to explicitly define which URLs users can access through the portal. By configuring an allow list with only https://internal-app.company.local, users are restricted to that specific internal web application, and all other URLs are blocked. This provides granular control over web-based resources in the SSL VPN portal without relying on network-layer restrictions.

Exam trap

The trap here is that candidates often confuse network-layer controls (firewall policies or split tunneling) with application-layer controls (URL Access), assuming that blocking traffic at the IP/port level is sufficient to restrict web-based access within an SSL VPN portal.

How to eliminate wrong answers

Option A is wrong because setting a default bookmark only pre-populates the user's portal with a link to the application; it does not restrict access to other URLs, so users could still navigate to other internal or external sites via the portal. Option B is wrong because a firewall policy controls traffic at the network layer (IP/port), not the application-layer URL access within the SSL VPN web mode portal; users could still access other web applications on the same IP or port if not explicitly blocked at the URL level. Option C is wrong because split tunneling controls whether client traffic goes through the VPN tunnel or directly to the internet for tunnel-mode VPNs, not for web mode portals; it does not restrict which URLs users can access within the portal.

582
Multi-Selectmedium

An administrator is troubleshooting an IPsec VPN that is not passing traffic. The Phase 1 and Phase 2 are both up. Which TWO CLI commands can be used to verify the VPN tunnel status and traffic flow? (Choose two.)

Select 2 answers
A.diagnose vpn tunnel list
B.execute ping-options source
C.diagnose vpn ike config
D.diagnose netlink interface list
E.diagnose sys session list
AnswersA, E

diagnose vpn tunnel list is the primary command for checking the live operational state of IPsec tunnels, showing phase 1 and phase 2 status, SPI values, and negotiation successes or failures. It clearly indicates whether the tunnel is established or down, making it the first step when a VPN connection is not working.

Why this answer

'diagnose vpn tunnel list' displays the status of all IPsec VPN tunnels, including Phase 1 and Phase 2 security associations (SAs), their uptime, and the number of packets transmitted and received. This allows the administrator to verify that the tunnel is established and to check for any packet drops or errors that might indicate a traffic flow issue.

Exam trap

The trap here is that candidates assume 'diagnose vpn ike config' (Option C) shows tunnel status because it relates to IKE, but it only displays static configuration, not the dynamic operational state or traffic counters.

583
MCQmedium

A FortiGate administrator needs to ensure that all outbound DNS queries from internal clients are inspected for malicious domains. The administrator has a DNS filter profile configured. What additional configuration is required on the firewall policy to make the DNS filter effective?

A.Enable SSL deep inspection on the policy
B.Configure FortiGuard DNS filtering service on the FortiGate
C.Set the inspection mode to proxy-based
D.Apply the DNS filter profile to a firewall policy that matches DNS traffic (UDP/TCP port 53)
AnswerD

A DNS filter profile only inspects traffic when attached to a firewall policy whose destination matches DNS. Applying it to a policy matching UDP and TCP port 53 forces internal client queries through the profile, enabling malicious domain blocking.

Why this answer

A DNS filter profile must be explicitly applied to a firewall policy that matches DNS traffic (UDP/TCP port 53) to be effective. Without this association, the FortiGate will not inspect DNS queries against the configured DNS filter profile, even if the profile is defined globally or under Security Profiles.

Exam trap

The trap here is that candidates often assume configuring a DNS filter profile globally or under Security Profiles is sufficient, but FortiGate requires explicit policy attachment for the profile to take effect on traffic.

How to eliminate wrong answers

Option A is wrong because SSL deep inspection is not required for DNS filtering; DNS traffic is typically unencrypted, and enabling SSL inspection would add unnecessary overhead without improving DNS inspection. Option B is wrong because configuring the FortiGuard DNS filtering service is part of the DNS filter profile setup, not an additional configuration on the firewall policy; the policy itself needs the profile applied. Option C is wrong because while proxy-based inspection can support DNS filtering, flow-based inspection also supports DNS filtering in FortiOS 6.0 and later; the inspection mode is not a prerequisite for applying a DNS filter profile to a policy.

584
MCQeasy

What is the purpose of configuring an aggregate interface on a FortiGate?

A.To enable VLAN tagging on a physical interface
B.To combine multiple physical interfaces into one logical interface for increased throughput and redundancy
C.To separate management traffic from data traffic
D.To connect two different network segments with a firewall in between
AnswerB

An aggregate interface (also called a link aggregation group or LACP bundle) combines multiple physical interfaces into one logical interface to increase total throughput and provide link redundancy. It leverages link aggregation protocols like 802.3ad or static configuration to treat several physical members as a single logical link, with traffic load-balanced across members and automatic failover if a member link goes down. This is the foundational definition of link aggregation, making this the correct answer.

Why this answer

An aggregate interface (also known as a Link Aggregation Group or LAG) combines multiple physical FortiGate interfaces into a single logical interface. This increases throughput by load-balancing traffic across the member links and provides redundancy: if one physical link fails, traffic continues over the remaining links. FortiGate supports both static aggregation and LACP (IEEE 802.3ad) for dynamic negotiation.

Exam trap

The trap here is that candidates confuse link aggregation with VLAN trunking or interface redundancy protocols like VRRP, but aggregate interfaces specifically combine bandwidth and provide link-level redundancy, not IP-level failover or VLAN separation.

How to eliminate wrong answers

Option A is wrong because VLAN tagging is configured on a physical or aggregate interface via subinterfaces, not by creating an aggregate interface itself. Option C is wrong because separating management traffic from data traffic is achieved through dedicated management interfaces, administrative access controls, or VDOMs, not by link aggregation. Option D is wrong because connecting two different network segments with a firewall in between describes the fundamental role of a firewall (routing/security), not the purpose of an aggregate interface.

585
Multi-Selecthard

An admin needs to configure a FortiGate to allow multiple internal servers to be accessible from the internet using the same public IP but different ports. For example, internal server A (192.168.1.10:80) should be reachable via 203.0.113.10:8080, and internal server B (192.168.1.20:443) via 203.0.113.10:8443. Which TWO configuration steps are required?

Select 2 answers
A.Create two separate VIPs, one for each server, and add them to a VIP group
B.Disable NAT on the policy to preserve the source IP
C.Configure a firewall policy with destination set to the VIP group and action set to allow
D.Configure Central SNAT to translate the source IP
E.Create a single VIP with port forwarding that maps multiple ports
AnswersA, C

A VIP group aggregates multiple Virtual IP (VIP) objects into a single destination address object. Each VIP in the group has its own external-to-internal IP/port mapping, so when the group is used as a policy destination, the FortiGate checks the inbound packet against each VIP member, performs the matching DNAT, and forwards to the correct internal server. This design is the only way to expose two different internal servers through distinct public IPs/ports under one logical policy.

Why this answer

Each internal server requires a unique Virtual IP (VIP) to map a specific external port to a specific internal IP and port. Adding these VIPs to a VIP group allows a single firewall policy to reference all of them, enabling the FortiGate to differentiate traffic based on the destination port and forward it to the correct internal server.

Exam trap

The trap here is that candidates often think a single VIP with multiple port mappings can handle different internal servers, but FortiGate VIPs are one-to-one mappings; a VIP group is required to aggregate multiple VIPs under one policy.

586
MCQeasy

Which IPS detection method analyzes traffic patterns over time to identify attacks that are characterized by a threshold of events?

A.Protocol decoder-based detection
B.Rate-based detection
C.Signature-based detection
D.Anomaly-based detection
AnswerB

Rate-based detection continuously samples traffic and compares event frequency against a configured threshold within a time window, flagging anomalies when the count is exceeded. This directly satisfies the stem's requirement for analysing patterns over time to catch threshold-characterised attacks, unlike signature or anomaly methods.

Why this answer

Rate-based detection (also known as threshold-based detection) monitors traffic patterns over a defined time window and triggers an alert when the number of events (e.g., connection attempts, SYN packets) exceeds a predefined threshold. This method is specifically designed to identify attacks that are characterized by a threshold of events, such as DoS/DDoS floods or brute-force login attempts, rather than relying on static signatures or protocol anomalies.

Exam trap

Fortinet often tests the distinction between rate-based and anomaly-based detection, and the trap here is that candidates confuse 'threshold of events' with 'anomaly detection,' but anomaly detection uses baselines and statistical deviations, not fixed thresholds, while rate-based detection explicitly uses a predefined event count over time.

How to eliminate wrong answers

Option A is wrong because protocol decoder-based detection analyzes traffic by validating protocol fields and state transitions (e.g., checking if an HTTP request conforms to RFC 7230), not by counting events over time. Option C is wrong because signature-based detection matches traffic against predefined patterns (e.g., a specific byte sequence in a packet payload) and does not use temporal thresholds or event counts. Option D is wrong because anomaly-based detection establishes a baseline of normal behavior and flags deviations (e.g., sudden spike in DNS queries), but it does not rely on a fixed threshold of events; instead, it uses statistical models or machine learning to detect outliers.

587
MCQeasy

What is the primary function of Fortinet Single Sign-On (FSSO) in a FortiGate deployment?

A.To provide two-factor authentication using FortiToken
B.To sync FortiGate configuration with Active Directory
C.To authenticate users against a RADIUS server
D.To collect user login events from Active Directory for user-based policies
AnswerD

FSSO's primary function is to automatically identify users based on their existing Active Directory login events and map those events to the source IP address of the client machine. A collector agent on the network monitors domain controller security logs or uses RPC calls to track successful user logons, then sends this mapping to the FortiGate. This enables the firewall to enforce user-based policies without prompting for credentials, because the user has already been authenticated by AD. The wrong answers describe other security features, but this is the exact mechanism FSSO provides.

Why this answer

Fortinet Single Sign-On (FSSO) is designed to collect user login events from Active Directory (AD) domain controllers. It monitors authentication traffic (e.g., via NetAPI or polling the AD security event log) to map IP addresses to usernames, enabling FortiGate to enforce user-based firewall policies without requiring users to manually authenticate to the firewall.

Exam trap

The trap here is that candidates often confuse FSSO with direct authentication methods (like RADIUS or LDAP) and assume it performs user authentication, when in fact it only collects existing authentication events from Active Directory for policy enforcement.

How to eliminate wrong answers

Option A is wrong because FSSO does not provide two-factor authentication; that is the function of FortiToken, which integrates with FortiGate for 2FA. Option B is wrong because FSSO does not sync FortiGate configuration with Active Directory; configuration synchronization is handled by FortiManager or ADOMs, not FSSO. Option C is wrong because FSSO does not authenticate users against a RADIUS server; RADIUS authentication is a separate method where the FortiGate acts as a RADIUS client, whereas FSSO passively collects AD login events.

588
MCQmedium

An admin configures two static routes to the same destination with different distances. The route with distance 10 points to ISP1, and the route with distance 20 points to ISP2. The admin wants to use ISP2 only if ISP1 fails. What is the expected behavior?

A.Traffic will load-balance between ISP1 and ISP2
B.Traffic will use ISP1 until its route is removed, then use ISP2
C.The route with distance 20 will be ignored entirely
D.Both routes will be active simultaneously, and the FortiGate will choose based on source IP
AnswerB

The lower administrative distance (10) on the ISP1 route makes it the most preferred static route, so it is installed as the active route in the routing table and all matching traffic uses ISP1. As long as that route exists and is reachable, the distance-20 ISP2 route stays inactive. If the ISP1 route is removed—for example, because the interface goes down or the route is administratively deleted—the FortiGate reevaluates the RIB and promotes the ISP2 route, shifting traffic to ISP2.

Why this answer

When two static routes have different administrative distances, the route with the lower distance (10) is preferred and installed in the routing table. The route with distance 20 remains in the routing table as a backup. If the preferred route (via ISP1) is removed due to a failure, the backup route (via ISP2) is automatically activated.

This behavior is fundamental to how FortiGate (and most routers) handle static routes with unequal distances.

Exam trap

The trap here is that candidates often think both routes are active and load-balancing occurs, but FortiGate only uses the route with the lowest administrative distance unless equal-cost load balancing is explicitly configured.

How to eliminate wrong answers

Option A is wrong because load-balancing requires equal-cost routes (same distance), but here distances are different (10 vs 20), so only the best route is used. Option C is wrong because the route with distance 20 is not ignored; it remains in the routing table as a backup and will be used if the primary route is removed. Option D is wrong because both routes are not active simultaneously; only the route with the lowest distance is active, and source IP is not a factor in static route selection.

589
MCQmedium

A remote user connects via SSL VPN web mode but cannot access internal resources. The SSL VPN portal is configured with the default settings. What is the most likely reason?

A.The user must be authenticated via LDAP
B.The user has not installed the FortiClient VPN plugin
C.Web mode only allows access to specific bookmarks configured in the portal
D.The SSL VPN policy is missing a security profile
AnswerC

In SSL VPN web mode, the user's entire accessible domain is restricted to the bookmarks that the administrator has explicitly defined in the user's assigned portal. Without pre-configured bookmarks to internal URLs, the portal displays no resources, and the user cannot navigate to any internal application. This is exactly the symptom described: a remote user can connect and authenticate, but there are no portal bookmarks, so no access is granted.

Why this answer

In SSL VPN web mode, the FortiGate acts as a proxy, granting access only to pre-configured bookmarks (URLs or applications) defined in the SSL VPN portal. Default portal settings do not include any bookmarks, so even after successful authentication, the user sees an empty portal and cannot reach internal resources. This is by design, as web mode does not provide full network-layer access like tunnel mode does.

Exam trap

The trap here is that candidates often assume SSL VPN always provides full network access or that a missing security profile is the cause, but the NSE4 exam specifically tests the distinction between web mode (bookmark-based) and tunnel mode (full access).

How to eliminate wrong answers

Option A is wrong because authentication via LDAP is not a requirement for SSL VPN web mode; the user can be authenticated using any supported method (local, RADIUS, etc.) and the portal will still function. Option B is wrong because FortiClient VPN plugin is only required for tunnel mode (full network access) or for host-check features; web mode operates entirely through the browser without any client software. Option D is wrong because security profiles (AV, web filter, IPS) are applied to firewall policies, not directly to SSL VPN policies; the SSL VPN policy itself does not require a security profile to allow web-mode access.

590
Multi-Selecthard

A FortiGate is configured with FSSO and Active Directory polling. Users report that they are frequently prompted for authentication even though they are logged into the domain. Which THREE possible causes should the administrator investigate?

Select 3 answers
A.The user's IP address has changed and the FortiGate still has a stale mapping
B.The FortiToken server is overloaded
C.The user's workstation is not sending logon events to the domain controller
D.The captive portal is enabled on the policy
E.The FortiGate is not polling the domain controllers correctly
AnswersA, C, E

In FSSO, the FortiGate associates a username with the source IP address of the workstation at the moment of logon. If the DHCP lease renews or the user moves to a different subnet, the IP changes without a corresponding logoff/logon event, so the FortiGate retains the stale mapping. Traffic from the new IP is therefore not matched to the user's FSSO group policy, causing the user to be treated as unauthenticated.

Why this answer

FSSO with Active Directory polling relies on the FortiGate maintaining a mapping between a user's domain logon and their IP address. If the user's IP address changes (e.g., due to DHCP lease renewal or moving to a different subnet) and the FortiGate still holds the old mapping, the firewall will not recognize the user as authenticated, prompting re-authentication. This is a common issue in dynamic IP environments where the FortiGate's polling interval may not immediately detect the change.

Exam trap

The trap here is that candidates often confuse FSSO polling with captive portal or FortiToken, assuming any authentication prompt must involve those technologies, when in fact the issue is a stale IP-to-user mapping caused by DHCP changes or delayed DC polling.

591
MCQhard

Refer to the exhibit. An administrator wants to enable SNMP access on the wan1 interface. Which of the following is the most efficient method?

A.Execute 'config system interface' and edit wan1, then set allowaccess ping https ssh snmp.
B.Change the interface type to 'management' to allow SNMP.
C.Execute 'config system interface' and edit wan1, then set snmp-index 1.
D.Configure an SNMP community under 'config system snmp community'.
AnswerA

The FortiGate CLI command 'config system interface' followed by 'edit wan1' and 'set allowaccess ping https ssh snmp' explicitly appends snmp to the interface's list of permitted management access services. This is the mandatory per-interface gate: even after defining an SNMP community globally, the FortiGate will only respond to SNMP requests on interfaces whose allowaccess includes snmp. Adding snmp to wan1 therefore enables SNMP agents to serve queries and traps on that interface while preserving existing ping, https, and ssh management access.

Why this answer

The 'allowaccess' parameter under 'config system interface' controls which management protocols (ping, https, ssh, snmp, etc.) are permitted on a given interface. By adding 'snmp' to the allowaccess list for wan1, the administrator enables SNMP access on that interface without changing its role or type.

Exam trap

The trap here is that candidates often confuse configuring an SNMP community (which defines who can query) with enabling SNMP access on an interface (which allows the SNMP agent to listen on that interface); both are required, but the question asks for the most efficient method to enable SNMP access on wan1, which is setting 'allowaccess snmp' on that interface.

How to eliminate wrong answers

Option B is wrong because changing the interface type to 'management' is not required; the 'management' type is used for dedicated management interfaces (e.g., FortiGate models with a separate MGMT port) and does not apply to a standard data interface like wan1. Option C is wrong because 'snmp-index' is used to assign an OID index for SNMP monitoring of the interface, not to enable SNMP access on the interface. Option D is wrong because configuring an SNMP community defines the community strings and hosts allowed to query the FortiGate, but it does not enable SNMP access on a specific interface; the interface-level 'allowaccess' must still be set.

592
MCQhard

Refer to the exhibit. The FortiGate has two default routes. The administrator attempts to ping 8.8.8.8 from the CLI and receives no response. What is the most likely reason?

A.The second route is overwriting the first route
B.Both routes are equal-cost and load-balancing is not working
C.The configuration is invalid because duplicate default routes are not allowed
D.The gateway 203.0.113.1 (port1) is unreachable
AnswerD

The route via 203.0.113.1 on port1 has an administrative distance of 10, making it the preferred route for all traffic. If that next-hop gateway becomes unreachable—for instance, port1 goes down, the connected network fails, or ARP resolution for 203.0.113.1 fails—the active route is removed or becomes unusable. FortiGate will not immediately fail over to the distance-20 route unless the primary route is completely removed; in many scenarios, traffic is dropped because the lower-distance route is still considered valid in the RIB but cannot forward packets. Thus, unreachability of the primary gateway directly explains the total loss of connectivity.

Why this answer

When a FortiGate has multiple default routes, it uses the route with the lowest distance (administrative distance) as the primary route. If the gateway for the primary route (203.0.113.1 on port1) is unreachable, the FortiGate will not be able to reach 8.8.8.8, even if a secondary default route exists. The ping fails because the device cannot ARP for the gateway or the next-hop is down, causing the route to be inactive.

Exam trap

The trap here is that candidates often assume both default routes are active and load-balanced, but FortiGate uses administrative distance to select a single active route, and if the gateway of that route is unreachable, the route becomes invalid and no traffic is forwarded until the next route is considered.

How to eliminate wrong answers

Option A is wrong because a second default route does not 'overwrite' the first; FortiGate supports multiple default routes and selects the best one based on distance or priority, not by overwriting. Option B is wrong because both routes are not equal-cost (they have different distances, 10 and 20), so load-balancing is not applicable; FortiGate uses the route with the lowest distance. Option C is wrong because duplicate default routes are allowed in FortiGate; they are valid as long as they have different distances or priorities, providing redundancy.

593
MCQhard

An administrator configures a dial-up IPsec VPN with IKEv2 to allow remote users to connect. The Phase 1 is set to use certificate-based authentication (PKI). Users can establish Phase 1, but Phase 2 fails with 'no proposal chosen'. The administrator checks the Phase 2 proposal: AES256-SHA256, and the remote network is 10.0.0.0/8 (the corporate LAN). What is the MOST likely cause?

A.The remote network in Phase 2 is set to 10.0.0.0/8
B.The remote network in Phase 2 is set to 0.0.0.0/0
C.The Phase 1 encryption algorithm is mismatched
D.The authentication type requires EAP instead of certificate
AnswerA

The remote network in Phase 2 should be 0.0.0.0/0 for dial-up, because the client's real IP is dynamic. Setting it to 10.0.0.0/8 means the FortiGate expects the client's IP to be in that range, which it is not.

Why this answer

The most likely cause is that the remote network (client subnet) in the Phase 2 configuration on the VPN gateway is set to 10.0.0.0/8 instead of the correct value (0.0.0.0/0) for dial-up clients. Since Phase 1 succeeds, authentication and encryption settings are correct. The 'no proposal chosen' error in Phase 2 indicates a traffic selector mismatch: the server expects the client's IP to be within the 10.0.0.0/8 range, but the client's actual IP typically falls outside that subnet.

Therefore, the Phase 2 negotiation fails.

Exam trap

The trap is that candidates often attribute Phase 2 failures to algorithm mismatches, but in IKEv2 dial-up VPNs, 'no proposal chosen' commonly results from an incorrect Phase 2 traffic selector. Specifically, the remote network (client subnet) on the server side must be set to 0.0.0.0/0 for dial-up clients, not the corporate LAN subnet.

How to eliminate wrong answers

Option B is wrong because setting the remote network to 0.0.0.0/0 would create a default route for all traffic, which is not the specific corporate LAN subnet and would still cause a Phase 2 mismatch if the gateway expects 10.0.0.0/8. Option C is wrong because Phase 1 is already established successfully, indicating that the encryption algorithms (including certificate-based authentication) are correctly matched; a Phase 1 mismatch would prevent Phase 1 from completing. Option D is wrong because certificate-based authentication (PKI) is explicitly configured and Phase 1 succeeds, so EAP is not required; EAP is typically used for extended authentication, not for basic IKEv2 Phase 1 with certificates.

594
MCQmedium

A FortiGate HA cluster is operating in active-passive mode. The active unit fails over to the passive unit. After the failover, some existing TCP sessions are dropped. What is the MOST likely cause?

A.The HA heartbeat interface has a high latency
B.The failover time is too slow, causing TCP timeouts
C.Session synchronization is not enabled or not working properly
D.The TCP sessions are using NAT, which cannot be synchronized
AnswerC

In active-passive HA, the standby unit does not have the active unit's session table unless session pickup (session synchronization) is enabled and functioning. When a failover occurs, the newly active unit has no knowledge of the established TCP connections, so it cannot forward packets for those flows and they must be re-established. If session sync is enabled but not working, the same result occurs, so the correct fix is to verify that the session pickup feature is properly configured and that heartbeat interface is carrying the synchronization updates.

Why this answer

In an active-passive FortiGate HA cluster, the passive unit only maintains existing TCP sessions if session synchronization (session-pickup) is enabled and functioning. When the active unit fails, the passive unit becomes active and must have the session state to continue forwarding packets for established connections. If session synchronization is not enabled or is broken (e.g., due to a misconfigured sync interface or high latency), the new active unit has no knowledge of existing sessions and drops them, forcing clients to re-establish connections.

Thus, the most likely cause is that session synchronization is not enabled or not working properly.

Exam trap

NSE4 often tests the misconception that NAT prevents session synchronization or that failover speed alone determines session continuity, when in fact session synchronization must be explicitly enabled and operational for existing sessions to survive a failover.

How to eliminate wrong answers

Option A is wrong because high latency on the HA heartbeat interface typically causes heartbeat timeouts and unnecessary failovers, but it does not directly cause existing TCP sessions to be dropped after a failover; session synchronization is the key factor. Option B is wrong because failover time being too slow would cause TCP timeouts only if the failover exceeds the TCP retransmission timeout, but FortiGate HA failover is usually fast (sub-second to a few seconds), and the question implies the failover occurred; the more direct cause is lack of session sync. Option D is wrong because NAT sessions can be synchronized in FortiGate HA; NAT does not prevent session synchronization, and claiming it cannot be synchronized is a misconception.

595
MCQmedium

An administrator wants to prevent employees from uploading sensitive credit card numbers via web forms. Which security profile feature is MOST appropriate to achieve this?

A.Antivirus with FortiSandbox integration
B.Data Leak Prevention (DLP) with a credit card number sensor
C.Web Filter to block all upload sites
D.Application Control to block web forms
AnswerB

Data Leak Prevention (DLP) with a credit card number sensor is correct because DLP examines the actual content of traffic and matches it against predefined sensors, such as the credit card number sensor, which uses pattern matching and Luhn algorithm validation to identify PCI-DSS regulated data. When the sensor triggers, the DLP policy can block the upload session in real time, preventing the sensitive information from leaving the network.

Why this answer

Data Leak Prevention (DLP) with a credit card number sensor is the most appropriate feature because it uses pattern matching (e.g., Luhn algorithm) to detect and block sensitive credit card numbers in HTTP POST requests, preventing data exfiltration via web forms. Unlike other security profiles, DLP is specifically designed to inspect content for sensitive data patterns and enforce policy actions such as blocking or logging.

Exam trap

The trap here is that candidates often confuse DLP with other security profiles like web filtering or application control, mistakenly thinking that blocking upload sites or web forms is a more direct solution, when DLP is the only feature designed for content-based data inspection and policy enforcement.

How to eliminate wrong answers

Option A is wrong because Antivirus with FortiSandbox integration focuses on detecting malware and analyzing suspicious files, not on identifying sensitive data patterns like credit card numbers in web form submissions. Option C is wrong because Web Filter to block all upload sites would prevent all file uploads, which is overly restrictive and does not address the specific need to detect and block credit card numbers within web forms. Option D is wrong because Application Control to block web forms would prevent all web form submissions entirely, disrupting legitimate business processes, rather than selectively scanning for sensitive data.

596
MCQeasy

Which of the following FortiGate operating modes allows the firewall to act as a Layer 3 device, performing NAT and routing between interfaces?

A.Flow-based inspection mode
B.NAT/Route mode
C.VLAN mode
D.Transparent mode
AnswerB

NAT/Route mode is the default operating mode for FortiGate, where each interface is assigned an IP address and the device performs Layer 3 routing between networks. It also enables network address translation (NAT), allowing traffic to be translated between different address domains. This mode is distinctly different from Transparent mode, which operates at Layer 2 without routing or NAT. Because the question asks about an operating mode that supports routing and NAT, NAT/Route mode is the correct answer.

Why this answer

NAT/Route mode (option B) is correct because it configures the FortiGate as a Layer 3 device with distinct interfaces in different subnets, enabling it to perform routing (forwarding packets based on routing table entries) and Network Address Translation (NAT) to translate private IP addresses to public IP addresses. This mode is the default and most common operational mode for perimeter firewalls, allowing policy-based routing and NAT rules to be applied between zones.

Exam trap

The trap here is confusing operational modes (NAT/Route vs. Transparent) with inspection modes (Flow-based vs. Proxy-based), leading candidates to incorrectly select Flow-based inspection mode as the answer for Layer 3 routing and NAT capabilities.

How to eliminate wrong answers

Option A is wrong because Flow-based inspection mode is a processing mode (not an operational mode) that inspects packets in a single pass using pattern matching and heuristics, but it does not define the firewall's Layer 3 routing or NAT capabilities. Option C is wrong because VLAN mode is not a standard FortiGate operational mode; VLANs are configured as sub-interfaces within NAT/Route or Transparent modes to segment traffic, but they do not independently enable Layer 3 routing or NAT. Option D is wrong because Transparent mode operates as a Layer 2 bridge (similar to a switch) without IP addresses on its interfaces, meaning it cannot perform NAT or routing between interfaces—it forwards traffic based on MAC addresses.

597
MCQeasy

An administrator needs to ensure that IPS signatures are updated automatically on the FortiGate. Which configuration should be verified?

A.The IPS engine is upgraded to the latest version.
B.The intrusion prevention profile is applied to the firewall policy.
C.The application control profile is set to 'monitor' for all applications.
D.The FortiGuard service is enabled and the signature update schedule is configured.
AnswerD

To automatically maintain up-to-date IPS signatures, the FortiGate must have the FortiGuard service enabled, which requires a valid subscription contract and network access to the FortiGuard distribution servers. Additionally, an administrator must configure a signature update schedule (e.g., daily or every 2 hours) so the device periodically downloads and installs the latest IPS signature package from FortiGuard. This combination directly ensures the signature database is refreshed without manual intervention, fulfilling the administrator's requirement.

Why this answer

Automatic IPS signature updates require the FortiGuard service to be enabled and a signature update schedule to be configured. Without a schedule, updates occur only manually; without the service enabled, the FortiGate cannot connect to FortiGuard distribution servers to retrieve new signatures.

Exam trap

The trap here is confusing IPS signature updates with IPS engine updates or profile application, leading candidates to select options that affect detection or inspection rather than the update mechanism itself.

How to eliminate wrong answers

Option A is wrong because upgrading the IPS engine version improves detection capabilities but does not enable automatic signature updates; signature updates and engine updates are separate processes. Option B is wrong because applying an intrusion prevention profile to a firewall policy enables IPS inspection on traffic but does not control how signatures are updated. Option C is wrong because setting the application control profile to 'monitor' for all applications configures application visibility, not IPS signature updates.

598
MCQeasy

An administrator is configuring a VLAN interface on a FortiGate. The physical interface is port2 and the VLAN ID is 100. Which of the following correctly creates the VLAN interface?

A.config system interface edit port2.100 set vlanid 100 set type vlan next end
B.config system interface edit port2 set vlanid 100 next end
C.config system interface edit port2.100 set type vlan next end
D.config system vlan edit port2.100 set vlanid 100 next end
AnswerA

The correct CLI creates a VLAN subinterface by editing port2.100 under config system interface. The name uses the dot notation to associate the subinterface with physical port2; set vlanid 100 tags traffic with 802.1Q VLAN 100, while set type vlan marks the interface as a VLAN interface. This sequence fully defines the logical interface and is the only valid way to add a VLAN on a FortiGate.

Why this answer

It uses the correct CLI syntax to create a VLAN subinterface on a FortiGate. The command `config system interface` enters the interface configuration context, `edit port2.100` creates or edits the subinterface named with the physical interface and VLAN ID, `set vlanid 100` assigns the VLAN tag, and `set type vlan` explicitly defines the interface type as VLAN. This matches the required configuration for 802.1Q VLAN tagging on FortiGate.

Exam trap

The trap here is that candidates often confuse the FortiGate CLI with Cisco IOS, where `interface port2.100` automatically implies a VLAN subinterface without needing an explicit `set type vlan` or `set vlanid` command, leading them to choose Option C or D.

How to eliminate wrong answers

Option B is wrong because it attempts to set the VLAN ID directly on the physical interface `port2` instead of creating a separate VLAN subinterface; FortiGate does not allow a VLAN ID on a physical interface. Option C is wrong because it creates the subinterface `port2.100` and sets the type to VLAN but omits the `set vlanid 100` command, which is mandatory to specify the 802.1Q tag. Option D is wrong because it uses the invalid command `config system vlan`; FortiGate does not have a `system vlan` configuration context—VLAN interfaces are always configured under `config system interface`.

599
Drag & Dropmedium

Drag and drop the steps to configure a static route on a FortiGate firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static routes on FortiGate are configured in the router static configuration context, requiring a sequence number, destination, device, and gateway.

600
MCQeasy

A FortiGate admin wants to ensure that traffic destined to a specific web server is inspected by an IPS profile. Which configuration is necessary?

A.Enable IPS on the firewall policy directly
B.Set the policy's action to 'IPS'
C.Create a security profile group containing the IPS profile and apply it to the policy
D.Configure a VIP for the web server
AnswerC

The correct approach is to create a security profile group that contains the IPS sensor and then apply that group to the firewall policy governing traffic to the web server. This groups the IPS sensor with other inspection profiles, enabling layered UTM inspection on accepted traffic. When the policy action is ACCEPT and the profile group is attached, all matching sessions are inspected by the IPS engine against its configured signatures and rules.

Why this answer

In FortiGate, IPS inspection is applied via a security profile group that includes the IPS profile, which is then attached to a firewall policy. The firewall policy itself does not have a direct 'enable IPS' toggle; instead, IPS profiles are part of the security profiles that must be explicitly assigned to the policy to inspect traffic.

Exam trap

The trap here is that candidates may think IPS can be enabled directly on the policy or that a special policy action exists for IPS, but FortiGate requires IPS to be applied as a security profile, not as a policy attribute.

How to eliminate wrong answers

Option A is wrong because FortiGate does not allow enabling IPS directly on the firewall policy; IPS is a security profile that must be applied through a security profile group or individually. Option B is wrong because setting the policy's action to 'IPS' is not a valid configuration; the policy action is either 'ACCEPT' or 'DENY', and IPS inspection is configured separately via security profiles. Option D is wrong because configuring a Virtual IP (VIP) is used for destination NAT and port forwarding, not for applying IPS inspection to traffic.

Page 7

Page 8 of 11

Page 9

All pages