Courseiva

Fortinet NSE 4 Network Security Professional NSE4 (NSE4) — Questions 601–675

773 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
Multi-Selecthard

An administrator is configuring an IPS profile on FortiGate to detect and block SQL injection attacks. The profile must be applied to inbound traffic to a web server. Which TWO settings should the administrator enable to achieve this goal? (Choose two.)

Select 2 answers
A.Add the 'SQL.Injection' signature to the IPS sensor and set action to 'block'.
B.Create a DoS policy to limit the number of connections per second.
C.Enable the HTTP protocol decoder in the application control profile.
D.Configure the IPS sensor to bypass traffic from trusted IP addresses.
E.Enable the IPS sensor in the firewall policy.
AnswersA, E

The 'SQL.Injection' signature is the specific pattern-matching rule that flags SQL injection attempts in HTTP payloads. Adding it to the IPS sensor and configuring the action as 'block' ensures FortiGate drops any matching traffic. Without this explicit inclusion, the signature must be part of a filter or default set; otherwise, the attack is not detected. This is the core action for IPS-based threat prevention.

Why this answer

SQL injection attacks are identified by specific IPS signatures, and adding 'SQL.Injection' to an IPS sensor with the action set to 'block' directly instructs FortiGate to detect and block those attacks. Option E is correct because an IPS sensor must be enabled within a firewall policy to apply its inspection to the traffic passing through that policy, ensuring the profile is active on inbound traffic to the web server.

Exam trap

The trap here is that candidates often confuse DoS policies (rate limiting) with IPS (signature-based detection), or mistakenly think application control profiles handle IPS signatures, when in fact IPS sensors are separate and must be explicitly enabled in a firewall policy.

602
MCQhard

During a security audit, the administrator runs the command 'diagnose firewall policy list' and sees the following output: policy id=1: allow from port1 to port2, src=10.0.0.0/8, dst=any, action=accept policy id=2: deny from port1 to port2, src=10.0.0.0/8, dst=172.16.0.0/12, action=deny policy id=3: allow from port1 to port2, src=any, dst=any, action=accept A host with IP 10.0.1.5 sends traffic to 172.16.0.1. Which policy will match?

A.Policy 3
B.Policy 1
C.Implicit deny
D.Policy 2
AnswerB

Policy 1 is correct because FortiGate uses a first-match model: it scans the policy list top-down and applies the first policy whose source, destination, and services match the packet. The source address in the traffic is within the 10.0.0.0/8 address range and the destination is any, so policy 1 matches all conditions for this session. Even though policy 2 may be more specific, it is placed after policy 1 and is therefore shadowed; the firewall never evaluates it for this traffic. Therefore policy 1's action (permit or deny) is what the audit should record.

Why this answer

Policy 1 matches first because FortiGate evaluates policies sequentially by ID. The source 10.0.1.5 is within 10.0.0.0/8 and the destination is any, so policy 1 matches and accepts the traffic. Although policy 2 would also match (172.16.0.1 is within 172.16.0.0/12), it is not evaluated because the first matching policy is applied.

Exam trap

The trap here is that candidates assume a deny rule with a more specific destination will override a broader allow rule, forgetting that FortiGate uses first-match logic based on policy ID order, not longest-prefix matching or specificity.

How to eliminate wrong answers

Option A is wrong because policy 3 is an 'allow any/any' catch-all, but it is evaluated after policy 1 and policy 2; since policy 1 matches first, policy 3 is never reached. Option C is wrong because the implicit deny only applies if no explicit policy matches; here policy 1 matches, so the traffic is accepted before any implicit deny is considered. Option D is wrong because policy 2's destination is 172.16.0.0/12, which includes 172.16.0.1, but policy 1 has a lower ID and matches first, so policy 2 is not evaluated for this traffic.

603
MCQeasy

Which FortiGuard subscription service is required for URL filtering and web categorization?

A.FortiGuard IPS
B.FortiGuard Application Control
C.FortiGuard Web Filtering
D.FortiGuard Antivirus
AnswerC

FortiGuard Web Filtering is the subscription service that provides comprehensive URL categorization and filtering, using a cloud-based database to classify websites into categories such as malware, Phishing, or gambling. This service enables FortiGate to enforce web access policies by comparing requested URLs against category and reputation data in real time. Without this subscription, URL filtering is unavailable, so it is the correct choice for this requirement.

Why this answer

FortiGuard Web Filtering provides URL categorization and filtering capabilities.

604
MCQmedium

An admin creates a firewall policy allowing HTTP traffic from internal users to the internet. Users complain that they cannot access HTTPS websites. The admin checks and sees that the policy only has HTTP service. What is the BEST course of action to allow HTTPS while maintaining security?

A.Create a new policy above the existing one with HTTPS service
B.Add the HTTPS service to the existing policy
C.Use a security policy that automatically adds HTTPS
D.Change the HTTP service to ALL services
AnswerB

Adding the HTTPS service object to the existing policy is the correct and most efficient approach. The policy already matches the desired source (internal users) and destination (internet) with a permit action for HTTP; extending the service list to include HTTPS (port 443/tcp) requires no change to the other match criteria or security profiles. This preserves least privilege by allowing only the specific web protocols intended, while avoiding policy duplication and administrative overhead. FortiGate security policies allow multiple service objects, so HTTP and HTTPS can coexist cleanly in the same rule.

Why this answer

Adding the HTTPS service (TCP/443) to the existing policy allows HTTPS traffic without creating a separate rule, which could introduce complexity or misordering issues. This approach maintains security by explicitly permitting only the required service rather than opening all traffic. FortiGate policies evaluate services as part of the match criteria, so modifying the existing policy is the most efficient and secure method.

Exam trap

The trap here is that candidates often think creating a new policy above the existing one is necessary for ordering, but FortiGate allows multiple services in a single policy, making modification the best practice for simplicity and security.

How to eliminate wrong answers

Option A is wrong because creating a new policy above the existing one could cause HTTPS traffic to match the new rule, but it introduces unnecessary policy bloat and potential misordering; however, the main issue is that it is less efficient than simply modifying the existing policy. Option C is wrong because FortiGate does not have a 'security policy that automatically adds HTTPS' — policies must be explicitly configured with the desired services. Option D is wrong because changing the service to ALL would permit all traffic (including unwanted protocols), violating the principle of least privilege and reducing security.

605
Multi-Selectmedium

An administrator wants to configure traffic shaping to limit bandwidth for YouTube video streaming. Which THREE objects or settings must be configured on the FortiGate to apply traffic shaping?

Select 3 answers
A.Traffic shaper (e.g., shared or per-IP shaper)
B.Application control profile to identify YouTube traffic
C.A DNS filter to block YouTube
D.A firewall policy that applies the traffic shaper and the application control profile
E.A static route for YouTube's IP range
AnswersA, B, D

A traffic shaper (shared or per-IP) is the concrete bandwidth-limiting mechanism. It defines maximum and/or guaranteed bandwidth rates in kilobits per second, and a per-IP shaper applies those limits independently to each client IP address, whereas a shared shaper aggregates all matching traffic under one bucket. This directly throttles throughput for the matched traffic, which is exactly what the administrator wants to accomplish for YouTube.

Why this answer

A traffic shaper (shared or per-IP) defines the bandwidth limits (e.g., maximum rate, guaranteed rate) that will be enforced on the traffic. This shaper must be created first to control YouTube streaming bandwidth.

Exam trap

The trap here is that candidates may think DNS filtering or static routes are needed for shaping, but FortiGate relies on application control for traffic identification and a firewall policy to bind the shaper, not on DNS or routing.

606
MCQmedium

A FortiGate administrator is configuring a hub-and-spoke IPsec VPN. The hub has multiple Phase 2 selectors for each spoke. What is the recommended way to simplify configuration on the hub when adding new spokes?

A.Use a single Phase 2 selector with 0.0.0.0/0.0.0.0 for both local and remote
B.Configure each spoke in a separate VDOM
C.Use aggressive mode for Phase 1
D.Use policy-based VPN instead of route-based
AnswerA

Setting both local and remote Phase 2 selectors to 0.0.0.0/0 creates an any-to-any proxy ID, so all traffic routed into the tunnel interface is encrypted without needing a separate selector per subnet or per spoke. In a route-based VPN, the tunnel interface decouples routing from IPsec proxy IDs, so a single Phase 2 definition can be reused across every spoke; new spokes simply reuse the same selector and rely on routing to direct traffic. This is the standard FortiGate recommendation for hub-and-spoke because it avoids negotiation failures caused by mismatched local/remote subnet definitions and eliminates per-spoke Phase 2 configuration at the hub.

Why this answer

Using a single Phase 2 selector with 0.0.0.0/0.0.0.0 for both local and remote simplifies hub configuration because it allows the hub to accept traffic for any subnet from any spoke without needing to define specific selectors per spoke. This is recommended in hub-and-spoke topologies to avoid manual updates when adding new spokes, as the hub's Phase 2 configuration becomes generic and automatically matches all spoke traffic.

Exam trap

The trap here is that candidates often think policy-based VPNs are simpler for hub-and-spoke, but they actually require explicit selector pairs per spoke, making the hub configuration more complex and less scalable.

How to eliminate wrong answers

Option B is wrong because configuring each spoke in a separate VDOM adds unnecessary administrative overhead and complexity, and does not simplify the Phase 2 selector configuration on the hub. Option C is wrong because aggressive mode for Phase 1 is less secure than main mode (it sends identities in plaintext) and is not related to simplifying Phase 2 selectors; it is typically used for remote access with dynamic IPs, not hub-and-spoke simplification. Option D is wrong because policy-based VPNs require explicit firewall policies for each subnet pair, which actually increases configuration effort when adding new spokes, whereas route-based VPNs with a single Phase 2 selector are simpler for hub-and-spoke designs.

607
MCQeasy

A FortiGate is configured with two WAN interfaces (port1 and port2) connected to different ISPs. The administrator wants to load-balance outbound traffic across both links using equal-cost routes. Which routing configuration should be applied?

A.Configure policy routes to direct traffic based on source IP.
B.Enable BGP to dynamically learn routes from both ISPs.
C.Configure static routes with equal distance and enable ECMP.
D.Configure static routes with different distances (e.g., 10 and 20) to the same destination.
AnswerC

Static routes with equal administrative distance and priority to the same destination are installed as ECMP (Equal-Cost Multi-Path) routes, allowing the FortiGate to spread outbound traffic across both WAN interfaces simultaneously. The FortiGate supports several load-balancing algorithms for ECMP, such as source-IP-based, weight-based, or usage-based, enabling granular control while still using both links. This is the correct way to achieve dual-WAN load balancing with static routing, and it pairs well with link health monitors to remove dead links dynamically.

Why this answer

ECMP (Equal-Cost Multi-Path) routing allows a FortiGate to load-balance outbound traffic across multiple interfaces when static routes have the same distance (administrative distance) and destination. By configuring two static routes with equal distance (e.g., 10) to 0.0.0.0/0 via port1 and port2, the FortiGate automatically distributes sessions across both links using a hash-based algorithm (e.g., source-destination IP), achieving the desired load balancing without dynamic routing protocols.

Exam trap

The trap here is that candidates confuse 'different distances' (which creates failover) with 'equal distances' (which enables load balancing), often selecting option D because they think varying metrics distributes traffic, but in reality, only equal administrative distances trigger ECMP load sharing.

How to eliminate wrong answers

Option A is wrong because policy routes are used for policy-based routing (PBR) based on criteria like source IP, not for simple load balancing across equal-cost links; they override the routing table and do not inherently provide ECMP load sharing. Option B is wrong because BGP is a dynamic routing protocol that can learn routes from ISPs, but it requires ISP cooperation and is unnecessary for simple outbound load balancing; ECMP with static routes is simpler and sufficient. Option D is wrong because configuring static routes with different distances (e.g., 10 and 20) creates a primary/backup (failover) scenario, not load balancing; the route with the lower distance is always preferred, and traffic never uses the higher-distance route unless the primary fails.

608
MCQmedium

A network administrator notices that users can access websites categorized as 'Pornography' despite a web filter profile blocking that category. The firewall policy uses the web filter profile and is applied to the users' traffic. What is the MOST likely cause?

A.The FortiGate cannot reach the FortiGuard servers
B.The web filter profile is applied to the wrong policy
C.The users are bypassing the FortiGate using a proxy
D.The web filter profile has the 'Override' feature enabled
AnswerA

When the FortiGate cannot reach the FortiGuard servers, web filtering cannot obtain real-time URL category ratings. In FortiOS, unrated or unknown URLs are treated as 'unrated' by default, and the default action for unrated URLs is 'allow' (fail-open). This means every visited website becomes accessible regardless of the web filter profile's block rules, because the firewall has no data to classify the site. The administrator should verify FortiGuard connectivity via `diagnose webfilter fortiguard-status` and confirm that outbound HTTPS (TCP/443) to FortiGuard servers is not being blocked by an upstream firewall or NAT policy.

Why this answer

The most likely cause is that the FortiGate cannot reach the FortiGuard servers. Web filter profiles rely on FortiGuard's cloud-based URL categorization to block categories like 'Pornography'. If the FortiGate loses connectivity to the FortiGuard servers (e.g., due to firewall rules, DNS issues, or proxy settings), it cannot retrieve the category rating for requested URLs, and the default action (often 'allow' if not explicitly set to block) will permit the traffic.

Exam trap

The trap here is that candidates often assume the web filter profile is misapplied or that users are bypassing the firewall, but the real issue is typically a connectivity failure to FortiGuard servers, which causes the filter to default to allowing unrated or uncategorized sites.

How to eliminate wrong answers

Option B is wrong because if the web filter profile were applied to the wrong policy, users would not be subject to that profile at all, but the question states the policy is applied to the users' traffic, so the profile is in the correct policy. Option C is wrong because while users could bypass the FortiGate using a proxy, this would mean their traffic does not traverse the FortiGate, so the web filter profile would not be applied; however, the question implies the traffic is going through the FortiGate (the policy is applied), making this less likely than a FortiGuard connectivity issue. Option D is wrong because the 'Override' feature allows users to bypass blocked categories after authentication, but it does not cause the block to be ignored entirely; it requires explicit user action and is not enabled by default.

609
MCQhard

A large enterprise uses a FortiGate 600E in NAT mode to protect its internal network. The security team has implemented an Application Control profile that categorizes applications and allows only 'Business' and 'General-Interest' categories. They have also applied an IPS sensor with default settings and enabled SSL inspection for outbound traffic. Recently, the helpdesk has received reports that some users cannot access a critical cloud-based CRM application, while others can. The CRM uses HTTPS on port 443. The Application Control profile is applied to the firewall policy for outbound traffic. The IPS sensor is also applied. The FortiGate is not configured for load balancing. Which of the following is the most likely cause of the issue?

A.The IPS sensor is detecting and blocking the CRM traffic as an attack.
B.The CRM application is not categorized in the Application Control database.
C.The FortiGate is performing load balancing and some users are directed to a different path.
D.SSL inspection is blocking the CRM traffic due to certificate validation failure.
AnswerB

Application Control in FortiGate matches traffic against a constantly updated signature database, and each signature is associated with a category. If the CRM application uses a proprietary protocol or a less-common of a known service, it may remain 'Uncategorized,' and any security policy whose Application Control profile sets the uncategorized action to 'deny' will block that traffic. This blocking is policy-specific, so if some users have a policy that omits or allows uncategorized traffic while others have a policy that denies it, only the latter group will experience the outage. This aligns perfectly with the reported symptom of only some users being unable to reach the CRM.

Why this answer

The Application Control profile is configured to allow only 'Business' and 'General-Interest' categories. If the CRM application is not categorized in FortiGuard's Application Control database, or if it falls under a different category (e.g., 'Uncategorized' or 'Unknown'), the FortiGate will block the traffic by default. This explains why some users can access the CRM (if they are using a different path or the application is categorized differently) while others cannot, as the FortiGate enforces the profile based on the application signature match.

Exam trap

The trap here is that candidates often assume IPS or SSL inspection is the culprit for selective access issues, but the key clue is that the problem affects only some users, pointing to a categorization mismatch in Application Control rather than a global block.

How to eliminate wrong answers

Option A is wrong because the IPS sensor with default settings is unlikely to block legitimate CRM HTTPS traffic on port 443 unless it matches a known attack signature, and the issue is user-specific, not global. Option C is wrong because the FortiGate 600E is explicitly stated as not configured for load balancing, so this cannot be the cause. Option D is wrong because SSL inspection certificate validation failure would affect all users equally, not just some, and the issue is isolated to a specific application, not all HTTPS traffic.

610
MCQhard

A FortiGate is configured with multiple policies. The first policy allows traffic from 10.0.0.0/8 to any destination. The second policy denies traffic from 10.0.1.0/24 to any destination. What happens when a packet from 10.0.1.5 to 8.8.8.8 arrives?

A.The packet is denied by implicit deny
B.The packet is allowed by the first policy
C.The packet matches both policies and is allowed
D.The packet is denied by the second policy
AnswerB

The first policy's source address range of 10.0.0.0/8 encompasses the packet's source IP 10.0.1.5, and if the other matching criteria (destination, service, incoming/outgoing interface) also align, FortiGate applies that policy's allow action. Policy evaluation is sequential and stops at the first match, so the allow decision is executed immediately. This makes the first policy the definitive rule that governs this traffic, regardless of what later policies define.

Why this answer

FortiGate firewall policies are evaluated in sequential order from top to bottom. The first policy matches source 10.0.0.0/8, which includes 10.0.1.5, and allows the traffic to any destination. Since the packet matches this policy first, it is accepted and the second policy is never evaluated.

Therefore, the packet is allowed by the first policy.

Exam trap

The trap here is that candidates often assume FortiGate uses a longest-prefix match or that a more specific deny policy will override a broader allow policy, but FortiGate strictly follows first-match order, not prefix length.

How to eliminate wrong answers

Option A is wrong because the packet matches an explicit allow policy (the first policy) before any implicit deny rule can apply; implicit deny only triggers when no explicit policy matches. Option C is wrong because FortiGate uses first-match logic, not a longest-prefix or combined-match approach; once a packet matches the first policy, subsequent policies are not checked. Option D is wrong because the second policy is never reached; the packet is evaluated against the first policy, which matches and allows it, so the deny policy is ignored.

611
Multi-Selecthard

Which TWO of the following are best practices when configuring IPS on a FortiGate in a high-throughput environment?

Select 2 answers
A.Set all signatures to block action to maximize security.
B.Set the IPS severity filter to high and above only.
C.Disable all custom signatures to simplify management.
D.Enable only relevant signatures based on the network environment.
E.Use flow-based inspection for better performance.
AnswersD, E

Enabling only signatures that matter to your deployed OS, applications, and services is the central best practice because it dramatically reduces false positive noise and the performance overhead of matching irrelevant rules. FortiGate allows you to create IPS policies that reference specific rule sets, and you can also use the 'Network Inspection' view to quickly see which signatures match your actual traffic. This approach keeps detection fidelity high and aligns with the recommendation to never run a blanket signature set.

Why this answer

Enabling only relevant signatures based on the network environment reduces false positives and unnecessary processing overhead, ensuring that IPS resources are focused on threats that actually apply to the traffic traversing the FortiGate. Option E is correct because flow-based inspection uses a single-pass, pattern-matching engine that offers higher throughput and lower latency compared to proxy-based inspection, making it ideal for high-throughput environments.

Exam trap

The trap here is that candidates often assume 'maximum security' means enabling all signatures or using the strictest action, but the NSE4 exam emphasizes that effective IPS in high-throughput environments requires balancing security with performance by selectively enabling relevant signatures and using flow-based inspection.

612
MCQhard

You are troubleshooting an SSL VPN connection. The user can reach the SSL VPN portal but cannot ping or access any internal resources. The portal shows the user as authenticated. Which configuration is MOST likely missing?

A.There is no firewall policy allowing traffic from ssl.root to the internal network
B.Client certificate authentication is required but not provided
C.Split tunneling is disabled
D.The SSL VPN realm is not configured correctly
AnswerA

In Fortinet's SSL VPN design, the SSL VPN interface (typically ssl.root) is just a virtual interface; after authentication, the tunnel is up but traffic is still subject to normal firewall policy checks. Without a policy that matches source ssl.root and destination internal network with the appropriate action (accept), the FortiGate silently drops the packets. Thus users can authenticate and establish the tunnel, but cannot reach internal resources until an explicit policy is created, often with NAT and security profiles as needed.

Why this answer

The user can authenticate and reach the SSL VPN portal, which indicates that the SSL VPN tunnel itself is established and authentication is successful. However, the inability to ping or access internal resources despite being authenticated points to a missing firewall policy that explicitly permits traffic from the SSL VPN interface (ssl.root) to the internal network. Without this policy, the FortiGate will drop all traffic from the SSL VPN tunnel, even though the user is logged in.

Exam trap

The trap here is that candidates assume authentication success implies full network access, but FortiGate requires an explicit firewall policy for SSL VPN traffic, separate from the authentication and tunnel setup.

How to eliminate wrong answers

Option B is wrong because client certificate authentication is an additional security layer for the authentication phase; if it were required but not provided, the user would not be able to authenticate or reach the portal at all. Option C is wrong because split tunneling controls whether traffic for internal networks is sent through the VPN tunnel or directly to the internet; disabling split tunneling would actually force all traffic through the tunnel, which would not prevent access to internal resources once the tunnel is up. Option D is wrong because the SSL VPN realm configuration affects the portal page and authentication settings; if the realm were misconfigured, the user would likely not see the correct portal or would fail authentication, but the user is already authenticated and on the portal.

613
Multi-Selecteasy

Which TWO of the following are prerequisites for configuring a high availability (HA) cluster on FortiGate? (Choose two.)

Select 2 answers
A.An HA heartbeat interface must be a dedicated interface.
B.All interfaces must be configured with static IP addresses.
C.The FortiGate units must be running the same firmware version.
D.The configuration must be identical on both units.
E.The FortiGate units must be the same model.
AnswersC, E

Running the same firmware version is a strict prerequisite for FortiGate HA. Both units must have the exact same FortiOS build, including any minor patches or hotfixes, because differences in firmware can cause protocol incompatibilities and prevent successful HA synchronization. Even minor version discrepancies can break the HA heartbeat and failover behavior, so Fortinet requires matching firmware before enabling HA.

Why this answer

FortiGate HA requires all cluster members to run the same firmware version to ensure configuration compatibility and consistent behavior. Mismatched firmware can lead to synchronization failures or unpredictable failover events, as the HA heartbeat and session synchronization protocols depend on identical code bases.

Exam trap

The trap here is that candidates often assume identical configuration is required before forming the cluster, but FortiGate automatically synchronizes the primary's configuration to the secondary, making pre-existing identical configs unnecessary.

614
MCQmedium

A FortiGate has multiple WAN interfaces (port1, port2) connected to different ISPs. The administrator wants traffic from the internal network to use port1 for general internet access but use port2 for traffic to a specific cloud service (203.0.113.0/24). Which feature should be used to achieve this?

A.Create a VIP for the cloud service
B.Configure static routes with different distances
C.Use SD-WAN rules to load balance
D.Use policy-based routing (PBR) to route traffic based on destination
AnswerD

Policy-based routing (PBR) allows a FortiGate to match traffic using source and destination IP, port, protocol, or even application, and explicitly assign the outgoing interface and source address. This lets you send traffic destined to a specific cloud service through port1 or port2 regardless of the default routing table lookup. PBR is the correct way to implement a static, destination-based WAN selection for specific services.

Why this answer

Policy-based routing (PBR) allows you to override the default routing table based on criteria such as source/destination IP, protocol, or port. In this scenario, PBR can match traffic destined to 203.0.113.0/24 and force it out through port2, while all other internet traffic follows the default route via port1. This provides granular control without affecting the general routing behavior.

Exam trap

The trap here is that candidates often confuse SD-WAN load balancing with policy-based routing, assuming that SD-WAN rules can enforce a strict 'always use this interface for this destination' policy, when in fact SD-WAN is primarily for dynamic load balancing and failover, not for static, deterministic path selection based solely on destination.

How to eliminate wrong answers

Option A is wrong because a Virtual IP (VIP) is used for destination NAT (port forwarding) to map a public IP to an internal server, not to control outbound path selection. Option B is wrong because static routes with different distances influence the routing table based on administrative distance, but they cannot selectively route traffic based on destination subnet when both interfaces have a default route; they would simply prefer one default route over the other for all traffic. Option C is wrong because SD-WAN rules load-balance or failover traffic across multiple links based on performance metrics or volume, but they do not provide the deterministic, policy-based path selection required to send specific traffic to a specific interface while using another for general internet access.

615
MCQhard

After upgrading FortiGate firmware, the administrator notices that the 'config router static' command now shows a new keyword 'distance' instead of 'weight'. The upgrade also changed the ECMP load-balancing behavior. What was the likely change in the ECMP algorithm?

A.The ECMP algorithm changed from source-IP-based to weighted (hash-based)
B.The ECMP algorithm changed from weighted to source-dest-IP
C.The ECMP algorithm is now configurable via 'config system ecmp'
D.The ECMP algorithm changed from source-dest-IP to round-robin
AnswerB

The FortiOS upgrade replaced the legacy weighted ECMP algorithm with a hash-based algorithm that hashes both the source and destination IP addresses (source-dest-IP-based). Previously, the route's 'weight' value determined how much traffic each path carried; after the upgrade, that weight attribute is no longer used, and path selection for a session is deterministic based on the source and destination IP pair, ensuring session stickiness. The 'distance' setting still influences route selection but does not provide proportional load sharing; this is the default behavior in the upgraded FortiOS environment.

Why this answer

In FortiOS 6.4, the default ECMP method was weighted, using the 'weight' parameter in static routes. Starting with FortiOS 7.0, the 'weight' parameter was replaced by 'distance', and the default ECMP algorithm changed to source-IP-based hash (also referred to as source-dest-IP hash). This change enhances load balancing by distributing traffic based on source/destination IP addresses rather than priority weights.

Exam trap

The trap is that candidates may assume the change was from source-IP-based to weighted because the new keyword 'distance' seems like a weight metric. However, the actual change was from weighted to source-IP-based hash, as the 'weight' parameter was deprecated and replaced by 'distance' for administrative distance, not for load-balancing weight.

How to eliminate wrong answers

Option B is wrong because the change is from weighted to source-IP-based hashing, not from weighted to source-dest-IP; source-dest-IP is a separate hash algorithm that can be configured but is not the default after the upgrade. Option C is wrong because ECMP load-balancing is configured via 'config system settings' with the 'ecmp-algorithm' command, not via 'config system ecmp', which does not exist in FortiOS. Option D is wrong because the algorithm changed from weighted to source-IP-based hashing, not from source-dest-IP to round-robin; round-robin is not a supported ECMP algorithm in FortiOS.

616
MCQmedium

An administrator wants to use Fortinet Single Sign-On (FSSO) with Active Directory to transparently authenticate users. Which component is responsible for polling Active Directory for user logon events?

A.Active Directory Domain Controller
B.FortiGate directly with NTLM authentication
C.FortiAuthenticator
D.FSSO Collector Agent
AnswerD

The FSSO Collector Agent is the correct component because it is explicitly designed to poll the Active Directory security event logs for user logon and logoff events. It runs on a Windows server, uses WMI or NetAPI to query DCs, maintains an IP-to-user mapping table, and transmits that data to FortiGate over the FSSO protocol. This passive collection provides transparent SSO for users already authenticated to AD, without requiring re-authentication.

Why this answer

The FSSO Collector Agent is the component that polls Active Directory domain controllers for security event logs (specifically event ID 4624 for logon events). It then maps these events to user IP addresses and forwards the authentication information to the FortiGate, enabling transparent user identification without requiring client-side software.

Exam trap

The trap here is that candidates often confuse the FSSO Collector Agent with FortiAuthenticator, assuming FortiAuthenticator is always required for FSSO, when in fact the Collector Agent is the primary component for polling Active Directory in a standard FSSO deployment.

How to eliminate wrong answers

Option A is wrong because the Active Directory Domain Controller itself does not poll for logon events; it generates security logs but relies on an external agent (like the FSSO Collector Agent) to poll and process those logs. Option B is wrong because FortiGate directly with NTLM authentication is a separate method (NTLM-based FSSO) that uses browser challenges, not polling of Active Directory logs. Option C is wrong because FortiAuthenticator can act as an FSSO collector in some deployments, but the question specifically asks for the component responsible for polling Active Directory; in a standard FSSO setup, the Collector Agent (installed on a Windows server) performs this polling, while FortiAuthenticator is typically used for RADIUS or LDAP-based authentication, not direct polling of AD logon events.

617
MCQmedium

A network administrator configures an application control profile to block social media applications. Users can still access Facebook through a web browser. What is the MOST likely reason?

A.The application signatures are outdated
B.Application control is not enabled for HTTPS traffic without deep inspection
C.The firewall policy is in proxy-based mode
D.The application control profile is not applied to the correct policy
AnswerB

This is the root cause. Facebook uses HTTPS by default, and application control identifies applications by inspecting the content and patterns within the traffic flow. Without SSL/TLS deep inspection (also called SSL inspection or decryption), the FortiGate only sees the encrypted payload and cannot match the application signature against the actual application data. While it might see the SNI (Server Name Indication) field or the destination IP, that information can be misleading or blocked by TLS 1.3 encrypted SNI, so the firewall cannot confidently identify Facebook as the application. Therefore, enabling deep inspection in the firewall policy is mandatory for application control to work on HTTPS traffic.

Why this answer

Application control relies on deep inspection (SSL/TLS decryption) to identify applications within encrypted HTTPS traffic. Without deep inspection enabled, the FortiGate can only see the encrypted tunnel and cannot inspect the payload to determine that the traffic is Facebook, even if the application control profile is correctly applied. Option B is correct because HTTPS traffic must be decrypted via deep inspection for application control to function.

Exam trap

The trap here is that candidates assume application control works on all traffic by default, overlooking that HTTPS encryption hides application signatures and requires explicit deep inspection configuration.

How to eliminate wrong answers

Option A is wrong because outdated signatures would cause a broader failure to block social media, not a selective failure where Facebook works via HTTPS but might be blocked over HTTP; the issue is specifically with encrypted traffic. Option C is wrong because proxy-based mode is not required for application control; flow-based mode also supports application control and deep inspection, and the mode does not determine whether HTTPS traffic is decrypted. Option D is wrong because if the profile were not applied to the correct policy, no social media would be blocked at all, including HTTP access; the fact that users can access Facebook via browser suggests the profile is applied but cannot inspect encrypted traffic.

618
MCQeasy

An administrator wants to block the use of social media applications like Facebook and Twitter on the company network. Which security profile should be used?

A.DNS Filter profile
B.Web Filter profile
C.Application Control profile
D.IPS profile
AnswerC

Application Control is the correct mechanism because it inspects packet byte patterns, protocol behavior, and other traffic attributes against the FortiGuard application database to identify applications regardless of the URL, port, or destination domain. It enables a firewall policy to log, allow, or block specific apps such as Facebook or Twitter even when they are accessed through a web browser, a mobile client, or different domains. This provides the granular visibility needed to block social media application usage rather than merely filtering web pages.

Why this answer

The Application Control profile is designed to identify and block specific applications, including social media platforms like Facebook and Twitter, regardless of the port or protocol they use. Unlike web filtering, which relies on URL categorization, application control inspects traffic patterns and signatures to enforce granular policies on application usage.

Exam trap

The trap here is that candidates often confuse web filtering (URL-based) with application control (signature-based), assuming that blocking a URL category like 'Social Networking' will stop all social media traffic, but native apps and encrypted streams bypass URL filtering entirely.

How to eliminate wrong answers

Option A is wrong because a DNS Filter profile blocks or redirects traffic based on domain name queries, but social media apps may use hardcoded IP addresses or non-DNS methods, making DNS filtering insufficient. Option B is wrong because a Web Filter profile controls access based on URL categories (e.g., 'Social Networking'), but it cannot block traffic from native mobile apps or encrypted connections that bypass HTTP inspection. Option D is wrong because an IPS profile focuses on detecting and preventing network-based attacks and vulnerabilities, not on enforcing acceptable use policies for specific applications.

619
Multi-Selectmedium

A FortiGate administrator is configuring intrusion prevention (IPS) for a web server. The administrator wants to both block known exploits and detect anomalous traffic patterns. Which TWO features should be enabled? (Choose two.)

Select 2 answers
A.IPS signatures
B.Web filter
C.Antivirus
D.Anomaly detection
E.Application control
AnswersA, D

IPS signatures are the core of intrusion prevention: the FortiGate inspector compares each packet's payload and header fields against a database of known exploit patterns and CVE-based indicators. This allows the device to match, log, and drop malicious traffic in real time, flagging only packets that precisely match a recognized attack signature. It is the only option here that actively inspects for exploit content, so it directly addresses the administrator's goal of blocking intrusion attempts.

Why this answer

IPS signatures (A) are correct because they contain predefined patterns of known exploits, allowing the FortiGate to match and block malicious traffic against a web server. Anomaly detection (D) is correct because it establishes a baseline of normal traffic and alerts on deviations, enabling detection of zero-day or unusual patterns that signatures may miss.

Exam trap

The trap here is that candidates confuse 'anomaly detection' with 'application control' or 'web filter', thinking those features also detect unusual traffic patterns, but anomaly detection is a distinct IPS sub-feature for behavioral analysis.

620
MCQeasy

An administrator wants to authenticate VPN users against an external LDAP server. Which authentication method should be configured in the user group for the SSL VPN portal?

A.RADIUS
B.FSSO
C.Local
D.LDAP
AnswerD

LDAP authentication enables the FortiGate to validate VPN users by performing a direct bind to the LDAP server (such as Active Directory or OpenLDAP) using the user's distinguished name and password. The FortiGate can also retrieve group memberships during the authentication process, allowing LDAP-based groups to be used in firewall policies. This is the most straightforward and correct method when the authentication source is an LDAP server, as it avoids an extra RADIUS or other proxy layer.

Why this answer

To authenticate VPN users against an external LDAP server, the user group for the SSL VPN portal must be configured with the LDAP authentication method. This directs FortiGate to bind directly to the LDAP server (e.g., Active Directory or OpenLDAP) using the configured LDAP server object, performing a simple bind or SASL bind to verify user credentials. Other methods like RADIUS, FSSO, or Local would not leverage the LDAP server directly.

Exam trap

The trap here is that candidates often confuse 'LDAP' as a protocol with 'RADIUS' as a protocol, assuming both are interchangeable for external authentication, but FortiGate requires the LDAP method specifically when the authentication source is an LDAP directory server, not a RADIUS server.

How to eliminate wrong answers

Option A is wrong because RADIUS is a separate authentication protocol that uses a RADIUS server (e.g., FreeRADIUS or NPS) to proxy authentication, not a direct LDAP bind; it adds an intermediary and does not authenticate directly against LDAP. Option B is wrong because FSSO (Fortinet Single Sign-On) is used for transparent authentication based on Windows domain logon events, not for direct credential validation against an LDAP server for VPN access. Option C is wrong because Local authentication uses locally stored user accounts on the FortiGate, which bypasses any external LDAP server entirely.

621
Multi-Selectmedium

A FortiGate admin needs to block all traffic from the 'Guest' VLAN (192.168.100.0/24) to the internal network (10.0.0.0/8) except for DNS traffic (UDP 53) to the internal DNS server at 10.0.0.10. Which TWO firewall policy configuration elements are required to achieve this? (Choose two.)

Select 2 answers
A.An address group for the internal DNS server
B.A firewall policy with source 'Guest' VLAN, destination 'Internal network', service 'ALL', action 'deny'
C.A firewall policy with source 'Guest' VLAN, destination 'Internal DNS server', service 'DNS', action 'accept'
D.A traffic shaper to limit DNS traffic
E.A schedule object to apply the policies only during business hours
AnswersB, C

This is the key deny-all policy: setting source to the Guest VLAN, destination to the Internal network, service to ALL, and action to DENY creates a catch-all that blocks every non-explicitly-allowed guest-to-internal flow. In FortiOS, policies are evaluated top-down on a first-match basis, so this deny must be placed after the DNS accept policy (or a higher priority allow) if DNS is to remain permitted. Without this deny rule, any implicit or later allow policies could still let guest traffic reach internal resources.

Why this answer

A deny policy with source 'Guest' VLAN (192.168.100.0/24), destination 'Internal network' (10.0.0.0/8), and service 'ALL' will block all traffic from the Guest VLAN to the internal network. Option C is correct because an explicit accept policy for DNS (UDP 53) to the internal DNS server (10.0.0.10) must be placed before the deny policy, as FortiGate firewall policies are evaluated in order from top to bottom, and the first matching policy determines the action.

Exam trap

The trap here is that candidates often think an address group (Option A) is necessary for the DNS server, but a single address object works just as well, and the real key is the policy ordering between the explicit accept and the explicit deny.

622
Matchingmedium

Match each FortiGate routing concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manually configured path to a destination network

Link-state routing protocol for internal networks

Path-vector routing protocol for internet and WAN

Routes traffic based on source/destination or service

Load-balances traffic across multiple routes with same cost

Why these pairings

In FortiGate, static routing relies on manual configuration, while dynamic routing uses protocols like OSPF and BGP. Policy-based routing forwards based on packet characteristics, and ECMP load-balances over equal-cost paths. Common confusions involve swapping the definitions of static and dynamic routing, or confusing dynamic routing with policy-based routing.

623
MCQeasy

Which FortiGate feature allows the administrator to scan SMTP, IMAP, and POP3 traffic for spam and apply actions such as tagging or discarding?

A.Email filter profile
B.Application control profile
C.Antivirus profile
D.Web filter profile
AnswerA

The Email filter profile is the correct FortiGate feature for SMTP scanning. It performs protocol-aware inspection of SMTP, IMAP, and POP3 traffic, applying spam rules, IP reputation, header/content analysis, and optional greylisting to classify and block unsolicited messages. This is the only profile specifically designed to detect spam and phishing content inside email traffic, including SMTP relay conversations.

Why this answer

The Email Filter profile is the correct feature because it is specifically designed to scan SMTP, IMAP, and POP3 traffic for spam and phishing content. It allows administrators to apply actions such as tagging the subject line, discarding the email, or quarantining based on spam scores, blacklists, and heuristics.

Exam trap

The trap here is that candidates confuse the Email Filter profile with the Antivirus profile, thinking spam is a type of virus, but spam detection uses different heuristics and databases (e.g., FortiGuard Antispam) than antivirus signatures.

How to eliminate wrong answers

Option B (Application control profile) is wrong because it identifies and controls application traffic (e.g., Facebook, Skype) using signatures, not email content scanning for spam. Option C (Antivirus profile) is wrong because it scans for malware signatures in files and attachments, not for spam classification or tagging. Option D (Web filter profile) is wrong because it controls access to web URLs and categories, not email protocols like SMTP, IMAP, or POP3.

624
Multi-Selecthard

A FortiGate administrator is planning an upgrade from FortiOS 6.4 to 7.2. Which THREE steps should be performed before the upgrade? (Choose three.)

Select 3 answers
A.Verify hardware compatibility with the target firmware
B.Check the upgrade path and required intermediate versions
C.Back up the current configuration
D.Remove all firewall policies
E.Enable automatic firmware checks
AnswersA, B, C

Verify hardware compatibility by consulting Fortinet's Hardware Compatibility Guide before upgrading. Some FortiGate models have limited lifecycle support or hardware constraints such as insufficient memory or CPU architecture that prevent running newer FortiOS versions. Attempting an unsupported upgrade on such platforms can fail during installation or cause a device brick, so confirming model support is the first essential pre-flight check.

Why this answer

Verifying hardware compatibility with the target firmware is essential because FortiGate models have specific hardware limitations (e.g., CPU, RAM, storage) that may not support newer FortiOS versions. For example, older models like the FortiGate 100D cannot upgrade beyond FortiOS 6.0, and attempting to install 7.2 could result in a failed boot or bricked device. This step ensures the hardware meets the minimum requirements for the target firmware.

Exam trap

The trap here is that candidates may think removing firewall policies is necessary to avoid compatibility issues during the upgrade, but FortiOS automatically handles policy migration, and deleting them only adds unnecessary risk and downtime.

625
MCQhard

An administrator configures a web filter profile to block the URL category 'Pornography'. The profile is applied to a policy for the sales department. Users report they can still access some sites that should be blocked. The administrator verifies that the FortiGuard web filter service is licensed and the FortiGate has internet connectivity. What should the administrator check next?

A.Verify that the antivirus profile is not interfering with web filtering.
B.Ensure the web filter profile has 'FortiGuard category based filter' enabled and the action for 'Pornography' is set to 'Block'.
C.Check if the sales department policy is using NAT that might bypass the FortiGate.
D.Confirm that the FortiGate has a static route to the FortiGuard servers.
AnswerB

In FortiOS, a web filter profile must have the FortiGuard Category Based Filter toggle enabled, and the specific category (e.g., 'Pornography') must have its action explicitly set to 'Block'. Even if the category is listed, if the action is 'Monitor' or 'Allow', or if a URL exemption or override rule matches the request, the traffic will not be blocked. The policy must also reference this profile and be applied to the correct source/destination, but the most direct cause of a failure to block is an incorrect category action or profile configuration.

Why this answer

In FortiOS, a web filter profile only enforces FortiGuard category blocking if the 'FortiGuard category based filter' toggle is enabled within the profile and the specific category (e.g., Pornography) has its action set to 'Block'. If the toggle is off, or the category action is left at 'Allow' or 'Monitor', the profile will not block those sites even though the FortiGuard license is valid and connectivity is fine. This is the most common misconfiguration when categories appear to be ignored.

Exam trap

NSE4 often tests the assumption that a valid FortiGuard license alone enables category blocking — candidates overlook that the 'FortiGuard category based filter' toggle must be explicitly enabled and each category's action set to Block.

How to eliminate wrong answers

Option A is wrong because antivirus profiles operate on file inspection and do not override or bypass web filter category decisions — they are independent security profiles applied in the same policy. Option C is wrong because NAT is performed by the FortiGate itself; it cannot 'bypass' the FortiGate's own policy enforcement, and the policy is already matching the sales department traffic. Option D is wrong because the administrator already verified the FortiGate has internet connectivity and the FortiGuard service is licensed, which implies FortiGuard server reachability is functional.

626
Multi-Selectmedium

A network admin needs to configure a FortiGate to allow remote VPN users (IPsec VPN) to access a web server in the DMZ. The VPN users are assigned IPs from 10.10.10.0/24. The web server is at 192.168.2.10:80. Which TWO objects must be created to define the traffic for the firewall policy? (Choose two.)

Select 2 answers
A.A service object for HTTP (TCP/80)
B.An address object for the web server 192.168.2.10
C.An address object for the VPN user subnet 10.10.10.0/24
D.A user group object for VPN authentication
E.A schedule object for business hours
AnswersB, C

The web server address object is mandatory because it defines the destination of the traffic in the firewall policy. FortiGate requires both source and destination address objects in every IPv4 policy, and this object uniquely identifies 192.168.2.10 as the server. Without it, the policy cannot match traffic to the web server, so the rule cannot be correctly created.

Why this answer

The firewall policy must specify the destination address of the traffic, which is the web server at 192.168.2.10. Without an address object for this server, the policy cannot match the destination IP of the VPN users' HTTP requests.

Exam trap

The trap here is that candidates often think a service object must be created for HTTP, but FortiGate includes predefined services for common protocols like HTTP, making custom creation unnecessary unless the port is non-standard.

627
MCQmedium

A FortiGate administrator configures an SSL VPN web mode portal. Users can access internal web applications but cannot access internal file shares via SMB. What is the most likely reason?

A.The SSL VPN policy does not allow SMB traffic
B.The fileserver requires client certificates for authentication
C.The firewall policy for SSL VPN is configured with the wrong interface
D.Web mode does not support the SMB protocol; users must use tunnel mode to access fileshares
AnswerD

Web mode is a clientless browser-based reverse proxy that only supports HTTP, HTTPS, and certain web applications. The SMB protocol, which runs on TCP port 445 and requires native network layer connectivity, cannot be proxied by web mode. To access SMB fileshares, users must connect using SSL VPN tunnel mode, which creates a virtual interface on the client and routes SMB traffic through the FortiGate.

Why this answer

SSL VPN web mode operates as a reverse proxy, translating HTTP/HTTPS traffic only. SMB (Server Message Block) is a non-web protocol that requires direct network-layer connectivity, which web mode cannot provide. Tunnel mode creates a virtual network interface that allows any IP-based protocol, including SMB, to traverse the VPN.

Therefore, the correct solution is to use tunnel mode for file share access.

Exam trap

The trap here is that candidates often assume SSL VPN policies or firewall rules are misconfigured, overlooking the fundamental architectural limitation that web mode only supports web-based applications, not arbitrary TCP/UDP protocols like SMB.

How to eliminate wrong answers

Option A is wrong because the SSL VPN policy controls access at the application level via the portal, not by filtering specific protocols like SMB; the issue is a protocol limitation, not a policy restriction. Option B is wrong because client certificate authentication is unrelated to protocol support; even if the fileserver required certificates, web mode still cannot proxy SMB traffic. Option C is wrong because the firewall policy interface assignment affects routing, not the protocol capabilities of the SSL VPN portal; web mode inherently lacks SMB support regardless of interface configuration.

628
Multi-Selectmedium

A FortiGate administrator needs to prevent data leakage by blocking the upload of files containing credit card numbers via web traffic. Which THREE components must be configured? (Choose three.)

Select 3 answers
A.Application control profile to block file upload applications
B.DLP profile with a rule to detect credit card numbers
C.Firewall policy that applies the DLP profile and SSL inspection to the traffic
D.Antivirus profile to scan the files for malware
E.SSL deep inspection to decrypt HTTPS traffic
AnswersB, C, E

A DLP profile is the FortiGate component responsible for content inspection to prevent data leakage. It includes predefined signatures for sensitive patterns such as credit card numbers, social security numbers, and other PII, as well as support for custom regular expressions. When a rule detects a match in the traffic, the configured action (block, log, or allow with notification) is enforced. This forms the core detection mechanism needed to stop credit card data from being uploaded.

Why this answer

A DLP (Data Loss Prevention) profile is specifically designed to inspect content for sensitive data patterns, such as credit card numbers, using predefined or custom data patterns. When configured with a rule to detect credit card numbers, the DLP profile can block or log the upload of files containing such data over web traffic.

Exam trap

The trap here is that candidates may think application control (option A) or antivirus (option D) can detect sensitive data, but they are designed for different purposes—application control manages app usage, and antivirus detects malware, not data patterns.

629
MCQmedium

A FortiGate admin has configured FSSO (Fortinet Single Sign-On) using Active Directory polling. Users authenticate to the domain but when accessing the internet through the FortiGate, they are still prompted for credentials. What is the MOST likely cause?

A.The FortiGate is not polling the AD domain controllers
B.The users are using non-Windows machines
C.The firewall policy does not have FSSO authentication enabled
D.The FortiGate is not joined to the domain
AnswerA

In FSSO polling mode, the FortiGate acts as a collector agent: it periodically connects to Active Directory domain controllers over LDAP, queries for user logon events (e.g., event ID 4624), and builds a mapping between authenticated usernames and their source IP addresses. If polling is not configured (or the service account's credentials are invalid, or the polling interval is mis-set), the FortiGate never receives that mapping. Consequently, the security policy cannot correlate the incoming traffic with any FSSO user group, so the session is treated as unauthenticated and falls through to the default deny/action rather than prompting for credentials.

Why this answer

In FSSO with Active Directory polling, the FortiGate must be configured to poll the domain controllers to retrieve user logon events. If polling is not set up or fails, the FortiGate will not have the user-to-IP mapping, and thus cannot bypass authentication for domain users, causing them to be prompted for credentials when accessing the internet.

Exam trap

The trap here is that candidates often assume the FortiGate must be domain-joined (Option D) or that the policy is misconfigured (Option C), when the real issue is the lack of polling to collect user logon events.

How to eliminate wrong answers

Option B is wrong because FSSO polling works with any OS that authenticates to the domain; non-Windows machines can still be mapped via IP if they log on to AD. Option C is wrong because the firewall policy must have FSSO authentication enabled to use the user mappings, but the prompt indicates the mapping itself is missing, not the policy configuration. Option D is wrong because the FortiGate does not need to be joined to the domain for FSSO polling; it only needs network access to the domain controllers and the correct service account credentials.

630
MCQmedium

An administrator notices that traffic matching a firewall policy is not being logged. The policy has logging enabled. The FortiGate has local disk storage. What should the administrator check first?

A.Whether the FortiGate has a valid FortiAnalyzer subscription
B.Whether FortiCloud logging is enabled
C.The disk health and available space using 'diagnose sys disk' commands
D.The log severity level on the policy
AnswerC

When local logs are missing, the first step is to verify the storage subsystem with 'diagnose sys disk' to inspect disk health, mount status, and available space. A full or failing disk, or an exhausted inode table, can cause log writes to fail silently, resulting in no entries in the local log view. This command reveals whether the disk is online, has sufficient free blocks, and has no file-system errors. Only after confirming the disk is healthy should you examine logging filters or remote destinations.

Why this answer

When a FortiGate policy has logging enabled but logs are not appearing, and the device uses local disk storage, the first thing to check is whether the disk is healthy and has available space. FortiOS stops writing logs when the disk is full or failing, and 'diagnose sys disk' commands reveal disk health, usage, and log partition status. This is the most direct and common cause of missing local logs.

Exam trap

NSE4 often tests the assumption that logging issues are always about severity or remote destinations — candidates overlook that local disk health and free space are the first thing to verify when local logging silently stops.

How to eliminate wrong answers

Option A is wrong because a FortiAnalyzer subscription is only required for remote logging to FortiAnalyzer — local disk logging does not depend on it, and the question specifies the FortiGate has local disk storage. Option B is wrong because FortiCloud logging is a separate remote logging destination; enabling or disabling it does not affect local disk logging. Option D is wrong because log severity level on the policy filters which events are logged, but if logging is enabled and the severity is set to a reasonable level, the more likely cause of zero logs is a disk issue — and the question states logging is enabled.

631
MCQmedium

A FortiGate administrator wants to configure a dial-up IPsec VPN where remote users connect using VPN clients with pre-shared key authentication. The company has recently experienced a data breach where the PSK was compromised. What is the best method to improve security without changing all clients immediately?

A.Switch to aggressive mode with a complex PSK
B.Enable XAuth with a second authentication factor using FortiToken
C.Increase the PSK length to 64 characters
D.Migrate to certificate-based authentication for Phase 1
AnswerD

Certificate-based Phase 1 authentication replaces the shared PSK with a unique asymmetric key pair per dial-up peer, binding each client's identity to its certificate. During IKE main mode, certificates enable mutual authentication without ever transmitting a shared secret in the clear, and compromised certificates can be individually revoked via a CRL or OCSP without affecting other peers. This eliminates the single-point-of-failure shared secret and is the correct way to harden a dial-up IPsec VPN.

Why this answer

Migrating to certificate-based authentication eliminates reliance on a static pre-shared key (PSK), which is inherently vulnerable to compromise. Certificates provide asymmetric cryptographic proof of identity, ensuring that even if a PSK is leaked, the attacker cannot authenticate without a valid certificate. This is the most robust long-term fix for PSK compromise in IPsec VPNs.

Exam trap

The trap here is that candidates often confuse user authentication (XAuth) with Phase 1 authentication, mistakenly believing that adding a second factor like FortiToken fixes the compromised PSK, when in fact the PSK is still used and vulnerable in the initial IKE exchange.

How to eliminate wrong answers

Option A is wrong because aggressive mode actually reduces security by sending the PSK in cleartext during Phase 1 negotiation, making it easier to capture and exploit. Option B is wrong because XAuth with FortiToken adds a second authentication factor for user identity, but it does not replace or secure the compromised PSK used in Phase 1; the PSK remains the weak link. Option C is wrong because increasing the PSK length to 64 characters only increases brute-force resistance, but does not address the fact that the PSK has already been compromised and is known to an attacker.

632
Drag & Dropmedium

Drag and drop the steps to create a firewall policy allowing HTTP traffic from internal to DMZ into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Firewall policies require defining interfaces, source/destination addresses, and services before enabling.

633
MCQeasy

Which statement best describes the implicit deny policy at the end of a FortiGate policy list?

A.It denies all traffic that does not match any explicit policy, and it logs the denied traffic
B.It can be moved to a different position in the policy list
C.It can be disabled or deleted by the admin
D.It is always present and denies any traffic that does not match an explicit allow policy
AnswerD

The implicit deny is always present as the last effective rule in the FortiGate policy list, regardless of how many explicit policies are configured. Any traffic that does not match an explicit allow policy is dropped by this default rule, ensuring that all unmatched packets are blocked. This is a mandatory security control that cannot be removed or repositioned, providing a safe default deny posture.

Why this answer

The implicit deny policy is a built-in, last-resort rule at the bottom of the FortiGate policy list that silently drops any traffic not matching an explicit allow policy. It cannot be moved, disabled, or deleted because it is a fundamental security mechanism ensuring that only explicitly permitted traffic is allowed through the firewall.

Exam trap

The trap here is that candidates often think the implicit deny can be configured or removed like an explicit policy, but FortiGate enforces it as an unchangeable, always-present rule that cannot be logged or repositioned.

How to eliminate wrong answers

Option A is wrong because the implicit deny policy does not log denied traffic by default; logging must be explicitly configured on an explicit deny policy. Option B is wrong because the implicit deny policy is fixed at the very end of the policy list and cannot be repositioned. Option C is wrong because the implicit deny policy is a permanent, non-removable safeguard that cannot be disabled or deleted by the administrator.

634
MCQhard

An administrator configures SSL deep inspection with a CA certificate. Users accessing an internal site (internal.company.com) receive a certificate error. The administrator wants to avoid the error without disabling deep inspection. What should be done?

A.Replace the CA certificate with a self-signed one
B.Use certificate inspection instead of deep inspection
C.Disable certificate validation in the deep inspection profile
D.Add internal.company.com to the SSL/SSH inspection exemption list
AnswerD

Adding internal.company.com to the SSL/SSH inspection exemption list instructs the FortiGate to pass those sessions without decrypting or re-signing the certificate, so the client receives the original certificate issued by the company's internal PKI. This eliminates the certificate error because the client sees a chain it already trusts, while allowing deep inspection to continue for other traffic. It is the recommended approach for internal domains that have their own CA or for applications with certificate pinning that cannot tolerate interception.

Why this answer

Adding internal.company.com to the SSL/SSH inspection exemption list tells the FortiGate to bypass deep inspection for that specific site, allowing the internal CA certificate to be used without triggering a certificate error. This avoids the error while keeping deep inspection enabled for all other traffic, which is the administrator's goal.

Exam trap

The trap here is that candidates may think disabling certificate validation (Option C) is a quick fix, but that compromises security and is not the intended method to handle trusted internal sites; the correct approach is to use the exemption list to selectively bypass inspection.

How to eliminate wrong answers

Option A is wrong because replacing the CA certificate with a self-signed one would still cause certificate errors for clients that do not trust the self-signed CA, and it does not address the root cause of the mismatch between the internal site's certificate and the CA used for deep inspection. Option B is wrong because certificate inspection only examines the certificate metadata without decrypting traffic, which would not resolve the certificate error and would lose the security benefits of deep inspection. Option C is wrong because disabling certificate validation in the deep inspection profile would bypass all certificate checks, making the system vulnerable to man-in-the-middle attacks and defeating the purpose of deep inspection.

635
MCQmedium

An administrator has configured the policy shown in the exhibit. Traffic to the web server at 10.0.1.10 over HTTPS is allowed, but users complain that they cannot access the web server's login page. The IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts. The application list 'Block_Social_Media' blocks Facebook and Twitter. What is the most likely cause of the issue?

A.The IPS sensor is blocking the login page due to a false positive.
B.The firewall policy action is set to 'deny' but the exhibit shows 'accept'.
C.The HTTPS service is not correctly defined and blocking the traffic.
D.The application control profile is blocking the web application.
AnswerD

The application control profile is the only profile configured in the policy that can identify and block specific web applications by their signatures, even when the underlying HTTP/HTTPS service is valid. When a user attempts to access the login page, the FortiGate can classify the traffic as a known application and apply the profile's 'block' action, denying the request. This is a common cause of access failure when the base policy action is accept and HTTPS is correctly defined.

Why this answer

The policy explicitly allows HTTPS traffic to 10.0.1.10, but the application control profile 'Block_Social_Media' is applied. This profile blocks Facebook and Twitter, which are web-based applications. If the web server's login page is served over HTTPS and is incorrectly classified by the FortiGate as a social media application (e.g., due to shared CDN or similar traffic patterns), the application control profile will block it, preventing user access despite the firewall policy allowing the service.

Exam trap

The trap here is that candidates assume the IPS sensor is the cause of the block, but the question specifies the IPS sensor only blocks SQL injection attempts, not login pages, while the application control profile explicitly blocks social media applications that could be misclassifying the web server's traffic.

How to eliminate wrong answers

Option A is wrong because the IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts, not login pages; a false positive for SQL injection would block specific HTTP requests containing malicious patterns, not the entire login page. Option B is wrong because the exhibit shows the policy action as 'accept', and the question states traffic is allowed; a 'deny' action would block all traffic, not just the login page. Option C is wrong because HTTPS is a well-defined service (TCP/443) and the policy explicitly allows it; if the service were misdefined, all HTTPS traffic would be blocked, not just the login page.

636
MCQmedium

A FortiGate admin is troubleshooting an IPsec VPN tunnel that fails to establish. The remote site uses aggressive mode. The local FortiGate is configured for main mode. The admin sees 'no proposal chosen' in the IKE debug. What is the MOST likely cause?

A.The pre-shared key is incorrect
B.The IKE mode (main vs aggressive) does not match between peers
C.The local firewall is blocking UDP port 500
D.The Phase 2 encryption algorithm is not supported
AnswerB

Main mode and Aggressive mode differ in the number of IKE messages and whether the SA proposal is sent in the first packet with the same structure. When one peer is set to Main mode and the other to Aggressive mode, the responder sees a proposal that does not match the expected exchange type and therefore rejects it with a NO_PROPOSAL_CHOSEN notify, because the transforms are not considered valid for the configured mode. This is one of the classic causes of this exact error on FortiGate.

Why this answer

The 'no proposal chosen' error in IKE debug indicates a mismatch in the IKE parameters proposed by the peers. Since the remote site uses aggressive mode and the local FortiGate is configured for main mode, the IKE mode mismatch prevents the peers from agreeing on a proposal. IKE main mode and aggressive mode use different packet formats and exchange sequences, so they cannot negotiate a common proposal even if all other parameters match.

Exam trap

The trap here is that candidates often associate 'no proposal chosen' only with encryption or authentication algorithm mismatches, overlooking that IKE mode mismatch is also a proposal-level failure that triggers the same error in IKE debug.

How to eliminate wrong answers

Option A is wrong because an incorrect pre-shared key would cause an authentication failure (e.g., 'invalid cookie' or 'authentication failed') in IKE debug, not a 'no proposal chosen' error. Option C is wrong because if UDP port 500 were blocked, the FortiGate would not receive any IKE packets at all, leading to a timeout or 'no response' message, not a proposal mismatch. Option D is wrong because Phase 2 encryption algorithm mismatches are detected during Phase 2 negotiation (Quick Mode), not during Phase 1 (IKE) where the 'no proposal chosen' error occurs.

637
MCQmedium

An administrator wants to use ZTNA (Zero Trust Network Access) to secure access to an internal application. Which component is required on the client device to enforce ZTNA policies?

A.FortiManager
B.FortiToken
C.FortiClient
D.FortiAnalyzer
AnswerC

FortiClient is the endpoint agent that performs the critical ZTNA posture assessment, checking for compliance criteria such as updated antivirus definitions, disk encryption, and approved software versions. It communicates this telemetry to a FortiGate or FortiEMS, which then issues a short-lived token only if the endpoint is compliant and the user identity is verified. When the user attempts to access a ZTNA-protected application, FortiClient presents that token, enabling the FortiGate to enforce granular access and maintain a secure connection. This makes FortiClient the mandatory client-side enforcement component that embodies ZTNA's continuous trust verification.

Why this answer

FortiClient is the required endpoint component for ZTNA because it acts as the ZTNA agent on the client device, establishing a secure tunnel (via IPSec or SSL VPN) to the FortiGate and enforcing posture checks (e.g., OS version, antivirus status) before granting access. Without FortiClient, the FortiGate cannot verify the device's trust level or enforce ZTNA access policies at the endpoint.

Exam trap

The trap here is that candidates often confuse FortiClient with FortiToken, assuming that MFA alone is sufficient for ZTNA, but ZTNA requires endpoint posture enforcement via FortiClient, not just authentication factors.

How to eliminate wrong answers

Option A is wrong because FortiManager is a centralized management platform for multiple FortiGate devices, not an endpoint component; it does not reside on the client device or enforce ZTNA policies locally. Option B is wrong because FortiToken is a two-factor authentication (2FA) hardware or software token used for MFA, not for device posture assessment or ZTNA policy enforcement on the client. Option D is wrong because FortiAnalyzer is a logging and analytics appliance that collects logs from FortiGate and other Fortinet devices; it does not run on the client or enforce access policies.

638
MCQeasy

An administrator needs to configure a FortiGate to allow web traffic from the internal network to the Internet. The internal network is 192.168.1.0/24 and the WAN interface is port1 with IP 203.0.113.1. Which firewall policy is correct?

A.Source: internal, Destination: port1, Service: HTTP/HTTPS, Action: ACCEPT
B.Source: port1, Destination: internal, Service: HTTP/HTTPS, Action: ACCEPT
C.Source: external, Destination: internal, Service: HTTP/HTTPS, Action: ACCEPT
D.Source: internal, Destination: port1, Service: ALL, Action: ACCEPT
AnswerA

This policy correctly implements outbound web access: traffic originates from the internal network, exits via the port1 interface that connects to the Internet, and is restricted to HTTP/HTTPS services. Because FortiGate firewall policies are interface-based and stateful, this single policy also allows the corresponding return traffic from external web servers to flow back to the internal users without an explicit reverse rule. The Action ACCEPT ensures that the traffic is permitted, aligning with the required use case.

Why this answer

The firewall policy must match traffic originating from the internal network (source: internal) destined for the Internet via the WAN interface (destination: port1), and the service must be restricted to HTTP/HTTPS to allow web traffic only. The action ACCEPT permits the traffic. This aligns with the standard stateful inspection flow where source and destination interfaces are defined based on traffic direction.

Exam trap

The trap here is that candidates often confuse the source and destination interfaces in a policy, thinking the destination should be the internal network instead of the WAN interface for outbound traffic, or they select Service: ALL to avoid missing any protocol, ignoring the requirement for web traffic only.

How to eliminate wrong answers

Option B is wrong because it reverses the source and destination interfaces: traffic from port1 (WAN) to internal would be inbound, not outbound web traffic from internal to the Internet. Option C is wrong because 'external' is not a valid source interface in this context; the source must be the internal network interface, and the destination interface must be port1 for outbound traffic. Option D is wrong because it uses Service: ALL, which would allow all protocols (e.g., SSH, SMTP) instead of restricting to HTTP/HTTPS as required for web traffic only, violating the principle of least privilege.

639
MCQeasy

An administrator wants to ensure that traffic to a specific web server always exits through a particular ISP link, regardless of route changes. Which feature should be configured?

A.Equal-cost multi-path (ECMP) routing
B.Policy-based routing (PBR)
C.Static route with higher distance
D.SD-WAN with load balancing
AnswerB

Policy-based routing matches traffic against criteria such as source, destination or service, then forwards it via a specified gateway, overriding the destination-based lookup in the routing table. This guarantees the web server's traffic always exits the chosen ISP link despite route changes.

Why this answer

Policy-based routing (PBR) allows you to override the routing table by applying a route map to match traffic (e.g., source/destination IP, port) and explicitly set the next-hop interface or ISP link. This ensures traffic to the specific web server always exits through the designated ISP, regardless of dynamic route changes or the routing table's default behavior.

Exam trap

The trap here is that candidates confuse PBR with static routing or SD-WAN load balancing, thinking that a static route with a higher distance or SD-WAN can force traffic to a specific link, but only PBR provides the granular match-and-set logic to override the routing table for specific traffic flows regardless of route changes.

How to eliminate wrong answers

Option A is wrong because ECMP distributes traffic across multiple equal-cost paths for load balancing, not for pinning traffic to a specific link. Option C is wrong because a static route with a higher distance (administrative distance) acts as a backup route and only takes effect when the primary route is unavailable, not for forcing traffic to a particular link when the primary route is active. Option D is wrong because SD-WAN with load balancing distributes traffic across multiple WAN links based on policies or performance metrics, which does not guarantee that all traffic to a specific web server always uses the same ISP link.

640
MCQhard

A FortiGate is configured with two WAN interfaces in an SD-WAN zone. The administrator wants to ensure voice traffic uses the interface with the lowest latency. Which SD-WAN configuration should be used?

A.Set the strategy to 'Manual'
B.Set the strategy to 'Load Balance'
C.Configure an SD-WAN rule with a performance SLA that monitors latency and set strategy to 'Best Quality'
D.Use policy-based routing with a higher priority for voice traffic
AnswerC

This is correct because a performance SLA defines the latency threshold and probing mechanism, and the Best Quality strategy inspects those live SLA results to choose the WAN interface with the lowest measured latency. When the SLA detects that a WAN link's latency exceeds the threshold, the FortiGate dynamically fails over voice traffic to the best-performing member, ensuring optimal real-time voice quality.

Why this answer

SD-WAN rules with a performance SLA allow the FortiGate to monitor real-time latency on each WAN interface and dynamically route voice traffic to the interface with the lowest latency. The 'Best Quality' strategy selects the best-performing interface based on the SLA metrics, ensuring optimal voice quality.

Exam trap

The trap here is that candidates often confuse policy-based routing (PBR) with SD-WAN rules, not realizing that PBR lacks dynamic SLA-based path selection and cannot automatically adapt to changing network conditions.

How to eliminate wrong answers

Option A is wrong because setting the strategy to 'Manual' requires the administrator to statically assign traffic to a specific interface, which cannot adapt to changing latency conditions. Option B is wrong because 'Load Balance' distributes traffic across interfaces based on load, not latency, and does not guarantee the lowest-latency path for voice traffic. Option D is wrong because policy-based routing (PBR) uses static routing rules that do not dynamically adjust based on real-time latency measurements, unlike SD-WAN rules with performance SLAs.

641
MCQeasy

A FortiGate administrator needs to check the current HA status of a cluster to determine which unit is the primary. The administrator has CLI access to both units. Which command should be executed on either unit to display the HA status, including the primary unit's hostname and priority?

A.show system ha
B.get system ha status
C.diagnose sys ha status
D.diagnose sys ha dump
AnswerB

This command displays a concise summary of the HA status, including the primary unit's hostname, priority, and HA uptime. It is the standard command to quickly verify which unit is primary and its attributes. It works on either unit and provides the necessary information directly.

Why this answer

The command 'get system ha status' is the correct choice because it provides a clear summary of the HA status, including the primary unit's hostname and priority. It is the standard command for quickly determining which unit is active and its attributes, making it ideal for this scenario.

Exam trap

The trap here is confusing the configuration command 'show system ha' with the operational status command 'get system ha status'.

642
MCQeasy

A FortiGate has been configured with two WAN interfaces (wan1, wan2) in an SD-WAN zone. The administrator wants to ensure that traffic for a specific internal server uses only wan1. What is the most appropriate method?

A.Disable wan2 in the SD-WAN zone
B.Use policy routing with a higher priority for wan1
C.Configure a static route with a higher distance for wan2
D.Create an SD-WAN rule to match the server's traffic and set the preferred member to wan1
AnswerD

Creating an SD-WAN rule that matches the server's traffic (e.g., by destination IP address) and setting the preferred member to wan1 is the correct solution because SD-WAN rules are evaluated after policy routes and allow granular, application-aware egress selection. The preferred member setting ensures that wan1 is used for matching sessions, while other traffic can still be load-balanced or failed over across the WAN interfaces based on SD-WAN health-check and performance SLA. This approach is the recommended, flexible, and maintainable way to steer specific traffic in a Fortinet SD-WAN design.

Why this answer

SD-WAN rules allow granular traffic steering based on application, source, or destination. By creating an SD-WAN rule that matches the traffic destined for the internal server and setting the preferred member to wan1, the FortiGate will use SD-WAN's policy-based routing to ensure that traffic egresses exclusively via wan1, while other traffic can still use both WAN interfaces as per other rules.

Exam trap

The trap here is that candidates often confuse policy routing (Option B) with SD-WAN rules, not realizing that SD-WAN rules are the proper mechanism for per-traffic member selection within an SD-WAN zone, and that policy routing operates at a different layer and can override SD-WAN behavior if not carefully managed.

How to eliminate wrong answers

Option A is wrong because disabling wan2 in the SD-WAN zone removes it from all load-balancing and failover, which is overly broad and not a targeted solution for a single server's traffic. Option B is wrong because policy routing (PBR) operates independently of SD-WAN and can create conflicts; SD-WAN rules are the intended method for per-traffic member selection within an SD-WAN zone. Option C is wrong because configuring a static route with a higher distance for wan2 affects all traffic using that route, not just the specific server's traffic, and static routes do not integrate with SD-WAN's application-aware steering.

643
MCQmedium

A FortiGate administrator receives reports that some users are receiving spam emails despite an email filter profile being applied to the SMTP traffic. The email filter profile has 'spam' action set to 'discard'. What is the most likely reason spam is still reaching users?

A.The internal email server receives email directly from the internet without passing through the FortiGate
B.The spam dictionary is not updated with latest spam signatures
C.The email filter profile is not configured to scan outbound emails
D.The email filter profile is applied to the wrong policy direction (inbound vs outbound)
AnswerA

If the internal mail server's MX record points to a public IP that is reachable directly from the internet (i.e., not behind the FortiGate), SMTP packets will never traverse the firewall. Since the FortiGate can only inspect traffic that physically passes through its interfaces, the email filter profile—regardless of how it is configured—will never see these messages. This is the definitive root cause: the FortiGate is completely out of the data path for inbound SMTP, so no email filtering can occur.

Why this answer

If the internal email server receives email directly from the internet without passing through the FortiGate, the email filter profile applied to SMTP traffic on the FortiGate will never inspect those messages. The FortiGate can only filter traffic that actually traverses it; any email routed around the FortiGate bypasses all security profiles entirely.

Exam trap

The trap here is that candidates often assume the email filter profile is correctly applied and focus on configuration details (like dictionary updates or policy direction), rather than verifying whether the traffic actually passes through the FortiGate at the network level.

How to eliminate wrong answers

Option B is wrong because the spam action is set to 'discard', which relies on the FortiGate's real-time spam detection (e.g., FortiGuard AntiSpam, heuristics, or RBL checks), not a static dictionary; an outdated dictionary would reduce detection accuracy but would not cause all spam to pass through. Option C is wrong because the issue is about spam reaching users from external sources, not outbound emails; outbound scanning is irrelevant to incoming spam delivery. Option D is wrong because the email filter profile is applied to SMTP traffic, and the direction (inbound vs outbound) is already implied by the traffic flow; if the profile were applied to the wrong direction, it would not inspect the traffic at all, but the question states the profile is applied to SMTP traffic, so the more fundamental issue is that the traffic never reaches the FortiGate.

644
MCQeasy

Which of the following security profiles is used to prevent malicious files from being downloaded via HTTP, FTP, or email by inspecting the content of the traffic?

A.Antivirus
B.Application Control
C.Web Filter
D.Intrusion Prevention System (IPS)
AnswerA

The Antivirus security profile is the correct answer because it is specifically designed to detect and block malware such as viruses, worms, and trojans by scanning file content and network traffic against a signature database. It operates at the file level, inspecting uploaded/downloaded files, email attachments, and other data streams, and can also use heuristics and sandboxing to catch unknown threats. This is the direct mechanism for preventing infections, which is the goal of the question.

Why this answer

Antivirus (option A) is the correct security profile because it performs deep content inspection of files transferred via HTTP, FTP, or email protocols. It uses signature-based detection and heuristics to identify and block malicious files (e.g., executables, scripts, or archives) before they reach the user, directly preventing malware downloads.

Exam trap

The trap here is confusing 'content inspection for malicious files' with broader security functions like IPS (which inspects network-level exploits) or Web Filter (which inspects URLs), leading candidates to overlook that Antivirus is the only profile specifically designed for file-level malware detection.

How to eliminate wrong answers

Option B (Application Control) is wrong because it identifies and controls application traffic (e.g., Facebook, YouTube) based on signatures and behavior, not file content inspection for malware. Option C (Web Filter) is wrong because it controls access to websites based on URL categories or reputation, not scanning the actual file payload for malicious content. Option D (Intrusion Prevention System) is wrong because it analyzes network traffic for exploit signatures and anomaly patterns (e.g., SQL injection, buffer overflows), not file-level malware scanning.

645
MCQmedium

You run the following command on a FortiGate: ``` diagnose sys session filter dport 443 diagnose sys session list ``` The output shows: ``` proto=6 proto_state=01 duration=3600 expire=3599 ``` What does this indicate?

A.The session has been established for 3600 seconds and has 3599 seconds remaining before timeout.
B.The session is using TCP state 01 (SYN_SENT) and is still in the process of establishing.
C.The session has been idle for 3600 seconds and will expire in 3599 seconds.
D.The session is using UDP protocol and will expire in 3599 seconds.
AnswerA

In FortiGate's session table output, the Duration field shows the total time elapsed since the session was first created, while the Expire field shows the remaining time before the session is removed from the table. A duration of 3600 seconds means the session has been active for exactly one hour, and an expire value of 3599 seconds indicates that timeout will occur in just under one hour. This interpretation is correct because these fields measure session age and remaining lifetime, not idle time or connection state.

Why this answer

The output shows `duration=3600` and `expire=3599`, which indicate the session has been active for 3600 seconds and has 3599 seconds remaining before timeout. The `proto=6` confirms TCP (protocol 6), and `proto_state=01` represents the TCP state for an established connection (ESTABLISHED), not a handshake state.

Exam trap

The trap here is confusing `duration` (time since session creation) with idle time, and misinterpreting `proto_state=01` as a handshake state (SYN_SENT) instead of the correct ESTABLISHED state.

How to eliminate wrong answers

Option B is wrong because `proto_state=01` in FortiGate's session table represents TCP state ESTABLISHED (not SYN_SENT); SYN_SENT would be state 02. Option C is wrong because `duration` measures the total time since the session was created, not idle time; idle time is tracked separately via the `idle` field in the session list. Option D is wrong because `proto=6` explicitly indicates TCP, not UDP (which would be proto=17).

646
MCQmedium

An administrator configures a FortiGate to use NTP for time synchronization. After configuration, the FortiGate still shows the wrong time. Which command should the administrator run to verify NTP status?

A.show system ntp
B.execute ntp status
C.diagnose sys time status
D.diagnose sys ntp status
AnswerD

The 'diagnose sys ntp status' command is the correct FortiOS diagnostic to display the current NTP daemon runtime status. It reports whether NTP synchronization has been enabled, the IP address of the last selected NTP server, the synchronization status (e.g., synchronized or unsynchronized), and the measured time offset. This is the only command among the listed options that shows real-time NTP synchronization information, making it the correct answer.

Why this answer

'diagnose sys ntp status' is the FortiGate CLI command that provides detailed NTP synchronization status, including whether the FortiGate is synchronized to an NTP server, the stratum level, and the last sync time. This command is specifically designed for troubleshooting NTP issues, unlike the other options which either show configuration or are invalid.

Exam trap

The trap here is that candidates confuse configuration commands (show system ntp) with diagnostic commands, or they assume a generic 'ntp status' command exists, when Fortinet specifically uses 'diagnose sys ntp status' for operational verification.

How to eliminate wrong answers

Option A is wrong because 'show system ntp' displays the NTP configuration (e.g., server addresses, authentication settings), not the operational status or synchronization state. Option B is wrong because 'execute ntp status' is not a valid FortiGate command; the correct execute command for NTP is 'execute ntp sync' to force synchronization. Option C is wrong because 'diagnose sys time status' shows the system time and time source (e.g., NTP, manual), but it does not provide detailed NTP peer status, offset, or jitter information.

647
MCQeasy

A FortiGate administrator needs to ensure that all internal users (10.0.0.0/8) accessing the internet use a single public IP address 203.0.113.10 for source NAT. Which NAT configuration should be used?

A.Create a Central SNAT rule with a Dynamic IP Pool using overload
B.Enable NAT on the outgoing interface policy without an IP pool
C.Create a policy-based NAT rule with fixed port range
D.Configure a VIP with port forwarding
AnswerA

A Central SNAT rule with a Dynamic IP Pool in overload mode references a configured pool of public addresses and applies source network address translation independently of firewall policies. Overload (PAT) creates a unique mapping of internal IP:port to the selected public IP:port, allowing many internal users to share a single public address. This is the appropriate method when the required public IP is not the interface IP and must be shared by all internal clients.

Why this answer

Central SNAT with a Dynamic IP Pool using overload (Port Address Translation) allows all internal users in 10.0.0.0/8 to share a single public IP (203.0.113.10) by dynamically mapping multiple private source IPs and ports to unique source ports on the public IP. This is the standard method for many-to-one NAT, ensuring all outbound internet traffic appears from the same public address.

Exam trap

The trap here is that candidates often confuse enabling NAT on the interface policy (Option B) with using a specific IP pool, not realizing that interface NAT uses the interface's own IP and cannot force a different public address without an explicit IP pool.

How to eliminate wrong answers

Option B is wrong because enabling NAT on the outgoing interface policy without an IP pool uses the interface's own IP address (typically the WAN IP) for source NAT, not a specific public IP like 203.0.113.10, and may not guarantee a single IP if the interface has multiple addresses. Option C is wrong because a policy-based NAT rule with fixed port range would restrict the number of concurrent sessions to the size of the port range, causing connection failures under load, and is not designed for many-to-one overload NAT. Option D is wrong because a VIP with port forwarding is used for inbound destination NAT (port mapping to internal servers), not for outbound source NAT from internal users to the internet.

648
MCQmedium

An administrator configures a FortiGate in transparent mode. Which of the following is correct regarding transparent mode operation?

A.The FortiGate performs NAT between its interfaces.
B.The FortiGate interfaces can be on different subnets.
C.The FortiGate requires a management IP on each interface.
D.The FortiGate is invisible to end devices and does not modify IP addresses.
AnswerD

Transparent mode is designed to be invisible to end devices, acting as an inline security appliance without modifying IP addresses or making routing decisions. The FortiGate inspects frames at Layer 2, allowing IP packets to pass through unchanged, which is why it is often deployed without requiring any network redesign. This invisibility is the defining characteristic that makes the statement correct.

Why this answer

In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses without performing any IP-level modifications. This means it does not perform NAT, and end devices are unaware of its presence, making option D correct.

Exam trap

The trap here is that candidates confuse transparent mode with NAT/Route mode, assuming that all FortiGate modes perform NAT or require IP addresses on each interface, when in fact transparent mode is purely Layer 2 and does not modify IP headers.

How to eliminate wrong answers

Option A is wrong because transparent mode does not perform NAT; NAT is a Layer 3 function used in NAT/Route mode. Option B is wrong because all interfaces in transparent mode must belong to the same subnet to maintain Layer 2 bridging. Option C is wrong because transparent mode requires only a single management IP (typically on the management interface or a dedicated VLAN), not an IP on each interface.

649
MCQmedium

A FortiGate is set to NAT/Route mode. The admin wants traffic from internal users to the internet to use an IP address on the WAN interface for source NAT. Which configuration is required?

A.Set the FortiGate to transparent mode
B.Configure a policy route to force traffic through a specific interface
C.Configure a virtual IP mapping internal IPs to the WAN IP
D.Enable NAT on the policy from internal to WAN and set the outgoing interface to the WAN interface
AnswerD

This is the correct method for source NAT in NAT/Route mode. By enabling NAT on the firewall policy from internal to WAN and specifying the outgoing interface as the WAN interface, the FortiGate translates the source IP of each internal packet to the address of that WAN interface (or the configured IP pool), allowing return traffic to be routed back and enabling internal hosts to access the Internet using public addressing.

Why this answer

In NAT/Route mode, source NAT (SNAT) is configured by enabling NAT on the firewall policy that governs traffic from the internal network to the WAN interface. When NAT is enabled on the policy and the outgoing interface is set to the WAN interface, FortiGate automatically translates the source IP of internal users to the primary IP address of that WAN interface (or a configured IP pool). This is the standard method for allowing internal users to access the internet with a public IP address.

Exam trap

The trap here is that candidates often confuse virtual IP (VIP) for source NAT, but VIP is strictly for destination NAT (inbound traffic), whereas source NAT for outbound traffic requires enabling NAT on the firewall policy.

How to eliminate wrong answers

Option A is wrong because transparent mode operates at Layer 2 without routing or NAT capabilities, which would prevent the required source NAT for internet access. Option B is wrong because policy routes control the path traffic takes based on routing criteria, not source NAT; they do not perform IP address translation. Option C is wrong because a virtual IP (VIP) is used for destination NAT (port forwarding), mapping an external IP/port to an internal server, not for source NAT of outbound traffic.

650
MCQeasy

What is the purpose of the 'safe search' option in a FortiGate web filter profile?

A.It enforces the use of HTTPS for search engines
B.It allows users to bypass URL filters during safe search
C.It filters explicit content from search engine results
D.It blocks all search engine traffic
AnswerC

The safe search option in FortiGate is designed to force search engines to enable their built-in safe search modes, effectively stripping adult or explicit content from the search results returned to users. It accomplishes this by manipulating DNS or rewriting URLs so that the search engine applies its restrictive content settings for every query. This ensures that even if a user has not configured their own search preferences, the network policy enforces a family-friendly search experience.

Why this answer

The 'safe search' option in a FortiGate web filter profile forces supported search engines (such as Google, Bing, and Yahoo) to filter explicit content from search results. This is achieved by appending specific parameters to the search engine URLs (e.g., &safe=active for Google), ensuring that adult or offensive material is suppressed regardless of the user's individual search settings.

Exam trap

The trap here is that candidates often confuse 'safe search' with 'HTTPS enforcement' or 'URL filtering', assuming it blocks or bypasses traffic rather than understanding it modifies search engine queries to filter explicit content.

How to eliminate wrong answers

Option A is wrong because safe search does not enforce HTTPS; HTTPS enforcement is a separate feature in the web filter or SSL inspection profile. Option B is wrong because safe search does not allow users to bypass URL filters; it operates independently to modify search engine queries, not to grant exceptions. Option D is wrong because safe search does not block all search engine traffic; it only modifies the search results to exclude explicit content while still allowing legitimate searches.

651
MCQmedium

An organization uses Application Control to allow only business-critical applications and block social media. The administrator has configured the profile to block Facebook and Twitter, but users can still access Facebook. The firewall policy applies the profile correctly. What is the most likely cause?

A.The application control profile is applied to the wrong direction.
B.Facebook is not included in the default application signatures.
C.SSL inspection is not enabled on the firewall policy.
D.The FortiGate is in flow-based inspection mode.
AnswerC

Without SSL deep inspection, HTTPS sessions appear as opaque flows to the security engine, allowing FortiGate to see only the initial TLS ClientHello (including SNI) and encrypted data afterward. Application control cannot read the HTTP Host header, cookies, or URI paths needed to confidently match the traffic to the 'Facebook' application, so HTTPS requests like news feed or chat are not blocked. The correct remedy is to enable an SSL/SSH inspection profile (typically 'deep-inspection') on the policy and install the FortiGate CA on client devices, allowing the Security Processing Unit to decrypt, inspect, and re-encrypt the session. This is why the answer identifies missing SSL inspection as the root cause.

Why this answer

Application Control relies on SSL inspection to identify applications like Facebook that use HTTPS. Without SSL inspection enabled on the firewall policy, FortiGate can only see encrypted traffic as generic SSL/TLS flows and cannot match the application signatures for Facebook. Enabling SSL inspection (deep inspection or certificate-based inspection) allows the FortiGate to decrypt the traffic and apply the application control profile correctly.

Exam trap

The trap here is that candidates assume application control works on encrypted traffic by default, but FortiGate requires explicit SSL inspection to decrypt and identify HTTPS applications like Facebook.

How to eliminate wrong answers

Option A is wrong because the application control profile is applied to the firewall policy, which is bidirectional by default; the direction is not the issue since the policy is correctly applied and the traffic is passing through it. Option B is wrong because Facebook is included in the default application signatures provided by FortiGuard; the administrator would not need to add it manually. Option D is wrong because flow-based inspection mode does not prevent application control from working; it actually supports application control and can still identify applications, but without SSL inspection, encrypted traffic remains opaque regardless of inspection mode.

652
MCQeasy

A FortiGate administrator needs to allow all internal users (10.0.0.0/8) to access a web server in the DMZ (192.168.1.100) using HTTPS. The administrator wants to apply a web filter profile to block malicious URLs while allowing legitimate traffic. Which of the following is the correct policy configuration?

A.Policy: source=internal, destination=DMZ, service=ALL, action=ACCEPT, web filter profile=default
B.Policy: source=internal, destination=DMZ, service=HTTP, action=ACCEPT, web filter profile=default
C.Policy: source=internal, destination=DMZ, service=HTTPS, action=ACCEPT, web filter profile=default
D.Policy: source=internal, destination=DMZ, service=HTTPS, action=DENY, web filter profile=default
AnswerC

This policy precisely matches the requirement: the HTTPS service object maps to TCP port 443, allowing encrypted web sessions from internal users to the DMZ, while action=ACCEPT forwards the traffic. The web filter profile is applied after the traffic is accepted, enabling URL and content inspection of the HTTPS sessions, provided that SSL inspection (deep or certificate-based) is already configured on the FortiGate. This is the only option that both permits the required traffic and enforces the intended security control.

Why this answer

The policy must match the HTTPS service (TCP/443) to allow encrypted web traffic to the DMZ web server, and the web filter profile is applied to inspect the HTTPS traffic for malicious URLs. The default web filter profile can block malicious URLs while allowing legitimate HTTPS traffic, provided SSL inspection is configured to enable content filtering.

Exam trap

The trap here is that candidates often confuse the service requirement (HTTPS vs HTTP) or assume that applying a web filter profile to HTTPS traffic works without SSL inspection, leading them to select option B or A, or they mistakenly think a DENY action with a web filter profile can still allow traffic.

How to eliminate wrong answers

Option A is wrong because it uses service=ALL, which would allow all protocols (including non-web traffic) unnecessarily, violating the principle of least privilege and potentially exposing the DMZ to unwanted traffic. Option B is wrong because it specifies service=HTTP (TCP/80), but the requirement is to access the web server using HTTPS (TCP/443), so HTTP would not match the traffic and the policy would not be applied. Option D is wrong because action=DENY would block all HTTPS traffic to the web server, preventing access entirely, which contradicts the requirement to allow legitimate traffic.

653
Multi-Selecteasy

Which TWO of the following are valid methods to view real-time debug output on a FortiGate? (Choose two.)

Select 2 answers
A.diagnose sniffer packet
B.diagnose debug enable
C.diagnose sys session list
D.execute tail log
E.diagnose debug flow
AnswersA, E

diagnose sniffer packet is the Fortinet CLI command that invokes the built-in packet capture engine to display live packets as they traverse the specified interface(s) or VLAN(s). It accepts real-time filters such as 'port 443' or host IPs, and a verbosity level (1-6) controlling header vs. full payload display. Because it immediately streams captured frames to the terminal, it is a legitimate real-time traffic-viewing tool.

Why this answer

Diagnose debug flow and diagnose sniffer packet are real-time debug commands. Execute tail log is not a standard command.

654
MCQeasy

A FortiGate administrator wants to block access to a list of known malicious websites. The list is updated frequently by a third-party threat intelligence feed. Which FortiGate feature should the administrator use to dynamically block these sites without manual intervention?

A.Static URL filter
B.External threat feed connector
C.DNS filter
D.FortiGuard web filter category
AnswerB

External threat feed connectors allow the FortiGate to subscribe to external feeds and automatically update blocklists. These can be used in firewall policies or web filter profiles to block malicious sites. This provides dynamic, automatic updates without manual intervention, satisfying the requirement.

Why this answer

External threat feed connectors enable the FortiGate to ingest blocklists from external sources and use them in policies. They support automatic updates, so the administrator does not need to manually maintain the list. This is the correct feature for dynamically blocking sites from a third-party threat intelligence feed.

Exam trap

The trap here is confusing FortiGuard categories with external threat feeds; FortiGuard is Fortinet-maintained, while external feeds are third-party and require a connector.

655
MCQhard

A FortiGate with multiple WAN interfaces uses policy-based routing (PBR) to route traffic from a specific subnet out of a particular interface. The admin also has a firewall policy allowing that subnet to the internet. However, the traffic is not being routed as expected. What could be the issue?

A.The firewall policy is placed above the PBR rule
B.The PBR rule does not have a matching protocol or service defined
C.The PBR rule uses an incorrect source or destination address
D.The FortiGate is in transparent mode
AnswerC

Policy routes are matched against the source and destination addresses specified in the rule; if either address does not overlap the actual traffic's addresses, the PBR lookup will not produce a match. As a result, the traffic falls through to the regular routing table and may be sent out a different WAN interface. This is the most direct and common reason a PBR rule is silently ignored.

Why this answer

Policy-based routing (PBR) is evaluated before firewall policies. If the PBR rule specifies an incorrect source or destination address, traffic from the intended subnet will not match the PBR rule and will fall through to the default routing table, potentially exiting via a different interface. The firewall policy alone cannot override the routing decision; the PBR rule must correctly identify the traffic to steer it to the desired egress interface.

Exam trap

The trap here is that candidates often assume firewall policy order or missing service definitions are the root cause, when in fact PBR's address matching is the precise mechanism that must be correctly configured for traffic to be routed as intended.

How to eliminate wrong answers

Option A is wrong because firewall policies are evaluated after PBR rules; the order of firewall policies relative to PBR rules does not affect routing decisions. Option B is wrong because PBR rules do not require a protocol or service definition—they can match based solely on source/destination addresses; omitting these fields does not prevent the rule from applying. Option D is wrong because transparent mode does not affect PBR functionality; PBR operates at Layer 3 and is available in both NAT/Route and transparent modes, though transparent mode typically bridges traffic rather than routing it.

656
MCQmedium

An administrator configures an email filter profile to block spam. Users complain that legitimate emails from a specific partner are being blocked. The admin wants to allow emails from that partner's domain without disabling spam filtering for other domains. What is the BEST approach?

A.Add the partner's domain to the IP allowlist in the email filter profile
B.Increase the spam threshold until the emails pass
C.Disable spam filtering for the entire firewall policy
D.Create a separate firewall policy for the partner's traffic without email filtering
AnswerA

Adding the partner's domain to the IP allowlist (or domain allowlist) in the email filter profile explicitly exempts that sender from spam scanning and blocking. This is a targeted action: only the partner's emails bypass the spam and content checks, while all other traffic remains subject to the full email filtering policy. It is the most efficient and secure way to ensure legitimate business emails are delivered without weakening protection for everyone else.

Why this answer

Adding the partner's domain to the IP allowlist in the email filter profile is the best approach because it creates a specific exception for that domain while keeping spam filtering active for all other traffic. The allowlist overrides the spam detection engine for matching senders, ensuring legitimate emails are not blocked without weakening the overall security posture.

Exam trap

The trap here is that candidates often confuse increasing the spam threshold (a global sensitivity adjustment) with creating a targeted exception, or they incorrectly assume that disabling filtering entirely is the simplest fix, when FortiOS allows precise allowlisting within the same profile.

How to eliminate wrong answers

Option B is wrong because increasing the spam threshold would reduce the sensitivity of the filter globally, allowing more spam to pass for all domains, not just the partner's. Option C is wrong because disabling spam filtering for the entire firewall policy removes protection for all traffic, which is an overly broad and insecure solution. Option D is wrong because creating a separate firewall policy without email filtering would require duplicating all other security profiles and could introduce policy order issues, plus it still disables filtering entirely for that traffic rather than creating a targeted exception.

657
Multi-Selectmedium

A FortiGate administrator is investigating a performance issue and suspects that a large number of incomplete TCP connections are consuming session table resources. Which TWO commands would help identify such sessions? (Choose two.)

Select 2 answers
A.diagnose debug flow filter dport 80 ; diagnose debug enable
B.diagnose sys session stat
C.diagnose sniffer packet any 'tcp' 4
D.diagnose sys session filter state syn-sent ; diagnose sys session list
E.diagnose sys session filter proto 6 ; diagnose sys session list
AnswersB, D

`diagnose sys session stat` is the correct first command because it presents a concise summary of session table statistics, including totals for sessions in various states such as TCP SYN-SENT, SYN-RECV, ESTABLISHED, FIN-WAIT, and others. By observing an unusually high count in the SYN-SENT bucket, an administrator can quickly confirm whether incomplete (half-open) connections are accumulating and contributing to the performance problem. This aggregate view is fast, non-intrusive, and gives immediate insight into the session table distribution without listing individual sessions.

Why this answer

Diagnose sys session list with filter can show sessions by state. Diagnose sys session stat shows counts by state. The sniffer shows packets, not session state; debug flow is for tracing specific streams.

658
MCQmedium

A FortiGate administrator has configured a route-based IPsec VPN. After Phase 2 is up, traffic is not passing. The administrator verifies that the firewall policy allows traffic and the routes are correct. What should the administrator check next?

A.The static route uses the VPN interface as the outgoing interface
B.The remote gateway's IP address is reachable
C.The pre-shared key is correct
D.The Phase 2 proposal includes the correct local and remote subnets
AnswerA

In a route-based VPN, the virtual IPsec interface serves as the tunnel endpoint, and the static route must specify that interface as the outgoing interface for the remote subnet. Without this route, the FortiGate has no entry in its routing table to direct traffic into the IPsec tunnel, even if Phase 1 and Phase 2 SAs are fully established. The route triggers the actual forwarding decision, causing the kernel to encapsulate and encrypt matching traffic over the tunnel.

Why this answer

In a route-based IPsec VPN, traffic is routed to the VPN tunnel interface (e.g., 'to_remote'). Even if firewall policies and static routes exist, the static route must explicitly use the VPN interface as the outgoing interface. If the static route points to a different interface or a next-hop IP instead of the tunnel interface, the kernel will not forward traffic into the IPsec tunnel, causing Phase 2 to be up but no traffic to pass.

This is a common misconfiguration that breaks the route-based VPN model.

Exam trap

The trap here is that candidates assume Phase 2 being up guarantees traffic flow, overlooking that route-based VPNs require the static route to explicitly use the tunnel interface as the outgoing interface, not just any valid next-hop.

How to eliminate wrong answers

Option B is wrong because the remote gateway's IP address being reachable is a prerequisite for Phase 1 (IKE) to establish, not a cause for traffic failure after Phase 2 is up. Option C is wrong because an incorrect pre-shared key would prevent Phase 1 from completing, but the question states Phase 2 is up, meaning Phase 1 and authentication succeeded. Option D is wrong because if the Phase 2 proposal included incorrect local or remote subnets, Phase 2 would not come up; since Phase 2 is up, the proposal is correct, and the issue lies in how traffic is routed to the tunnel.

659
MCQeasy

A FortiGate is deployed in NAT/Route mode. The administrator wants to create a policy that allows internal users to access the internet and also translates their private IP addresses to the public IP of the FortiGate's WAN interface. Which policy configuration is required?

A.Configure a virtual IP (VIP) for the WAN interface
B.Set the policy action to ACCEPT and enable SNAT in the policy advanced options
C.Add a static route with NAT enabled
D.Enable NAT on the firewall policy
AnswerD

Enabling NAT on the firewall policy is the explicit mechanism for source NAT in NAT/route mode. When checked, the FortiGate overwrites the source IP of matching outbound sessions with the IP address of the egress interface (or an IP pool if configured). This is the correct and minimal configuration to allow internal private hosts to initiate Internet-bound sessions.

Why this answer

In NAT/Route mode, enabling NAT on the firewall policy performs source NAT (SNAT) by default, translating the private source IP addresses of internal users to the public IP address of the FortiGate's WAN interface. This is the standard method for allowing internal users to access the internet while hiding their private addresses behind a single public IP.

Exam trap

The trap here is that candidates may confuse source NAT (enabled on the firewall policy) with destination NAT (configured via VIPs) or mistakenly think NAT is a routing feature, leading them to select options like static route with NAT or VIP configuration.

How to eliminate wrong answers

Option A is wrong because a virtual IP (VIP) is used for destination NAT (DNAT), translating incoming traffic's destination IP to an internal server, not for translating source IPs of outbound traffic. Option B is wrong because while setting the policy action to ACCEPT is necessary, SNAT is not a separate toggle in advanced options; NAT is enabled directly on the firewall policy, and there is no 'SNAT' checkbox distinct from the NAT option. Option C is wrong because static routes do not have a NAT feature; NAT is configured at the firewall policy level, not on routing entries.

660
MCQeasy

Which security profile is used to detect and prevent network-based attacks by analyzing traffic patterns and comparing them against known attack signatures?

A.DLP profile
B.IPS profile
C.Web filter profile
D.Antivirus profile
AnswerB

The IPS security profile uses a continuously updated FortiGuard IPS signature database, protocol anomaly detection, and packet-level deep inspection to identify and block network attack attempts in real time. It covers known CVE exploits, SQL injection, cross-site scripting, and other malicious network traffic. As the dedicated intrusion prevention mechanism, it is the correct profile for detecting and preventing network attacks.

Why this answer

The Intrusion Prevention System (IPS) profile is specifically designed to detect and prevent network-based attacks by inspecting traffic patterns and comparing them against a database of known attack signatures. Unlike other security profiles that focus on content or application-layer threats, the IPS profile operates at the network and transport layers to identify malicious patterns such as exploit attempts, buffer overflows, and denial-of-service attacks.

Exam trap

The trap here is that candidates often confuse the IPS profile with the Antivirus profile, mistakenly thinking that antivirus handles all signature-based detection, but antivirus only scans files for malware, not network traffic patterns for attack signatures.

How to eliminate wrong answers

Option A is wrong because a DLP (Data Loss Prevention) profile is used to monitor and prevent the unauthorized transmission of sensitive data, not to detect network-based attacks via traffic pattern analysis. Option C is wrong because a Web filter profile controls access to websites based on categories, URLs, or content, and does not analyze traffic patterns for attack signatures. Option D is wrong because an Antivirus profile scans files and content for malware signatures, but it does not analyze general network traffic patterns or detect network-layer attacks like those identified by an IPS.

661
MCQmedium

A FortiGate administrator configures a captive portal on a VDOM to authenticate users connecting to a guest SSID. The authentication method is set to LDAP. Users can reach the captive portal login page, but after entering valid credentials, they receive an authentication failure. The LDAP server is reachable from the FortiGate. What is the MOST likely cause?

A.The user is not a member of the configured user group
B.The captive portal is using HTTP instead of HTTPS
C.The captive portal interface is not in the same VDOM as the LDAP server
D.The LDAP server requires TLS and FortiGate is using plain LDAP
AnswerA

FortiGate uses LDAP for credential validation, but the firewall policy specifies a particular user group that must contain the authenticated account. After the LDAP bind succeeds, FortiGate performs a group lookup against the configured group; if the user is not a member, the captive portal rejects the login even though the password was correct. This is an authorization failure rather than an authentication failure, and it is the classic cause of a captive portal rejecting valid LDAP creds.

Why this answer

The most likely cause is that the user is not a member of the configured user group. In FortiGate, when LDAP authentication is used for a captive portal, the FortiGate first verifies the user's credentials against the LDAP server. Even if the credentials are valid, the FortiGate then checks whether the authenticated user belongs to a specific user group that is permitted to access the captive portal.

If the user is not a member of that group, the authentication fails, even though the LDAP server itself accepts the credentials.

Exam trap

The trap here is that candidates often assume LDAP authentication failure is always due to connectivity or protocol issues (like TLS or HTTP), but FortiGate's group membership enforcement is a distinct step that can cause failure even with valid credentials and a reachable server.

How to eliminate wrong answers

Option B is wrong because using HTTP instead of HTTPS for the captive portal would not cause an authentication failure after valid credentials are entered; it would only expose credentials in transit but not prevent successful authentication. Option C is wrong because the captive portal interface and the LDAP server do not need to be in the same VDOM; the LDAP server is reachable from the FortiGate, and VDOM separation does not affect LDAP authentication as long as routing permits. Option D is wrong because if the LDAP server required TLS and the FortiGate used plain LDAP, the connection would fail entirely, and the user would not even reach the captive portal login page or receive an authentication failure after entering credentials; instead, a timeout or connection error would occur.

662
MCQeasy

An administrator needs to send logs from a FortiGate to a remote FortiAnalyzer for centralized log storage and analysis. Which configuration step is required on the FortiGate?

A.Configure a firewall policy allowing traffic from FortiGate to FortiAnalyzer on port 514
B.Set the FortiAnalyzer as the log destination in Log Settings
C.Create a log forwarding rule to forward all logs to the FortiAnalyzer
D.Install a FortiGate connector on the FortiAnalyzer
AnswerB

Set the FortiAnalyzer as the log destination in Log Settings. Under System > Log Settings (or via CLI 'config log fortianalyzer setting'), the administrator must specify the FortiAnalyzer IP address and enable log transmission. This action directs the FortiGate to send logs using the native FortiAnalyzer protocol, which provides reliable, acknowledged log delivery. Without this configuration, logs will never leave the FortiGate, regardless of any firewall policies or forwarding rules.

Why this answer

To send logs to FortiAnalyzer, the administrator must configure the FortiAnalyzer as a remote log destination under Log Settings. This is done via 'config log fortianalyzer setting' and specifying the server IP and other parameters.

663
Multi-Selectmedium

An administrator wants to ensure that all DNS traffic from internal users is filtered by the FortiGate to block malicious domains. Which TWO configurations are necessary? (Choose two.)

Select 2 answers
A.Set DNS server to FortiGate's IP
B.Apply the DNS filter profile to a firewall policy that matches DNS traffic
C.Create a DNS filter profile and set action for malicious domains to 'block'
D.Enable sinkhole on the DNS filter profile
E.Configure SSL deep inspection for DNS over HTTPS
AnswersB, C

To enforce DNS filtering, the administrator must create a firewall policy that matches outbound DNS traffic (typically UDP/TCP port 53 from internal clients) and attach the DNS filter profile to that policy. Only when the profile is referenced by a policy does the FortiGate's DNS proxy engine evaluate each query against the FortiGuard category database. Without this policy binding, the profile remains an unused configuration object and all DNS traffic passes unfiltered.

Why this answer

A DNS filter profile must be applied to a firewall policy that matches DNS traffic for the filtering to take effect. Without this policy-level binding, the DNS filter profile is not enforced, even if it is configured. This ensures that all DNS queries from internal users are inspected by the FortiGate.

Exam trap

The trap here is that candidates often think configuring the DNS filter profile alone is enough, forgetting that it must be explicitly applied to a firewall policy to be enforced.

664
MCQhard

An administrator executes 'diagnose debug flow' for a specific session and sees the output: 'id=20085 trace_id=10 func=print_pkt_detail line=5567 msg="vd-root:0 received packet via port1".' Later, the trace shows 'msg="Deny by policy"'. What is the most likely next step the administrator should take?

A.Check the routing table for the destination
B.Review the firewall policies that apply to the traffic and modify as needed
C.Restart the FortiGate to clear session table
D.Enable session helper for the protocol
AnswerB

The debug flow output's 'Deny by policy' verdict means the FortiGate's firewall policy engine evaluated the packet against the configured policy set and explicitly rejected it, typically due to the absence of a matching permit policy, a matching explicit deny policy, or a policy that disallows the tuple (source, destination, service, user, etc.). Because the packet is denied before session creation, the administrator should inspect the policy list with `diagnose firewall policy list` or via the GUI, and either adjust the existing policy's matching criteria/action or create a new permit policy that allows the legitimate traffic. Correctly aligning the policy to the intended traffic flow is the direct and standard fix, avoiding unnecessary service disruption.

Why this answer

The debug flow output shows the packet was received on port1 and then hit 'Deny by policy', meaning a firewall policy explicitly blocked the traffic. The next logical step is to review the firewall policies that match the traffic's source, destination, service, and incoming interface, and adjust them to permit the intended flow.

Exam trap

NSE4 often tests debug flow message interpretation — candidates see 'Deny by policy' and jump to routing or session issues instead of recognizing it as a firewall policy match failure.

How to eliminate wrong answers

Option A is wrong because the trace already shows the packet reached policy evaluation — routing was resolved enough to select a policy, so routing is not the failure point. Option C is wrong because restarting the FortiGate is disruptive and unnecessary; the deny is a policy decision, not a stuck session table. Option D is wrong because session helpers (e.g., for FTP, SIP) affect application-layer inspection and pinhole creation, not the initial policy deny decision.

665
MCQeasy

A FortiGate administrator receives an alert that the FortiGuard antivirus database on the firewall is outdated. Which subscription service must be active to update the antivirus signatures?

A.FortiGuard IPS Service
B.FortiGuard Application Control Service
C.FortiGuard Antivirus Service
D.FortiGuard Web Filtering Service
AnswerC

FortiGuard Antivirus Service is responsible for delivering up-to-date antivirus engines and virus signature files to the FortiGate, enabling scanning of files, email attachments, and web downloads for known malware. When the administrator sees an alert that antivirus signatures are outdated or failed to update, this is the subscription service to verify and troubleshoot. Without this service, the FortiGate cannot reliably block malicious content based on virus definitions. Therefore, it is the correct choice.

Why this answer

The FortiGuard Antivirus Service subscription is the specific entitlement that provides signature updates for the antivirus engine on a FortiGate. Without an active FortiGuard AV subscription, the FortiGate cannot download updated virus definition databases, which is exactly the alert described. Each FortiGuard subscription is licensed and updated independently, so only the AV service covers AV signature refresh.

Exam trap

NSE4 often tests whether candidates can map a specific FortiGuard update (AV, IPS, App Control, Web Filter) to the correct subscription service, since all four are bundled in UTM and candidates assume any active subscription updates everything.

How to eliminate wrong answers

Option A is wrong because the FortiGuard IPS Service delivers intrusion prevention signatures and engine updates, not antivirus definitions. Option B is wrong because the Application Control Service provides application signature databases for identifying and controlling applications, not virus signatures. Option D is wrong because the Web Filtering Service provides URL/category ratings and web filtering databases, which are unrelated to antivirus signature updates.

666
MCQeasy

A network administrator needs to configure a FortiGate to participate in SNMP monitoring. Which CLI command enables SNMP agent on the FortiGate?

A.config system snmp set status enable
B.set system snmp enable
C.set snmp agent enable
D.enable snmp service
AnswerA

The valid FortiGate CLI sequence to turn on SNMP is navigating to the `config system snmp` branch and running `set status enable`. This `config` block manages the SNMP agent hosted on the FortiGate; `status enable` is the required toggle to start the agent. Issuing these commands enables SNMP to listen on the management interface and allows you to then configure SNMP communities, hosts, and trap receivers within the same configuration section.

Why this answer

The correct command to enable the SNMP agent on a FortiGate is 'config system snmp' followed by 'set status enable'. This enters the SNMP configuration context and activates the SNMP agent, which is required for the FortiGate to respond to SNMP queries from management systems. Without this command, the SNMP service remains disabled regardless of other SNMP settings.

Exam trap

The trap here is that candidates often confuse the FortiGate CLI syntax with Cisco IOS commands, where 'snmp-server enable' or 'snmp-server community' are used, leading them to select a similarly phrased but incorrect option like 'enable snmp service'.

How to eliminate wrong answers

Option B is wrong because 'set system snmp enable' is not a valid FortiGate CLI command; the correct syntax requires entering the 'config system snmp' context first. Option C is wrong because 'set snmp agent enable' does not exist in FortiGate CLI; the agent is controlled via the 'status' parameter under 'config system snmp'. Option D is wrong because 'enable snmp service' is not a valid FortiGate command; SNMP is managed through the 'config system snmp' hierarchy, not a simple service enable command.

667
MCQmedium

A FortiGate is configured with two ISPs (WAN1 and WAN2) and uses SD-WAN for load balancing. The administrator notices that traffic to a critical SaaS application is being sent over the slower link. What should the administrator do to ensure this traffic uses the faster link?

A.Create an SD-WAN rule to match the SaaS application's destination and set preferred member to the faster link.
B.Remove the slower link from the SD-WAN interface.
C.Increase the bandwidth on the slower link.
D.Configure policy-based routing for the SaaS application.
AnswerA

An SD-WAN rule configured with an application match for the SaaS traffic and a preferred member set to the faster link is the correct approach because SD-WAN rules can steer traffic based on Layer 7 application signatures and dynamic link performance metrics. The preferred member acts as a tie-breaker, forcing the traffic to use the specified interface as long as it meets the SD-WAN health-check SLA (latency, jitter, packet loss), while still allowing automatic failover to the backup link if the preferred link degrades. This preserves redundancy and ensures the SaaS application consistently uses the best-performing path.

Why this answer

SD-WAN rules allow you to define traffic steering policies based on application or destination, and setting a preferred member explicitly directs matching traffic to the faster link. This overrides the default load-balancing algorithm, ensuring critical SaaS traffic uses the optimal path without affecting other traffic.

Exam trap

The trap here is that candidates often confuse SD-WAN rules with policy-based routing, thinking PBR can achieve the same result, but PBR lacks SD-WAN's application awareness, SLA monitoring, and seamless failover integration.

How to eliminate wrong answers

Option B is wrong because removing the slower link from the SD-WAN interface would eliminate redundancy and failover capability, not solve the traffic steering issue. Option C is wrong because increasing bandwidth on the slower link does not change the SD-WAN load-balancing decision; the traffic would still be sent to that link based on the current algorithm. Option D is wrong because policy-based routing (PBR) is a static routing mechanism that does not integrate with SD-WAN's dynamic path selection, performance SLA monitoring, or application-based steering, and it can conflict with SD-WAN rules.

668
MCQmedium

A FortiGate administrator needs to forward logs to a FortiAnalyzer for centralized management. The FortiAnalyzer is reachable at 10.0.1.100. Which configuration step is required on the FortiGate to send logs to this FortiAnalyzer?

A.Configure a syslog server under Log Setting
B.Add a firewall policy allowing traffic from FortiGate to FortiAnalyzer
C.Configure the FortiAnalyzer in System > FortiAnalyzer
D.Enable logging to FortiCloud instead
AnswerC

This is the correct method because it establishes the native, authenticated FortiAnalyzer connection. Under System > FortiAnalyzer, you specify the FortiAnalyzer IP address, set an access token or serial number, and enable logging; this configures the FortiGate to use FortiAnalyzer's proprietary logging protocol (FAS) with features like log buffering, encryption, and compression. The CLI equivalent, 'config log fortianalyzer setting', offers the same options and is often used in automated deployments. Once configured, the FortiGate begins forwarding all configured log types to FortiAnalyzer for centralized logging, analytics, and reporting.

Why this answer

To send logs to FortiAnalyzer, the administrator must configure the FortiAnalyzer server under System > FortiAnalyzer or via CLI using 'config log fortianalyzer setting set server 10.0.1.100'. The log forwarding policy is not used for FortiAnalyzer.

669
Multi-Selectmedium

An administrator is configuring a FortiGate to send logs to a FortiAnalyzer. Which TWO of the following are required? (Choose two.)

Select 2 answers
A.Enable local logging on the FortiAnalyzer
B.Create a firewall policy on the FortiGate to allow log traffic
C.Ensure network connectivity between FortiGate and FortiAnalyzer
D.Disable local logging on the FortiGate
E.Configure the FortiGate to send logs to the FortiAnalyzer
AnswersC, E

Ensuring network connectivity between the FortiGate and FortiAnalyzer is the essential prerequisite because the FortiGate must be able to reach the FortiAnalyzer's IP address on the correct port (e.g., HTTPS 443, SSH 22, or Syslog 514). Without IP reachability, proper routing, and administrative access enabled on the interface, log transmission cannot occur regardless of any other configuration. This step verifies the underlying transport path and is often the root cause when logs fail to appear on the FortiAnalyzer.

Why this answer

The FortiGate must have IP reachability to the FortiAnalyzer to send logs over the network, typically using TCP port 514 (syslog) or FortiGate's proprietary log forwarding protocol. Without network connectivity, log transmission will fail regardless of configuration.

Exam trap

The trap here is that candidates often think a firewall policy is needed to allow log traffic, but FortiGate's own traffic (including logs) is not subject to firewall policies; only transit traffic requires policies.

670
MCQmedium

An administrator is configuring a new FortiGate HA cluster in active-passive mode. The administrator wants to ensure that the primary unit is always the same physical device, even after a reboot or failure, as long as it is operational. Which HA setting should the administrator configure?

A.Set the HA priority to a higher value on the preferred primary unit.
B.Configure the HA group ID to match the unit's serial number.
C.Set the HA mode to active-active.
D.Enable HA override on the preferred primary unit.
AnswerD

Enabling HA override allows a unit with a higher priority to take over as primary when it becomes available, even if another unit is currently primary. This ensures the preferred unit always becomes primary after a reboot or failure, as long as it is operational. Override must be enabled on the unit that should become primary.

Why this answer

To ensure a specific unit always becomes primary when available, the administrator should enable HA override on that unit and set its priority higher than the other unit. Override allows the unit to preempt the current primary after it reboots or recovers from a failure, maintaining a consistent primary device.

Exam trap

The trap here is assuming that setting a higher priority alone is sufficient; without override enabled, the unit will not reclaim the primary role after recovering from a failure.

671
MCQhard

A FortiGate HA cluster is experiencing frequent failovers. The administrator checks the HA event log and sees repeated 'Heartbeat loss' messages. The heartbeat interfaces are connected directly via a crossover cable. What is the MOST likely cause?

A.The session pickup option is enabled
B.The HA uptime monitor is enabled and tracking a failed interface
C.The HA override setting is disabled
D.The heartbeat interface has a duplex mismatch
AnswerD

A duplex mismatch on the heartbeat interface is the classic cause of intermittent heartbeat loss: one side runs at full duplex and the other at half duplex, leading to late collisions, CRC errors, and frame drops that tend to occur in bursts. These dropped frames are exactly what the HA process sees as a missing heartbeat. If the heartbeat timeout is repeatedly exceeded, the cluster concludes the peer is down and triggers a failover; once traffic resumes, another lost burst starts the cycle, producing the observed frequent failovers.

Why this answer

A duplex mismatch on the heartbeat interface causes intermittent link errors and dropped heartbeat packets, leading to repeated 'Heartbeat loss' messages and frequent failovers. Since the interfaces are directly connected via crossover cable, a speed/duplex mismatch is the most likely physical-layer cause.

Exam trap

NSE4 often tests physical-layer causes of HA instability; the trap is overlooking duplex mismatch and instead blaming HA settings like override or session pickup.

How to eliminate wrong answers

Option A is wrong because session pickup affects session synchronization, not heartbeat integrity, and would not cause heartbeat loss. Option B is wrong because HA uptime monitoring tracks interface availability for failover decisions but does not generate heartbeat loss messages on a direct link. Option C is wrong because HA override controls whether a higher-priority unit preempts, not heartbeat communication reliability.

672
MCQmedium

An administrator needs to configure two-factor authentication for SSL VPN users using FortiToken. Which configuration is required on the FortiGate?

A.Enable two-factor authentication globally on the FortiGate
B.Enable FortiToken on the user account and configure the authentication scheme to require token
C.Install the FortiToken mobile app on the FortiGate
D.Create a separate firewall policy for token-based authentication
AnswerB

To enforce two-factor, assign a FortiToken to the user account in the user definition (e.g., register the FortiToken Mobile seed) and then set the required authentication method in the authentication scheme to 'FortiToken' or 'Token-based'. The scheme, not the firewall policy, defines how many and which authentication factors are accepted, and this scheme is then referenced by the security policy using identity-based authentication. Without assigning the token and enforcing it in the scheme, merely having the app installed does nothing.

Why this answer

FortiGate requires two-factor authentication to be enabled on the user account itself (via the 'Two-factor Authentication' field set to 'FortiToken') and then an authentication scheme must be configured that includes a 'Token' requirement. This ensures that the user must provide both their password and a one-time token from the FortiToken device or app during SSL VPN login.

Exam trap

The trap here is that candidates assume two-factor authentication is a global setting or that installing the app on the FortiGate is required, when in fact it is a per-user configuration combined with an authentication scheme and rule.

How to eliminate wrong answers

Option A is wrong because FortiGate does not have a global toggle for two-factor authentication; it must be configured per user or per user group. Option C is wrong because the FortiToken mobile app is installed on the user's smartphone, not on the FortiGate itself; the FortiGate only needs the token seed or serial number. Option D is wrong because firewall policies do not control authentication methods; they control traffic flow based on source/destination, and token-based authentication is handled at the authentication profile or scheme level, not in a firewall policy.

673
MCQhard

An administrator needs to implement two-factor authentication for SSL VPN access using FortiToken. Which configuration steps are required?

A.Assign a FortiToken to the user and set the user's authentication method to two-factor
B.Configure the RADIUS server to send FortiToken challenges
C.Enable FortiToken on the firewall policy
D.Enable two-factor authentication on the SSL VPN portal settings
AnswerA

In FortiOS, two-factor authentication is a property of the user object, not the service. You must first assign a FortiToken (hardware or mobile token) to the user, then set the user's 'Two-factor Authentication' to 'FortiToken' (or 'Email' etc). Only then will FortiGate challenge the user with a token code during any authentication flow, including firewall login, SSL VPN, or IPsec. This ensures the token is bound to the user and enforced universally.

Why this answer

To implement two-factor authentication for SSL VPN using FortiToken, you must assign a FortiToken to the user and set the user's authentication method to two-factor. This is done in the user configuration (e.g., under User & Authentication > User Definition) by selecting 'FortiToken' as the second factor and linking the token serial number. This ensures that during SSL VPN login, the user must provide both their password and a one-time password from the FortiToken, which is validated locally by the FortiGate without requiring an external RADIUS server.

Exam trap

The trap here is that candidates often assume two-factor authentication can be enabled globally on the SSL VPN portal or firewall policy, but Fortinet specifically requires the token to be assigned to the individual user object with the authentication method set to two-factor, making option A the only correct step among the choices.

How to eliminate wrong answers

Option B is wrong because configuring the RADIUS server to send FortiToken challenges is not required; FortiToken authentication is handled natively by the FortiGate itself, not via RADIUS challenge-response. Option C is wrong because enabling FortiToken on the firewall policy is not a valid step; firewall policies control traffic flow but do not have a direct setting for FortiToken—two-factor authentication is configured at the user or authentication rule level. Option D is wrong because enabling two-factor authentication on the SSL VPN portal settings is not sufficient; the portal settings control interface behavior (e.g., web mode options) but do not enforce token-based authentication—that requires the user object to have the token assigned and the authentication method set to two-factor.

674
MCQmedium

A network administrator needs to configure a FortiGate to allow administrative access from a specific management subnet only. Which configuration step should be taken?

A.Create a local-in policy to permit traffic from the management subnet.
B.Disable administrative access on all interfaces except the management interface.
C.Configure an inbound firewall policy allowing HTTPS from the management subnet to the FortiGate's interface IP.
D.Under system > admin > settings, restrict administrative access to trusted hosts.
AnswerD

Restricting administrative access to trusted hosts under System > Admin > Settings limits logins to the specified management subnet, satisfying the requirement that only that subnet may administer the FortiGate. Other admin settings do not enforce source-address restrictions.

Why this answer

The 'Trusted Hosts' feature under System > Admin > Settings allows you to restrict administrative access (HTTPS, SSH, Telnet, etc.) to specific source IP addresses or subnets. This is the intended method for limiting management access to a management subnet without affecting other traffic or interface configurations.

Exam trap

The trap here is that candidates often confuse local-in policies with trusted hosts, thinking that a local-in policy is the primary method for restricting management access, when in fact trusted hosts is the simpler and correct approach for source-based restriction.

How to eliminate wrong answers

Option A is wrong because a local-in policy filters traffic destined to the FortiGate itself, but it is typically used for advanced traffic shaping or rate limiting, not for restricting administrative access based on source subnet; using it for this purpose would be overly complex and not the standard practice. Option B is wrong because disabling administrative access on all interfaces except the management interface does not restrict access by source IP; it only limits which interfaces can be used for management, but any host on the management subnet could still access the FortiGate from that interface. Option C is wrong because an inbound firewall policy controls traffic passing through the FortiGate (forward traffic), not traffic destined to the FortiGate itself (local-in traffic); administrative access is governed by local-in policies or trusted hosts, not by standard firewall policies.

675
MCQmedium

During an IPsec VPN troubleshooting, you run 'diagnose vpn ike config' and see the output includes 'peer-id: any'. What does this mean?

A.The FortiGate will accept connections from any remote IP address.
B.The FortiGate will use aggressive mode for IKE negotiation.
C.The Phase 2 selectors are configured for any protocol.
D.The FortiGate will accept any peer identity during IKE authentication.
AnswerD

In FortiOS, when the Phase 1 configuration sets peer-id to 'any' (or leaves it unset), the FortiGate does not validate the identity payload sent by the remote gateway during IKE negotiation. Instead, it accepts any peer ID, relying solely on the PSK or certificate for authentication. This is useful when the remote peer uses a dynamic identifier, but it should be used with caution because identity-based verification is disabled. This is the correct behavior.

Why this answer

The 'peer-id: any' output in 'diagnose vpn ike config' indicates that the FortiGate is configured to accept any peer identity during IKE authentication. This means the FortiGate will not validate the identity presented by the remote peer (e.g., IP address, FQDN, or user ID) against a specific value in the Phase 1 configuration. This is common when using pre-shared keys and not requiring strict peer identity validation.

Exam trap

The trap here is that candidates often confuse 'peer-id: any' with allowing any source IP address (Option A), but it specifically controls identity validation during IKE authentication, not the remote gateway IP.

How to eliminate wrong answers

Option A is wrong because 'peer-id: any' refers to the peer identity used during IKE authentication, not the source IP address; the remote IP address is controlled by the 'remote-gw' setting. Option B is wrong because aggressive mode is determined by the 'mode' setting (aggressive vs. main) in the Phase 1 configuration, not by the peer-id value. Option C is wrong because Phase 2 selectors (protocol, port, etc.) are configured separately under the Phase 2 settings, and 'peer-id: any' has no relation to them.

Page 8

Page 9 of 11

Page 10

All pages