Courseiva

CCNA Firewall Policies and NAT Questions

75 of 193 questions · Page 1/3 · Firewall Policies and NAT · Answers revealed

1
MCQhard

A FortiGate has two firewall policies: Policy ID 1 (source: 10.0.1.0/24, destination: 203.0.113.0/24, action: allow, NAT: enabled) and Policy ID 2 (source: 10.0.1.0/24, destination: all, action: allow, NAT: enabled, IP pool: pool1). A user from 10.0.1.10 sends traffic to 203.0.113.5. Which policy will the traffic match and why?

A.Both policies will be applied because the traffic matches both
B.Policy ID 2 because it has a broader destination and is more inclusive
C.Policy ID 1 because it is the first matching policy in the list
D.Neither policy; implicit deny will block the traffic
AnswerC

FortiGate performs a sequential lookup from the top of the policy list, and the first policy whose source, destination, service, user, and other attributes match the packet becomes the winner. Here, Policy ID 1 meets the session's source and destination, so the lookup terminates immediately. Consequently, Policy ID 1 is the only rule applied, even if later rules are equally or more general.

Why this answer

Policy ID 1 is correct because FortiGate uses a sequential, first-match policy evaluation model. Traffic from 10.0.1.10 to 203.0.113.5 matches the source and destination of Policy ID 1 exactly, and since it appears first in the policy list, it is applied immediately. Once a match is found, no further policies are evaluated, even if a later policy (like Policy ID 2) also matches.

Exam trap

The trap here is that candidates often assume a broader or more inclusive policy (like 'destination all') will override a more specific one, but FortiGate's first-match logic means policy order, not specificity, determines which policy is applied.

How to eliminate wrong answers

Option A is wrong because FortiGate does not apply multiple policies to the same traffic; it stops at the first match. Option B is wrong because FortiGate does not select policies based on inclusivity or broader destination; it strictly follows the order in the policy list. Option D is wrong because the traffic explicitly matches Policy ID 1, which has an allow action, so the implicit deny is never reached.

2
MCQhard

An administrator configures a VIP for port forwarding: public IP 203.0.113.10 port 8080 to internal server 10.0.1.10 port 80. External users can connect to http://203.0.113.10:8080 but receive a timeout. The firewall policy allows traffic from any to the VIP on destination port 8080. The internal server is reachable from internal hosts. What is the most likely problem?

A.The internal server is not running a web server
B.The VIP is not associated with the policy
C.The policy destination service is set to HTTP (port 80) instead of port 8080
D.The source NAT is not configured
AnswerC

The policy's destination service is incorrectly set to HTTP (port 80) instead of the pre-NAT destination port 8080. FortiGate evaluates firewall policies against the packet's original destination port before any NAT translation occurs, so the policy must match the port the client connects to (i.e., the external port on the VIP, 8080). Using service HTTP (port 80) will cause the implicit deny rule to drop the packets because the session's destination port does not match the policy's service. The correct fix is to change the service to the pre-NAT port (e.g., a custom TCP/8080 service) or adjust the VIP to listen on port 80.

Why this answer

The firewall policy must match the destination port of the incoming traffic. External users connect to port 8080 on the VIP, but if the policy's destination service is set to HTTP (port 80), the policy will not match traffic destined for port 8080. Even though the VIP translates the destination to port 80 on the internal server, the firewall policy evaluation occurs before NAT translation, so the policy must match the original destination port (8080).

Exam trap

The trap here is that candidates mistakenly think the policy should match the internal server's port (80) because the VIP translates to that port, but FortiOS policy evaluation occurs before NAT, so the policy must match the original destination port (8080).

How to eliminate wrong answers

Option A is wrong because the internal server is reachable from internal hosts, confirming the web server is running and functional. Option B is wrong because VIPs in FortiOS are automatically associated with firewall policies that reference them; the VIP does not need a separate association step. Option D is wrong because source NAT (SNAT) is not required for inbound port forwarding; the VIP handles destination NAT, and return traffic is automatically handled by the session table without explicit SNAT configuration.

3
MCQeasy

A FortiGate administrator needs to allow inbound SSH access from the internet to a single internal server at IP 10.0.1.10. The public IP on the WAN interface is 203.0.113.5. Which type of object should be configured to map the public IP and port to the internal server?

A.IP Pool
B.Central NAT policy
C.Virtual IP (VIP)
D.Address object
AnswerC

A Virtual IP (VIP) is the FortiOS object that enables destination NAT and port forwarding for inbound traffic, which is exactly what is needed to allow SSH from the internet to an internal server. The administrator defines a VIP entry with the public interface IP and TCP port 22, maps it to the internal server's private IP and port 22, and then uses that VIP as the destination in a firewall policy that permits tcp/22. When a packet arrives for the public IP, the FortiGate rewrites the destination address to the internal IP, allowing the session to reach the SSH daemon.

Why this answer

A Virtual IP (VIP) object is the correct choice because it specifically maps a public IP and port (203.0.113.5:22) to a private IP and port (10.0.1.10:22) for inbound destination NAT (DNAT). This allows external SSH traffic to reach the internal server by translating the destination address and port at the FortiGate WAN interface.

Exam trap

The trap here is that candidates often confuse IP Pools (used for source NAT) with Virtual IPs (used for destination NAT), leading them to select Option A when the question clearly requires inbound mapping.

How to eliminate wrong answers

Option A is wrong because an IP Pool is used for source NAT (SNAT) to translate the source IP of outbound traffic, not for inbound destination mapping. Option B is wrong because Central NAT policy is a centralized method to define NAT rules, but it still requires a VIP object to specify the destination translation; it is not the object itself. Option D is wrong because an Address object only defines a network or host IP for policy matching, but it does not provide the port mapping or translation functionality needed for inbound access.

4
MCQmedium

An administrator runs 'diagnose firewall iprope list 100000' and sees 'action=deny' entries for traffic that should be allowed. The policy list shows an allow policy with ID 1 for that traffic. What is the most likely cause of the deny?

A.The traffic is being blocked by a local-in policy
B.The implicit deny rule is being triggered because the policy is disabled
C.The firewall policy is not installed in the kernel due to an error
D.A security profile is dropping the traffic after the policy matches
AnswerC

The 'diagnose firewall iprope list' command displays the kernel's actual IPv4 firewall policy list. If a policy fails to install—due to memory constraints, commit errors, or conflicting objects—it will be absent from this output, causing traffic to fall through to the implicit deny rule. An error message in the command's output or a missing policy ID is the direct indicator of a kernel installation failure, making this the correct explanation.

Why this answer

The 'diagnose firewall iprope list 100000' command displays the kernel-level firewall policy list. If the policy list shows an allow policy (ID 1) but the kernel entries show 'action=deny', it indicates that the policy was not successfully installed into the kernel's connection tracking or firewall engine. This typically occurs due to a policy installation error, such as a configuration inconsistency or a failure during the commit process, causing the kernel to fall back to a default deny action for that traffic.

Exam trap

The trap here is that candidates assume the policy list shown in the GUI or CLI always reflects the active kernel state, but Fortinet tests the understanding that a policy may exist in the configuration yet fail to install into the kernel, causing unexpected denies despite an apparent allow rule.

How to eliminate wrong answers

Option A is wrong because local-in policies apply to traffic destined to the FortiGate itself (e.g., management traffic), not to traffic passing through the firewall, and the question describes traffic that should be allowed by a policy, implying transit traffic. Option B is wrong because if the policy were disabled, it would not appear in the policy list as an allow policy with ID 1; a disabled policy is not evaluated, and the implicit deny would only apply if no other policy matches, but here the policy exists and is enabled. Option D is wrong because security profiles (e.g., antivirus, web filter) are applied after a policy match and would not cause a 'deny' action in the kernel iprope list; they would instead log a separate action like 'block' or 'reset' at the application layer, not a kernel-level deny.

5
MCQeasy

An administrator needs to block access to specific websites based on their FQDN (e.g., *.example.com). The FortiGate should match the destination domain regardless of the IP address the domain resolves to. Which type of address object should the admin use in the firewall policy destination?

A.Geography object
B.Subnet object
C.Wildcard FQDN object
D.FQDN object
AnswerC

Wildcard FQDN supports patterns with * to match multiple domains.

Why this answer

A Wildcard FQDN object allows the FortiGate to match traffic based on the destination domain name pattern (e.g., *.example.com) regardless of the IP address the domain resolves to. This object type performs DNS-based policy enforcement, where the FortiGate inspects the SNI field in the TLS handshake or the Host header in HTTP to match the FQDN pattern, not the destination IP.

Exam trap

The trap here is that candidates often confuse a standard FQDN object with a Wildcard FQDN object, assuming the FQDN object supports wildcard patterns or dynamic IP resolution, when in fact it only resolves to a static IP at policy installation time and cannot match patterns like *.example.com.

How to eliminate wrong answers

Option A is wrong because a Geography object matches traffic based on the source or destination IP address's geographic location (country), not the FQDN. Option B is wrong because a Subnet object matches traffic based on a specific IP address or range (e.g., 10.0.0.0/24), which cannot account for dynamic IP resolution of a domain. Option D is wrong because a standard FQDN object resolves the domain to a single IP address at policy installation time and does not support wildcard patterns like *.example.com; it also cannot match traffic if the domain resolves to multiple IPs or changes over time.

6
Multi-Selecthard

A FortiGate is configured with policy-based NAT and multiple IP pools. The administrator wants traffic from the 192.168.1.0/24 subnet to use IP pool 'POOL1' (203.0.113.1-203.0.113.10) and traffic from 192.168.2.0/24 to use IP pool 'POOL2' (203.0.113.11-203.0.113.20). Which THREE steps are necessary?

Select 3 answers
A.Create two firewall policies, one for each subnet
B.In each policy, enable NAT and select the corresponding IP pool
C.Configure a single firewall policy with both subnets in the source address group
D.Create two IP pool objects, POOL1 and POOL2
E.Enable Central NAT and define two NAT policies
AnswersA, B, D

Two firewall policies are required because policy-based NAT binds the source translation directly to the policy entry. Since each subnet must egress with a different public IP pool, a separate policy for each subnet allows the FortiGate to select the correct pool based on the source address. This creates a clean one-to-one mapping of source subnet to NAT pool, with no reliance on routing or additional match conditions.

Why this answer

Policy-based NAT requires separate firewall policies to apply different IP pools to different source subnets. Each firewall policy can have its own NAT settings, including a specific IP pool, allowing traffic from 192.168.1.0/24 to use POOL1 and traffic from 192.168.2.0/24 to use POOL2.

Exam trap

The trap here is that candidates may think a single policy with multiple source addresses can apply different NAT pools, but FortiGate policy-based NAT requires separate policies for distinct NAT configurations.

7
MCQhard

An organization has a FortiGate with two internet connections (WAN1 and WAN2). They want traffic to a specific web service (203.0.113.50 port 443) to always exit via WAN2. All other internet traffic should use WAN1. Which feature should be used to achieve this?

A.Central NAT policy to force the traffic out of WAN2
B.Static route with a higher priority for WAN2 to 203.0.113.0/24
C.SD-WAN with a strategy of 'Best Quality'
D.Policy-based routing (PBR) configured with a policy matching the destination and service
AnswerD

PBR overrides the routing table lookup for matching traffic, letting you steer sessions to 203.0.113.50:443 out WAN2 while the default route sends everything else via WAN1. A plain static route cannot selectively match destination plus service, so PBR satisfies the per-service egress constraint.

Why this answer

Policy-based routing (PBR) allows you to override the routing table based on match criteria such as source/destination IP, port, or protocol. In this scenario, you create a PBR policy that matches destination 203.0.113.50 and service TCP/443, then sets the next-hop to the WAN2 gateway. This ensures that only traffic to that specific web service exits via WAN2, while all other traffic follows the default route via WAN1.

Exam trap

The trap here is that candidates confuse policy-based routing with static routing or SD-WAN strategies, assuming that a more specific static route or a quality-based SD-WAN rule can achieve the same per-service interface selection, but only PBR provides the necessary layer-4 granularity to match both destination IP and port.

How to eliminate wrong answers

Option A is wrong because Central NAT policy controls source NAT translation (e.g., which IP address traffic is masqueraded to), not the egress interface selection; it cannot force traffic out of a specific WAN link. Option B is wrong because a static route with a higher priority (lower administrative distance) for 203.0.113.0/24 would direct all traffic to that subnet (including other ports or services) via WAN2, not just port 443, and it does not provide per-service granularity. Option C is wrong because SD-WAN with 'Best Quality' strategy selects the best path based on link quality metrics (latency, jitter, packet loss) rather than forcing traffic to a specific interface; it would not guarantee that the traffic always exits via WAN2.

8
MCQeasy

A FortiGate administrator wants to restrict access to a sensitive server (10.0.0.100) such that only users who authenticate via LDAP can access it. Which firewall policy configuration is required?

A.Policy: source any, destination 10.0.0.100, service any, action accept
B.Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP
C.Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP, set groups "LDAP-Users"
D.Policy: source any, destination 10.0.0.100, service any, action accept, enable FSSO authentication
AnswerC

This is the correct configuration because it enables authentication, selects LDAP as the authentication type, and explicitly restricts access to members of the LDAP-Users group. In FortiOS, an identity-based policy with a specified group enforces both authentication (credentials verified against LDAP) and authorization (group membership checked). After a user authenticates successfully and is a member of LDAP-Users, the accept action permits traffic to 10.0.0.100.

Why this answer

It combines the required firewall policy elements: enabling authentication, setting the authentication type to LDAP, and restricting access to members of the LDAP group 'LDAP-Users'. This ensures that only users who successfully authenticate via LDAP and belong to the specified group can reach the sensitive server at 10.0.0.100. Without the group restriction, any authenticated LDAP user could access the server, which does not meet the requirement of restricting access to only authenticated users.

Exam trap

The trap here is that candidates often think enabling authentication alone is sufficient, but they overlook the critical need to specify a group to restrict access to only the intended subset of authenticated users.

How to eliminate wrong answers

Option A is wrong because it allows all traffic without any authentication, completely bypassing the requirement to restrict access to authenticated users. Option B is wrong because while it enables authentication and sets the auth-type to LDAP, it does not specify a group; this would allow any user who can authenticate via LDAP to access the server, which is too permissive and does not enforce the intended restriction. Option D is wrong because FSSO (Fortinet Single Sign-On) authentication is used for transparent authentication based on Windows domain logins and is not the same as requiring explicit LDAP authentication; it does not meet the requirement for users to authenticate via LDAP.

9
MCQhard

An admin notices that a firewall policy allowing inbound HTTPS to a server is not matching traffic. The policy has source set to 'all', destination to the server's IP, and service to HTTPS. The admin checks the policy list and sees that policy ID 1 matches the traffic. What is the MOST likely reason the intended policy (ID 10) is not matching?

A.Policy ID 1 has a higher priority and matches before policy ID 10
B.The firewall policy is disabled
C.The service object for HTTPS is misconfigured in policy ID 10
D.The destination address is incorrect in policy ID 10
AnswerA

FortiGate security policies are evaluated sequentially from the top of the policy table, and the first policy that matches all criteria (source, destination, service, schedule, etc.) is applied, terminating the lookup. Policy ID 1 has a lower numeric ID, which places it above policy ID 10 in the default ordering, so it is evaluated first. Because policy ID 1 already matches the inbound traffic, policy ID 10 is never reached, even if its configuration is perfectly valid. This is a classic policy shadowing issue where a broader or earlier policy overrides a more specific later one.

Why this answer

Policy ID 1 has a higher priority because FortiGate evaluates firewall policies in sequential order from top to bottom. When policy ID 1 matches the traffic (e.g., it also allows HTTPS to the same destination), the traffic is processed by policy ID 1 and never reaches policy ID 10. This is the most likely reason the intended policy is not matching.

Exam trap

The trap here is that candidates may think policy ID numbers determine priority, but FortiGate uses the sequential order in the policy list, not the ID number, and the default policy ID 1 is often an 'allow all' or 'deny all' rule that matches before any lower-ID policies.

How to eliminate wrong answers

Option B is wrong because if the firewall policy were disabled, it would simply not match traffic, but the admin would see no match for policy ID 10, not a match on policy ID 1. Option C is wrong because a misconfigured service object for HTTPS in policy ID 10 would cause the policy to not match HTTPS traffic, but it would not explain why policy ID 1 matches the traffic. Option D is wrong because an incorrect destination address in policy ID 10 would prevent matching, but again, it does not account for policy ID 1 matching the traffic.

10
MCQeasy

An admin needs to allow outbound HTTP and HTTPS traffic from the internal network to the internet. Which two built-in service objects can be used in a single firewall policy to achieve this?

A.WEB and SSL
B.ANY and HTTPS
C.ALL_TCP and ALL_UDP
D.HTTP and HTTPS
AnswerD

The predefined service objects 'HTTP' (TCP/80) and 'HTTPS' (TCP/443) directly match the two standard ports used for outbound web browsing. Using these built-in objects allows the firewall to enforce the policy narrowly and consistently, without the need to create custom definitions. This is the best practice because it enables the exact traffic required while blocking everything else.

Why this answer

HTTP (TCP/80) and HTTPS (TCP/443) are the two built-in service objects that specifically match outbound web traffic. A single firewall policy can include both service objects to allow HTTP and HTTPS traffic from internal users to the internet, which is the most precise and secure way to permit web browsing without opening unnecessary ports.

Exam trap

The trap here is that candidates may confuse the generic term 'WEB' with the actual built-in service object name 'HTTP', or assume that 'ANY' is acceptable for simplicity, overlooking the security risk of opening all protocols.

How to eliminate wrong answers

Option A is wrong because 'WEB' is not a standard FortiGate built-in service object; the correct objects are HTTP and HTTPS. Option B is wrong because 'ANY' would allow all protocols and ports, which is overly permissive and violates the principle of least privilege, while HTTPS alone would only permit encrypted web traffic, not HTTP. Option C is wrong because ALL_TCP and ALL_UDP would allow all TCP and UDP traffic, including non-web services like SSH, FTP, or DNS, which is too broad and insecure for a web-only policy.

11
MCQmedium

An administrator has configured a firewall policy that allows outbound traffic from a subnet to the internet, with NAT enabled. The external IP is 203.0.113.1. However, the administrator wants all traffic from a specific internal server (10.0.0.10) to appear with source IP 203.0.113.2. What should the administrator do?

A.Create a VIP with the external IP and apply it to the policy
B.Create an IP Pool with 203.0.113.2 and reference it in the policy
C.Configure route-based NAT
D.Set the NAT to 'Use Outgoing Interface Address'
AnswerB

An IP Pool allows selecting a different source NAT IP.

Why this answer

An IP Pool in FortiGate allows you to override the source IP address for specific traffic, even when NAT is enabled on the policy. By creating an IP Pool with the single address 203.0.113.2 and referencing it in the firewall policy, traffic from 10.0.0.10 will be NATed to that specific IP instead of the outgoing interface address (203.0.113.1). This is the standard method for fixed source NAT (also called 'static NAT' or 'one-to-one NAT') for a specific host.

Exam trap

The trap here is confusing Virtual IP (VIP) with IP Pool: VIP is for destination NAT (inbound), while IP Pool is for source NAT (outbound), and many candidates mistakenly apply a VIP to change the source IP of outbound traffic.

How to eliminate wrong answers

Option A is wrong because a Virtual IP (VIP) is used for destination NAT (port forwarding), not for changing the source IP of outbound traffic; applying a VIP to a policy would translate the destination address of incoming traffic, not the source of outgoing traffic. Option C is wrong because route-based NAT is a concept for VPNs or policy-based routing, not a direct method to specify a fixed source IP for NAT; FortiGate uses IP Pools for that purpose. Option D is wrong because setting NAT to 'Use Outgoing Interface Address' would NAT all traffic to the IP of the outgoing interface (203.0.113.1), which is exactly what the administrator wants to avoid for the specific server.

12
MCQmedium

A FortiGate administrator is configuring a Virtual IP (VIP) to allow external users to access an internal web server (192.168.1.10) using the public IP 203.0.113.10 on port 80. The admin creates a VIP with mapped IP 192.168.1.10 and port 80. A firewall policy is created from WAN to DMZ with destination set to the VIP. External users report that they can access the web server. What additional step is needed to allow the internal server to respond correctly?

A.No additional step is needed; the FortiGate automatically performs reverse NAT for established sessions
B.Create a second VIP for the return traffic
C.Add a policy from DMZ to WAN allowing the internal server to reply
D.Configure static routing on the internal server to route through the FortiGate
AnswerA

No additional configuration is required because FortiGate's session table maintains bidirectional state for every translated flow. When a server responds to a VIP-mapped connection, the FortiGate identifies the session via the 5-tuple, performs the reverse DNAT, and rewrites the source IP back to the original VIP address. This automatic reverse NAT is inherent to stateful inspection, so any manual return-path setup is unnecessary.

Why this answer

When a FortiGate performs destination NAT (DNAT) via a VIP for inbound traffic, it automatically creates a session entry that includes the reverse NAT mapping. For return traffic from the internal server, the FortiGate uses this session to perform source NAT (SNAT) back to the original public IP (203.0.113.10). This is called 'implicit reverse NAT' and requires no additional configuration; the session state ensures the reply packets are correctly translated and forwarded to the external client.

Exam trap

The trap here is that candidates often think a separate outbound policy or NAT rule is required for return traffic, but FortiGate's stateful firewall and implicit reverse NAT handle this automatically, making additional policies or VIPs unnecessary.

How to eliminate wrong answers

Option B is wrong because a second VIP is not needed; reverse NAT is handled automatically by the session table, not by a separate VIP object. Option C is wrong because no explicit policy from DMZ to WAN is required for return traffic; FortiGate's stateful inspection allows reply packets to traverse based on the existing session created by the inbound policy. Option D is wrong because the internal server does not need static routing through the FortiGate for return traffic; the server's default gateway should point to the FortiGate's DMZ interface, but this is a basic network requirement, not an additional step specific to VIP functionality.

13
MCQmedium

An admin configures a VIP to map public IP 203.0.113.10 to internal server 10.0.1.100 on port 80. External users can reach the server via the public IP. However, internal users cannot access the server using the public IP. What is the MOST likely cause?

A.The VIP does not have NAT reflection enabled
B.The server is not responding to internal requests
C.The firewall policy for internal to VIP is missing
D.The VIP is configured on a different interface
AnswerA

The VIP lacks NAT reflection (also called NAT hairpin or loopback), which is required for internal users to reach the same VIP that external users can access. With NAT reflection disabled, a packet from an internal client destined to the VIP's public IP hits the FortiGate but is neither source-NATed nor properly routed back, so the session never establishes. This perfectly matches the symptom where external users work, but internal users cannot use the public IP.

Why this answer

The most likely cause is that NAT reflection (also known as hairpin NAT or NAT loopback) is not enabled on the VIP. When an internal user sends a request to the public IP (203.0.113.10), the FortiGate must translate the source IP back to the internal network and loop the traffic back through the VIP to reach the internal server (10.0.1.100). Without NAT reflection, the FortiGate drops the packet because it sees the destination as the VIP's public IP but the source is from the same internal subnet, causing asymmetric routing or no reply.

Exam trap

The trap here is that candidates often assume internal users can always reach a server via its public IP because the VIP is working externally, overlooking the need for NAT reflection to handle traffic sourced from the same subnet as the destination server.

How to eliminate wrong answers

Option B is wrong because the server is reachable from external users, proving it responds to requests; internal users failing to reach it via the public IP is a NAT/routing issue, not a server responsiveness problem. Option C is wrong because internal-to-VIP traffic does not require a separate firewall policy if the VIP is configured with NAT reflection; the existing policy for external-to-VIP traffic typically handles the loopback, and a missing policy would cause a different symptom (e.g., no traffic at all). Option D is wrong because the VIP is configured on the correct interface (the one with the public IP), and if it were on a different interface, external users would also fail to reach the server.

14
MCQhard

A FortiGate is configured with two policies: Policy A allows traffic from trust to untrust with schedule 'WorkHours' (Mon-Fri 9-17). Policy B allows traffic from trust to untrust with schedule 'Always'. A user sends traffic at 8:00 AM on Saturday. Which policy matches?

A.Policy B because Policy A's schedule is not active
B.Policy A because schedules are evaluated after policy order
C.Both policies match and the first one in order is used
D.No policy matches because Policy A is first but schedule inactive
AnswerA

FortiGate checks schedule objects as part of policy matching. Policy A's WorkHours schedule covers only Monday to Friday 09:00-17:00, so at 08:00 on Saturday it is inactive and cannot match; evaluation continues to Policy B, whose Always schedule is active.

Why this answer

Policy B is correct because at 8:00 AM on Saturday, the 'WorkHours' schedule (Mon-Fri 9-17) is not active. FortiGate evaluates policies sequentially; when the first matching policy's schedule is inactive, the firewall skips it and continues to the next policy. Policy B with schedule 'Always' matches and permits the traffic.

Exam trap

The trap here is that candidates assume the first matching policy in the list always applies, forgetting that an inactive schedule causes the policy to be skipped entirely, allowing a later policy with 'Always' to match.

How to eliminate wrong answers

Option B is wrong because schedules are evaluated during policy matching, not after policy order; an inactive schedule causes the policy to be skipped, not matched. Option C is wrong because only one policy can match per session; FortiGate uses the first policy with all conditions (including active schedule) met. Option D is wrong because Policy A is skipped due to inactive schedule, but Policy B then matches and permits the traffic, so a policy does match.

15
MCQhard

An admin configures a central SNAT rule to translate source IP 10.0.0.0/24 to IP pool 203.0.113.1-203.0.113.10 using overload (PAT). A policy-based NAT on a specific policy also translates the same source to the interface IP. Traffic from 10.0.0.0/24 to the internet shows source IP as the interface IP, not from the IP pool. What is the reason?

A.The central SNAT rule is disabled
B.The policy is using fixed port range
C.Policy-based NAT overrides central SNAT rules
D.The IP pool is out of addresses
AnswerC

This is correct because FortiOS applies policy-based NAT with higher priority than central NAT objects. When an administrator configures a source NAT directly on the firewall policy (such as selecting an IP pool), that per-policy NAT is evaluated before any central SNAT rule. The central NAT feature only serves as a fallback for policies that do not have their own NAT configuration, so the policy's own NAT action takes precedence and effectively masks the central SNAT rule.

Why this answer

Policy-based NAT (PBNAT) takes precedence over central SNAT rules because it is applied directly to a specific firewall policy. When a policy matches traffic, its NAT configuration (including translation to the interface IP) is evaluated before any central SNAT rules. This override occurs regardless of the central SNAT rule's order or status, as PBNAT is considered more specific and thus higher priority in FortiOS.

Exam trap

The trap here is that candidates often assume central SNAT rules are always evaluated first or that all NAT rules are additive, but FortiOS gives policy-based NAT higher priority, causing the central rule to be silently ignored when a conflicting policy-based translation exists.

How to eliminate wrong answers

Option A is wrong because if the central SNAT rule were disabled, traffic would either not be translated or would use the default behavior (e.g., no SNAT), but the observed behavior shows translation to the interface IP, indicating a different NAT rule is active. Option B is wrong because fixed port range affects port allocation behavior, not the selection of which NAT rule applies; it does not cause a central SNAT rule to be overridden. Option D is wrong because if the IP pool were out of addresses, traffic would typically fail or fall back to no SNAT, not be translated to the interface IP; the pool exhaustion would not trigger a different translation source.

16
MCQmedium

An admin runs 'diagnose sys session filter dport 443' and sees output showing sessions with 'proto=6' and 'expire=3599'. The admin notices that these sessions are not being cleaned up after the firewall policy that allowed them is deleted. What is the reason?

A.The sessions are using UDP protocol, which has a longer timeout
B.The sessions are protected by a different policy that still exists
C.The sessions are in a different VDOM
D.FortiGate does not delete existing sessions when a policy is removed; sessions must be cleared manually
AnswerD

FortiGate evaluates policies only for new sessions; deleting a policy does not tear down sessions already established under it. Those entries persist until expiry or manual clearing via diagnose sys session clear, satisfying the stated scenario.

Why this answer

When a firewall policy is deleted on a FortiGate, the existing sessions that were created by that policy are not automatically removed. The FortiGate continues to process those sessions until they expire naturally based on their timeout values. In this case, the sessions with 'proto=6' (TCP) and 'expire=3599' seconds remaining will persist until the timer counts down, even though the originating policy no longer exists.

The admin must manually clear them using 'diagnose sys session clear' or wait for the timeout to expire.

Exam trap

The trap here is that candidates often assume FortiGate automatically removes sessions when a policy is deleted, similar to how some other firewalls handle stateful inspection, but FortiGate requires manual intervention or timeout expiration to clear sessions.

How to eliminate wrong answers

Option A is wrong because 'proto=6' indicates TCP, not UDP; UDP uses protocol number 17 and has different timeout behavior. Option B is wrong because the output shows sessions with 'expire=3599', meaning they are still active and not yet protected by another policy; if another policy existed, the sessions would still be subject to the same timeout behavior, but the question states the policy that allowed them was deleted. Option C is wrong because the 'diagnose sys session filter dport 443' command without a VDOM filter applies to the current VDOM, and the output does not indicate a different VDOM; sessions in different VDOMs would require explicit VDOM filtering.

17
MCQeasy

A company has a FortiGate with two ISPs: wan1 (primary) and wan2 (backup). They want all outbound traffic from internal users to use wan1, and if wan1 fails, traffic should automatically fail over to wan2. The administrator configures static routes: default route via wan1 gateway with distance 10 and default route via wan2 gateway with distance 20. They also configure an SD-WAN zone with both interfaces and set a strategy of 'Manual' with 'Best Quality' for wan1. After testing, failover does not occur when wan1 goes down. What is the most likely reason?

A.The SD-WAN zone does not include the backup interface wan2.
B.The SD-WAN strategy is set to Manual, which does not automatically failover; the administrator should use an automatic strategy or configure link health monitoring.
C.The static routes have the same distance, so failover does not occur.
D.The firewall policy does not bind to the SD-WAN zone; it binds to wan1 interface directly.
AnswerB

With the SD-WAN strategy set to Manual, FortiGate uses the configured static routes and does not automatically re-evaluate link health to move traffic away from a failed interface. Automatic failover requires either an automatic strategy such as Lowest Cost or Best Quality combined with a performance SLA, or explicit link health monitoring to trigger a route update when wan1 goes down. Since neither is configured, the manual strategy explains why failover does not occur; this is the correct resolution.

Why this answer

When the SD-WAN strategy is set to 'Manual', the FortiGate does not automatically perform failover based on interface or link health. Manual mode requires explicit administrator action or must be combined with link health monitoring to trigger a switch. Without an automatic strategy or configured health checks, the SD-WAN zone will continue to use wan1 even if it goes down, preventing failover to wan2.

Exam trap

The trap here is that candidates assume static route distance alone handles failover, but when SD-WAN is configured with a Manual strategy, the SD-WAN rule overrides the routing table and prevents automatic failover unless link health monitoring is enabled.

How to eliminate wrong answers

Option A is wrong because the SD-WAN zone includes both wan1 and wan2 as stated in the scenario, so the backup interface is present. Option C is wrong because the static routes have different distances (10 and 20), which is the correct configuration for failover; equal distances would cause ECMP, not prevent failover. Option D is wrong because the firewall policy binding to the SD-WAN zone is not the issue; the policy can bind to the zone, but the failover failure is due to the SD-WAN strategy setting, not the policy binding.

18
Multi-Selectmedium

An admin needs to create a firewall policy that allows SMTP traffic (TCP/25) from the internal network (10.0.0.0/24) to a mail server in the DMZ (172.16.1.10). Additionally, the admin wants to ensure that the mail server can only be accessed by the internal network, not from the internet. Which THREE settings must be configured in the firewall policy? (Choose three.)

Select 3 answers
A.Source interface set to 'internal'
B.Set schedule to 'always'
C.Destination interface set to 'dmz'
D.Service set to 'SMTP'
E.Enable NAT to translate source IP
AnswersA, C, D

The source interface is a mandatory field in a FortiGate firewall policy that identifies the ingress interface through which traffic enters the firewall. For internal clients reaching an SMTP server in the DMZ, setting the source interface to 'internal' ensures the policy only matches traffic arriving from the trusted internal segment. Without this specific interface binding, the policy could unintentionally match traffic from other interfaces, creating a security exposure. This interface pair is the first classification criterion that FortiGate uses when building a session.

Why this answer

The source interface must be set to 'internal' to restrict the firewall policy to traffic originating from the internal network (10.0.0.0/24). This ensures that only hosts on the internal interface can reach the mail server, effectively blocking any internet traffic that would arrive on a different interface like 'wan'.

Exam trap

The trap here is that candidates often think NAT is required for traffic between internal and DMZ zones, but FortiGate does not require NAT for inter-zone traffic unless the destination network is private and overlapping, and the question explicitly wants to restrict access from the internet, not translate addresses.

19
Multi-Selectmedium

A FortiGate admin needs to allow inbound HTTPS traffic to a web server while also applying an application control profile to block certain web applications. The web server has a VIP configured. Which TWO components are necessary for this configuration?

Select 2 answers
A.A central SNAT rule to translate the server's response
B.A VIP configured to map the public IP to the web server's private IP
C.A security profile group containing only the antivirus profile
D.A traffic shaping policy to prioritize HTTPS
E.A firewall policy with destination set to the VIP and application control profile applied
AnswersB, E

The VIP performs destination NAT, translating the public IP to the web server's private IP so inbound HTTPS connections reach the internal host. This satisfies the stem's requirement by providing the address translation the firewall policy references as its destination.

Why this answer

A Virtual IP (VIP) is required to map the public IP address to the web server's private IP, allowing inbound traffic to reach the internal server. Option E is correct because a firewall policy must have the destination set to the VIP and must include an application control profile to enforce blocking of specific web applications on the HTTPS traffic.

Exam trap

The trap here is that candidates often think a central SNAT rule is required for return traffic, but FortiGate automatically handles reverse NAT for VIP traffic, making option A a common distractor.

20
MCQeasy

What is the default action of the implicit deny policy at the end of the firewall policy list?

A.Monitor (log only)
B.Allow
C.Deny
D.Redirect to authentication
AnswerC

Deny is correct because FortiOS includes an unmodifiable, last-resort implicit deny policy that drops any packet that does not match an explicit IPv4 or IPv6 firewall policy. This policy is evaluated only after all explicit policies have been checked and no match is found, meaning it effectively enforces a default-close security posture. It is not visible in the policy list, cannot be removed or reordered, and by default does not log, so administrators often create an explicit deny-all rule with logging to gain visibility into blocked traffic.

Why this answer

In FortiGate firewalls, the implicit deny policy at the end of the firewall policy list has a default action of 'Deny'. This means any traffic that does not match an explicit firewall policy is automatically dropped. This is a fundamental security principle to ensure that only explicitly permitted traffic is allowed through the firewall.

Exam trap

The trap here is that candidates may confuse the implicit deny with the 'deny' action available in explicit policies, or mistakenly think that the implicit deny can be changed to 'allow' or 'monitor' to simplify troubleshooting, but FortiGate's design enforces a strict default-deny stance for unmatched traffic.

How to eliminate wrong answers

Option A is wrong because 'Monitor (log only)' is not a default action for the implicit deny policy; logging is a separate setting that can be enabled on any policy, but the implicit deny itself does not log by default. Option B is wrong because 'Allow' would violate the security model of a firewall, which is designed to block unauthorized traffic by default; allowing all unmatched traffic would create a significant security hole. Option D is wrong because 'Redirect to authentication' is a feature used for captive portal or user authentication policies, not for the implicit deny; the implicit deny simply drops traffic without any redirection.

21
MCQhard

An admin runs the command 'diagnose firewall iprope list 100000' and sees the following output: id=2000000000 action=deny flag=0x0 src-interface=any dst-interface=any proto=0 src-addr=0.0.0.0-255.255.255.255 dst-addr=0.0.0.0-255.255.255.255 What does this entry represent?

A.A loopback interface policy
B.The implicit deny policy at the end of the policy list
C.A user-created deny policy that blocks all traffic
D.A NAT policy that translates all addresses
AnswerB

The all-zero source and destination with proto=0 and deny action is the default drop rule FortiGate applies after all configured policies are evaluated. Its id=2000000000 confirms it is the final implicit deny, not an admin-created policy.

Why this answer

The output shows an entry with id=2000000000, action=deny, and source/destination addresses covering all possible IPs (0.0.0.0-255.255.255.255). In FortiGate, the implicit deny policy is automatically inserted at the end of the policy list with a high ID (typically 2000000000) and matches any traffic that hasn't been permitted by earlier policies. This is not a user-created policy but the built-in default deny rule.

Exam trap

The trap here is that candidates may confuse the high ID (2000000000) with a user-created policy or think it's a NAT rule, but FortiGate reserves this ID specifically for the implicit deny, which is automatically generated and cannot be manually created or removed.

How to eliminate wrong answers

Option A is wrong because a loopback interface policy would reference a specific loopback interface (e.g., 'loopback') in the src-interface or dst-interface field, not 'any'. Option C is wrong because user-created deny policies have IDs in the normal range (e.g., 1-65535), not the reserved high ID 2000000000, and they would not automatically cover all IP ranges unless explicitly configured. Option D is wrong because NAT policies are configured under 'config firewall policy' with action set to 'accept' and include NAT-related options (e.g., 'set nat enable'), not a deny action with a catch-all address range.

22
MCQhard

An administrator configures a Central SNAT policy to translate traffic from the internal network (10.0.0.0/8) to the internet using the IP pool 'pool1'. The administrator also has a firewall policy that uses policy-based NAT with an IP pool 'pool2'. Both policies match the same traffic. Which NAT will be applied?

A.Central SNAT using pool1
B.Both NAT rules are applied in sequence
C.The traffic is dropped due to conflicting NAT configurations
D.Policy-based NAT using pool2
AnswerA

Central SNAT rules are evaluated before any policy-based NAT. In FortiGate's NAT execution order, central source NAT takes precedence over the NAT settings configured inside a firewall policy, so a matching central SNAT rule using pool1 is selected. The session's source IP is translated to an address from pool1, and the policy's NAT configuration is completely bypassed.

Why this answer

Central SNAT policies have higher priority than policy-based NAT when both match the same traffic. In FortiOS, Central SNAT is evaluated before firewall policies, and if a match is found, the policy-based NAT within the firewall policy is ignored. Therefore, pool1 is applied.

Exam trap

The trap here is that candidates assume policy-based NAT within a firewall policy takes precedence because it is more specific, but FortiOS gives Central SNAT higher priority regardless of specificity.

How to eliminate wrong answers

Option B is wrong because FortiOS does not apply both NAT rules in sequence; only the Central SNAT policy is used, and the policy-based NAT is bypassed. Option C is wrong because there is no conflict that causes traffic to be dropped; the system deterministically selects the Central SNAT policy. Option D is wrong because policy-based NAT using pool2 is overridden by the higher-priority Central SNAT policy when both match the same traffic.

23
MCQhard

An administrator configures a Virtual IP (VIP) to map public IP 203.0.113.10 to internal server 10.0.1.10 on port 443. The firewall policy uses the VIP as the destination address. External users report they cannot connect. The administrator checks the policy and sees the destination interface is 'wan1' and source interface is 'wan1'. What is the most likely issue?

A.The destination interface should be the internal interface, not wan1
B.The policy needs NAT enabled
C.The source interface should be the internal interface
D.The VIP is not associated with the policy
AnswerA

After the virtual IP (VIP) performs destination NAT (DNAT), the packet's destination IP becomes the internal server's private address. To deliver that packet, the firewall must route it out the interface that connects to that server, which is the internal interface. If the policy's destination interface is mistakenly set to wan1, the firewall will attempt to send the packet back out the WAN interface, causing the traffic to fail or be misrouted. Therefore, the destination interface must be the internal interface to match the post-DNAT forwarding path.

Why this answer

The VIP maps the public IP to the internal server, but the firewall policy's destination interface is set to 'wan1', which is the external interface. Traffic arriving on wan1 and destined for the VIP must be processed by a policy where the destination interface is the internal interface (e.g., 'internal' or 'lan') so that the firewall can route the decapsulated traffic to the private server. Setting the destination interface to wan1 prevents the firewall from forwarding the traffic to the internal network, breaking connectivity.

Exam trap

The trap here is that candidates often confuse the source and destination interface roles in a VIP policy, assuming the destination interface should match the incoming interface (wan1) rather than the internal interface where the server resides.

How to eliminate wrong answers

Option B is wrong because NAT is already implicitly handled by the VIP configuration; the VIP performs destination NAT (DNAT) and does not require an explicit NAT policy. Option C is wrong because the source interface should remain 'wan1' as traffic originates from the external network; changing it to the internal interface would block legitimate inbound traffic. Option D is wrong because the VIP is associated with the policy via the destination address field; the issue is the interface mismatch, not a missing association.

24
MCQeasy

An administrator wants to allow access to an internal web server from the internet using a public IP address 203.0.113.10. The internal server has IP 10.0.0.5. Which FortiGate feature should be configured to translate the destination IP?

A.Virtual IP (VIP)
B.Central SNAT
C.Policy-based routing
D.IP Pool
AnswerA

A Virtual IP (VIP) is the correct object for destination NAT on FortiGate. It maps an external public IP address (and optionally a port) to a private, internal server IP, so inbound traffic destined for the public address is forwarded to the internal web server. The translation applies to the destination address of the packet, exactly what is required to expose an internal web server to the internet.

Why this answer

A Virtual IP (VIP) is the correct feature because it performs destination NAT (DNAT), translating the public destination IP 203.0.113.10 to the internal server IP 10.0.0.5. This allows inbound traffic from the internet to reach the internal web server by rewriting the destination IP address in the packet header as it traverses the FortiGate.

Exam trap

The trap here is confusing destination NAT (VIP) with source NAT (IP Pool or Central SNAT), leading candidates to select a source NAT option when the question explicitly asks for destination IP translation.

How to eliminate wrong answers

Option B (Central SNAT) is wrong because Central SNAT is used for source NAT (SNAT), translating the source IP of outbound traffic, not the destination IP of inbound traffic. Option C (Policy-based routing) is wrong because policy-based routing controls the path a packet takes based on routing policies, not IP address translation. Option D (IP Pool) is wrong because an IP Pool is used for source NAT (SNAT) to translate the source IP of outbound traffic to a range of public IPs, not for destination translation of inbound traffic.

25
MCQhard

A FortiGate has a policy that allows traffic from 10.0.0.0/8 to any destination with NAT enabled using an IP pool 'Pool1' (203.0.113.10-203.0.113.20). The admin notices that internal servers using fixed ports (e.g., SIP) are failing. What is the likely cause?

A.The policy order is incorrect
B.The IP pool is configured with one-to-one NAT
C.The IP pool uses fixed port range, which should work
D.The IP pool is configured with overload (PAT), which changes source ports
AnswerD

Overload (PAT) translates many internal IPs to a single external IP by dynamically assigning unique source ports for each session. This changes the original SIP source port (e.g., 5060) to some random high port, breaking protocol expectations because SIP and RTP require consistent port mapping. The FortiGate's overload mode is exactly the condition that alters ports, leading to call setup and media failures. Thus, this is the correct explanation for the reported symptom.

Why this answer

When an IP pool is configured with overload (PAT), the FortiGate translates the source IP address and also changes the source port to a random high port. For protocols like SIP that rely on fixed source ports (e.g., UDP 5060), this port remapping breaks the application because the SIP server expects traffic from a specific port. Option D correctly identifies this as the root cause.

Exam trap

The trap here is that candidates assume any IP pool will preserve source ports, but overload (PAT) mode explicitly changes them, which breaks applications that require fixed source ports like SIP, DNS, or TFTP.

How to eliminate wrong answers

Option A is wrong because policy order is irrelevant here; the traffic is matching the correct policy, but the NAT behavior is causing the issue. Option B is wrong because one-to-one NAT preserves the source port, so fixed-port protocols like SIP would work; the problem is with overload (PAT) changing ports. Option C is wrong because a fixed port range in the IP pool does not prevent PAT from altering source ports; the pool's overload mode overrides any fixed port configuration.

26
Multi-Selectmedium

A FortiGate administrator is troubleshooting why traffic from a specific host (10.0.1.100) to a web server (203.0.113.50) is being denied. The administrator has confirmed that a firewall policy exists that should allow the traffic. Which TWO diagnostic commands would help identify the issue?

Select 2 answers
A.get system performance status
B.diagnose firewall policy list
C.diagnose debug flow
D.execute ping-options source 10.0.1.100
E.diagnose sniffer packet any 'host 203.0.113.50' 4
AnswersB, C

Executing `diagnose firewall policy list` prints every firewall policy entry with its ID, sequence, source, destination, service, action, and status in the exact evaluation order. This lets an administrator verify that a policy allowing 10.0.1.100 to 203.0.113.50 actually exists, is enabled, and is not overshadowed by an earlier deny-all or more specific deny rule. Because FortiGate matches first-match, checking the ordered list is an essential step in confirming whether the configuration matches the expected permit.

Why this answer

'diagnose firewall policy list' displays the effective policy table, including policy IDs, match criteria, and action (accept/deny). This helps verify whether the policy intended for the traffic is actually present and in the correct order. Option C is correct because 'diagnose debug flow' enables real-time packet flow tracing, showing exactly which policy is matched (or not) and why the traffic is denied, such as a policy hit with action 'deny' or a session table lookup failure.

Exam trap

The trap here is that candidates often confuse packet sniffing (which shows raw traffic) with flow debugging (which shows the firewall's internal decision process), leading them to choose 'diagnose sniffer packet' instead of 'diagnose debug flow' for identifying policy-based denials.

27
Multi-Selectmedium

A FortiGate has two firewall policies for HTTP traffic to the internet: Policy A (source: 10.0.1.0/24) and Policy B (source: 10.0.2.0/24). Both policies have the same destination and service. The admin wants to apply a traffic shaper to limit bandwidth for Policy B. Which TWO actions are correct? (Choose two.)

Select 2 answers
A.Apply the shaper to both policies and use a different shaper for Policy B
B.Use a QoS queue on the outgoing interface
C.Create a traffic shaping policy that matches Policy B's source and apply the shaper
D.Enable traffic shaping on the VDOM
E.Configure a traffic shaper and apply it directly to Policy B in the firewall policy settings
AnswersC, E

A traffic shaping policy (under Firewall Objects > Traffic Shapers or Policy & Objects > Traffic Shaping Policies) allows you to create a separate rule that matches traffic based on source and destination addresses, services, and even the firewall policy. By configuring a shaping policy that matches Policy B's source address and applying the desired shaper to it, you can shape exactly the traffic permitted by Policy B without modifying Policy A. This is a valid alternative to per-policy shaper assignment and is useful when you need to shape traffic across multiple policies or when the shaper should apply to both forward and reverse directions.

Why this answer

A traffic shaping policy can match the source address of Policy B (10.0.2.0/24) and apply a specific shaper, allowing granular bandwidth control without affecting Policy A. Option E is correct because FortiGate allows a traffic shaper to be applied directly within a firewall policy's 'Traffic Shaping' settings, which overrides any default or VDOM-level shaping. Both methods achieve the goal of limiting bandwidth for Policy B only.

Exam trap

The trap here is that candidates often think a QoS queue on the interface is sufficient for per-policy shaping, but it applies to all egress traffic indiscriminately, whereas FortiGate requires explicit shaper assignment at the policy or traffic shaping policy level to differentiate between source subnets.

28
Multi-Selecteasy

Which TWO statements about firewall policy order are true?

Select 2 answers
A.If a packet does not match any policy, it is allowed by default
B.Policies are evaluated in the order they appear (top-down)
C.A more specific policy should be placed below a less specific one to avoid shadowing
D.Once a policy is matched, subsequent policies are still evaluated for logging purposes
E.Policy order can be changed by dragging policies in the GUI or using CLI commands
AnswersB, E

FortiGate firewall policies are stored in an ordered sequence and are evaluated from top to bottom when a new session's first packet arrives. The first policy that matches the packet's attributes (source, destination, service, interface) is applied, and no further policies are checked. This first-match model ensures that the administrator's intended precedence dictates the outcome.

Why this answer

FortiGate firewalls evaluate policies sequentially from top to bottom. The first policy that matches the packet's source, destination, service, and other attributes is applied, and no further policies are checked. This top-down evaluation is fundamental to policy design and troubleshooting.

Exam trap

The trap here is that candidates often confuse the default action (implicit deny) with an allow-all, or they mistakenly think that logging can be performed by multiple policies after a match, when in reality only the matched policy's logging settings apply.

29
MCQmedium

An administrator needs to block traffic from a specific geographic region (e.g., country) from reaching the corporate web server. Which type of address object should be used to define the source?

A.Wildcard FQDN object
B.FQDN object
C.Subnet object
D.Geography object
AnswerD

A geography object groups IP addresses by country, letting the policy match traffic by geographic origin rather than by individual IP or FQDN. This satisfies the requirement to block a specific region from reaching the web server without maintaining manual address lists.

Why this answer

A Geography object in FortiGate is specifically designed to represent traffic based on geographic location (e.g., country, continent). When used in a firewall policy's source field, it allows the administrator to block or allow traffic originating from an entire country without needing to manage individual IP addresses or subnets, leveraging FortiGate's GeoIP database.

Exam trap

The trap here is that candidates may confuse Geography objects with FQDN or Subnet objects, mistakenly thinking they can manually define country IP ranges via subnets, but FortiGate's GeoIP feature automates this with a dedicated object type.

How to eliminate wrong answers

Option A is wrong because a Wildcard FQDN object matches domain names with wildcard patterns (e.g., *.example.com) and is used for web filtering or DNS-based policies, not for blocking traffic based on geographic region. Option B is wrong because an FQDN object resolves to a specific IP address or set of IP addresses via DNS, which cannot represent an entire country's IP range. Option C is wrong because a Subnet object defines a specific IP range (e.g., 192.168.1.0/24) and would require manually aggregating all IP ranges for a country, which is impractical and error-prone.

30
MCQeasy

A FortiGate administrator wants to allow traffic from the internal network to a specific external server using its fully qualified domain name (FQDN) rather than an IP address, because the server's IP changes frequently. Which type of address object should the administrator create for the destination?

A.Subnet object
B.Wildcard FQDN object
C.Geography object
D.FQDN object
AnswerD

An FQDN object represents a single, fully qualified domain name and dynamically resolves it to the current IP address at connection time. The FortiGate periodically refreshes the resolved IP addresses based on DNS TTL, so if the server's address changes, the policy remains valid without manual edits. This makes it the correct choice when allowing traffic to a specific server known by a domain name, especially when its IP is not static.

Why this answer

FQDN object. FortiGate FQDN objects resolve domain names to IP addresses dynamically, allowing the firewall to update the destination IP automatically when the server's IP changes. This is ideal for scenarios where the external server uses a fully qualified domain name and its IP address is not static.

Exam trap

The trap here is that candidates may confuse Wildcard FQDN objects (used for domain pattern matching) with standard FQDN objects (used for DNS resolution to a single IP), leading them to select Option B incorrectly.

How to eliminate wrong answers

Option A is wrong because a Subnet object defines a range of IP addresses using a network prefix (e.g., 10.0.0.0/24), which cannot accommodate a dynamically changing IP address tied to an FQDN. Option B is wrong because a Wildcard FQDN object is used for matching multiple subdomains (e.g., *.example.com) in firewall policies, not for resolving a single FQDN to its current IP address. Option C is wrong because a Geography object identifies traffic based on geographic location (country or region) using IP geolocation databases, not by domain name resolution.

31
MCQhard

A FortiGate has a policy that enables NAT with an IP pool that uses overload (port address translation). The administrator notices that some applications are failing because they require a fixed source port range. What should the administrator do to resolve this?

A.Change the IP pool type to 'Fixed Port Range'
B.Disable NAT and use policy-based routing
C.Use Central SNAT instead of policy-based NAT
D.Enable 'Preserve Source Port' in the firewall policy
AnswerA

In FortiOS, an IP pool configured as Fixed Port Range allocates source ports from a contiguous range for each NAT session rather than randomly selecting them as in Overload mode. This deterministic port assignment is essential when the destination service expects a stable or predictable source port per connection, such as legacy protocols or inter-server communications with port-based ACLs. Select this pool type in the IP pool configuration and reference it in the firewall policy's Dynamic IP Pool setting to satisfy the application requirement.

Why this answer

When an IP pool uses overload (PAT), the FortiGate dynamically assigns source ports from a default range (typically 1024-65535). Some applications require a fixed source port range (e.g., SIP or FTP) to function correctly. Changing the IP pool type to 'Fixed Port Range' allows the administrator to define a specific, static range of source ports that the FortiGate will use for NAT, ensuring the application receives traffic on the expected ports.

Exam trap

The trap here is that candidates may confuse 'Preserve Source Port' (a valid IP pool setting) with a firewall policy option, or assume that Central SNAT inherently provides fixed port ranges, when in fact the IP pool type must be explicitly changed to 'Fixed Port Range'.

How to eliminate wrong answers

Option B is wrong because disabling NAT and using policy-based routing would bypass NAT entirely, which does not address the need for a fixed source port range and could break connectivity for other traffic. Option C is wrong because Central SNAT is a different method of configuring NAT (centralized vs. policy-based) but does not inherently provide a fixed source port range; the IP pool type must still be set to 'Fixed Port Range'. Option D is wrong because 'Preserve Source Port' is not a valid option in FortiGate firewall policies; the correct feature to preserve the original source port is 'Preserve Source Port' in the IP pool configuration, not in the policy itself.

32
MCQmedium

An administrator needs to configure a firewall policy that allows internal users to access a specific web server on the internet using its domain name. The web server's IP address may change. Which type of address object should be used as the destination in the policy?

A.IP Range object that covers the entire public IP space
B.Subnet object with the current IP address
C.FQDN address object
D.Geography object
AnswerC

An FQDN address object resolves the domain name to its current IP addresses and refreshes them via DNS, so the policy keeps working when the server's address changes. A static IP object would break on change, failing the requirement that the destination track the domain.

Why this answer

An FQDN (Fully Qualified Domain Name) address object allows the firewall to resolve the domain name to an IP address dynamically. This is essential when the web server's IP address may change, as the firewall will periodically perform DNS resolution to update the destination IP in the policy, ensuring continuous access without manual reconfiguration.

Exam trap

The trap here is that candidates often confuse FQDN objects with static DNS entries or assume a subnet object is sufficient, overlooking the dynamic IP change scenario that FQDN objects are specifically designed to handle.

How to eliminate wrong answers

Option A is wrong because an IP Range object covering the entire public IP space would allow traffic to any internet destination, violating the principle of least privilege and creating a massive security risk. Option B is wrong because a Subnet object with the current IP address is static; if the server's IP changes, the policy will fail to match the new IP, blocking access. Option D is wrong because a Geography object matches traffic based on geographic location (country), not a specific host or domain, and cannot ensure traffic reaches the correct web server.

33
Multi-Selectmedium

An administrator is configuring policy-based routing (PBR) on a FortiGate to route traffic from a specific subnet (172.16.1.0/24) through a different internet connection (wan2) instead of the default route via wan1. The administrator has created a PBR rule matching source 172.16.1.0/24 and set the gateway to the next-hop IP on wan2. The traffic is still using wan1. Which THREE of the following could be causing the issue? (Choose three.)

Select 3 answers
A.The PBR rule's gateway is not reachable from the FortiGate
B.The PBR rule's priority is set too high (e.g., 100) and a static route with lower priority is used instead
C.The PBR rule is applied to the wrong incoming interface
D.The PBR rule is disabled
E.The PBR rule's destination is set to 'all' but the traffic's destination is not covered
AnswersA, C, D

For a PBR rule to be used, the FortiGate must be able to reach the configured gateway (next-hop). If the gateway is on a directly connected network, the FortiGate must resolve its MAC address via ARP; if the gateway is on a remote network, it must have a valid route to that gateway. When the next-hop is unreachable, the PBR rule is marked as inactive and is skipped during evaluation, causing the traffic to fall through to the normal routing table lookup. Even if a default static route exists, an unreachable PBR next-hop will never be used, so this directly explains why the rule is not matching.

Why this answer

PBR requires the specified next-hop gateway to be reachable via a directly connected route or a static route; if the gateway IP on wan2 is not reachable (e.g., due to a missing ARP entry or link failure), the FortiGate will fall back to the routing table and use the default route via wan1. The FortiGate performs a reachability check on the PBR gateway before applying the rule.

Exam trap

The trap here is that candidates often overlook the gateway reachability requirement for PBR, assuming any IP can be used as a next-hop, or they confuse PBR priority with static route administrative distance.

34
MCQhard

An admin is configuring a policy-based NAT rule (central NAT) to translate internal users' source IPs to the external IP of the FortiGate interface. However, users complain that some applications fail. The admin notices that the NAT rule is using 'dynamic IP pool' with overload. What is the MOST likely cause of the application failures?

A.The IP pool is exhausted and no more translations are available
B.The route to the destination is missing
C.The applications are sensitive to NAT and require a fixed port range
D.The firewall policy does not have NAT enabled
AnswerC

Several application-layer protocols, including SIP and FTP, embed IP addresses and TCP/UDP port numbers inside the payload. When overload NAT (PAT) dynamically assigns a different source port for each translation, the embedded port may no longer match the actual translated port, causing the peer to reject the session. A policy-based central NAT rule can be configured with a fixed port range or static port mapping, ensuring that the translated source port always matches what the application advertises. This is why application sensitivity is the correct reason for setting up such a NAT rule.

Why this answer

Applications sensitive to NAT, such as SIP, H.323, or FTP, often require a fixed port range or an explicit NAT rule that preserves the original source port. When a dynamic IP pool with overload (PAT) is used, the FortiGate may change the source port, breaking protocols that embed IP addresses or port information in the payload. This is the most likely cause of application failures in this scenario.

Exam trap

The trap here is that candidates often assume IP pool exhaustion (Option A) is the cause, but the question specifies 'some applications fail' rather than all traffic failing, pointing to application-layer NAT sensitivity rather than resource exhaustion.

How to eliminate wrong answers

Option A is wrong because an exhausted IP pool would cause new sessions to fail, but existing sessions would continue; the complaint is about application failures, not a complete inability to connect. Option B is wrong because a missing route would prevent all traffic to the destination, not just specific applications. Option D is wrong because the question states a policy-based NAT rule is configured, which inherently enables NAT; the firewall policy does not need a separate NAT enable checkbox when central NAT is used.

35
Multi-Selectmedium

An admin needs to configure NAT so that internal users (10.0.0.0/24) accessing the internet (any destination) are translated using an IP pool (203.0.113.10-203.0.113.20) with overload. The admin also needs to ensure that traffic from a specific server (10.0.0.100) always uses a fixed source port range (10000-20000) when translated. Which TWO configuration steps are required? (Choose two.)

Select 2 answers
A.Configure the IP pool with one-to-one NAT
B.Create a central SNAT rule for 10.0.0.0/24 using the IP pool with overload enabled
C.Use policy-based NAT instead of central SNAT
D.Disable NAT on the firewall policy for the server
E.Create a central SNAT rule for 10.0.0.100 using the IP pool with fixed port range enabled
AnswersB, E

A central SNAT rule for 10.0.0.0/24 using an IP pool with overload enabled is the correct approach because it implements many-to-one NAT via Port Address Translation (PAT). This allows all internal users in the subnet to share the public IP addresses in the pool, with each connection being distinguished by its source port. Central SNAT is consulted before firewall policy lookup, making it efficient and independent of policy sequencing for simple outbound translation.

Why this answer

Central SNAT allows you to translate traffic from the entire 10.0.0.0/24 subnet using an IP pool (203.0.113.10-203.0.113.20) with overload (PAT), which is the standard method for enabling many internal users to share a smaller pool of public IPs. Option E is correct because you need a separate, more specific central SNAT rule for the server 10.0.0.100 that uses the same IP pool but with a fixed port range (10000-20000) enabled, ensuring its translated source ports always fall within that range.

Exam trap

The trap here is that candidates often think a single SNAT rule can handle both the subnet translation and the server's fixed port requirement, but FortiOS requires two separate rules with different specificity and the fixed port range option enabled only on the server's rule.

36
MCQmedium

An admin configures a firewall policy with a schedule object that restricts access to Monday to Friday from 9:00 to 17:00. A user attempts to connect on Saturday at 10:00. Which of the following best describes what happens?

A.The traffic is allowed because the schedule is only used for logging
B.The traffic is allowed because the schedule is optional
C.The FortiGate skips this policy and tries the next policy; if no match, implicit deny blocks the traffic
D.The traffic is denied because the schedule is not valid
AnswerC

During firewall policy lookup, the FortiGate checks all match criteria in sequence per policy, including the schedule. If the current time does not fall within the configured schedule for a policy, that policy is skipped and evaluation proceeds to the next policy with its own schedule and other conditions. If no subsequent policy matches, the packet is dropped by the implicit deny rule, which is the default drop-all behavior at the end of the policy table.

Why this answer

When a firewall policy includes a schedule, the policy is only active during the specified time. Outside that schedule, the policy is skipped entirely, and the FortiGate evaluates the next policy in the list. If no subsequent policy matches, the implicit deny rule at the end blocks the traffic.

Therefore, on Saturday at 10:00, the policy is skipped, and if no other policy allows it, the traffic is denied.

Exam trap

NSE4 often tests the behavior of schedules in firewall policies, and candidates may incorrectly think that the schedule itself denies traffic or that the policy is still evaluated but with a different action, rather than being skipped entirely.

How to eliminate wrong answers

Option A is wrong because schedules are not used for logging; they actively control whether a policy is enforced. Option B is wrong because schedules are not optional; if a schedule is configured, it dictates when the policy is active. Option D is wrong because the traffic is not denied by the schedule itself; the schedule simply makes the policy inactive, and the denial occurs due to the implicit deny if no other policy matches.

37
MCQmedium

A FortiGate administrator observes that traffic from a specific subnet is being denied even though there is an allow policy for that subnet. The administrator checks the policy list and sees an explicit deny policy above the allow policy. What should the administrator do to allow the traffic?

A.Add a new policy with a higher ID
B.Move the allow policy above the deny policy
C.Disable the deny policy
D.Delete the deny policy
AnswerB

FortiGate evaluates policies top-down and stops at the first match, so the explicit deny above the allow policy blocks the subnet before the allow is reached. Moving the allow policy above the deny makes it match first, satisfying the requirement to permit that traffic.

Why this answer

FortiGate policies are evaluated sequentially from top to bottom (lowest ID to highest ID). The first matching policy is applied. If an explicit deny policy appears above an allow policy for the same subnet, the deny policy will match first and drop the traffic.

Moving the allow policy above the deny policy ensures it is evaluated first, allowing the traffic.

Exam trap

The trap here is that candidates may think adding a new policy with a higher ID (Option A) will override the deny policy, but they fail to understand that FortiGate evaluates policies in order of ID (lowest to highest), so a higher ID policy is evaluated later and will never be reached if a deny policy with a lower ID matches first.

How to eliminate wrong answers

Option A is wrong because adding a new policy with a higher ID places it below the existing policies in the list, so it would still be evaluated after the deny policy and never be reached. Option C is wrong because disabling the deny policy is an unnecessary workaround that leaves a disabled policy in the configuration, potentially causing confusion and not addressing the root cause of policy ordering. Option D is wrong because deleting the deny policy is overly aggressive; the deny policy may be needed for other traffic, and the correct solution is to reorder policies rather than remove a potentially valid rule.

38
MCQmedium

An admin needs to allow traffic from a specific IP to a web server on port 8080. The web server is behind a VIP that forwards port 80 to port 8080. When configuring the security policy, which destination should be used?

A.The virtual IP address of the FortiGate
B.The real server IP address
C.The VIP object
D.Any destination, because the VIP translates automatically
AnswerC

The correct method is to define a firewall policy that uses the VIP object as the destination. The VIP object links the public IP to the internal server, and when a packet matches the policy, FortiGate automatically performs destination NAT, rewriting the destination to the real server IP. This policy also allows you to specify the allowed source IP, fulfilling the requirement to permit traffic from that specific IP to the web server.

Why this answer

When a VIP is used to translate the destination IP and port (e.g., from public IP:80 to private server IP:8080), the security policy must reference the VIP object as the destination. FortiGate matches the policy using the original destination IP before destination NAT is applied. The VIP object represents the original destination (the external IP) that clients use, so referencing it ensures the policy correctly permits the traffic.

Exam trap

The trap is that candidates may incorrectly select the real server IP (the post-NAT destination) instead of the VIP object. However, FortiGate checks the original destination IP against the policy, so the VIP object must be used as the destination.

How to eliminate wrong answers

Option A is wrong because the virtual IP address of the FortiGate (the interface IP) is not the destination after translation; the VIP object represents the translated destination, not the interface IP. Option B is wrong because the real server IP address is the internal, private IP of the web server, but the security policy must match the destination after NAT (the VIP object), not the pre-translation real server IP. Option D is wrong because the destination is not 'any'; the policy must explicitly specify the VIP object to correctly match the translated traffic, as the VIP translation does not automatically apply to all destinations.

39
MCQmedium

A FortiGate has multiple VDOMs. The administrator needs to allow traffic from VDOM A (port1) to VDOM B (port2). What type of firewall policy is required?

A.An inter-VDOM policy on the inter-VDOM link interface
B.A policy using a virtual wire pair
C.A regular intra-VDOM policy on VDOM A with destination interface port2
D.A policy on each VDOM with the same source/destination
AnswerA

An inter-VDOM link provides a virtual connection between two VDOMs, and traffic crossing that link is controlled by an inter-VDOM policy. This policy is configured on the inter-VDOM link interface and functions as a firewall rule that specifies permitted source/destination addresses and services between the VDOMs. Without this policy, the inter-VDOM link will deny all traffic by default, so it is the essential configuration element for inter-VDOM communication.

Why this answer

When traffic must cross from one VDOM to another on a FortiGate, an inter-VDOM policy is required. This policy is applied to the inter-VDOM link interface, which acts as the logical boundary between VDOMs. It allows the firewall to enforce separate routing and security contexts while forwarding traffic between VDOMs.

Exam trap

The trap here is that candidates often assume a regular intra-VDOM policy with a cross-VDOM destination interface will work, but FortiGate enforces strict VDOM isolation and requires the explicit inter-VDOM link and policy to route traffic between VDOMs.

How to eliminate wrong answers

Option B is wrong because a virtual wire pair is used to transparently bridge two interfaces within the same VDOM, not to route traffic between separate VDOMs. Option C is wrong because a regular intra-VDOM policy on VDOM A cannot specify port2 as the destination interface if port2 belongs to a different VDOM; the destination interface must be in the same VDOM. Option D is wrong because placing a policy on each VDOM with the same source/destination does not create an inter-VDOM link; inter-VDOM traffic requires a dedicated inter-VDOM link interface and a single inter-VDOM policy on that link.

40
MCQhard

An admin configures an IP Pool with type 'Overload' for outbound traffic from the 192.168.1.0/24 subnet. The pool uses a single public IP 203.0.113.10. After a few hours, users are unable to access external websites. The admin checks the session table and sees many sessions with the same public IP and different source ports. What is the most likely issue?

A.The session helper is misconfigured
B.The IP Pool has run out of available source ports
C.The IP Pool's public IP has been blacklisted by external websites
D.The firewall policy is not referencing the IP Pool
AnswerB

With overload NAT (also called PAT or IP masquerading), all internal hosts are mapped to a single public IP address. The FortiGate must assign a unique source port number to each concurrent session per protocol (TCP and UDP have separate port spaces). The theoretical maximum is around 65,535 ports per protocol, minus reserved ports and those held in TIME_WAIT. When every available source port is already used, the IP pool becomes exhausted and the FortiGate cannot translate new sessions, causing connection failures for new traffic even though existing sessions continue to work.

Why this answer

The IP Pool is configured with type 'Overload' (Port Address Translation), which maps multiple internal hosts to a single public IP by using unique source ports. With a single public IP (203.0.113.10), the maximum number of concurrent sessions is limited by the available source ports (approximately 65,535 per IP, minus reserved ports). Once all source ports are consumed, new outbound sessions cannot be established, causing users to lose access to external websites.

Exam trap

The trap here is that candidates may confuse 'Overload' with 'Static NAT' or think the issue is policy-related, but the key clue is the session table showing many sessions with the same public IP and different source ports, which directly points to source port exhaustion under PAT.

How to eliminate wrong answers

Option A is wrong because a misconfigured session helper would affect specific application-layer protocols (e.g., FTP, SIP) by failing to translate embedded IP addresses or ports, not cause a complete exhaustion of source ports for all outbound traffic. Option C is wrong because blacklisting by external websites would block traffic to specific destinations, not prevent new sessions from being created due to port exhaustion; the session table would still show active sessions with the same public IP. Option D is wrong because if the firewall policy were not referencing the IP Pool, no NAT would be applied, and sessions would use the egress interface's IP directly, not the pool's IP; the symptom of many sessions with the same public IP and different source ports indicates that the IP Pool is indeed being used.

41
MCQhard

An administrator configures a policy-based NAT rule to translate traffic from 10.0.0.0/8 to 203.0.113.1 using an IP Pool with overload. Later, they also enable Central SNAT for the same traffic. The traffic is not being NAT'd as expected. What is the MOST likely reason?

A.Both NAT methods are applied, causing double NAT
B.Central SNAT overrides policy-based NAT
C.The IP Pool used in policy-based NAT is also used in Central SNAT, causing a conflict
D.Policy-based NAT always overrides Central SNAT
AnswerB

Central SNAT is evaluated before policy-based NAT, so once enabled it takes precedence and the policy-based rule no longer translates the 10.0.0.0/8 traffic. Disabling Central SNAT or consolidating the rules restores the intended overload translation.

Why this answer

Central SNAT (Source NAT) is a centralized NAT policy that takes precedence over policy-based NAT rules when both are configured for the same traffic. In FortiGate, Central SNAT is evaluated before policy-based NAT, and if a matching Central SNAT rule exists, it will override any policy-based NAT configuration. This is by design to provide a more predictable and manageable NAT architecture.

Exam trap

The trap here is that candidates often assume policy-based NAT is always applied because it is configured directly on the firewall policy, but FortiGate's Central SNAT has a higher precedence, leading to unexpected NAT behavior when both are enabled.

How to eliminate wrong answers

Option A is wrong because double NAT would occur only if both NAT methods were applied sequentially, but Central SNAT overrides policy-based NAT, so only one NAT translation is applied. Option C is wrong because using the same IP Pool in both Central SNAT and policy-based NAT does not inherently cause a conflict; the conflict arises from the precedence order, not the pool itself. Option D is wrong because policy-based NAT does not always override Central SNAT; in fact, Central SNAT has higher priority and overrides policy-based NAT when both are configured for the same traffic.

42
MCQmedium

A FortiGate has two policies for traffic from port1 to port3: Policy 1 (destination 10.0.1.0/24, schedule always, action accept) and Policy 2 (destination 10.0.2.0/24, schedule 'Weekdays', action accept). A packet destined to 10.0.2.10 arrives on Wednesday at 2 PM. Which policy is applied?

A.Policy 2 because it matches the destination and the schedule is active
B.Both policies are applied sequentially
C.Neither; the implicit deny applies
D.Policy 1 because it is listed first
AnswerA

Policy 2 is the effective policy because FortiGate selects the first policy from the top that matches ALL required criteria: source interface/address, destination interface/address, service, and schedule. Policy 1 does not match the destination (its destination does not include port3 or the target IP), so it is skipped. Policy 2 matches the destination and its schedule is currently active, so it both matches and is the first matching policy; therefore traffic is permitted. In FortiGate's sequential top-down evaluation, only the first full match is used.

Why this answer

Policy 2 is applied because it matches the destination IP (10.0.2.10) and the schedule 'Weekdays' is active on Wednesday at 2 PM. FortiGate uses a first-match approach only when multiple policies have the same priority; here, Policy 1 does not match the destination, so Policy 2 is the only matching policy. Since the schedule is valid, the action 'accept' is executed.

Exam trap

The trap here is that candidates assume policy order alone determines matching (Option D), but they overlook that the destination must match first, and schedules must be active for the policy to be considered.

How to eliminate wrong answers

Option B is wrong because FortiGate does not apply multiple policies sequentially to a single session; it uses a first-match model where only the first matching policy is applied. Option C is wrong because the implicit deny only applies when no explicit policy matches the traffic, but Policy 2 matches and is active. Option D is wrong because Policy 1 does not match the destination (10.0.2.10 is not in 10.0.1.0/24), so it is not considered regardless of its order.

43
MCQhard

An organization wants to authenticate VPN users using an LDAP server. They configure an LDAP server object and a user group. However, users are unable to authenticate. The administrator checks the logs and sees 'authentication failed' errors. What is the most common misconfiguration?

A.The user group is not configured with the correct members
B.The LDAP server uses SSL/TLS but the FortiGate is not configured for it
C.The LDAP server bind DN or password is incorrect
D.The LDAP server is not reachable from the FortiGate
AnswerC

The bind DN (distinguished name) and password constitute the FortiGate's service account credentials for connecting to the LDAP directory. If either is incorrect, the LDAP server rejects the bind operation with an 'invalid credentials' error (LDAP result code 49). This prevents the FortiGate from performing any directory queries, so the authentication process fails immediately at the initial bind stage, which is exactly what the user would see as an authentication failure.

Why this answer

The most common misconfiguration when LDAP authentication fails is an incorrect bind DN or password. The FortiGate uses the bind DN to authenticate to the LDAP server before it can search for users; if these credentials are wrong, the LDAP server rejects the bind request, resulting in an 'authentication failed' log entry. This error occurs even before user credentials are checked, making it a frequent root cause.

Exam trap

The trap here is that candidates assume 'authentication failed' refers to the VPN user's credentials, but it actually indicates the LDAP server rejected the FortiGate's bind request due to incorrect bind DN or password.

How to eliminate wrong answers

Option A is wrong because the user group membership affects authorization (which users are allowed), not the initial LDAP bind authentication; the 'authentication failed' error occurs at the bind stage, not after a successful user lookup. Option B is wrong because if the LDAP server uses SSL/TLS but FortiGate is not configured for it, the error would typically be a connection timeout or TLS handshake failure, not a generic 'authentication failed' message. Option D is wrong because if the LDAP server were unreachable, the log would show a connection error or timeout, not an 'authentication failed' error, which indicates the server was reached but rejected the bind.

44
MCQeasy

An administrator is creating firewall policies for a FortiGate that separates the internal network (10.0.1.0/24) from a DMZ (192.168.1.0/24). The goal is to allow HTTP traffic from the internal network to the DMZ web server (192.168.1.10) but deny all other traffic. What is the recommended security posture for the implicit deny policy?

A.Set the allow policy to also deny all other traffic using security profiles
B.Disable the implicit deny policy and create a catch-all deny policy
C.Create an explicit deny policy with logging enabled before the allow policy
D.Rely on the implicit deny policy at the end of the policy list, which will block all traffic not explicitly allowed
AnswerD

FortiGate's implicit deny is the last policy in the lookup chain, dropping any packet that does not match an earlier explicit policy. This default-deny behavior implements a least-privilege model, ensuring only services explicitly permitted by firewall policies are reachable. It is always active and cannot be removed, making it a reliable baseline for secure network segmentation.

Why this answer

The implicit deny policy is a default, hidden policy at the end of the FortiGate policy list that denies all traffic not explicitly allowed by preceding policies. Since the administrator wants to allow only HTTP traffic from internal to the DMZ web server and deny all other traffic, relying on the implicit deny is the correct and recommended security posture. It automatically blocks everything else without requiring manual configuration, ensuring no unintended traffic is permitted.

Exam trap

The trap here is that candidates may think they need to create an explicit deny policy with logging to block unwanted traffic, not realizing that the implicit deny already performs this function and that placing a deny policy before the allow policy would break the intended traffic flow.

How to eliminate wrong answers

Option A is wrong because setting the allow policy to also deny all other traffic using security profiles is not a valid approach; security profiles inspect allowed traffic but do not deny traffic that is not explicitly permitted. Option B is wrong because disabling the implicit deny policy and creating a catch-all deny policy is unnecessary and introduces risk; the implicit deny already provides the same functionality without manual intervention. Option C is wrong because creating an explicit deny policy with logging enabled before the allow policy would block all traffic, including the desired HTTP traffic, since FortiGate processes policies in sequential order from top to bottom.

45
MCQmedium

An administrator configures a firewall policy allowing traffic from the internal network to the internet with NAT enabled. Users report that some outbound connections fail intermittently. The administrator runs 'diagnose sys session list' and sees many sessions in 'proto_state=01' with a short TTL. What is the most likely cause?

A.The firewall policy has the wrong source interface
B.The destination port is blocked by an implicit deny rule
C.The antivirus profile is blocking the connections
D.The IP pool used for SNAT has exhausted its address range
AnswerD

When a firewall policy uses SNAT with a configured IP pool, the FortiGate must select an available IP address and a free port from that address to translate the source IP for new outbound sessions. If the IP pool's address range is exhausted — meaning all IPs are already assigned to active sessions with all their port ranges used — the FortiGate cannot allocate a source IP, so it drops the connection and logs an event such as 'no source IP available' or 'IP pool exhausted.' This exactly matches the symptom: the policy is matched, but connections fail due to a NAT resource shortage, which is the correct answer.

Why this answer

The 'diagnose sys session list' output showing many sessions in 'proto_state=01' with a short TTL indicates that sessions are failing to establish properly. When the IP pool used for Source NAT (SNAT) exhausts its address range, new outbound connections cannot obtain a translated source IP, causing them to fail intermittently. This matches the symptom of intermittent failures as the pool becomes temporarily depleted.

Exam trap

The trap here is that candidates may misinterpret 'proto_state=01' as a protocol or state machine error, rather than recognizing it as a symptom of NAT resource exhaustion, leading them to incorrectly select options related to policy misconfiguration or security profiles.

How to eliminate wrong answers

Option A is wrong because a wrong source interface would cause all traffic to fail consistently, not intermittently, and the session list would show no matching policy hits rather than specific proto_state values. Option B is wrong because an implicit deny rule would block traffic entirely, not intermittently, and would not produce sessions with a short TTL in the session table. Option C is wrong because an antivirus profile blocking connections would typically show specific virus detection logs or content inspection failures, not a proto_state=01 indicating a NAT resource exhaustion issue.

46
MCQmedium

An administrator needs to ensure that a firewall policy applies only during business hours (Monday to Friday, 9:00 AM to 6:00 PM). What object should be configured and applied to the policy?

A.Service group
B.Address group
C.Schedule object
D.Traffic shaper
AnswerC

A schedule object is the FortiGate construct designed specifically to define when a policy is valid and enforceable, using either a recurring weekly/daily pattern or a one-time date and time range. By attaching a schedule object such as 'Business Hours' (e.g., 08:00–18:00, Monday–Friday) to the policy, FortiGate will evaluate and apply that policy only within the defined window; outside that window the policy is skipped entirely. This is exactly what the administrator needs to ensure the policy applies only at the intended times.

Why this answer

A schedule object in FortiGate defines time-based conditions (e.g., recurring weekly windows like Monday–Friday 09:00–18:00) that can be applied directly to a firewall policy. When a schedule is attached, the policy is enforced only during the specified time range, making it the correct object for restricting policy activation to business hours.

Exam trap

The trap here is that candidates confuse a schedule object with a service group or traffic shaper, mistakenly thinking time-based access can be achieved via port grouping or QoS policies, whereas FortiGate explicitly requires a schedule object for time-of-day policy enforcement.

How to eliminate wrong answers

Option A is wrong because a service group is used to group multiple protocol/port definitions (e.g., TCP/80, TCP/443) for application-layer matching, not for time-based enforcement. Option B is wrong because an address group aggregates IP addresses or FQDN objects for source/destination matching, not for controlling when a policy is active. Option D is wrong because a traffic shaper controls bandwidth allocation and QoS (e.g., guaranteed/ maximum bandwidth), not the temporal activation of a firewall policy.

47
MCQmedium

An administrator configures a Virtual IP (VIP) to map the public IP 203.0.113.10 port 8080 to the internal server 192.168.1.100 port 80. External users report they cannot connect. The firewall policy allows inbound traffic to the VIP. What is the MOST likely missing configuration?

A.The destination in the firewall policy is set to the public IP directly instead of the VIP object
B.The VIP is configured with port forwarding disabled
C.The server's default gateway is not set to the FortiGate
D.The source NAT is not configured
AnswerA

FortiGate matches inbound traffic against the VIP object, not the public IP. If the policy destination is the raw public IP, the connection never maps to the internal server, so external users fail despite the policy appearing to permit traffic.

Why this answer

When a Virtual IP (VIP) is configured, the firewall policy must reference the VIP object as the destination, not the public IP address directly. If the policy uses the public IP (203.0.113.10) as the destination, the FortiGate will not perform the destination NAT translation to the internal server (192.168.1.100). The VIP object contains the mapping logic, so the policy must point to that object for the translation to occur.

Exam trap

The trap here is that candidates assume the firewall policy should use the public IP as the destination, not realizing that the VIP object must be referenced in the policy for the NAT translation to be applied.

How to eliminate wrong answers

Option B is wrong because port forwarding is implicitly enabled when you define a VIP with a specific port mapping (8080 to 80); there is no separate 'port forwarding disabled' toggle that would block this. Option C is wrong because the server's default gateway does not need to be the FortiGate for inbound connections; return traffic can be routed via the FortiGate if the VIP uses source NAT (central NAT) or if the server's gateway points to the FortiGate, but this is not the most likely missing configuration for inbound connectivity failure. Option D is wrong because source NAT is not required for inbound VIP traffic; the VIP handles destination NAT, and source NAT (e.g., for return traffic) is a separate configuration that is not essential for initial inbound connections.

48
Multi-Selecteasy

A FortiGate administrator needs to block all traffic from a specific IP address (10.0.0.100) to the internet, but allow all other internal users. The administrator has created a firewall policy with source=10.0.0.100, destination=all, service=all, action=DENY, and placed it at the top of the policy list. Which TWO additional steps should the administrator take to ensure the block is effective? (Choose two.)

Select 2 answers
A.Enable the policy
B.Configure an IP Pool for the deny policy
C.Add a schedule to the policy for business hours
D.Ensure no other policy above this one allows traffic from 10.0.0.100
E.Set the action to ACCEPT
AnswersA, D

In FortiGate, firewall policies are created in a disabled state by default unless explicitly enabled at creation. A disabled policy is not evaluated in the policy lookup, so even if it matches the source/destination/service, traffic will not be denied. For the deny action to be enforced, the policy must have its status set to 'enable' so the FortiOS kernel includes it in the ordered rule evaluation.

Why this answer

A newly created firewall policy in FortiGate is disabled by default. The administrator must explicitly enable the policy for it to be enforced. Without enabling, the deny rule will not process traffic, leaving the block ineffective.

Exam trap

The trap here is that candidates often forget that new policies are disabled by default, and they may overlook the importance of policy order when a deny rule is placed at the top but a previous ACCEPT rule exists for the same source.

49
MCQmedium

You run the following CLI command on a FortiGate: # diagnose debug flow filter saddr 192.168.1.10 # diagnose debug flow show function enable # diagnose debug enable You then initiate a ping from 192.168.1.10 to 8.8.8.8. The output shows 'no matching policy'. What does this indicate?

A.The traffic is being NAT'd but not logged
B.The debug filter is incorrectly configured
C.There is a routing issue preventing the traffic
D.The traffic is dropped by the implicit deny rule
AnswerD

The implicit deny rule is the final entry in the FortiGate policy table, and it drops any traffic that does not match an explicit allow or deny policy. By default, the implicit deny rule does not generate log entries, which explains the absence of logs in the output. The diagnose flow would show the packet count incrementing at this rule, confirming that the traffic is silently dropped here. This is the correct and most common reason for traffic failing to pass through a FortiGate when policies appear to be missing.

Why this answer

The 'no matching policy' output from the debug flow indicates that the FortiGate evaluated the packet against its firewall policy table and found no explicit policy permitting the traffic from source 192.168.1.10 to destination 8.8.8.8. Since no matching policy exists, the packet is implicitly denied by the default deny-all rule at the end of the policy table, which drops the traffic without logging unless explicitly configured. This is the expected behavior when no permit policy is configured for the traffic flow.

Exam trap

The trap here is that candidates often confuse 'no matching policy' with a routing problem or NAT misconfiguration, but the debug flow output explicitly pinpoints the firewall policy layer as the point of failure, not routing or NAT.

How to eliminate wrong answers

Option A is wrong because NAT is applied after a policy match, and 'no matching policy' means the traffic never reached the NAT stage; logging is also a policy-level action that only occurs after a match. Option B is wrong because the debug filter is correctly configured with the source address 192.168.1.10, and the output specifically shows the packet being processed; the filter is not the cause of the 'no matching policy' result. Option C is wrong because routing is evaluated before firewall policies, and if there were a routing issue, the debug flow would show 'no route to destination' or similar, not 'no matching policy'; the presence of a route is implied by the packet reaching the policy lookup stage.

50
MCQhard

You execute 'get firewall policy 5' and see the following output: policyid=5 name="test" status=enable schedule="always" logtraffic=all What does 'logtraffic=all' mean?

A.Only the first packet of each session will be logged
B.Only traffic that triggers a security profile will be logged
C.Only traffic that is denied by the policy will be logged
D.All traffic matching the policy will be logged, regardless of action
AnswerD

The 'all' setting for the 'logtraffic' option on a Fortinet firewall policy instructs the device to log every session that matches the policy, regardless of the action taken (accept or deny). This includes sessions that are allowed through as well as those that are explicitly blocked. It is the most comprehensive logging mode for a policy and is often used for audit compliance or troubleshooting. Therefore, this option correctly describes the behavior of 'logtraffic=all'.

Why this answer

'logtraffic=all' in FortiGate firewall policy configuration means that every packet belonging to a session matching this policy will be logged, regardless of whether the action is accept or deny. This is distinct from other log settings like 'logtraffic=utm' or 'logtraffic=disable', and it ensures full audit trail for all traffic handled by the policy.

Exam trap

The trap here is that candidates often confuse 'logtraffic=all' with 'logtraffic=session-start' or think it only logs denied traffic, but FortiGate's granular log options require precise understanding of each keyword's behavior.

How to eliminate wrong answers

Option A is wrong because logging only the first packet of each session is the behavior of 'logtraffic=session-start', not 'logtraffic=all'. Option B is wrong because logging only traffic that triggers a security profile is the behavior of 'logtraffic=utm' (UTM-based logging), not 'logtraffic=all'. Option C is wrong because logging only denied traffic is the behavior of 'logtraffic=deny', not 'logtraffic=all'.

51
MCQhard

Refer to the exhibit. An administrator configures the policies as shown. Traffic from 10.0.0.0/8 to the internet on HTTP is denied. What is the most likely reason?

A.The Allow-HTTP policy uses service HTTP but the traffic uses HTTPS
B.The Deny-All policy is placed above the Allow-HTTP policy
C.The Allow-HTTP policy has the wrong source interface
D.The Allow-HTTP policy is disabled
AnswerB

In FortiOS, policy evaluation is top-down and first-match; the first policy whose source/destination/service matches the traffic is applied. The Deny-All policy has a lower sequence number (e.g., policy ID 0) and appears above the Allow-HTTP policy, so it matches all traffic and denies the HTTP session before the allow policy is ever evaluated. Specificity does not override order, so the deny-all wins.

Why this answer

In FortiGate firewall policies, the first matching policy is applied to traffic. The Deny-All policy is placed above the Allow-HTTP policy, so traffic from 10.0.0.0/8 to the internet on HTTP matches the Deny-All policy first and is denied before reaching the Allow-HTTP policy. This is a classic policy ordering issue.

Exam trap

The trap here is that candidates often assume policies are evaluated based on a 'most specific match' logic rather than the actual sequential order, leading them to overlook the policy placement as the root cause.

How to eliminate wrong answers

Option A is wrong because the question states traffic uses HTTP, not HTTPS, so the service mismatch is not the reason. Option C is wrong because the source interface is not specified as incorrect in the exhibit; the issue is policy order, not interface mismatch. Option D is wrong because the Allow-HTTP policy is not disabled; it is simply never evaluated due to the higher priority of the Deny-All policy.

52
MCQmedium

An administrator is troubleshooting a FortiGate firewall policy that is supposed to allow HTTP traffic from the internal network to the internet. The policy is configured with source 'all', destination 'all', service 'HTTP', and action 'ACCEPT'. However, users report that HTTP traffic is being blocked. The administrator checks the policy list and sees that the policy is enabled. What is the most likely reason for the block?

A.The service 'HTTP' is not defined in the FortiGate services list.
B.The policy is placed below a more specific deny policy that matches the traffic.
C.The policy has NAT disabled, so return traffic cannot find its way back.
D.The policy does not have a schedule applied, so it is always active.
AnswerB

Firewall policies are evaluated top-down, and the first matching policy is applied. If a deny policy appears above the allow policy and matches the same traffic (e.g., source 'all', destination 'all', service 'ALL'), then HTTP traffic will be blocked before reaching the allow policy. The administrator should check the policy order and move the allow policy above any conflicting deny policy.

Why this answer

Firewall policies on a FortiGate are processed sequentially from top to bottom. The first policy that matches the traffic determines the action. If a deny policy appears earlier in the list and matches the same source, destination, and service, the traffic will be blocked regardless of a later allow policy.

Therefore, the most likely cause is that the allow policy is positioned below a conflicting deny policy.

Exam trap

The trap here is assuming that an enabled allow policy will always permit traffic, ignoring the sequential evaluation order where an earlier deny policy can override it.

53
MCQmedium

A FortiGate administrator runs the following command and sees output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate about the session?

A.The session has expired
B.The session is being blocked by a firewall policy
C.The session is an active TCP connection that has been established for 1 hour
D.The session is using UDP
AnswerC

This is correct because 'duration=3600' means the connection has been established for exactly 3600 seconds, which is 1 hour, and 'proto=6' is the IP protocol number for TCP. The 'expire=3599' field shows the remaining lifetime in seconds, so the session is still active. An established TCP session with bidirectional traffic is exactly what a FortiGate tracks in its session table, confirming it is not merely a one-way packet but an ongoing connection.

Why this answer

The output shows `proto=6`, which is the protocol number for TCP, and `proto_state=01`, which in FortiGate's session table indicates an established TCP connection (state ESTABLISHED). The `duration=3600` seconds means the session has been active for exactly 1 hour, and `expire=3599` seconds shows the remaining time before the session times out. This confirms the session is an active TCP connection that has been established for 1 hour, making option C correct.

Exam trap

The trap here is that candidates confuse `duration` with `expire`, assuming a high duration means the session is about to end, when in fact `expire` shows the remaining lifetime, and `proto_state=01` is the key indicator of an active established TCP session.

How to eliminate wrong answers

Option A is wrong because `expire=3599` indicates the session still has 3599 seconds left before expiry, not that it has expired. Option B is wrong because a blocked session would not appear in the session list at all; the `diagnose sys session list` command only shows active sessions that have passed firewall policy inspection. Option D is wrong because `proto=6` explicitly identifies the protocol as TCP, not UDP (which would be proto=17).

54
Multi-Selectmedium

An administrator needs to block access to a specific website using FQDN address objects. Which TWO steps are necessary?

Select 2 answers
A.Create an FQDN address object for the website
B.Add a firewall policy with destination set to the FQDN object and action DENY
C.Create a wildcard FQDN address object
D.Configure a DNS filter to block the FQDN
E.Create a VIP for the website
AnswersA, B

An FQDN address object allows the FortiGate to resolve the website's fully qualified domain name to one or more IP addresses dynamically, referencing the site by name in security policies. This object is a required building block because websites frequently change their IPs, and a static address object would become stale quickly. Creating the object alone does not block traffic; it must be combined with a deny policy to enforce the block.

Why this answer

Creating an FQDN address object (Option A) is necessary because it allows the firewall to resolve the fully qualified domain name to an IP address dynamically, enabling policy enforcement based on the domain rather than a static IP. Adding a firewall policy with destination set to that FQDN object and action DENY (Option B) is required to actually block traffic to the website by matching the resolved IP addresses against the policy. Without both steps, the firewall cannot identify and deny traffic to the specific website using FQDN-based control.

Exam trap

The trap here is that candidates often confuse DNS filtering (Option D) with FQDN-based firewall policies, but DNS filtering only prevents DNS resolution, not direct IP access, while FQDN address objects in a firewall policy block traffic at the network layer regardless of how the destination IP is obtained.

55
MCQmedium

A FortiGate admin creates a new firewall policy with source address object 'Internal_Net' and destination 'All'. After saving, traffic from 'Internal_Net' is not matching the new policy but instead matches an older policy with a broader source. What is the MOST likely cause?

A.The source address object 'Internal_Net' has an incorrect subnet mask
B.The new policy is placed below the older policy in the policy list
C.The new policy is disabled
D.Traffic shaping is applied to the new policy and is interfering
AnswerB

FortiGate firewall policies are evaluated sequentially from the top of the policy list downward, and the first policy whose source, destination, and service match the packet is applied. If the new policy is created below an older, broader policy that also matches the same traffic, the older policy will intercept the traffic before the new policy is ever considered. This first-match behavior is the reason traffic appears to hit the older policy, regardless of the new policy's content. The fix is to move the new policy above the older one in the policy list.

Why this answer

A FortiGate firewall evaluates policies sequentially from top to bottom, applying the first match. If the new policy is placed below an older policy with a broader source definition, traffic from 'Internal_Net' will match the older policy first and never reach the new policy. Therefore, option B is the correct answer.

Exam trap

The trap here is that candidates assume a newly created policy will automatically take precedence over older policies, but FortiGate requires manual reordering to enforce policy priority, unlike some vendors that use a most-specific-match logic.

How to eliminate wrong answers

Option A is wrong because an incorrect subnet mask on 'Internal_Net' would cause the object to not match the source IP, but the question states traffic is matching an older policy, implying the source object is functional. Option C is wrong because a disabled policy would show as greyed out in the GUI and generate a log entry indicating 'deny' or 'no match', but the traffic is matching an older policy, not being dropped. Option D is wrong because traffic shaping does not prevent policy matching; it only affects bandwidth allocation after a policy is matched, and would not cause traffic to skip the new policy.

56
MCQeasy

An admin wants to block all traffic from the internet to a specific internal server except for the IP address 203.0.113.50. Which firewall policy configuration achieves this using the principle of least privilege?

A.Configure a VIP with restricted source
B.Use a local-in policy to block the server IP
C.Create a deny policy from internet to server with any source, then an allow policy from source 203.0.113.50 to the server above it
D.Create a single allow policy from source 203.0.113.50 to the server and rely on implicit deny for all other traffic
AnswerC

This approach follows the least-privilege principle by creating a broad deny policy for any internet source to the server, then placing a more specific allow policy above it for source 203.0.113.50. Because FortiGate evaluates policies top-down with first-match logic, the allow policy captures the permitted host while all other sources fall through to the explicit deny and are blocked. Without the explicit deny, the implicit deny at the bottom would still block other traffic, but an explicit deny makes the intent clear and reduces reliance on a default behavior.

Why this answer

It follows the principle of least privilege by explicitly denying all traffic from the internet to the internal server (with a deny policy using any source), then placing an explicit allow policy above it for source 203.0.113.50. In FortiGate firewall policy processing, policies are evaluated top-down, so the more specific allow rule for the trusted source is matched first, while the broader deny rule below it blocks all other internet traffic. This ensures only the permitted IP address can reach the server, and all other traffic is explicitly blocked.

Exam trap

The trap here is that candidates often think a VIP with restricted source (Option A) can control source access, but VIPs only handle destination translation and do not enforce source-based filtering; the actual access control must be done via firewall policies.

How to eliminate wrong answers

Option A is wrong because a VIP (Virtual IP) with restricted source is used for destination NAT (port forwarding) and does not control source-based access; it translates the destination IP/port but still relies on firewall policies to permit or deny traffic, so it does not achieve the explicit block-all-except-one requirement. Option B is wrong because a local-in policy controls traffic destined to the FortiGate itself (management traffic), not traffic passing through the FortiGate to an internal server; it cannot be used to filter transit traffic to a specific server. Option D is wrong because relying on implicit deny alone violates the principle of least privilege; while it would block other traffic, it does not provide an explicit deny rule, making it harder to audit and potentially allowing unintended traffic if the implicit deny is accidentally overridden or if there are other policies that match before it.

57
MCQmedium

An administrator needs to allow VoIP traffic from a remote branch (192.168.2.0/24) to the main office (10.0.0.0/8) using UDP ports 5060 and 10000-20000. What is the most efficient way to define the service in the firewall policy?

A.Create a service group containing both service objects
B.Use a custom service object with port range 5060-20000
C.Create two separate firewall policies, one for each port range
D.Use the predefined 'VoIP' service object
AnswerA

Creating a service group that contains both the SIP service object (UDP/TCP 5060) and the RTP service object (UDP 10000-20000) lets a single firewall policy match the full VoIP call flow. This is the correct approach because FortiGate service groups are logical sets of service objects that allow you to consolidate multiple protocols without expanding the policy count.

Why this answer

Creating a service group allows you to combine two separate service objects (one for UDP 5060 and one for UDP 10000-20000) into a single logical group, which can then be applied in one firewall policy. This is the most efficient method as it avoids duplicating policies or using an overly broad port range, and it leverages FortiGate's service group feature for clean, manageable rule sets.

Exam trap

The trap here is that candidates often assume a single port range (5060-20000) is acceptable for efficiency, overlooking the security risk of opening unnecessary ports, or they mistakenly rely on the predefined 'VoIP' service object without verifying its exact port definitions.

How to eliminate wrong answers

Option B is wrong because using a single custom service object with port range 5060-20000 would incorrectly include ports 5061-9999, which are not required for VoIP traffic and could introduce security risks by allowing unintended traffic. Option C is wrong because creating two separate firewall policies for each port range is inefficient and increases administrative overhead; it also violates the principle of least complexity in firewall design. Option D is wrong because the predefined 'VoIP' service object in FortiGate typically includes a broader set of ports and protocols (e.g., SIP over TCP, RTP over UDP) that may not match the exact requirement of UDP ports 5060 and 10000-20000, potentially allowing unwanted traffic or missing necessary ports.

58
Multi-Selectmedium

A FortiGate administrator is configuring a firewall policy to allow inbound HTTPS traffic from the internet to an internal web server. The web server has a private IP address 10.0.0.10. The administrator wants to translate the destination IP to the internal server using a Virtual IP (VIP). Which TWO of the following must be configured for the VIP to work correctly? (Choose two.)

Select 2 answers
A.An IP Pool must be configured for the web server's return traffic
B.The VIP must have port forwarding enabled with the external and internal ports set to 443
C.The VIP must have the external IP set to a public IP address assigned to the FortiGate's WAN interface
D.The firewall policy must use the VIP as the destination address object
E.The firewall policy must have NAT enabled
AnswersC, D

The external IP of a virtual IP must be one of the IP addresses assigned to the FortiGate's incoming interface, typically a public IP on the WAN. That address is the destination of the inbound packet, and only traffic addressed to the FortiGate itself can be intercepted and translated to the mapped internal server. If the external IP is not configured on the interface, the FortiGate has no way to receive that packet and the VIP cannot work.

Why this answer

A Virtual IP (VIP) must map a public IP address (typically assigned to the FortiGate's WAN interface) to the internal private IP of the web server. Without setting the external IP to a public address, the VIP cannot receive inbound traffic from the internet. Option D is correct because the firewall policy must reference the VIP as the destination address object; this triggers the destination NAT translation from the public IP to the private IP 10.0.0.10.

Exam trap

The trap here is that candidates often think port forwarding must be explicitly enabled for any port-based VIP, but FortiGate's VIP automatically performs port mapping without requiring the 'port forwarding' checkbox when the external and internal ports are the same.

59
MCQeasy

A junior admin is creating firewall policies and wants to ensure that all traffic not explicitly permitted is denied. Which FortiGate mechanism provides this behavior by default?

A.The security profile group
B.The default route
C.The last explicit deny policy in the policy list
D.The implicit deny rule
AnswerD

The implicit deny rule is a built-in, invisible final policy on every FortiGate firewall; any session that does not match an explicit allow or explicit deny policy is automatically dropped and logged. This rule cannot be deleted or disabled, ensuring that the firewall always enforces a default-deny posture for all unpermitted traffic. It is the true answer to the question because it is automatically applied, requiring no configuration, and it closes the gap that would otherwise allow traffic to pass unchecked.

Why this answer

The implicit deny rule is a default, hidden policy at the end of the FortiGate firewall policy list that denies all traffic not explicitly permitted by any user-created policy. This behavior is inherent to the FortiGate operating system and ensures a default-deny posture without requiring manual configuration. It is always present and cannot be deleted or moved, providing a safety net that blocks any unmatched traffic.

Exam trap

The trap here is that candidates may think the last explicit deny policy (Option C) is the default mechanism, but FortiGate's implicit deny rule is always present and active by default, whereas an explicit deny policy must be manually added and is not a default behavior.

How to eliminate wrong answers

Option A is wrong because a security profile group is a collection of security profiles (e.g., antivirus, web filter) applied to a firewall policy, not a mechanism that denies traffic by default. Option B is wrong because the default route controls where traffic is forwarded, not whether it is permitted or denied; it does not enforce access control. Option C is wrong because while an explicit deny policy can be added to the policy list, it is not present by default; the implicit deny rule is the built-in mechanism that denies all unmatched traffic without requiring any explicit policy.

60
MCQhard

A FortiGate administrator configures a Central SNAT policy to translate internal IPs to a single public IP for internet access. However, traffic from a specific internal server (10.0.1.100) must use a different public IP. The administrator also creates a policy-based NAT rule in the firewall policy for that server. Which NAT method takes precedence?

A.Central SNAT takes precedence over policy-based NAT
B.Policy-based NAT takes precedence because it is more specific
C.Central SNAT takes precedence because it is evaluated after policy-based NAT
D.The most recently created rule takes precedence
AnswerA

Central SNAT policies are evaluated independently of firewall policies and always take precedence over legacy policy-based NAT on FortiGate. Once central NAT is enabled, any existing policy-based NAT entries are effectively bypassed, and the translator uses the central SNAT rule regardless of how specific or general the policy-based NAT rule is. This precedence is deterministic: the central NAT engine runs first, and a matched central SNAT rule directly defines the source address translation.

Why this answer

In FortiGate, when both Central SNAT and policy-based NAT (configured within a firewall policy) are present, Central SNAT takes precedence. This is because Central SNAT is evaluated before policy-based NAT in the NAT processing order, and once a match is found in Central SNAT, the system applies it and does not proceed to policy-based NAT. The specific server's traffic (10.0.1.100) would still be subject to the Central SNAT rule unless a more specific Central SNAT rule is created for that IP.

Exam trap

The trap here is that candidates often assume policy-based NAT is more specific and thus takes precedence, but FortiGate's NAT evaluation order is fixed and Central SNAT always overrides policy-based NAT regardless of specificity.

How to eliminate wrong answers

Option B is wrong because policy-based NAT does not take precedence over Central SNAT; FortiGate evaluates Central SNAT first, and a match there overrides any policy-based NAT configuration. Option C is wrong because Central SNAT is evaluated before policy-based NAT, not after; the order is Central SNAT → policy-based NAT → VIP/load balancing. Option D is wrong because FortiGate does not use a 'most recently created rule' precedence for NAT; it follows a strict evaluation order based on NAT type, not creation time.

61
MCQmedium

An admin wants to block access to malicious websites using FortiGuard Web Filtering. Which policy configuration is necessary to apply the web filter profile to HTTP/HTTPS traffic?

A.Configure a DNS filter instead of a web filter
B.Create a policy with action DENY and a web filter profile
C.Create an allow policy for HTTP/HTTPS and apply a web filter profile
D.Use an application control profile to block malicious sites
AnswerC

Creating an allow policy for HTTP/HTTPS and attaching a web filter profile is the correct approach because the web filter profile inspects every allowed web request and compares each URL against FortiGuard categories or a custom block list. If a site is categorized as malicious or matches a blocked URL pattern, the web filter blocks the connection while still permitting access to other legitimate sites. This is the built-in mechanism for controlling web access based on URL reputation and content classification.

Why this answer

FortiGate requires an explicit allow policy for HTTP/HTTPS traffic to pass through the firewall before a web filter profile can inspect and block malicious URLs. The web filter profile is applied as a security policy feature on an allow policy, not on a deny policy, since deny policies drop traffic before inspection can occur. Without an allow policy, the traffic would be blocked by default, and the web filter would never see the traffic to apply its filtering rules.

Exam trap

The trap here is that candidates often think a deny policy can have a web filter profile applied to block malicious sites, but FortiGate only applies security profiles on allow policies, and deny policies simply drop traffic without inspection.

How to eliminate wrong answers

Option A is wrong because a DNS filter is used to block domains based on DNS queries, not to inspect HTTP/HTTPS content for malicious URLs; FortiGuard Web Filtering requires a web filter profile, not a DNS filter. Option B is wrong because a policy with action DENY drops all traffic before any security profiles, including web filter profiles, can be applied; web filter profiles can only be attached to allow policies where traffic is permitted and then inspected. Option D is wrong because an application control profile is designed to identify and control application traffic (e.g., Facebook, YouTube), not to block malicious websites based on URL categories; that is the function of a web filter profile.

62
MCQmedium

An admin needs to create a firewall policy that matches traffic based on the destination being a specific geographic location (e.g., France). Which address object should be used?

A.A geography object
B.An FQDN object
C.A subnet object
D.A wildcard FQDN object
AnswerA

A geography object is the correct choice because FortiGate maintains an IP geolocation database that maps IP addresses to countries, and the firewall can match traffic based on the source or destination country directly in the policy. This allows the admin to create a rule that permits or denies all traffic originating from or destined to a specific country without needing to enumerate individual IP ranges. The object type is designed specifically for country-based matching, making it the accurate tool for this requirement.

Why this answer

A geography object is specifically designed to match traffic based on geographic location (country, continent, or region) using the GeoIP database integrated into FortiOS. When a firewall policy needs to allow or deny traffic to or from a specific country like France, a geography object is the correct address object type because it dynamically resolves IP ranges assigned to that country by IANA/RIRs.

Exam trap

The trap here is that candidates may confuse geography objects with FQDN or wildcard FQDN objects, mistakenly thinking domain-based objects can represent geographic regions, when in fact only geography objects leverage the GeoIP database for location-based matching.

How to eliminate wrong answers

Option B is wrong because an FQDN object matches traffic based on a fully qualified domain name, not geographic location, and relies on DNS resolution to IP addresses. Option C is wrong because a subnet object defines a specific IP range or network prefix, which cannot represent an entire country's dynamic IP allocations. Option D is wrong because a wildcard FQDN object matches multiple domain names using a wildcard pattern (e.g., *.example.com), which has no relation to geographic location.

63
MCQeasy

A FortiGate administrator needs to create a firewall policy that allows traffic from the internal network to the DMZ. The internal network is 10.0.0.0/24 and the DMZ network is 172.16.0.0/24. Which source and destination address objects should be used in the policy?

A.Source: 172.16.0.0/24, Destination: 10.0.0.0/24
B.Source: all, Destination: all
C.Source: 10.0.0.0/24, Destination: all
D.Source: 10.0.0.0/24, Destination: 172.16.0.0/24
AnswerD

This policy correctly matches the internal network as the source and the DMZ network as the destination. It restricts traffic to the intended flow. The addresses should be defined as firewall address objects, but the subnets are the correct values. This is the precise configuration required.

Why this answer

The firewall policy must match the specific source and destination networks to allow only the desired traffic. Using the internal subnet as source and DMZ subnet as destination creates a precise policy. Other combinations either reverse the direction or are too permissive, failing to meet the requirement.

Exam trap

The trap here is reversing the source and destination or using 'all' when a specific subnet is required.

64
Multi-Selectmedium

A FortiGate administrator needs to configure source NAT for a group of internal servers (10.0.1.100-10.0.1.110) so that each server uses a unique public IP from the range 203.0.113.20-203.0.113.30. The requirement is that each internal IP maps to a fixed external IP (one-to-one mapping) and not port overload. Which TWO settings should be configured in the IP Pool? (Choose two.)

Select 2 answers
A.Type: Overload
B.Enable 'Fixed Port Range'
C.External IP Range: 203.0.113.20-203.0.113.30
D.Type: One-to-One
E.Use Central SNAT instead of IP Pool
AnswersC, D

Specifying 'External IP Range: 203.0.113.20-203.0.113.30' defines a pool with exactly 11 usable public addresses (203.0.113.20, 21, ..., 30), matching the number of internal servers that must be translated. In one-to-one NAT, each inbound request to a given public IP is forwarded to the associated internal host alongside outbound sessions, preserving the port and eliminating port-exhaustion risk. This range is the correct external IP pool definition because its count precisely satisfies the stated requirement.

Why this answer

The External IP Range must be set to 203.0.113.20-203.0.113.30 to define the pool of public IPs that will be mapped one-to-one to the internal servers. Option D is correct because Type: One-to-One ensures each internal IP is permanently mapped to a unique external IP, without port address translation (PAT), meeting the requirement of fixed one-to-one mapping.

Exam trap

The trap here is that candidates often confuse 'One-to-One' with 'Overload' and select 'Type: Overload' thinking it still provides unique IPs, but Overload always uses PAT and cannot guarantee a fixed external IP per internal host.

65
MCQmedium

An organization has multiple remote sites connected via IPsec VPN. The administrator needs to ensure that traffic from the internal network (10.0.0.0/8) to the VPN destination (10.10.0.0/16) uses a specific interface (port2) instead of the default route. Which feature should be configured?

A.Central NAT
B.Static route with higher distance
C.Policy-based routing
D.Traffic shaping
AnswerC

Policy-based routing (PBR) in FortiOS lets you define a rule that matches specific criteria — such as source IP, source interface, protocol, or port — and then explicitly sets the output interface and next-hop gateway, overriding the routing table lookup. For an organization with multiple remote sites connected via IPSec, PBR can steer traffic from each site's subnet toward the appropriate VPN tunnel or local gateway. This is exactly the capability needed when destination-based routing alone would send all traffic over the same path.

Why this answer

Policy-based routing (PBR) allows you to override the default routing table by matching traffic based on source/destination addresses and directing it to a specific egress interface (port2). This is the correct feature because the requirement is to force traffic from 10.0.0.0/8 to 10.10.0.0/16 out port2, bypassing the default route.

Exam trap

The trap here is confusing policy-based routing with static route manipulation; candidates often think a static route with a higher distance can override the default route, but distance only affects route preference, not the ability to force traffic out a specific interface when a default route with lower distance exists.

How to eliminate wrong answers

Option A is wrong because Central NAT is used for centralized NAT policy management in SD-WAN or hub-and-spoke topologies, not for overriding routing decisions. Option B is wrong because a static route with a higher distance (administrative distance) would only be used as a backup if the primary route fails; it cannot force traffic out a specific interface when a lower-distance default route exists. Option D is wrong because traffic shaping controls bandwidth allocation and QoS, not the path or interface selection for traffic.

66
MCQeasy

A FortiGate has two firewall policies: Policy 1 (ID 1) allows HTTP from any to 10.0.0.0/8, and Policy 2 (ID 2) denies all traffic from 192.168.1.0/24 to any. Traffic from 192.168.1.10 to 10.0.0.5 on port 80 is received. Which policy will match first?

A.Policy 1 (ID 1) will match and accept the traffic
B.Both policies will match, and the traffic will be denied
C.Policy 2 (ID 2) will match and deny the traffic
D.Neither policy matches, so the traffic is dropped by default deny
AnswerA

FortiGate firewall policies are evaluated sequentially from the top of the policy list, and Policy 1 (ID 1) is positioned before Policy 2. Because the traffic in question matches all criteria of Policy 1 — source, destination, and service — it triggers the allow action immediately. Once a matching policy is found, the FortiGate stops processing further policies and applies the matched policy's action, thus accepting the traffic.

Why this answer

Policy 1 (ID 1) matches first because FortiGate evaluates firewall policies in sequential order from top to bottom (lowest ID to highest ID) until a match is found. The source IP 192.168.1.10 falls within the 'any' source of Policy 1, and the destination 10.0.0.5 is within 10.0.0.0/8, with HTTP (port 80) matching the service. Since Policy 1 matches, it is applied and the traffic is accepted, even though Policy 2 would also match if reached.

Exam trap

The trap here is that candidates assume a more specific source (192.168.1.0/24) will override a broader source (any) due to specificity, but FortiGate uses sequential order, not longest-prefix matching, for policy selection.

How to eliminate wrong answers

Option B is wrong because FortiGate stops at the first matching policy; it does not evaluate or combine multiple policies for the same traffic. Option C is wrong because Policy 2 has a higher ID (2) than Policy 1 (1), so it is evaluated after Policy 1, which already matches and accepts the traffic. Option D is wrong because Policy 1 explicitly matches the traffic, so the implicit default deny is never reached.

67
MCQmedium

A network administrator notices that traffic from the internal network (10.0.1.0/24) to the internet is not being matched by the intended firewall policy (ID 10). The policy uses source address 'internal_subnet' (10.0.1.0/24) and destination address 'all'. There is another policy (ID 5) with source 'all' and destination 'all' that also matches this traffic. What is the most likely reason policy 10 is not being matched?

A.Policy 5 has a higher priority because it is above policy 10 in the policy list
B.Policy 10 is configured with an expired security certificate
C.The source address object 'internal_subnet' is incorrectly configured
D.Policy 10 has a schedule that is not active
AnswerA

In Fortinet FortiGate, firewall policies are evaluated sequentially from top to bottom; the first matching policy is applied. Since Policy 5 is listed above Policy 10, and both match the same traffic (e.g., source internal_subnet, destination, service), FortiGate selects Policy 5 and stops evaluating further. Therefore, Policy 10 is never reached, making its order, not its settings, the cause of its non-execution.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom, and the first matching policy is applied. Since policy 5 with source 'all' and destination 'all' is listed above policy 10, traffic from 10.0.1.0/24 to the internet matches policy 5 first, preventing policy 10 from ever being evaluated. This is the most likely reason the intended policy is not being matched.

Exam trap

The trap here is that candidates may think policy priority is based on specificity or configuration details like certificates or schedules, but FortiGate strictly uses sequential order from top to bottom, making the position of the 'all' policy the critical factor.

How to eliminate wrong answers

Option B is wrong because security certificates are used for SSL inspection or VPN authentication, not for matching traffic to firewall policies; an expired certificate would not prevent a policy from being matched. Option C is wrong because if the source address object 'internal_subnet' were incorrectly configured, the traffic would not match policy 10 at all, but the question states the traffic is being matched by another policy, implying the object is correct. Option D is wrong because a schedule that is not active would cause the policy to be inactive only during certain times, but the question does not indicate a time-based issue, and the traffic is still being matched by policy 5, which has no schedule restriction.

68
MCQmedium

A FortiGate admin has configured a firewall policy allowing traffic from the internal network (10.0.1.0/24) to the internet (any). Users report that they cannot access a specific website (203.0.113.5). The admin runs 'diagnose firewall fqdn list' and sees that the FQDN object used in a policy above the allow policy resolves to an IP that includes 203.0.113.5. What is the MOST likely cause?

A.The destination NAT on the allow policy is misconfigured
B.The FortiGate's DNS server is not resolving the FQDN correctly
C.The antivirus profile on the allow policy is blocking the website
D.The FQDN object resolved to the IP after the policy was created, but the policy lookup uses the cached IP and matches before the allow policy
AnswerD

FortiGate evaluates policies top-down, and the FQDN object above the allow policy resolves to an IP covering 203.0.113.5. That cached address matches first, so traffic hits the upper policy's action instead of the intended allow rule. Policy order and FQDN cache timing, not routing, cause the block.

Why this answer

The FQDN object in a policy above the allow policy resolved to an IP that includes 203.0.113.5. FortiGate performs policy lookup based on cached IP addresses for FQDN objects. Since the FQDN object's cached IP now matches the destination IP of the website, traffic hits the higher-priority policy (which likely denies or otherwise blocks the traffic) before reaching the allow policy.

This is why users cannot access the website despite the allow policy existing.

Exam trap

The trap here is that candidates assume the allow policy will always match traffic to the website, but they overlook that FortiGate evaluates policies top-down and uses cached IP addresses for FQDN objects, so a higher-priority policy with a matching cached IP can intercept the traffic before the allow policy is reached.

How to eliminate wrong answers

Option A is wrong because destination NAT is not involved in this scenario; the issue is about policy matching order based on cached FQDN resolution, not NAT misconfiguration. Option B is wrong because the FQDN resolved correctly (the admin sees the IP in the list), so DNS resolution is not the problem. Option C is wrong because there is no indication that an antivirus profile is blocking the website; the problem is policy precedence, not security profile filtering.

69
MCQeasy

Which address object type can be used to match traffic based on the source country?

A.Wildcard FQDN
B.FQDN
C.Geography
D.Subnet
AnswerC

Geography address objects in FortiOS match traffic based on the country, continent, or region associated with an IP address, using the built-in GeoIP database. These objects directly support policies such as geo-blocking or allowing traffic from a specific nation, without requiring the administrator to enumerate IP ranges. This is the only object type in the list whose matching logic is explicitly based on the geopolitical location of the packet endpoints, making it the correct answer.

Why this answer

The Geography address object type in FortiGate allows you to match traffic based on the source or destination country by using the ISO 3166-1 alpha-2 country codes. This is configured within a firewall policy to enforce geo-blocking or geo-allowance, leveraging FortiGuard's GeoIP database to map IP addresses to countries.

Exam trap

The trap here is that candidates may confuse Geography with FQDN or Subnet, assuming that DNS resolution or IP ranges can inherently determine country, but only the Geography object leverages the dedicated GeoIP database for country-based matching.

How to eliminate wrong answers

Option A is wrong because Wildcard FQDN is used to match multiple subdomains with a pattern (e.g., *.example.com) and has no relation to geographic location. Option B is wrong because FQDN resolves to a single IP address or set of IP addresses via DNS, not to a country. Option D is wrong because Subnet defines a range of IP addresses using CIDR notation and cannot inherently identify the source country without external GeoIP mapping.

70
Multi-Selecthard

An administrator is configuring traffic shaping on a firewall policy to limit bandwidth for YouTube. Which THREE components are required?

Select 3 answers
A.A traffic shaper object that defines bandwidth limits
B.A firewall policy that matches YouTube traffic
C.A static route for the YouTube subnet
D.A schedule object to apply the shaper only during business hours
E.Enable traffic shaping on the firewall policy and assign the traffic shaper
AnswersA, B, E

A traffic shaper object is the core definition of a bandwidth profile in Fortinet. It specifies parameters such as guaranteed bandwidth, maximum bandwidth, and traffic priority, enabling controlled allocation of network resources. Without this object, there is no shaping policy to reference, so creating it is an essential first step.

Why this answer

A traffic shaper object is a fundamental component that defines the bandwidth limits (e.g., guaranteed bandwidth, maximum bandwidth, priority) that will be applied to traffic. Without this object, the firewall has no parameters to enforce rate limiting. In FortiGate, the traffic shaper object is created under 'Traffic Shapers' and can be per-policy or per-IP.

Exam trap

The trap here is that candidates mistakenly think a schedule or static route is mandatory, but FortiGate only requires the traffic shaper object, the matching firewall policy, and the shaper assignment on that policy.

71
MCQeasy

What is the purpose of a schedule object in a firewall policy?

A.To specify the time of day when the policy is effective
B.To set the bandwidth limit for the policy
C.To prioritize traffic based on application
D.To limit the number of concurrent sessions
AnswerA

A schedule object defines the time window (such as 09:00–17:00 on weekdays) during which a firewall policy may be enforced. In FortiOS, the schedule condition is evaluated when a new session is being established; if the current time falls outside the schedule, the policy will not match, and the permitted traffic will be denied or evaluated by subsequent policies. This allows administrators to apply time-based access control, such as blocking employee internet access after business hours.

Why this answer

A schedule object in a FortiGate firewall policy defines the time range (e.g., specific hours, days of the week, or recurring intervals) during which the policy is active. When the current time falls outside the schedule, the policy is automatically disabled, allowing administrators to enforce time-based access control without manual intervention. This is distinct from other policy attributes like bandwidth shaping or session limits.

Exam trap

The trap here is that candidates confuse schedule objects with other time-related features like session timeouts or idle timeouts, or assume schedule objects can control bandwidth or application priority, when in fact they only control the policy's active time window.

How to eliminate wrong answers

Option B is wrong because bandwidth limits are configured via traffic shaping policies or per-policy bandwidth limits, not through schedule objects. Option C is wrong because traffic prioritization based on application is handled by application control profiles or QoS policies, not by schedule objects. Option D is wrong because limiting concurrent sessions is a separate policy setting (session limit) or a global session table parameter, not a function of schedule objects.

72
MCQeasy

An administrator needs to allow outbound DNS traffic (UDP port 53) from multiple internal subnets to the internet. Which object type should be used to group the subnets into a single source in the firewall policy?

A.VIP group
B.Schedule group
C.Address group
D.Service group
AnswerC

An address group is the correct object because it bundles multiple address objects—such as subnets, IP ranges, and FQDNs—into a single named entity. This address group can then be used as the source field in an outbound policy, effectively allowing all internal subnets to initiate DNS queries. This is exactly what the administrator needs to match the source subnets for outbound UDP port 53 traffic.

Why this answer

An address group is the correct object type to group multiple internal subnets into a single source in a firewall policy. In FortiGate, address groups allow you to combine multiple IP addresses or subnets (IPv4 or IPv6) into a logical group, which can then be referenced as the source in a single firewall policy. This simplifies administration by reducing the number of policies needed to allow outbound DNS traffic from multiple subnets.

Exam trap

The trap here is that candidates often confuse address groups with service groups, mistakenly thinking that grouping subnets is done via service objects, but service groups only define protocols and ports, not IP addresses.

How to eliminate wrong answers

Option A is wrong because a VIP group is used to group multiple virtual IP (VIP) objects for destination NAT (port forwarding) or load balancing, not for grouping source subnets. Option B is wrong because a schedule group is used to group time-based schedules (e.g., daily, weekly) to control when a policy is active, not to define source addresses. Option D is wrong because a service group is used to group multiple service definitions (e.g., DNS, HTTP, HTTPS) by protocol/port, not to group source IP subnets.

73
MCQhard

You run the following command on a FortiGate: 'diagnose sys session filter dport 443' and see: proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate?

A.The session is in SYN_SENT state and the three-way handshake is not yet complete
B.The session is using UDP and the duration is 3600 seconds
C.The session is being torn down and will expire in 3599 seconds
D.The session is fully established and has been active for 3600 seconds
AnswerA

In FortiOS session table output, the proto_state field for TCP is shown in hex; a value of 01 corresponds to SYN_SENT (0x01), meaning the initial SYN packet was sent but the SYN-ACK has not yet been received. This indicates the three-way handshake is still in progress and the session is not yet established. Therefore, the correct interpretation is that the connection is incomplete.

Why this answer

The output shows `proto=6`, which indicates TCP, and `proto_state=01`, which corresponds to the TCP state SYN_SENT (0x01). This means the session has sent a SYN but has not yet received a SYN-ACK, so the three-way handshake is incomplete. The `duration=3600` and `expire=3599` indicate the session has been tracked for 3600 seconds and will expire in 3599 seconds, but the state confirms it is not yet established.

Exam trap

The trap here is that candidates see `duration=3600` and `expire=3599` and assume the session is established and about to expire, but the `proto_state=01` (SYN_SENT) clearly indicates the handshake is incomplete, not that the session is active or being torn down.

How to eliminate wrong answers

Option B is wrong because `proto=6` indicates TCP, not UDP (UDP is protocol 17). Option C is wrong because the session is in SYN_SENT state (0x01), not being torn down; a teardown would show states like FIN_WAIT or TIME_WAIT. Option D is wrong because a fully established TCP session would show `proto_state=02` (ESTABLISHED), not `01` (SYN_SENT).

74
Multi-Selecthard

A FortiGate admin is troubleshooting an issue where internal users cannot access a specific external service over TCP/443. The admin confirms that the firewall policy allows HTTP/HTTPS. Which TWO CLI commands should the admin use to diagnose? (Choose two.)

Select 2 answers
A.diagnose firewall iprope list
B.diagnose debug flow
C.diagnose sys session filter dport 443
D.get system performance status
E.execute ping 8.8.8.8
AnswersA, B

The 'diagnose firewall iprope list' command displays the compiled IPv4/IPv6 policy chains exactly as the kernel traverses them during packet evaluation. It is invaluable for verifying the relative ordering of allow and deny policies in the actual dataplane, because a policy buried below a broad deny rule will never be reached. This tool exposes both the explicit policies and the implicit deny at the end, letting you confirm whether a matching allow rule exists before any drop rule in the sequence.

Why this answer

'diagnose firewall iprope list' displays the kernel's internal firewall rule chains, allowing the admin to verify whether the policy lookup is matching the expected rule for TCP/443 traffic. This command helps confirm that the policy is installed and active in the kernel, which is essential for troubleshooting policy-based access issues.

Exam trap

The trap here is that candidates often choose 'diagnose sys session filter dport 443' thinking it directly shows sessions, but they forget that it only sets a filter and requires an additional command to display results, making it incomplete for immediate diagnosis.

75
Multi-Selectmedium

An administrator needs to allow inbound SSH access from the internet to a specific internal server (10.0.1.10) on port 22. The WAN IP is 203.0.113.10. Which THREE configuration steps are required?

Select 3 answers
A.Ensure the firewall policy allows the SSH service (port 22)
B.Create a firewall policy from WAN to internal interface with destination set to the VIP
C.Configure a source NAT IP pool for outbound traffic
D.Create a Virtual IP (VIP) mapping 203.0.113.10:22 to 10.0.1.10:22
E.Enable SSL inspection on the policy
AnswersA, B, D

Traffic arriving at the FortiGate for the public IP and port 22 must be matched by a firewall policy whose destination is the VIP's mapped address (the private server IP) and whose service includes SSH. Without a policy that explicitly allows port 22/TCP as the service, the FortiGate will drop the session even if the VIP object exists and is correctly configured. Remember that on FortiGate, an inbound DNAT translation (VIP) does not automatically permit traffic; the policy is the only place where the action (accept) is decided.

Why this answer

Option D is correct because a Virtual IP (VIP) performs destination NAT (DNAT), mapping the public WAN address 203.0.113.10 on port 22 to the internal server 10.0.1.10 on port 22, which is the essential first step to make the internal host reachable from the internet. Option B is correct because a firewall policy must be created with the incoming interface as WAN and the outgoing interface as the internal/LAN interface, with the destination set to that VIP object, so the firewall permits and forwards the translated traffic to the server. Option A is correct because the policy must explicitly allow the SSH service on TCP port 22, since inbound traffic is denied by default and the service must be matched in the policy for the connection to be accepted.

Option C is incorrect because a source NAT IP pool applies to outbound traffic (masquerading internal clients behind a public address) and is irrelevant to publishing an internal server for inbound SSH. Option E is incorrect because SSL inspection applies to TLS/HTTPS traffic and cannot inspect SSH, which is not an SSL/TLS protocol, so enabling it would not enable or secure this inbound SSH access.

Exam trap

The trap here is that candidates often assume configuring a VIP alone is sufficient, forgetting that a firewall policy must also be created to permit the translated traffic, and they may confuse source NAT (Option C) with destination NAT required for inbound access.

Page 1 of 3 · 193 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Firewall Policies and NAT questions.