Courseiva

CCNA Security Profiles Questions

75 of 182 questions · Page 2/3 · Security Profiles · Answers revealed

76
Multi-Selecthard

An administrator receives alerts about a possible data breach. Sensitive data (credit card numbers) might be leaving the network via email. The admin wants to detect and block such emails. Which THREE security profiles should be combined?

Select 3 answers
A.Web filter profile
B.SSL deep inspection profile
C.Email filter profile
D.Data leak prevention (DLP) profile
E.Antivirus profile
AnswersB, C, D

The SSL deep inspection profile performs full TLS/SSL decryption and re-encryption, using a FortiGate-issued CA certificate to terminate the client connection and then open a new secure connection to the server. This decrypted traffic is then fed to other UTM profiles—email filter, DLP, antivirus—so they can see the actual payload. Without this profile, any encrypted SMTP/IMAPS/webmail traffic remains opaque, and data exfiltration could pass undetected. In the context of an email-related breach alert, this is the enabling profile that makes content inspection possible.

Why this answer

B is correct because SSL deep inspection is required to decrypt SSL/TLS-encrypted email traffic (e.g., SMTP over TLS) so that the FortiGate can inspect the content for sensitive data like credit card numbers. Without decryption, the DLP and email filter profiles cannot see the payload of encrypted emails, rendering them ineffective.

Exam trap

The trap here is that candidates often forget that encrypted email traffic (e.g., Gmail, Office 365) requires SSL deep inspection to be decrypted before DLP and email filtering can work, leading them to incorrectly omit the SSL deep inspection profile.

77
MCQmedium

An administrator wants to block users from uploading sensitive documents through webmail. Which security profile should be configured on the FortiGate to achieve this goal?

A.Data Leak Prevention (DLP)
B.Antivirus
C.Application control
D.Web filter
AnswerA

DLP (Data Leak Prevention) profiles in FortiOS inspect traffic content, not just metadata. It can match file content against predefined or custom sensitive data patterns (e.g., credit card numbers or confidential labels like 'INTERNAL ONLY') using full-content scanning. When a match occurs, the firewall can block the upload, log it, and optionally send a notification. Unlike antivirus or web filter, DLP operates at the content-inspection layer of the proxy and can be applied to HTTP/HTTPS, FTP, and email protocols, making it the appropriate choice for preventing sensitive-data exfiltration via uploads.

Why this answer

Data Leak Prevention (DLP) is the correct security profile because it is specifically designed to inspect content (e.g., file names, patterns, or keywords) in traffic such as webmail uploads and block sensitive data from leaving the network. DLP sensors can be configured with rules to match patterns like credit card numbers, social security numbers, or custom keywords, and then take action such as blocking or logging the session.

Exam trap

The trap here is that candidates may confuse the function of DLP with web filtering or application control, thinking that blocking the webmail application entirely is equivalent to preventing data leaks, when in fact DLP is the only profile that inspects the actual content being transmitted.

How to eliminate wrong answers

Option B (Antivirus) is wrong because it focuses on detecting and blocking malware based on signatures, not on inspecting content for sensitive data patterns. Option C (Application control) is wrong because it identifies and controls applications (e.g., blocking webmail entirely) but does not inspect the actual data payload for sensitive content. Option D (Web filter) is wrong because it controls access to websites based on categories or URLs, not the content within uploaded files or messages.

78
MCQeasy

Refer to the exhibit. An administrator has created an IPS sensor with two entries. The first entry sets severity 'medium' and action 'block'. The second entry sets severity 'critical' and action 'block'. What will happen when a packet triggers an IPS signature with severity 'low'?

A.The packet will be allowed (pass).
B.The packet will be logged and a session will be created.
C.The packet will be blocked if the signature severity is 'low' or 'high'.
D.The packet will be blocked because the sensor is enabled.
AnswerA

Because this packet triggers no signature that has been explicitly configured with a drop, reset, or reject action, the IPS sensor applies its default pass behavior. The configured sensor only overrides the default for the specific signatures listed; all other traffic, including this packet, is allowed to proceed unmodified. IPS inspection does not preemptively block traffic; blocking requires a matching signature entry with a destructive action.

Why this answer

The IPS sensor in the exhibit defines rules only for severity 'medium' and 'critical', both with action 'block'. When a packet triggers a signature with severity 'low', it does not match any entry in the sensor. Therefore, the default action for unmatched signatures is to allow (pass) the traffic.

FortiGate IPS sensors apply actions only to explicitly configured severity levels; unlisted severities are not affected.

Exam trap

The trap here is that candidates assume an enabled IPS sensor blocks all traffic by default, but FortiGate IPS sensors only apply actions to signatures whose severity is explicitly listed in the sensor entries.

How to eliminate wrong answers

Option B is wrong because logging and session creation are not automatic for unmatched severity levels; they only occur if the sensor entry specifies 'log' or if the signature action is triggered. Option C is wrong because the sensor does not block 'low' severity signatures, and 'high' severity is not even listed in the sensor entries. Option D is wrong because simply enabling the sensor does not block all traffic; blocking only happens for signatures that match an entry with a 'block' action.

79
MCQhard

A FortiGate is configured with an IPS profile that includes a signature with a 'Pass' action. The firewall policy uses this IPS profile. What will happen when traffic matching that signature is detected?

A.The traffic is allowed, but the session is reset
B.The traffic is allowed without logging
C.The traffic is blocked and logged
D.The traffic is blocked and the session is reset
AnswerB

With the 'pass' action, the packet is allowed to continue to its destination and, by default, no log message is generated for the signature match. In FortiOS, logging for a pass action requires explicitly enabling the 'Log' toggle on the IPS rule or profile; otherwise the event is silently permitted. This makes 'allowed without logging' the correct outcome for a pass-only IPS profile.

Why this answer

When a signature with a 'Pass' action is triggered in an IPS profile applied to a firewall policy, FortiGate allows the traffic to pass through without any further inspection or logging for that specific signature. The 'Pass' action explicitly overrides the default IPS behavior, meaning the traffic is permitted and no log entry is generated for that signature match, as logging is only performed when the action is set to 'Block' or 'Reset'.

Exam trap

The trap here is that candidates often assume any IPS signature match will always generate a log entry or block traffic, but the 'Pass' action explicitly allows traffic and suppresses logging unless configured otherwise.

How to eliminate wrong answers

Option A is wrong because the 'Pass' action does not reset the session; resetting the session is associated with the 'Reset' action, not 'Pass'. Option C is wrong because the 'Pass' action allows traffic, not blocks it, and logging is not performed for 'Pass' actions unless explicitly configured with a separate log setting. Option D is wrong because the 'Pass' action neither blocks traffic nor resets the session; blocking and resetting are behaviors of 'Block' or 'Reset' actions.

80
MCQmedium

An administrator wants to integrate FortiSandbox with a FortiGate to analyze suspicious files. Which security profile must be configured to send files to FortiSandbox?

A.Application Control profile with FortiSandbox enabled
B.Antivirus profile with FortiSandbox enabled
C.IPS profile with FortiSandbox enabled
D.Web Filter profile with FortiSandbox enabled
AnswerB

An Antivirus profile is the correct integration point because FortiGate's antivirus inspection can forward suspicious files to FortiSandbox for dynamic, sandbox-based analysis. During traffic inspection, the AV engine can detect unknown or low-confidence threats and send the associated file to FortiSandbox to identify zero-day malware. This provides an additional layer of protection beyond standard signature-based antivirus scanning.

Why this answer

FortiSandbox integration with FortiGate requires the Antivirus profile to be configured with FortiSandbox enabled. This is because FortiSandbox is designed to analyze suspicious files that are typically detected by the antivirus engine, and the Antivirus profile is the only security profile that can forward files to FortiSandbox for advanced threat detection. The Antivirus profile uses the 'fortisandbox' option under 'scan-mode' to send files that cannot be conclusively determined as clean or malicious.

Exam trap

The trap here is that candidates often assume FortiSandbox can be integrated with multiple security profiles (like IPS or Web Filter) for file analysis, but only the Antivirus profile supports the file-forwarding mechanism to FortiSandbox.

How to eliminate wrong answers

Option A is wrong because Application Control profiles are used to identify and control network applications, not to send files to FortiSandbox; they lack the file-scanning and forwarding mechanism required for sandbox analysis. Option C is wrong because IPS profiles focus on intrusion prevention by inspecting network traffic for attack signatures, not on file-level analysis or forwarding files to external sandboxes. Option D is wrong because Web Filter profiles control web access based on URL categories and content filtering, and they do not have the capability to send files to FortiSandbox for analysis.

81
MCQhard

A company with 500 employees uses FortiGate as their internet gateway. They recently enabled SSL deep inspection using the built-in CA certificate. After deployment, many users report that they cannot access their online banking websites. The error message in the browser says 'The certificate is not trusted'. The administrator has already pushed the FortiGate CA certificate to all domain-joined computers via Group Policy. However, the problem persists for banking sites. The administrator also notices that banking sites load fine on mobile devices that do not have the CA certificate installed. What is the most likely cause and solution?

A.Disable SSL inspection entirely to avoid certificate issues.
B.The CA certificate is not properly installed on all computers. Re-deploy via Group Policy.
C.Use certificate inspection instead of deep inspection for all traffic.
D.Banking websites use certificate pinning. Exempt them from deep inspection using an SSL inspection exemption list.
AnswerD

Banking platforms frequently implement certificate pinning by hard-coding the expected public key or certificate fingerprint in the client or browser. When FortiGate performs deep inspection, it replaces the original server certificate with its own re-signed copy, causing the pin validation to fail and the connection to be blocked. The recommended fix is to add these banking domains to the SSL exemption list so the FortiGate passes the original certificate untouched, preserving deep inspection for all other domains.

Why this answer

Banking websites often use HTTP Public Key Pinning (HPKP) or certificate pinning, where the browser expects a specific certificate or public key from the server. When FortiGate performs SSL deep inspection, it re-signs the server's certificate with its own CA, breaking the pinning validation. This causes the 'certificate not trusted' error even when the FortiGate CA is trusted, because the browser detects that the presented certificate does not match the pinned certificate.

The correct solution is to exempt banking sites from deep inspection using an SSL inspection exemption list, allowing the original server certificate to pass through.

Exam trap

The trap here is that candidates assume the issue is always a missing CA certificate deployment, but the real problem is certificate pinning, which causes trust failures even when the CA is trusted, because the browser checks the pinned certificate hash against the presented certificate.

How to eliminate wrong answers

Option A is wrong because disabling SSL inspection entirely would remove security visibility for all HTTPS traffic, which is an overreaction and not necessary; the issue is specific to pinned certificates. Option B is wrong because the problem persists despite the CA certificate being properly deployed via Group Policy, and the error is not due to missing CA trust but due to certificate pinning validation failure. Option C is wrong because certificate inspection (which only inspects the certificate metadata, not the content) would still present the original server certificate to the browser, but it does not address the root cause of pinning; however, the question states deep inspection is enabled, and switching to certificate inspection would not resolve the pinning issue because the browser still sees the original certificate, which is actually correct for pinned sites—but the real fix is exemption, not a global change to certificate inspection.

82
Drag & Dropmedium

Drag and drop the steps to perform a factory reset on FortiGate via CLI into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Factory reset is done with execute factoryreset, then confirm; device reboots to defaults.

83
MCQhard

Given the above IPS sensor configuration, what will happen when traffic matching a high-severity IPS signature is detected?

A.The traffic will be logged but not blocked.
B.The traffic will be blocked only if the signature is enabled globally.
C.The traffic will be blocked because the sensor has a block action.
D.The traffic will be allowed because no entry exists for high severity.
AnswerD

This is correct because the IPS sensor contains no entry for high-severity signatures, and an unmatched signature in FortiGate IPS results in an implicit pass. The sensor only applies actions (block, reset, or log) to traffic that matches a defined signature or severity override. With no high-severity rule in the sensor, the traffic is allowed and forwarded without inspection-based action.

Why this answer

The IPS sensor configuration shown does not include an entry for high-severity signatures. Without a specific action defined for high severity, the sensor defaults to allowing the traffic while still generating a log entry. This is a common behavior in FortiGate IPS where only explicitly configured severity levels have defined actions.

Exam trap

The trap here is that candidates assume high-severity signatures are automatically blocked by default, but FortiGate requires explicit action configuration per severity level, and the default action is to allow.

How to eliminate wrong answers

Option A is wrong because logging without blocking would require a 'monitor' or 'pass' action explicitly configured for high severity, which is absent. Option B is wrong because global signature enablement does not override the per-severity action configuration; the sensor's action table determines blocking, not global status. Option C is wrong because the sensor does not have a block action for high severity; the block action is only defined for critical and medium severity levels in the provided configuration.

84
MCQhard

An administrator has configured an IPS sensor to block critical-severity attacks. However, after a week, they notice that a known exploit (CVE-2021-44228) is still getting through. Which configuration change should be made to improve detection?

A.Set the IPS sensor severity filter to 'low' and above.
B.Change the IPS sensor action from 'default' to 'block' for all signatures.
C.Create a custom IPS signature for the exploit.
D.Enable the specific IPS signature for the exploit in the sensor.
AnswerD

Enabling the specific signature for CVE-2021-44228 closes the detection gap, since severity-based blocking only acts on signatures already enabled and rated critical. If that signature is disabled or absent from the sensor's active set, traffic matching the exploit passes uninspected regardless of the critical-severity policy.

Why this answer

The IPS sensor must have the specific signature for CVE-2021-44228 (Log4Shell) enabled to detect and block it. Even if the sensor is set to block critical-severity attacks, the signature for this exploit may be disabled by default in the sensor's signature database. Enabling the specific signature ensures the sensor inspects traffic for the exploit's unique patterns and applies the configured action.

Exam trap

The trap here is that candidates assume setting the severity filter to 'critical' or changing the action to 'block' globally will catch all critical exploits, but they forget that individual signatures must be explicitly enabled in the sensor to be evaluated.

How to eliminate wrong answers

Option A is wrong because lowering the severity filter to 'low' and above would cause the sensor to process more signatures, but it does not enable a disabled signature; the exploit's signature may still be disabled regardless of severity. Option B is wrong because changing the action from 'default' to 'block' for all signatures would override per-signature actions and could cause false positives or performance issues, but it still does not enable a disabled signature. Option C is wrong because creating a custom IPS signature is unnecessary when the vendor (Fortinet) already provides a signature for CVE-2021-44228; the issue is that the signature is disabled, not missing.

85
MCQeasy

Which FortiGate security feature can be used to block outgoing emails that contain specific keywords, such as confidential information?

A.Email Filter
B.Web Filter
C.Application Control
D.Antivirus
AnswerA

Email Filter is the correct feature because it is specifically designed to inspect SMTP traffic, including outgoing email. It can block outbound spam using anti-spam techniques such as IP reputation, Bayesian filtering, and content analysis. This feature is protocol-aware for email and can enforce policies on both inbound and outbound messages.

Why this answer

Email Filter is the correct answer because it is the FortiGate security profile specifically designed to inspect SMTP, POP3, and IMAP traffic for content violations. It can block outgoing emails based on keyword patterns, such as 'confidential', by matching against defined filter rules in the email filter profile, which operates at the application layer.

Exam trap

The trap here is that candidates often confuse Email Filter with Antivirus or Web Filter, mistakenly thinking that keyword blocking is a general security function rather than a specific email content inspection feature.

How to eliminate wrong answers

Option B (Web Filter) is wrong because it controls HTTP/HTTPS web traffic, not email protocols like SMTP, and cannot inspect email message bodies or headers for keywords. Option C (Application Control) is wrong because it identifies and controls application traffic (e.g., blocking Gmail or Outlook) but does not perform deep content inspection of email bodies for specific keywords. Option D (Antivirus) is wrong because it scans for malware signatures in file attachments and content, not for arbitrary keyword patterns like 'confidential'.

86
MCQhard

An administrator runs the CLI command: 'diagnose sys session list | grep -i dns' and sees sessions with dst port 53. The administrator has configured a DNS filter profile on the firewall policy. However, DNS requests are not being filtered. What is the MOST likely cause?

A.The DNS filter profile is applied to the wrong policy direction
B.DNS filtering requires proxy-based inspection mode on the policy
C.The DNS filter profile has no rules defined
D.The FortiGate is in transparent mode
AnswerB

FortiGate has two inspection modes: flow-based and proxy-based. DNS filtering uses the proxy engine to inspect the DNS query and compare the domain against a FortiGuard category, so the policy controlling the client DNS traffic must be configured for proxy-based inspection mode. If the policy is left in flow mode, the FortiGate performs session-based forwarding and does not decrypt/intercept the DNS protocol payload, so the DNS filter profile is silently ignored. This is the correct reason the DNS filter is ineffective for the administrator's setup.

Why this answer

DNS filtering on FortiGate requires proxy-based inspection mode because it needs to reassemble and inspect the full DNS transaction (request and response) to apply filtering rules. Flow-based inspection only examines individual packets and cannot perform the deep application-layer analysis needed for DNS filtering. Therefore, even if the DNS filter profile is correctly applied to the policy, it will not work unless the policy's inspection mode is set to proxy-based.

Exam trap

The trap here is that candidates often assume DNS filtering works like other security profiles (e.g., web filtering) that can operate in flow-based mode, but DNS filtering specifically requires proxy-based inspection due to the nature of DNS protocol inspection.

How to eliminate wrong answers

Option A is wrong because the DNS filter profile is applied to a firewall policy, which is inherently directional (from source to destination); applying it to the wrong direction would not cause the sessions to appear with dst port 53, and the administrator already sees such sessions, indicating traffic is hitting the policy. Option C is wrong because a DNS filter profile with no rules defined would still allow DNS traffic to pass through (default action is to allow), but the administrator states DNS requests are not being filtered, which implies the profile is not being applied at all, not that it lacks rules. Option D is wrong because transparent mode does not affect the ability to apply DNS filtering; FortiGate can perform DNS filtering in both transparent and NAT modes, so this is not the cause.

87
MCQhard

An administrator runs the command 'diagnose ips anomaly list' and sees many entries for 'tcp_src_session' with high counts. Users report slow internet. What is the most likely issue?

A.The IPS signature database is corrupted
B.The FortiGate has a hardware failure
C.A host on the network is infected with malware that is generating many outbound connections
D.The FortiGate is under a DDoS attack
AnswerC

A single internal host generating a high volume of outbound connections to multiple external destinations is a hallmark of malware infection or P2P activity. FortiOS IPS anomaly detection monitors such behavioral patterns—like excessive half-open connections or a source creating many sessions per second—and flags it as an anomaly. The command output would show this host's source IP with anomaly type and session counts, confirming the botnet-like behavior.

Why this answer

The 'diagnose ips anomaly list' command displays anomalies detected by the IPS engine, and 'tcp_src_session' tracks the number of TCP sessions originating from a single source IP. A high count indicates a single host is initiating an excessive number of outbound TCP connections, which is a classic sign of malware infection (e.g., a botnet client or worm) that is generating numerous outbound connections, consuming bandwidth and causing slow internet for users.

Exam trap

The trap here is that candidates often confuse 'tcp_src_session' (outbound from a source) with 'tcp_dst_session' (inbound to a destination) and incorrectly assume a DDoS attack, but the command specifically shows the source IP, not the destination, pointing to an internal infected host rather than an external attack.

How to eliminate wrong answers

Option A is wrong because a corrupted IPS signature database would typically cause IPS engine errors, not a specific spike in 'tcp_src_session' counts. Option B is wrong because hardware failure would manifest as system crashes, interface errors, or hardware alarms, not as a high count of outbound TCP sessions from a single source. Option D is wrong because a DDoS attack would likely show high counts in 'tcp_dst_session' (many sources to one destination) or 'udp_dst_session', not a single source generating many outbound sessions.

88
MCQmedium

A company recently deployed FortiGate with application control to manage cloud application usage. They want to allow Google Drive for business but block personal Google accounts. Which application control configuration approach is most effective?

A.Use web filtering to block the URL of personal Google Drive.
B.Configure IPS to block personal Google Drive traffic.
C.Use application control with specific signatures for 'Google Drive Business' and 'Google Drive Personal' and apply appropriate actions.
D.Create a rule to block all Google Drive applications.
AnswerC

FortiOS Application Control leverages FortiGuard application signatures that identify Google Drive and its sub-versions, including 'Google Drive Business' and 'Google Drive Personal,' based on flow characteristics and OAuth/authentication context. By applying separate actions—such as block for the Personal signature and allow for the Business signature—the administrator can enforce a granular policy. Each signature is matched to the specific application instance using SSL inspection, enabling precise control that is unavailable with URL or vulnerability-based methods.

Why this answer

FortiGate's application control uses application signatures to distinguish between different versions of the same application, such as 'Google Drive Business' and 'Google Drive Personal'. By configuring specific signatures with appropriate actions (allow for business, block for personal), you can enforce granular control over cloud application usage without affecting legitimate business traffic.

Exam trap

The trap here is that candidates often confuse web filtering (URL-based) with application control (signature-based), assuming that blocking a URL will effectively block personal accounts, but in reality, both account types use the same URL and only differ in application-layer metadata.

How to eliminate wrong answers

Option A is wrong because web filtering blocks URLs, but personal and business Google Drive often share the same base URL (drive.google.com), making URL-based blocking ineffective for distinguishing between account types. Option B is wrong because IPS is designed to detect and prevent network attacks and exploits, not to enforce application-level access policies based on user account type. Option D is wrong because blocking all Google Drive applications would also block the legitimate business use of Google Drive, which contradicts the requirement to allow business accounts.

89
Multi-Selectmedium

Which TWO of the following are required for full SSL inspection to work correctly?

Select 2 answers
A.The private key of each server certificate that will be inspected.
B.The FortiGate's CA certificate installed in the Trusted Root Certification Authorities store on client machines.
C.An intermediate CA certificate imported from the enterprise PKI.
D.A certificate on the FortiGate to generate session certificates.
E.A certificate signed by a public CA installed on the FortiGate.
AnswersB, D

This is a mandatory step because the FortiGate signs every session certificate it sends to clients using its own CA. Without adding that CA certificate to the Trusted Root Certification Authorities store, clients will reject the presented certificate as untrusted and display SSL errors or refuse the connection. This trust installation must be performed on every client that will have its traffic inspected, typically via Group Policy or MDM.

Why this answer

For full SSL inspection, the FortiGate must generate a session certificate on-the-fly for each HTTPS connection after decrypting it. This requires a CA certificate on the FortiGate to sign those session certificates. Additionally, client machines must trust this CA certificate, so it must be installed in their Trusted Root Certification Authorities store; otherwise, browsers will show certificate warnings and block the connection.

Exam trap

The trap here is that candidates often think the FortiGate needs the server's private key (Option A) to decrypt traffic, but in reality, full SSL inspection uses a man-in-the-middle approach where the FortiGate generates its own session certificates, requiring only its own CA certificate and client trust.

90
Multi-Selecthard

An administrator is troubleshooting why an application control profile is not detecting a custom application that uses a non-standard port. The administrator wants to ensure the application is properly identified. Which THREE steps should the administrator take? (Choose three.)

Select 3 answers
A.Set the application control action to 'block' for the application
B.Add a custom application signature based on the traffic pattern
C.Disable flow-based inspection and use proxy-based only
D.Ensure the application control profile is applied to the correct firewall policy
E.Enable SSL deep inspection if the application uses encryption
AnswersB, D, E

If the application is not covered by any built-in FortiGuard signature, the administrator should create a custom application signature based on the traffic's unique pattern. On FortiGate, this is done by defining a custom signature using attributes such as protocol, port, IP, or content-matching criteria in the application control profile. This directly adds detection capability for the unrecognized application, allowing it to be identified and controlled. Without a signature, the application remains invisible to the security inspection.

Why this answer

Option B is correct because application control can only identify a custom application on a non-standard port if a custom application signature is created that matches its traffic pattern, since the default signature database will not recognize it. Option D is correct because an application control profile only takes effect when it is attached to the firewall policy that handles the traffic; if it is applied to the wrong policy, the custom application will never be inspected or detected. Option E is correct because if the custom application's traffic is encrypted with SSL/TLS, the firewall cannot see the application-layer data needed for identification unless SSL deep inspection is enabled to decrypt and inspect it.

Option A is incorrect because setting the action to 'block' only controls what happens after identification and does nothing to help the firewall recognize the application. Option C is incorrect because disabling flow-based inspection and using proxy-based only is not a required step for identifying a custom application and may not even be supported or desirable in all deployments.

Exam trap

The trap is focusing on enforcement actions (like block) or inspection modes instead of the necessary steps for detection: custom signatures, correct policy application, and SSL inspection for encrypted traffic.

91
MCQmedium

An organization uses FortiSandbox to detect advanced threats. The administrator wants to ensure that files downloaded from the internet are sent to FortiSandbox for analysis before being delivered to users. Which Antivirus profile setting should be configured?

A.Enable 'Inline Scan' for FortiSandbox
B.Enable 'FortiSandbox Monitoring'
C.Enable 'FortiSandbox Quarantine'
D.Set 'Scan Mode' to 'Quick'
AnswerA

Inline Scan mode on FortiGate's FortiSandbox integration causes the firewall to submit a file to the sandbox and temporarily buffer the client's request until a verdict is returned. Only a 'clean' verdict releases the file to the end user; malicious or suspicious files are blocked and quarantined. This is the only mode that guarantees the file is not delivered before analysis completes, making it essential for preventing zero-day infections in real time.

Why this answer

To ensure files downloaded from the internet are sent to FortiSandbox for analysis before delivery to users, the 'Inline Scan' option for FortiSandbox must be enabled in the Antivirus profile. This setting causes the FortiGate to hold the file, send it to FortiSandbox, and only deliver it to the user after receiving a verdict (e.g., clean or malicious). Without inline scanning, files are delivered first and scanned asynchronously, which defeats the 'before delivery' requirement.

Exam trap

The trap here is that candidates confuse 'Inline Scan' with 'FortiSandbox Monitoring' or 'Quarantine', thinking any FortiSandbox-related option will send files before delivery, but only 'Inline Scan' enforces the synchronous hold-and-scan behavior required by the question.

How to eliminate wrong answers

Option B is wrong because 'FortiSandbox Monitoring' is not a valid setting in the Antivirus profile; it refers to a feature in the FortiSandbox itself for monitoring submissions, not a FortiGate profile option. Option C is wrong because 'FortiSandbox Quarantine' is not a setting in the Antivirus profile; quarantine actions are configured separately (e.g., in the FortiSandbox or via quarantine policies) and do not control whether files are sent for analysis before delivery. Option D is wrong because setting 'Scan Mode' to 'Quick' only affects the local scanning depth (e.g., file size or archive depth) and has no impact on FortiSandbox submission behavior; it does not enable inline sandboxing.

92
Multi-Selecthard

Which THREE steps are necessary when configuring SSL deep inspection on FortiGate? (Choose three.)

Select 3 answers
A.Add a static route to the internet.
B.Create an SSL inspection profile defining the inspection mode.
C.Configure a forward proxy server.
D.Apply the SSL inspection profile to a firewall policy.
E.Generate or import a CA certificate on FortiGate.
AnswersB, D, E

The SSL/SSH inspection profile is where you choose between certificate inspection (which looks only at the server certificate) and full SSL inspection (which decrypts, inspects, and re-encrypts traffic). It also lets you configure actions for invalid certificates, expired ones, and whether to inspect specific protocols like HTTPS or SMTPS. Without creating such a profile, there is no definition of how deep inspection should behave, making it a necessary first step.

Why this answer

An SSL inspection profile defines how FortiGate handles encrypted traffic, including the inspection mode (e.g., full or certificate-inspection). This profile is a mandatory component for deep inspection, as it specifies whether to decrypt, re-encrypt, or simply examine certificates.

Exam trap

The trap here is that candidates often confuse general network configuration steps (like static routes) with SSL inspection-specific steps, or mistakenly think a separate forward proxy server must be configured, when in fact FortiGate handles the proxy role internally.

93
Multi-Selectmedium

A FortiGate is configured with an application control profile to allow only 'business-approved' applications. Users are still able to use Skype for Business. The admin wants to ensure that only Skype for Business is allowed and other Skype variants are blocked. Which THREE steps should the admin take? (Choose three.)

Select 3 answers
A.Identify the exact application signatures for Skype for Business
B.Apply the application control profile to the firewall policy
C.Enable logging for all traffic to verify the application being used
D.Create a custom application signature for Skype for Business
E.Block all other Skype-related application signatures
AnswersA, B, E

To allow Skype for Business while blocking other Skype variants, you must first identify the exact application signatures that match Skype for Business traffic. The FortiGate application control database includes multiple signatures under the 'Skype' family, such as 'Skype.For.Business' and 'Skype.For.Business.Client', each with specific protocol and port definitions. Choosing the wrong signature could result in inadvertently blocking legitimate business traffic or allowing unauthorized peer-to-peer Skype connections. This step is foundational because the subsequent policy rule and blocking actions depend entirely on precisely matching the intended application.

Why this answer

The admin must first identify the exact application signatures for Skype for Business to distinguish it from other Skype variants. FortiGate's application control uses predefined signatures to classify traffic, and without knowing the specific signature IDs (e.g., 'Skype.For.Business'), the admin cannot selectively allow or block applications in the profile.

Exam trap

The trap here is that candidates may think creating a custom signature (Option D) is necessary when FortiGate already includes the required signatures, or they may confuse logging (Option C) as a configuration step rather than a verification tool.

94
MCQmedium

An administrator wants to allow users to override a blocked category (e.g., Social Networking) by entering an administrator-defined password. Which of the following must be configured?

A.Configure a DNS filter to bypass the block
B.Create a separate firewall policy with a higher priority that permits the traffic
C.Set the web filter profile to 'Monitor' mode instead of 'Block'
D.Enable 'Override' in the Web Filter profile and configure an authentication scheme
AnswerD

To correctly enable user overrides, you must turn on 'Override' in the Web Filter profile and configure an authentication scheme (e.g., local password or LDAP username/password) so the FortiGate can validate the user who submits the override request. You also need to define an authentication rule that lists which users or groups are allowed to override, and you can optionally set a duration for each override session. Once these are in place, users encountering a blocked page are prompted to enter credentials, and a successful authentication creates a temporary, logged exception that is visible in the override history.

Why this answer

To allow users to override a blocked web category by entering an administrator-defined password, you must enable the 'Override' feature within the Web Filter profile and configure an authentication scheme (e.g., using a local user or LDAP group). This allows users to bypass the block temporarily after authenticating with the defined password, rather than permanently changing the policy or filter mode.

Exam trap

The trap here is that candidates often confuse the Web Filter override with creating a separate firewall policy or changing the filter mode, not realizing that the override is a specific feature requiring both the override toggle and an authentication scheme to be configured within the web filter profile itself.

How to eliminate wrong answers

Option A is wrong because a DNS filter bypasses blocking based on DNS queries, not user authentication or password entry; it would allow all traffic to the domain, not a per-user override. Option B is wrong because creating a separate firewall policy with higher priority would permanently permit the traffic for all matching users, not require a password for temporary override. Option C is wrong because setting the web filter profile to 'Monitor' mode only logs the traffic without blocking it, eliminating the need for an override entirely.

95
MCQmedium

An administrator configures an email filter profile to block spam. Despite correct configuration, spam emails still reach users' inboxes. The FortiGate is deployed as a transparent bridge. What is the most likely reason?

A.The FortiGate does not have a valid FortiGuard license
B.The emails are encrypted with TLS and deep inspection is not enabled
C.The email filter profile is set to 'monitor' instead of 'block'
D.The firewall policy is using flow-based inspection, which does not support SMTP proxy
AnswerD

Email filtering for SMTP on FortiGate is performed by the antivirus/email filter proxy engine, which only operates in proxy-based inspection mode. When a firewall policy is set to flow-based inspection, the FortiGate uses a streamlined forwarding path that does not support SMTP proxy functionality, so the email filter profile is silently ignored for that traffic. To enforce email filtering, the policy must use proxy-based inspection (or configure a transparent proxy), allowing the FortiGate to buffer and scan SMTP messages before forwarding them.

Why this answer

In a transparent bridge deployment, FortiGate uses flow-based inspection by default, which does not support SMTP proxy-based email filtering. The email filter profile requires proxy-based inspection to intercept and block spam at the SMTP protocol level. Without enabling proxy-based inspection on the firewall policy, the FortiGate cannot apply the email filter profile effectively, allowing spam to pass through.

Exam trap

The trap here is that candidates often assume email filtering works regardless of inspection mode, but FortiGate specifically requires proxy-based inspection for SMTP proxy features like email filter profiles to function.

How to eliminate wrong answers

Option A is wrong because a valid FortiGuard license is required for real-time spam signature updates, but the email filter profile can still block spam based on local rules or heuristics even without a license; the issue here is that the filter is not being applied at all. Option B is wrong because TLS-encrypted emails would require deep inspection to decrypt and scan, but the question states the configuration is correct and spam still reaches inboxes, implying the filter is not being invoked rather than being bypassed by encryption. Option C is wrong because if the profile were set to 'monitor', it would log spam but not block it, yet the administrator would likely see logs indicating the action; the core problem is that the profile is not being applied due to inspection mode mismatch.

96
Multi-Selectmedium

A FortiGate is configured with a firewall policy that applies an Application Control profile and a Web Filter profile. The administrator wants to log all traffic blocked by the Web Filter profile. Which TWO configurations are required?

Select 2 answers
A.Enable 'Log All Blocked Sites' in the Web Filter profile
B.Set the global 'Logging' setting to 'Verbose'
C.Configure the Application Control profile to log blocked traffic
D.Enable 'Log All Traffic' or 'Log Violation Traffic' on the firewall policy
E.Enable 'Log All Allowed Sites' in the Web Filter profile
AnswersA, D

In the Web Filter profile, 'Log All Blocked Sites' is the switch that generates a log entry whenever the FortiGate denies access to a URL based on a blocked category or explicit URL. This profile-level toggle is required for the blocked request to appear in the traffic log along with the relevant URL filter category and action. Without it, even a matching firewall policy with logging enabled will not create a web-filter-specific blocked-site log record.

Why this answer

The Web Filter profile has a specific setting called 'Log All Blocked Sites' that, when enabled, generates log entries for all traffic that the web filter blocks. This is the direct mechanism to log blocked web traffic at the profile level. Option D is also correct because the firewall policy itself must have logging enabled—either 'Log All Traffic' or 'Log Violation Traffic'—to ensure that the log entries generated by the Web Filter profile are actually recorded and sent to the FortiGate's log system.

Exam trap

The trap here is that candidates often assume enabling logging only in the security profile (Web Filter) is sufficient, forgetting that the firewall policy must also have logging enabled to actually capture and store those log entries.

97
MCQmedium

An administrator needs to ensure that users cannot upload files to a specific cloud storage service via HTTPS, while still allowing them to view and download files from the same service. The FortiGate is currently performing SSL deep inspection on all outbound HTTPS traffic. Which security profile should the administrator configure to meet this requirement?

A.Antivirus
B.Data loss prevention (DLP)
C.Application control
D.Web filter
AnswerC

Application control can identify the cloud storage application and apply per-application actions. With SSL deep inspection enabled, it can see inside HTTPS and block only the upload action for that application while allowing download. This meets the requirement precisely without affecting other traffic.

Why this answer

Application control is designed to identify applications and their actions, even within encrypted traffic when SSL deep inspection is active. It can enforce policies that distinguish between upload and download actions for cloud storage apps. This allows the administrator to block uploads while permitting viewing and downloading, exactly as required.

Exam trap

The trap here is assuming that web filtering or DLP can control application-specific actions like upload versus download within an allowed application.

98
MCQmedium

An administrator wants to block an application named 'Skype' on the network. They create an application control profile and add a rule to block 'Skype'. However, after applying the profile to the policy, users can still use Skype. What is the most likely reason?

A.The application control profile is not enabled on the firewall policy
B.The application signature for Skype is outdated
C.The application control rule is set to 'monitor' instead of 'block'
D.Skype traffic is encrypted and SSL deep inspection is not enabled
AnswerD

Skype uses transport-layer encryption (TLS) to protect its signaling and media traffic. Without SSL deep inspection enabled in the firewall policy, the FortiGate cannot decrypt the SSL/TLS session to read the application-layer payload where the application signature resides. Consequently, the FortiGate sees only encrypted packets that do not match Skype's signature, so the block rule never triggers. To block Skype effectively, the administrator must enable SSL deep inspection with a valid CA certificate, allowing the FortiGate to proxy and inspect the traffic.

Why this answer

Skype uses proprietary encryption and often relies on peer-to-peer connections that bypass traditional port-based inspection. Without SSL deep inspection (also known as HTTPS inspection or certificate-based decryption), the FortiGate cannot decrypt the encrypted Skype traffic to match it against the application control signature. Application control relies on either protocol decoders or deep packet inspection (DPI) to identify applications; if the traffic is encrypted and not decrypted, the FortiGate sees only encrypted payloads and cannot apply the block rule.

Exam trap

The trap here is that candidates often assume application control can block any application by name alone, forgetting that encrypted traffic requires SSL deep inspection to be enabled on the firewall policy for the application signatures to work.

How to eliminate wrong answers

Option A is wrong because if the application control profile were not enabled on the firewall policy, the policy would not apply any application control at all, but the question states the profile was applied, so this is not the most likely reason. Option B is wrong because an outdated signature would cause a failure to detect new variants of Skype, but Skype itself is a well-known, long-standing application with stable signatures; an outdated signature is less likely than the fundamental encryption issue. Option C is wrong because if the rule were set to 'monitor' instead of 'block', the administrator would see log entries indicating the traffic was allowed, not that users could still use Skype without any indication; the question implies the block simply does not work, not that it is silently logging.

99
MCQeasy

Which security profile component is specifically designed to prevent data exfiltration by inspecting outgoing traffic for sensitive data patterns?

A.Application Control
B.Data Leak Prevention (DLP)
C.Antivirus
D.Web Filter
AnswerB

Data Leak Prevention (DLP) is the security profile specifically engineered to detect and prevent the unauthorized transmission of sensitive data. It uses deep content inspection techniques such as exact data matching, regex patterns, and file fingerprinting to identify regulated data elements like PCI-DSS card numbers, HIPAA-protected health records, and PII. DLP also considers contextual factors—source, destination, protocol, and direction—to enforce policies that block, quarantine, or log risky transmissions across SMTP, HTTP, FTP, and cloud apps.

Why this answer

Data Leak Prevention (DLP) is the security profile component specifically designed to inspect outgoing traffic for sensitive data patterns, such as credit card numbers, social security numbers, or custom regex patterns. It uses deep packet inspection (DPI) to analyze content in emails, web uploads, and file transfers, blocking or alerting on matches to prevent unauthorized data exfiltration.

Exam trap

The trap here is that candidates often confuse DLP with Web Filter or Application Control, thinking that blocking web categories or applications inherently prevents data exfiltration, but only DLP inspects the actual content of outgoing traffic for sensitive data patterns.

How to eliminate wrong answers

Option A is wrong because Application Control focuses on identifying and controlling application traffic (e.g., blocking Skype or Facebook) based on signatures, not on inspecting content for sensitive data patterns. Option C is wrong because Antivirus scans for malware signatures and heuristics in files and traffic, not for sensitive data patterns like credit card numbers or PII. Option D is wrong because Web Filter controls access to URLs and web categories (e.g., blocking gambling or adult sites), but does not inspect the content of outgoing traffic for sensitive data patterns.

100
MCQmedium

An organization uses FortiSandbox to analyze suspicious files. The FortiGate is configured to send files to FortiSandbox for analysis when the antivirus scan fails to reach a verdict. Which antivirus inspection mode must be used on the firewall policy for this integration to work?

A.Both flow and proxy modes support FortiSandbox equally
B.Deep inspection
C.Proxy-based inspection
D.Flow-based inspection
AnswerC

Proxy-based inspection is the correct mode because it fully buffers the file, forwards it to FortiSandbox, and pauses the session until a verdict is returned. This allows FortiGate to block the file before it reaches the client if FortiSandbox determines it is malicious. The connection-holding behavior is essential for quarantine and real-time enforcement. In contrast, flow-based inspection lacks this holding capability and therefore cannot provide the same level of blocking.

Why this answer

Proxy-based inspection buffers the file and can hold the connection until FortiSandbox returns a verdict. Flow-based does not support this hold-and-wait mechanism.

101
Multi-Selectmedium

A FortiGate administrator wants to block spam emails sent to the company's mail server. The mail server is behind the FortiGate. Which THREE configurations should be applied?

Select 3 answers
A.Enable DLP to filter spam
B.Configure Application Control to block email applications
C.Enable FortiGuard spam filtering in the Email Filter profile
D.Apply the Email Filter profile to the firewall policy that allows SMTP traffic to the mail server
E.Create an Email Filter profile with spam detection enabled
AnswersC, D, E

Enabling FortiGuard spam filtering within the Email Filter profile activates the cloud-based spam signature and reputation service. This satisfies the requirement to block spam, since the FortiGate must query FortiGuard to classify and reject unsolicited mail before it reaches the protected mail server.

Why this answer

Option C is correct because the FortiGate's Email Filter profile relies on FortiGuard Anti-Spam service to detect and tag/block spam based on FortiGuard's spam signature and IP reputation databases. Option E is correct because an Email Filter profile must first be created and its spam detection (and optionally other checks like banned words, DNSBL, HELO checks) enabled before it can take any action. Option D is correct because an Email Filter profile only takes effect when it is applied to the firewall policy that permits the SMTP traffic destined to the internal mail server.

Option A is not correct because DLP on FortiGate handles data leakage patterns (credit cards, SSNs, file types) rather than spam detection. Option B is not correct because Application Control identifies and blocks applications by signature/behavior, not spam content within SMTP sessions.

Exam trap

The trap here is that candidates confuse DLP or Application Control with email-specific spam filtering, failing to recognize that only the Email Filter profile with FortiGuard antispam can inspect SMTP message bodies and headers for spam content.

102
MCQeasy

A network administrator notices that a FortiGate IPS sensor is not detecting any attacks, even though there is known malicious traffic on the network. Which initial troubleshooting step should the administrator take?

A.Ensure the firewall policy is set to flow-based inspection.
B.Disable any DoS policies that might be blocking traffic.
C.Verify that the IPS engine is running and signatures are up to date.
D.Check that the FortiGate is configured in NAT mode.
AnswerC

The IPS engine (ipsengine) is the process that actually inspects packets against the signature database; if it is not running or has crashed, no IPS detection can occur. Additionally, the FortiGuard IPS package must be current, as outdated signatures will fail to match recently disclosed vulnerabilities. Running the command 'get ips status' verifies engine status and signature version, and 'execute update now' forces an update, making this the correct and direct remedy.

Why this answer

The first step in troubleshooting a non-functional IPS sensor is to verify that the IPS engine is running and that the IPS signatures are up to date. If the engine is stopped or signatures are outdated, the sensor cannot detect known malicious traffic regardless of other configurations. This foundational check ensures the detection mechanism itself is operational before investigating policy or mode settings.

Exam trap

The trap here is that candidates often jump to changing inspection modes or firewall policies, forgetting that the IPS engine must be running and signatures current for any detection to occur, which is the most basic and critical prerequisite.

How to eliminate wrong answers

Option A is wrong because flow-based inspection is not required for IPS; IPS can work with both flow-based and proxy-based inspection, and changing the inspection mode is not the initial troubleshooting step when the sensor is not detecting attacks. Option B is wrong because DoS policies are separate from IPS detection and disabling them would not enable IPS to detect attacks; they might block traffic but do not prevent IPS from analyzing it. Option D is wrong because NAT mode is unrelated to IPS detection; FortiGate can run IPS in both NAT and transparent mode, and the mode does not affect the IPS engine's ability to detect attacks.

103
MCQhard

A FortiGate administrator configures SSL deep inspection on a policy using a self-signed CA certificate. Users report that they see a certificate warning in their browsers when accessing HTTPS sites. What is the most effective solution to eliminate these warnings?

A.Use a publicly trusted CA certificate for the FortiGate
B.Disable deep inspection and use certificate inspection only
C.Add the websites to the exemption list in the SSL/SSH profile
D.Install the FortiGate's CA certificate on all client machines in the trusted root store
AnswerD

Installing the FortiGate's CA certificate into the trusted root store of every client establishes the FortiGate as a trusted certificate authority within the organization. When the FortiGate generates a per-session certificate signed by this CA, the client's browser accepts it without warnings because the CA is in its trust store. This directly addresses the root cause of the warning and is the recommended enterprise deployment practice for deep inspection.

Why this answer

The certificate warning occurs because the browser does not trust the FortiGate's self-signed CA certificate. By installing the FortiGate's CA certificate into the trusted root store on each client machine, the browser will trust certificates signed by that CA, eliminating the warning. This is the standard approach for self-signed CA certificates in SSL deep inspection environments.

Exam trap

The trap here is that candidates may think using a publicly trusted CA (Option A) is the solution, not realizing that the FortiGate must hold the private key for that CA, which is impractical and insecure; the correct approach is to trust the FortiGate's own CA internally.

How to eliminate wrong answers

Option A is wrong because using a publicly trusted CA certificate for the FortiGate would require the FortiGate to have the private key for that CA, which is a security risk and not standard practice; the FortiGate's self-signed CA is meant to be distributed internally. Option B is wrong because disabling deep inspection and using certificate inspection only would bypass the need for a trusted CA but would also eliminate the security benefits of inspecting encrypted traffic content. Option C is wrong because adding websites to the exemption list only prevents inspection for those specific sites, not all HTTPS sites, so users would still see warnings for non-exempted sites.

104
MCQhard

A company is implementing SSL/TLS inspection on a FortiGate to monitor encrypted traffic. They want to ensure that traffic to high-risk categories is blocked, while traffic to financial sites is inspected but not blocked. The administrator creates an SSL inspection profile that deep-inspects all traffic except traffic to financial sites. However, users report that they cannot access financial websites. What is the most likely cause?

A.The web filter profile is configured to block financial websites, overriding the SSL inspection exemption.
B.The SSL inspection profile should be set to certificate-inspection instead of deep-inspection for financial sites.
C.The SSL inspection profile must be applied after the web filter profile in the firewall policy.
D.The SSL inspection profile should have deep-inspection disabled for all categories except financial.
AnswerA

The SSL inspection exemption only controls whether the FortiGate decrypts the TLS stream; it does not disable URL/web filtering. FortiGuard can still classify the destination based on the SNI, IP address, or FQDN from the ClientHello, so if the web filter profile blocks the 'Financial Services' category, the session is denied regardless of the decryption bypass. The exemption is the wrong place to expect 'allow' semantics when the web filter policy explicitly says block.

Why this answer

The most likely cause is that the web filter profile applied in the same firewall policy is configured to block financial websites. Even though the SSL inspection profile exempts financial sites from deep inspection, the web filter profile operates independently and can block traffic based on URL category. Since the web filter is evaluated after SSL inspection, it will block the decrypted or even non-decrypted traffic to financial sites if the category is set to block, overriding the SSL inspection exemption.

Exam trap

The trap here is that candidates assume the SSL inspection exemption automatically prevents web filtering from blocking the traffic, but FortiGate applies web filter policies independently, so a block action in the web filter profile overrides any SSL inspection exemption.

How to eliminate wrong answers

Option B is wrong because certificate-inspection only validates the certificate without decrypting the payload, which would not allow the web filter to inspect the content; the issue is not about the inspection type but about the web filter blocking the category. Option C is wrong because the order of profiles within a firewall policy does not affect the evaluation; both SSL inspection and web filter profiles are applied in sequence, but the web filter can still block traffic regardless of the SSL inspection profile's exemption. Option D is wrong because disabling deep-inspection for all categories except financial would still allow the web filter to block financial sites if the web filter profile is configured to block them; the exemption in the SSL inspection profile does not prevent the web filter from blocking.

105
MCQeasy

Which FortiGate feature allows you to block access to specific URL categories such as 'Social Media' or 'Gambling'?

A.Web Filtering
B.Antivirus
C.Intrusion Prevention System (IPS)
D.Application Control
AnswerA

Web Filtering on FortiGate leverages the FortiGuard web filtering database to classify URLs into categories (e.g., social media, malware, phishing) and enforce per-policy allow, block, or warn actions based on those categories or a custom URL list. This directly controls which websites users can access, making it the correct feature for blocking specific sites. It can also be combined with local overrides and wildcard FQDN entries to fine-tune granular access control.

Why this answer

FortiGate's Web Filtering feature uses URL rating and category databases (e.g., FortiGuard) to block access to entire categories like 'Social Media' or 'Gambling' based on the destination URL. This is distinct from content inspection; it operates at the HTTP/HTTPS request level by matching the requested URL against predefined or custom category lists.

Exam trap

The trap here is confusing Application Control with Web Filtering, as both can block 'Social Media' but Application Control blocks based on application signatures (e.g., Facebook app traffic) while Web Filtering blocks based on URL categories, and candidates often overlook that Application Control cannot block a website accessed via a browser if the URL category is not explicitly blocked.

How to eliminate wrong answers

Option B (Antivirus) is wrong because it scans file content for malware signatures, not URL categories. Option C (IPS) is wrong because it detects and blocks network-based attacks using signatures, not URL categorization. Option D (Application Control) is wrong because it identifies and controls applications based on traffic patterns (e.g., Facebook app), not URL categories, and can be bypassed if the app uses different protocols or ports.

106
MCQhard

A user reports that a legitimate website is being blocked by FortiGate web filtering. The administrator checks and finds that the URL category is 'Unrated'. What is the most likely cause?

A.The DNS server is not resolving the domain.
B.The website is new and not yet categorized by FortiGuard.
C.The web filter is configured to block all unrated sites.
D.The website is in the 'Blocked' category.
AnswerB

FortiGuard classifies websites by continuously crawling and categorizing the public internet, but a brand-new domain or newly launched website may not yet have an entry in the FortiGuard rating database. When FortiGate receives a request for such a site, it returns a rating of 'Unrated', and the security policy's handling of the Unrated category determines whether the URL is allowed or blocked. Since no category has been assigned, the site is blocked not because it is malicious or inappropriate, but simply because it has not yet been reviewed — this is the well-known false-positive scenario for newly registered domains.

Why this answer

When a website is categorized as 'Unrated' in FortiGate web filtering, it means FortiGuard's web filtering database has not yet assigned a category to that URL. This commonly occurs for newly registered or recently launched websites that have not been crawled and classified by FortiGuard's rating infrastructure. The correct answer is B because the 'Unrated' status directly indicates the site is new and not yet categorized.

Exam trap

The trap here is that candidates may confuse the 'Unrated' category with a configuration setting (like blocking unrated sites) or a network issue (like DNS failure), rather than recognizing it as a FortiGuard rating status indicating the site has not yet been classified.

How to eliminate wrong answers

Option A is wrong because DNS resolution is unrelated to URL categorization; a DNS failure would result in a connection error, not an 'Unrated' category. Option C is wrong because while a web filter policy can be configured to block unrated sites, the question asks for the most likely cause of the 'Unrated' category itself, not the blocking action. Option D is wrong because if the website were in the 'Blocked' category, it would show that specific category in the logs, not 'Unrated'.

107
Multi-Selecthard

Which THREE factors should be considered when tuning IPS to reduce false positives?

Select 3 answers
A.Excluding trusted source IP addresses from certain signatures.
B.Enabling hardware acceleration for IPS processing.
C.Increasing the sensitivity of signatures to catch more attacks.
D.Adjusting the severity threshold for which signatures generate alerts.
E.Creating IPS filters to whitelist specific traffic patterns.
AnswersA, D, E

By creating a source-IP exemption list for specific signatures, known-good hosts such as domain controllers or admin workstations are skipped during detection. This reduces false positives without weakening protection for untrusted endpoints, since traffic from other sources still hits the full signature set. This is a targeted, address-based tuning measure that preserves detection efficacy where it matters.

Why this answer

Excluding trusted source IP addresses from certain signatures prevents the IPS from generating alerts for traffic that is known to be legitimate, directly reducing false positives. This is a common tuning technique in FortiGate IPS where you can create exceptions for specific sources or destinations to avoid unnecessary alerts from benign traffic.

Exam trap

The trap here is that candidates often confuse performance optimization (hardware acceleration) with accuracy tuning, or mistakenly think that increasing sensitivity reduces false positives, when in fact it does the opposite.

108
MCQmedium

An administrator has configured an SSL deep inspection profile with 'certificate inspection' for a firewall policy. Users report that they receive certificate errors when accessing HTTPS sites. What is the MOST likely reason?

A.The certificate installed on the FortiGate for SSL inspection is expired
B.The web server uses a self-signed certificate which is blocked by the inspection profile
C.The users' browsers do not trust the FortiGate's CA certificate
D.The FortiGate is not configured to re-sign certificates with its own CA certificate
AnswerB

In certificate inspection mode, the FortiGate does not decrypt the SSL stream but still inspects the server certificate during the handshake. A self-signed certificate is inherently untrusted because it is not issued by a recognized CA, so the inspection profile blocks the connection. This block prevents the browser from completing the handshake, resulting in certificate error messages being displayed to the user.

Why this answer

With 'certificate inspection' mode, the FortiGate does not decrypt traffic or present its own certificate to clients. It only inspects the server certificate during the SSL handshake. If the inspection profile is configured to block invalid certificates (e.g., self-signed, expired, untrusted CA), and the web server uses a self-signed certificate, the FortiGate will drop the connection.

Users may then see a certificate error or connection failure in their browsers. Option C is incorrect because certificate inspection never involves the FortiGate's CA certificate; that is only used in full SSL inspection when re-signing certificates.

109
MCQeasy

A network administrator wants to prevent users from downloading files with .exe extensions via HTTP and HTTPS. Which security profile feature should be used?

A.Web filter profile with URL filter to block .exe sites
B.Application control profile to block file transfer applications
C.Antivirus profile with 'block' action for file pattern matching .exe
D.IPS profile to block executable file transfers
AnswerC

The antivirus profile in FortiOS includes a file filter (or file pattern) capability that can match filenames, file extensions, or MIME types during protocol decoding. By configuring a file pattern for '.exe' and setting the action to 'block', FortiGate inspects the file's extension as it passes through HTTP (or HTTPS when deep inspection is enabled) and discards the file before it reaches the user. This is the correct method because the antivirus engine works at the content layer, not at the URL or application layer, and can enforce file-type blocking regardless of the website hosting the file.

Why this answer

The Antivirus profile in FortiGate can be configured with a file pattern matching rule to block files based on their extension, such as .exe. This feature operates at the application layer, inspecting HTTP and HTTPS traffic (via SSL inspection) to identify and block executable files before they reach the user. Option C is correct because it directly uses the antivirus engine's file pattern matching capability to enforce this policy.

Exam trap

The trap here is that candidates confuse URL filtering (which blocks sites) with file extension filtering (which blocks specific file types within allowed sites), leading them to choose the web filter profile option instead of the antivirus profile.

How to eliminate wrong answers

Option A is wrong because a web filter profile with URL filtering blocks access to entire websites or URL categories, not specific file extensions within HTTP/HTTPS downloads; it cannot inspect file content or extensions. Option B is wrong because an application control profile is designed to identify and control network applications (e.g., Skype, BitTorrent), not to block file transfers based on file extension; it does not inspect file payloads. Option D is wrong because an IPS profile is used to detect and prevent network-based attacks and vulnerabilities, not to block specific file types; it focuses on exploit signatures, not file extensions.

110
MCQmedium

An administrator wants to ensure that search engine results from Google, Bing, and Yahoo are filtered to exclude explicit content when users perform searches. Which feature should the administrator configure in the web filter profile?

A.FortiGuard category filter
B.URL filter
C.Safe search
D.DNS filter
AnswerC

Safe search: Safe search enforcement is a specific FortiGate feature that inserts the appropriate safe search cookies or query parameters (e.g., 'safe=active' for Google) into outbound requests to supported search engines. It also integrates with DNS-based and HTTPS inspection to prevent users from disabling this setting. Unlike category or URL filters, it actively modifies the request so the search engine itself returns filtered results, which is the only way to guarantee content-level safe search on the SERP.

Why this answer

Safe search is a feature within FortiGate's web filter profile that enforces search engine providers (Google, Bing, Yahoo) to filter explicit content from search results. It works by appending specific parameters to search URLs or using HTTPS inspection to inject the safe search cookie, ensuring compliance with content filtering policies.

Exam trap

The trap here is that candidates confuse category filtering (which blocks entire sites) with safe search (which filters content within allowed sites), leading them to select FortiGuard category filter instead of Safe search.

How to eliminate wrong answers

Option A is wrong because FortiGuard category filter blocks or allows entire categories of websites (e.g., 'Adult/Mature Content'), but it does not control the search results within allowed search engines. Option B is wrong because URL filter matches specific URLs or patterns, not the dynamic search result content from search engines. Option D is wrong because DNS filter blocks or redirects DNS queries to domains, but it cannot modify the content of search results returned by a search engine.

111
MCQmedium

An administrator configures a DLP sensor to detect credit card numbers in traffic. However, the sensor is not detecting any credit card numbers even though they are present in emails. What could be the reason?

A.Email traffic is encrypted and SSL deep inspection is not enabled
B.The DLP sensor is applied to the wrong policy
C.The credit card regular expression is incorrect
D.The DLP sensor is in 'Monitor' mode
AnswerA

This is correct because DLP sensors operate on cleartext payloads. When email traffic is protected by TLS/SSL and SSL deep inspection is not enabled, the sensor sees only ciphertext, so any regex pattern or data-identifier match is impossible. You must enable deep inspection on the applicable firewall policy so the FortiGate can decrypt the email and feed the plaintext to the DLP sensor.

Why this answer

If a DLP sensor is configured to detect credit card numbers in emails but is not detecting them, a likely reason is that the email traffic is encrypted (e.g., via TLS) and SSL deep inspection is not enabled on the FortiGate. Without SSL deep inspection, the FortiGate cannot see the contents of encrypted emails, so the DLP sensor cannot inspect the payload for credit card numbers. Therefore, enabling SSL deep inspection would allow the DLP sensor to detect the patterns.

Exam trap

NSE4 often tests the impact of encryption on inspection; candidates may overlook that without SSL deep inspection, DLP and IPS cannot see encrypted payloads, leading to false negatives.

How to eliminate wrong answers

Option B is wrong because if the DLP sensor were applied to the wrong policy, it would not detect any traffic, but the question states that credit card numbers are present in emails and the sensor is not detecting them; while possible, it is less likely than encryption, and the question asks for the reason 'could be' — but the most common and likely reason is encryption. Option C is wrong because if the credit card regular expression were incorrect, it would not detect, but the question implies the sensor is configured to detect credit card numbers; again, less likely than encryption. Option D is wrong because 'Monitor' mode would still detect and log, but not block; the question says 'not detecting any', so monitor mode would still detect.

112
MCQhard

A FortiGate in flow-based mode is configured with an antivirus profile to block infected files. A user downloads a .zip file containing a known virus, but the download is allowed and the file is not quarantined. What is the MOST likely reason?

A.The antivirus profile is not set to 'block' for virus outbreaks
B.The virus definition database is outdated
C.Flow-based inspection does not support antivirus for .zip archives
D.Flow-based inspection does not decompress archives by default
AnswerD

In flow-based inspection mode, the FortiGate processes files in a streaming fashion, reading data as it flows through and not buffering the whole file, which means it cannot decompress archive files like .zip before scanning their contents. Because the virus is hidden inside the .zip, the scanner never actually sees it, so the file passes through undetected even if signatures are current. Proxy-based inspection, in contrast, buffers the entire file and can decompress archives to scan each contained file, which is why flow mode fails in this situation. The default behavior in flow mode is not to decompress archives, making this the correct explanation.

Why this answer

In flow-based inspection mode, FortiGate does not decompress archive files (such as .zip) by default. This means the antivirus engine cannot inspect the contents of the compressed file, so even if a known virus is inside, it will not be detected or blocked. To inspect archives in flow-based mode, you must enable 'deep archive inspection' in the antivirus profile.

Exam trap

The trap here is that candidates assume flow-based and proxy-based modes behave identically regarding archive scanning, but FortiGate's flow-based mode requires explicit configuration to decompress archives, whereas proxy-based mode does it by default.

How to eliminate wrong answers

Option A is wrong because the antivirus profile's 'block' action for virus outbreaks is a separate setting for outbreak prevention, not for standard virus detection; the issue here is that the file inside the archive was never inspected. Option B is wrong because an outdated virus definition database would cause missed detection of new viruses, but the scenario specifies a 'known virus', implying the signature exists; the core problem is the lack of archive decompression, not signature age. Option C is wrong because flow-based inspection does support antivirus for .zip archives, but only if archive decompression is explicitly enabled; the statement that it does not support it at all is incorrect.

113
MCQeasy

Which of the following is a prerequisite for SSL deep inspection to work correctly on FortiGate?

A.A dedicated HTTPS firewall policy.
B.A firewall policy that has SSL inspection enabled.
C.The FortiGate must be operating in proxy mode.
D.An active FortiCare license.
AnswerB

The correct prerequisite is that the firewall policy permitting the HTTPS traffic must have SSL inspection enabled, meaning an SSL/SSH inspection profile is applied to that policy. This profile instructs the FortiGate to decrypt the traffic, apply security controls, and re-encrypt it, which is the essence of deep inspection. Without this profile attached, the policy merely forwards the encrypted traffic without any visibility.

Why this answer

SSL deep inspection requires a firewall policy with SSL inspection enabled to intercept and decrypt HTTPS traffic. Without such a policy, the FortiGate cannot apply the CA certificate to re-encrypt traffic for inspection, making deep inspection non-functional.

Exam trap

The trap here is that candidates often confuse the need for a firewall policy with SSL inspection enabled with the misconception that a separate HTTPS-only policy or proxy mode is mandatory, when in fact any policy matching HTTPS traffic can be configured for deep inspection.

How to eliminate wrong answers

Option A is wrong because a dedicated HTTPS firewall policy is not required; any firewall policy with the appropriate SSL inspection profile can handle HTTPS traffic. Option C is wrong because FortiGate supports SSL inspection in both proxy-based and flow-based modes, not exclusively proxy mode. Option D is wrong because an active FortiCare license is not a prerequisite for SSL deep inspection; it is required for FortiGuard services like web filtering but not for the inspection mechanism itself.

114
Multi-Selectmedium

A network admin wants to block all traffic from the BitTorrent application. The admin has enabled application control on the firewall policy. Which step is necessary to achieve this?

Select 1 answer
A.Add a DNS filter profile to block BitTorrent tracker domains
B.Add the BitTorrent application signature to the application control profile and set action to block
C.Set the application control inspection mode to proxy-based
D.Enable 'deep inspection' in the application control profile
E.Enable SSL deep inspection on the firewall policy
AnswersB

Application control profiles act on traffic only when the relevant application signature is present and its action is set to block. Adding the BitTorrent signature with a block action is therefore the necessary step to drop that application's traffic.

Why this answer

To block BitTorrent traffic, the admin must add the BitTorrent application signature to the application control profile and set the action to block (option B). Application control can detect BitTorrent even though it uses proprietary encryption—FortiGate uses protocol decoders and signature matching on unencrypted handshake data. SSL deep inspection (option E) is not required because BitTorrent does not use SSL/TLS encryption; enabling deep inspection would not help and would add unnecessary overhead.

Options A, C, and D are also unnecessary: DNS filter does not block the application itself, proxy-based inspection is not mandatory, and deep inspection (in the profile) is not the correct setting.

Exam trap

The trap is assuming that all encrypted applications require SSL deep inspection. BitTorrent uses proprietary protocol encryption, not SSL/TLS. Application control can identify BitTorrent without decryption by analyzing unencrypted portions of the traffic, so deep inspection is not needed.

115
Multi-Selecthard

An organization uses FortiMail for email filtering and FortiGate for web filtering. The administrator wants to ensure that email traffic is filtered for spam and malware before reaching the internal mail server. Which TWO steps should be taken? (Choose two.)

Select 2 answers
A.Configure FortiMail to scan incoming emails and then forward them to the internal mail server.
B.Apply an antivirus profile to the firewall policy that handles SMTP traffic.
C.Apply an email filter profile to the firewall policy that handles SMTP traffic.
D.Configure the FortiGate to route SMTP traffic through FortiMail using a policy-based routing or VIP.
E.Disable SMTP inspection on the FortiGate to avoid double scanning.
AnswersA, D

FortiMail must be configured as the mail gateway in inline mode, receiving incoming SMTP messages before any other mail server. It performs comprehensive email security functions—spam filtering, antivirus, phishing protection, and content inspection—using its own message-specific heuristics and reputation databases. Once a message is deemed clean, FortiMail relays it to the internal mail server, ensuring that only sanitized mail reaches the user's inbox.

Why this answer

Option A is correct because FortiMail is the dedicated email security appliance that must actually perform the spam and malware scanning of inbound messages before relaying them to the internal mail server. Option D is correct because the FortiGate must be configured to direct SMTP traffic to FortiMail first, typically via a policy route or a VIP/port-forwarding rule, so that mail is inspected before it reaches the internal mail server. Option B is not correct because an antivirus profile on the FortiGate only scans traffic passing through the firewall and does not provide the full email spam/malware filtering that FortiMail delivers.

Option C is not correct because FortiGate email filter profiles are not the mechanism used to filter SMTP for spam and malware in this FortiMail-based design. Option E is not correct because disabling SMTP inspection on the FortiGate would remove an additional layer of protection and does not accomplish the goal of filtering email through FortiMail.

Exam trap

The trap here is that candidates may think FortiGate's security profiles (antivirus, web filter) can replace FortiMail's dedicated email filtering, but FortiGate lacks the specialized spam and email malware detection engines that FortiMail provides.

116
MCQeasy

An administrator wants to apply a safe search policy to enforce strict search results on Google, Bing, and Yahoo. Which security profile feature should be used?

A.Web filter safe search enforcement
B.Application control to block search engines
C.DNS filter to block search engine domains
D.Web filter URL filter with keyword blocking
AnswerA

Safe search enforcement is a built-in Web Filter profile setting that forces supported search engines (Google, Bing, YouTube) to apply strict content filtering by automatically modifying search request URLs (e.g., appending 'safe=active' for Google and 'adlt=strict' for Bing) or by redirecting to a forced-search endpoint. Unlike blocking features, it does not deny access to the search engine; it preserves search capability while scrubbing explicit results, which directly satisfies the administrator's goal. It typically requires HTTPS inspection to rewrite embedded search URLs inside encrypted traffic.

Why this answer

Web filter safe search enforcement is the correct feature because it directly integrates with search engines (Google, Bing, Yahoo) to force the use of their built-in safe search parameters (e.g., Google's 'safe=active' parameter appended to URLs). This ensures that explicit content is filtered at the source, regardless of the user's browser settings or search engine choice.

Exam trap

The trap here is that candidates may confuse 'blocking search engines' (application control or DNS filter) with 'enforcing safe search within search engines' (web filter safe search enforcement), leading them to select an option that prevents access rather than controlling content.

How to eliminate wrong answers

Option B is wrong because application control blocks or allows applications (e.g., blocking all search engine traffic), but it cannot enforce safe search parameters within allowed search engines. Option C is wrong because a DNS filter blocks entire domains (e.g., blocking google.com), which would prevent access to search engines entirely, not enforce safe search. Option D is wrong because a URL filter with keyword blocking can block specific URLs or keywords in the URL, but it cannot dynamically inject safe search parameters into search engine queries, which is required for strict safe search enforcement.

117
Multi-Selectmedium

An administrator wants to configure a DNS filter to block access to known malicious domains and also enforce safe search on search engines. Which THREE settings are required in the DNS filter profile? (Choose three.)

Select 3 answers
A.Add entries to the static domain blocklist
B.Select 'Redirect to safe search' for search engines
C.Configure a DNS sinkhole IP address
D.Specify external DNS servers for resolution
E.Enable DNS filtering based on FortiGuard categories
AnswersA, B, E

Adding entries to the static domain blocklist within a DNS filter profile is correct because it allows you to manually specify exact domain names to always block, independent of FortiGuard categorization. This is useful for domains that are known threats or unwanted but may not yet be classified by FortiGuard, or for enforcing custom corporate policy. The blocklist takes precedence over category-based filtering, ensuring these domains are always denied.

Why this answer

Adding entries to the static domain blocklist allows the administrator to manually specify known malicious domains that should be blocked regardless of FortiGuard category ratings. This provides a hard-coded block for domains that may not yet be categorized or that the administrator wants to ensure are always blocked.

Exam trap

The trap here is that candidates often confuse the DNS sinkhole IP address (a response action) with a required setting for blocking, or they think external DNS servers must be specified in the profile, when in fact the DNS filter profile uses the FortiGate's system DNS settings by default.

118
MCQmedium

An administrator runs the following CLI command and sees the output: 'diagnose sys session list | grep -A 5 10.1.1.100' and finds a session with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the session?

A.The session is about to expire
B.The session has been active for approximately 1 second
C.The session has been active for 3600 seconds
D.The session is using UDP protocol
AnswerC

The 'duration' field in Fortinet's session output records the age of the session in seconds, counting upward from the moment the connection was first seen. In this output, duration=3600 directly indicates the session has been active for exactly 3600 seconds (one hour). This is the only option that matches the literal value in the CLI output.

Why this answer

The 'duration' field in Fortinet session output indicates the actual time the session has been alive (session age), while 'expire' indicates the remaining time before timeout. Here, duration=3600 means the session has been active for 3600 seconds (1 hour). expire=3599 is just slightly less than the duration, but the key is that duration is the age. Therefore, option C is correct.

Exam trap

Common mistake: Candidates think 'duration' is the timeout value, but in Fortinet's 'diagnose sys session list', 'duration' is the elapsed time since the session started, and 'expire' is the remaining time. The timeout is the sum of duration and expire (if not zero), but here duration is directly the age.

How to eliminate wrong answers

Option A is wrong because 'expire=3599' indicates the session still has 3599 seconds left, so it is not about to expire; it is nearly full duration. Option C is wrong because 'duration=3600' is the total session timeout value, not the actual time the session has been active; the active time is duration minus expire (1 second). Option D is wrong because 'proto=6' indicates TCP protocol (protocol number 6), not UDP (which is protocol 17).

119
MCQhard

An administrator runs 'diagnose ips anomaly list' and sees the following output: List of anomaly events: ID: 1, Type: tcp_syn_flood, Status: triggered, Count: 1500, Threshold: 1000 What does this indicate?

A.The IPS anomaly sensor is configured to block all TCP traffic.
B.The FortiGate has detected a single TCP SYN packet and is logging it.
C.The FortiGate is experiencing a TCP SYN flood attack and has triggered rate-based detection.
D.The FortiGate is performing a TCP SYN flood attack.
AnswerC

The output displays an anomaly event of type 'tcp_syn_flood' in the triggered state, which means the FortiGate has detected that the number of incompleted TCP SYN packets has exceeded the configured threshold for the anomaly sensor. This is rate-based detection because the sensor continuously monitors the rate of SYN packets and compares it against a threshold; when the rate shoots up, the anomaly is considered triggered and the configured action (such as dropping subsequent packets or sending an alert) is executed. Therefore, the FortiGate is correctly interpreting a TCP SYN flood attack targeting itself or a protected host.

Why this answer

The output from 'diagnose ips anomaly list' shows a tcp_syn_flood anomaly with a count of 1500 exceeding the threshold of 1000, and the status is 'triggered'. This indicates that the FortiGate's IPS anomaly sensor has detected a rate-based anomaly — specifically, the number of TCP SYN packets received per second has surpassed the configured threshold, which is a classic sign of a TCP SYN flood attack. The FortiGate has triggered its rate-based detection mechanism, which can then take configured actions such as alerting or blocking, confirming option C as correct.

Exam trap

The trap here is that candidates may confuse a triggered anomaly with a permanent block action or misinterpret the count as a single packet, when in fact the output clearly shows a rate-based threshold exceedance indicating an ongoing flood attack.

How to eliminate wrong answers

Option A is wrong because the IPS anomaly sensor does not block all TCP traffic; it only monitors and optionally blocks traffic that exceeds a specific rate threshold for a defined anomaly type, such as tcp_syn_flood. Option B is wrong because the output shows a count of 1500 and a threshold of 1000, indicating multiple packets have been detected over a rate interval, not a single packet, and the anomaly is triggered, not just logged. Option D is wrong because the FortiGate is the victim or detection point, not the attacker; the output indicates it is receiving an excessive number of SYN packets, not generating them.

120
MCQmedium

Which of the following best describes the difference between flow-based and proxy-based inspection for antivirus scanning?

A.Flow-based inspection reassembles the entire file before scanning, while proxy-based scans packets on the fly
B.Flow-based inspection scans first packet and allows, while proxy-based buffers the entire session
C.Flow-based inspection requires SSL deep inspection, while proxy-based does not
D.Flow-based inspection uses pattern matching and anomaly detection with low latency, while proxy-based provides full content reassembly and higher detection rates
AnswerD

This correctly captures the core trade-off. Flow-based inspection processes packets in a streaming fashion using pattern matching, protocol anomaly detection, and flow-level heuristics, keeping latency low and throughput high. Proxy-based inspection buffers and reassembles the entire payload, which allows for detecting complex evasions and embedded malware, but at the cost of higher latency and resource usage.

Why this answer

Flow-based inspection uses pattern matching and anomaly detection to scan traffic with low latency, while proxy-based inspection fully reassembles files and content, enabling deeper analysis and higher detection rates. In Fortinet's FortiOS, flow-based mode is optimized for performance, whereas proxy-based mode provides more thorough inspection by buffering and reconstructing the entire data stream before scanning.

Exam trap

The trap here is that candidates often confuse the performance characteristics, mistakenly thinking flow-based is 'less secure' or that proxy-based always requires SSL inspection, when in fact both modes can be applied to different inspection needs and SSL inspection is a separate configuration.

How to eliminate wrong answers

Option A is wrong because it reverses the roles: flow-based inspection scans packets on the fly without full reassembly, while proxy-based inspection buffers and reassembles the entire file before scanning. Option B is wrong because flow-based inspection does not simply 'scan first packet and allow'; it performs real-time pattern matching and anomaly detection on the flow, and proxy-based inspection buffers the entire session, not just the session but the content for full reassembly. Option C is wrong because SSL deep inspection is a separate feature that can be used with both flow-based and proxy-based inspection; it is not a defining difference between the two modes.

121
MCQeasy

A network administrator wants to prevent users from accessing known malicious websites using FortiGate. Which security profile should be applied to the firewall policy to achieve this goal?

A.Antivirus profile
B.Application control profile
C.IPS profile
D.Web filtering profile
AnswerD

A web filtering profile is purpose-built to control web access by evaluating each requested URL against FortiGuard's real-time web category database, which includes categories like gambling, adult, and malicious sites. It can block or allow entire categories, apply URL or DNS filtering, and log or warn users based on policy. This is the exact tool to prevent users from accessing inappropriate content, as it can be assigned to a firewall policy to filter both HTTP and HTTPS traffic.

Why this answer

Web filtering profile. FortiGate's web filtering profile uses URL rating and category-based filtering to block access to known malicious websites by leveraging FortiGuard's real-time threat intelligence. This is the specific security profile designed to control web access based on URL reputation, including blocking malicious URLs.

Exam trap

The trap here is that candidates often confuse web filtering with application control or IPS, mistakenly thinking that blocking malicious websites requires signature-based detection or application-layer control, rather than URL reputation-based filtering.

How to eliminate wrong answers

Option A is wrong because an Antivirus profile scans files for malware but does not block access to websites based on URL reputation or category. Option B is wrong because an Application control profile identifies and controls network applications (e.g., social media, streaming) but does not filter web URLs or block malicious websites. Option C is wrong because an IPS profile detects and prevents network-based attacks using signatures, but it is not designed to block access to known malicious websites based on URL filtering.

122
MCQmedium

An administrator wants to block upload of files containing credit card numbers via web forms. Which security profile should be used?

A.Antivirus profile
B.Web filter profile
C.Application control profile
D.Data leak prevention (DLP) profile
AnswerD

A Data Leak Prevention (DLP) profile is expressly designed to detect and prevent the transmission of sensitive information, including credit card numbers, by applying content inspection, regex pattern matching, and file fingerprinting to data in motion. On FortiGate, a DLP profile can be attached to a security policy to inspect HTTP, FTP, SMTP, and other protocols, and it can block, log, or allow based on predefined or custom data classifiers. This precisely matches the administrator's requirement to block uploads of files containing credit card data, making it the correct choice.

Why this answer

Data Leak Prevention (DLP) profiles on FortiGate are specifically designed to inspect traffic content for sensitive data patterns such as credit card numbers, SSNs, and custom regex patterns, and to block or log based on those matches. Blocking uploads of files containing credit card numbers via web forms is a classic DLP use case because DLP can scan HTTP POST bodies and file contents. The DLP profile is applied to a firewall policy, where it inspects the matching traffic.

Exam trap

NSE4 often tests the difference between content inspection (DLP, antivirus) and metadata/behavior inspection (web filter, app control), and candidates who pick 'web filter' because the traffic is web-based miss that DLP is the only profile that reads the actual data pattern.

How to eliminate wrong answers

Option A is wrong because antivirus profiles detect malware signatures and known malicious files, not sensitive data patterns like credit card numbers. Option B is wrong because web filter profiles categorize and block URLs or domains based on reputation and category, not the content of uploaded files. Option C is wrong because application control profiles identify and control applications by signature (e.g., Facebook, BitTorrent) but do not inspect payload content for data patterns.

123
MCQeasy

When configuring SSL inspection, which type of inspection decrypts and inspects all HTTPS traffic including applications using non-standard ports?

A.SSL Offloading
B.Certificate Inspection
C.Full SSL Inspection (Deep Inspection)
D.Flow-based Inspection
AnswerC

Full SSL inspection (also called deep inspection) terminates the SSL/TLS connection, decrypts the traffic, applies the full security feature set (IPS, antivirus, web filtering, application control) to the plaintext, and then re-encrypts it for the destination. This gives complete visibility and control over encrypted sessions. It requires installing the FortiGate CA certificate on managed endpoints so the client trusts the re-encrypted connection.

Why this answer

Full SSL Inspection (Deep Inspection) is the correct answer because it performs a man-in-the-middle decryption and re-encryption of all HTTPS traffic, regardless of the port used. This allows the FortiGate to inspect the payload of encrypted sessions, including those on non-standard ports, for threats and policy violations.

Exam trap

The trap here is confusing the processing mode (Flow-based vs. Proxy-based) with the actual SSL inspection method, leading candidates to incorrectly select Flow-based Inspection as a type of SSL decryption.

How to eliminate wrong answers

Option A is wrong because SSL Offloading only decrypts traffic destined to a protected server to reduce server load, not to inspect all HTTPS traffic including non-standard ports. Option B is wrong because Certificate Inspection only checks the SSL certificate validity and does not decrypt the traffic payload, so it cannot inspect the content of HTTPS sessions. Option D is wrong because Flow-based Inspection is a processing mode (flow vs. proxy) that can be used with SSL inspection, but it is not a type of SSL inspection itself.

124
MCQmedium

A FortiGate administrator wants to block outgoing DNS requests to known malware domains. Which security profile should be used?

A.Application control
B.Web filter
C.IPS
D.DNS filter
AnswerD

DNS filter is purpose-built to inspect outgoing DNS queries and compare the requested Fully Qualified Domain Name (FQDN) against FortiGuard DNS categories or an administrator-defined domain list. When a match occurs on a blocked category or domain, the filter can drop the query, return a synthetic NXDOMAIN, or redirect to a sinkhole IP to prevent resolution. This direct interception of the DNS request is why it is the correct feature for this requirement.

Why this answer

DNS Filter is the correct security profile because it is specifically designed to inspect and block DNS queries based on domain names, IP addresses, or categories. By configuring a DNS filter policy with a custom list of known malware domains, the FortiGate can intercept outgoing DNS requests and drop those matching the malicious entries, preventing the resolution of malware domains.

Exam trap

The trap here is that candidates often confuse DNS Filter with Web Filter, assuming that blocking malicious domains is a web filtering function, but DNS Filter operates at the DNS protocol level and is the correct profile for blocking DNS requests to specific domains.

How to eliminate wrong answers

Option A is wrong because Application Control identifies and controls application traffic (e.g., Skype, BitTorrent) based on signatures, not DNS queries to specific domains. Option B is wrong because Web Filter inspects HTTP/HTTPS traffic to block URLs or categories, but it does not inspect DNS requests themselves. Option C is wrong because IPS (Intrusion Prevention System) detects and blocks network-level attacks and exploits using signatures, not DNS queries to specific domain names.

125
MCQeasy

What is the primary function of protocol decoders in the FortiGate IPS engine?

A.They block malicious IP addresses based on reputation.
B.They normalize traffic for specific protocols to enable signature matching.
C.They rate-limit traffic to prevent DoS attacks.
D.They decrypt SSL/TLS traffic for inspection.
AnswerB

Protocol decoders are responsible for taking raw payloads from protocols such as HTTP, SMTP, or SMB and normalizing them into a canonical representation—stripping encoding differences, reassembling fragments, and resolving protocol ambiguities. This normalization is essential because IPS signatures are written against standardized protocol structures; without it, evasion techniques like mixed-case headers, extra whitespace, or chunked encoding would cause signatures to miss malicious content. Thus, the decoder directly enables accurate and reliable signature matching.

Why this answer

Protocol decoders in the FortiGate IPS engine analyze and normalize traffic for specific protocols (e.g., HTTP, DNS, SMTP) by parsing the protocol fields and reconstructing the data stream. This normalization allows IPS signatures to match against a consistent representation of the traffic, regardless of evasion techniques like fragmentation or encoding. Thus, their primary function is to enable accurate signature matching.

Exam trap

NSE4 often tests the role of protocol decoders versus other IPS components, so candidates may confuse decoders with SSL inspection or IP reputation, leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because blocking malicious IP addresses based on reputation is typically handled by IP reputation databases and firewall policies, not by protocol decoders. Option C is wrong because rate-limiting to prevent DoS attacks is a function of DoS policies or traffic shaping, not protocol decoders. Option D is wrong because SSL/TLS decryption for inspection is performed by SSL inspection profiles, which decrypt traffic before it reaches the IPS engine; protocol decoders do not decrypt SSL/TLS.

126
MCQeasy

What is the primary purpose of FortiSandbox integration with FortiGate antivirus?

A.To replace the local antivirus scanning engine
B.To perform SSL deep inspection
C.To cache antivirus signatures locally
D.To detect zero-day malware by analyzing file behavior in a sandbox environment
AnswerD

FortiSandbox is purpose-built to detect zero-day malware by detonating suspicious files in an isolated, virtualized environment and observing runtime behaviors such as API calls, registry modifications, and outbound network connections. This dynamic analysis uncovers threats lacking known signatures, complementing FortiGate's signature-based detection. The sandbox returns a risk rating to FortiGate, enabling it to block files that evade traditional antivirus.

Why this answer

FortiSandbox integration with FortiGate antivirus is designed to detect zero-day malware by analyzing file behavior in a sandbox environment. This allows FortiGate to forward suspicious files that evade signature-based detection to FortiSandbox for dynamic analysis, where behavioral patterns are examined to identify unknown threats. The integration enhances the existing antivirus engine rather than replacing it, providing a layered defense against advanced persistent threats.

Exam trap

The trap here is that candidates may confuse the purpose of FortiSandbox with signature-based updates or SSL inspection, mistakenly thinking it replaces or caches signatures, when in fact it provides behavioral detection for unknown threats.

How to eliminate wrong answers

Option A is wrong because FortiSandbox integration does not replace the local antivirus scanning engine; it complements it by handling files that the signature-based engine cannot classify, such as zero-day malware. Option B is wrong because SSL deep inspection is a separate feature of FortiGate that decrypts SSL/TLS traffic for content inspection, and it is not the primary purpose of FortiSandbox integration. Option C is wrong because caching antivirus signatures locally is a function of the FortiGate's antivirus profile and FortiGuard updates, not a purpose of FortiSandbox integration, which focuses on behavioral analysis rather than signature storage.

127
Drag & Dropmedium

Drag and drop the steps to configure a VLAN interface on FortiGate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VLAN interfaces require a physical parent, VLAN ID, IP address, and optional administrative access.

128
MCQhard

A FortiGate is configured with SSL deep inspection using a self-signed CA certificate. Users report that they see a certificate warning in their browser when accessing HTTPS sites. The admin wants to eliminate these warnings. What should the admin do?

A.Install the FortiGate's CA certificate on each client device's trusted root certificate store
B.Disable SSL deep inspection and rely on flow-based antivirus
C.Change the SSL inspection mode to certificate inspection only
D.Configure an SSL certificate exemption for all HTTPS traffic
AnswerA

Installing the FortiGate CA certificate into each client's trusted root store is the only way to make the browser accept the dynamically generated server certificates that FortiGate presents during MITM decryption. Without this trust anchor, every HTTPS session fails the chain validation and triggers a 'certificate not trusted' warning. This step validates the FortiGate as the legitimate signing authority for its intercepted sessions, eliminating warnings and restoring secure, transparent deep inspection.

Why this answer

When FortiGate performs SSL deep inspection, it decrypts HTTPS traffic by acting as a man-in-the-middle, using its own CA certificate to re-encrypt the connection. If the FortiGate's self-signed CA certificate is not trusted by the client, the browser will display a certificate warning because the issuer is not in the client's trusted root store. Installing the FortiGate's CA certificate on each client device's trusted root certificate store establishes trust, eliminating the warnings.

Exam trap

The trap here is that candidates may think disabling or bypassing SSL inspection (options B, C, or D) is a valid way to eliminate warnings, but the correct approach is to establish trust by distributing the FortiGate's CA certificate to clients.

How to eliminate wrong answers

Option B is wrong because disabling SSL deep inspection removes the ability to inspect encrypted traffic for threats, but it does not address the root cause of certificate warnings; it simply avoids the issue. Option C is wrong because certificate inspection only examines the certificate exchange without decrypting the payload, which prevents deep content inspection but still requires a trusted CA to avoid warnings if any interception is performed. Option D is wrong because configuring an SSL certificate exemption for all HTTPS traffic effectively bypasses inspection entirely, leaving the traffic unexamined and defeating the purpose of SSL deep inspection.

129
MCQhard

Refer to the exhibit. A FortiGate SSL VPN user is unable to connect. The debug output shows the above error. What is the most likely cause?

A.The SSL VPN certificate has expired.
B.The CA that issued the SSL VPN certificate is not trusted by the client.
C.The user's password is incorrect.
D.The firewall policy is blocking the SSL VPN port.
AnswerB

During the TLS handshake, FortiGate presents its SSL VPN server certificate to the client, which then attempts to build a trust path to a root CA in its local trust store. If the issuing CA is not installed in the client's trust store, the client aborts with an 'unknown CA' or 'untrusted certificate' error, and the login page is never displayed. This happens because the client cannot verify the server's identity, an essential prerequisite for establishing the encrypted tunnel and preventing man-in-the-middle attacks. The correct remediation is to either replace the self-signed or private certificate with one issued by a publicly trusted CA, or to push the private CA certificate to all client devices.

Why this answer

The debug output indicates an SSL/TLS handshake failure, specifically that the client does not trust the server's certificate. This occurs when the Certificate Authority (CA) that issued the SSL VPN certificate is not in the client's trusted root store. Option B correctly identifies this as the most likely cause because the error is a certificate trust issue, not an expiration or authentication problem.

Exam trap

The trap here is that candidates confuse certificate trust issues (CA not trusted) with certificate expiration, but the debug output clearly shows a trust chain failure, not a validity date error.

How to eliminate wrong answers

Option A is wrong because a certificate expiration error would typically produce a different debug message (e.g., 'certificate has expired') and would be logged as a validity period failure, not a trust chain issue. Option C is wrong because an incorrect password would result in an authentication failure at the login stage, not an SSL/TLS handshake error during the initial connection setup. Option D is wrong because a firewall policy blocking the SSL VPN port would prevent any TCP connection from being established, resulting in a timeout or 'connection refused' error, not an SSL handshake failure with certificate trust messages.

130
MCQhard

An administrator configures an application control profile to block 'Facebook' and 'Twitter' using application signatures. Users can still access Facebook via HTTPS. The firewall policy has application control enabled and SSL deep inspection is not configured. Why is Facebook not blocked?

A.The application signature for Facebook is not updated
B.The application control profile is configured in monitor-only mode
C.HTTPS traffic is encrypted and cannot be inspected without SSL deep inspection
D.Facebook uses a non-standard port that application control does not monitor
AnswerC

Facebook is reached over HTTPS, so the application signature cannot match inside the encrypted TLS payload. Without SSL deep inspection, the firewall sees only encrypted traffic and cannot identify or block the application, satisfying the stem's stated absence of deep inspection.

Why this answer

Without SSL deep inspection, the FortiGate cannot decrypt HTTPS traffic to inspect the application-layer payload. Application control relies on inspecting unencrypted traffic or using SSL inspection to identify applications within encrypted sessions. Since Facebook uses HTTPS, the encrypted traffic passes through without being matched against the application signature, so the block action is not enforced.

Exam trap

The trap here is that candidates assume application control can block any application regardless of encryption, overlooking the fundamental requirement for SSL deep inspection to inspect HTTPS traffic at the application layer.

How to eliminate wrong answers

Option A is wrong because the question states the administrator configured application signatures for Facebook and Twitter, and there is no indication the signatures are outdated; even if they were, the core issue is encryption, not signature version. Option B is wrong because the question says the firewall policy has application control enabled, and there is no mention of monitor-only mode; if it were monitor-only, the traffic would be logged but not blocked, yet the user can still access Facebook, which aligns with the lack of inspection, not a monitor-only setting. Option D is wrong because Facebook uses standard HTTPS ports (443) and application control monitors all ports by default; the issue is encryption, not port selection.

131
MCQhard

An administrator runs the command shown in the exhibit and sees anomalies detected from 10.1.1.100 to 10.2.2.200. The IPS sensor's anomaly settings are configured with the default actions. What will be the default action for the ICMP Flood anomaly?

A.Monitor
B.Block
C.Pass
D.Quarantine
AnswerB

Block is the correct default action for the ICMP flood anomaly in FortiGate. When the configured threshold is exceeded, the FortiGate drops packets from the offending source, protecting both the firewall itself and the downstream network. This reactive mitigation is the default because it immediately stops the flood while still allowing subsequent legitimate traffic once the rate falls below the threshold. Block is the security-first choice for flood anomalies.

Why this answer

By default, FortiGate IPS sensors set the action for ICMP Flood anomalies to 'Block'. This default action is defined in the IPS sensor configuration and is applied when the anomaly threshold is exceeded, as indicated by the detected anomalies from 10.1.1.100 to 10.2.2.200.

Exam trap

The trap here is that candidates often confuse the default action for anomaly-based IPS signatures with the default action for signature-based IPS rules, where 'Monitor' is the default, leading them to incorrectly select 'Monitor' for flood anomalies.

How to eliminate wrong answers

Option A is wrong because 'Monitor' is not the default action for ICMP Flood anomalies; it is a user-configurable action that logs the event without blocking traffic. Option C is wrong because 'Pass' would allow the traffic to bypass inspection, which is not the default behavior for detected anomalies. Option D is wrong because 'Quarantine' is an action typically used for compromised hosts in other security contexts, not the default action for ICMP Flood anomalies in an IPS sensor.

132
MCQeasy

A FortiGate administrator wants to block access to gambling websites using web filtering. Which FortiGuard category should be blocked?

A.Spam
B.Malware
C.Gambling
D.Pornography
AnswerC

FortiGuard has a dedicated 'Gambling' web filtering category that groups online casinos, sports-betting sites, lotteries, and similar services. To block access, the administrator should create or edit a web filter profile, locate the Gambling category, and set the action to "Block" (or "Monitor" for logging). This category is predefined by FortiGuard and periodically updated, so selecting it directly is the correct and precise method for enforcing a gambling-blocking policy.

Why this answer

FortiGuard web filtering uses pre-defined categories to classify websites. To block gambling sites, the administrator must select the 'Gambling' category in the web filter profile. This category specifically includes domains and URLs related to online betting, casinos, and other gambling activities.

Exam trap

The trap here is that candidates may confuse the 'Gambling' category with other content categories like 'Pornography' or 'Spam', but FortiGuard assigns distinct category IDs for each, and only the correct category will block the intended site type.

How to eliminate wrong answers

Option A is wrong because the 'Spam' category is used to filter unsolicited bulk email or spam-related content, not gambling websites. Option B is wrong because the 'Malware' category blocks sites known to host malicious software or exploits, which is unrelated to gambling content. Option D is wrong because the 'Pornography' category targets adult or explicit sexual content, not gambling sites.

133
MCQhard

An administrator integrates FortiGate with FortiSandbox for advanced threat detection. The FortiGate is configured to send files to FortiSandbox for analysis. Despite correct configuration, files are not being submitted. The administrator runs 'diagnose debug application fortisandbox -1' and sees 'no server configured'. What is the issue?

A.The FortiSandbox license has expired
B.Firewall policies are blocking communication to the FortiSandbox server
C.The FortiSandbox server IP address is not configured on the FortiGate
D.The antivirus profile is not configured to submit files to FortiSandbox
AnswerC

The debug output "no server configured" directly indicates the FortiGate lacks the FortiSandbox appliance's IP address, so file submission cannot initiate. Without that address, the FortiGate has no destination to send files to, regardless of other settings. Configuring the FortiSandbox server IP under the relevant security fabric or sandbox settings resolves the failure.

Why this answer

The debug output 'no server configured' explicitly indicates that the FortiGate does not have a FortiSandbox server IP address defined in its configuration. Without the server IP configured under 'config system fortisandbox', the FortiGate cannot establish a connection or submit files, regardless of other settings. This is a prerequisite step before any file submission can occur.

Exam trap

The trap here is that candidates often assume the issue is a firewall policy or license problem, but the debug output's exact wording 'no server configured' directly points to a missing server IP configuration, which is a common oversight.

How to eliminate wrong answers

Option A is wrong because an expired FortiSandbox license would generate a license-related error or warning in the debug output, not 'no server configured'. Option B is wrong because firewall policies blocking communication would result in connection timeouts or 'connection refused' errors, not a 'no server configured' message which indicates the server address is missing entirely. Option D is wrong because while the antivirus profile must have 'fortisandbox' enabled for submission, the debug message 'no server configured' points to a missing server IP configuration, not a profile misconfiguration.

134
MCQmedium

A FortiGate administrator wants to ensure that all DNS queries to known malware domains are blocked. The firewall policy allows DNS traffic. Which security profile must be applied?

A.Web filter profile
B.DNS filter profile
C.Antivirus profile
D.Application control profile
AnswerB

A DNS filter profile is the correct control because it specifically inspects DNS queries and applies FortiGuard threat intelligence to block malicious, botnet, or phishing domains at the resolution stage. It can also enforce safe search and sinkhole domains, preventing clients from reaching known bad destinations even if they use custom DNS servers. By operating at the DNS layer, it protects all protocols and applications that rely on name resolution, providing comprehensive, early defense.

Why this answer

To block DNS queries to known malware domains, the FortiGate must apply a DNS filter profile to the firewall policy that allows DNS traffic. The DNS filter profile uses FortiGuard's DNS threat database to block or redirect queries to malicious domains, botnets, and phishing sites. This is the purpose-built profile for DNS-layer protection.

Exam trap

The trap is choosing web filter because it also deals with 'domains' — but web filter inspects HTTP URLs, while DNS filter inspects the DNS query itself, which is the correct layer for blocking malware domain lookups.

How to eliminate wrong answers

Option A is wrong because a web filter profile inspects HTTP/HTTPS URL categories, not raw DNS queries — it cannot block a DNS lookup to a malware domain. Option C is wrong because an antivirus profile scans file content for malware signatures, not DNS query destinations. Option D is wrong because application control identifies and controls applications by protocol/behavior, not by DNS domain reputation.

135
Multi-Selectmedium

A network administrator wants to ensure that all users are blocked from accessing websites categorized as 'Pornography' and 'Hacking' on a FortiGate. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Create a URL filter to block all URLs containing 'pornography' and 'hacking'
B.Enable DNS filter and block the categories there
C.Apply the web filter profile to the firewall policy that governs outbound internet traffic
D.Enable SSL deep inspection to ensure the categories can be identified
E.Create a web filter profile and set the categories 'Pornography' and 'Hacking' to 'block'
AnswersC, E

Applying the web filter profile to the firewall policy that governs outbound internet traffic ensures that HTTP/HTTPS requests from internal users are inspected against the configured URL categories before the traffic is allowed to pass. This satisfies the stem’s constraint that all users must be blocked from accessing 'Pornography' and 'Hacking' sites, as the profile is enforced at the point where traffic exits the internal network to the internet.

Why this answer

A web filter profile must be applied to a firewall policy to enforce web filtering on outbound internet traffic. Without this association, the profile's settings (including category blocks) are not activated. The firewall policy is the enforcement point where security profiles are linked to traffic flows.

Exam trap

The trap here is that candidates often confuse URL filtering (pattern-based) with web filter category blocking (category-based), or assume SSL deep inspection is mandatory for category-based blocking when it is not required for domain-level categorization.

136
MCQmedium

A FortiGate administrator needs to ensure that all outbound DNS queries from internal clients are inspected for malicious domains. The administrator has a DNS filter profile configured. What additional configuration is required on the firewall policy to make the DNS filter effective?

A.Enable SSL deep inspection on the policy
B.Configure FortiGuard DNS filtering service on the FortiGate
C.Set the inspection mode to proxy-based
D.Apply the DNS filter profile to a firewall policy that matches DNS traffic (UDP/TCP port 53)
AnswerD

A DNS filter profile only inspects traffic when attached to a firewall policy whose destination matches DNS. Applying it to a policy matching UDP and TCP port 53 forces internal client queries through the profile, enabling malicious domain blocking.

Why this answer

A DNS filter profile must be explicitly applied to a firewall policy that matches DNS traffic (UDP/TCP port 53) to be effective. Without this association, the FortiGate will not inspect DNS queries against the configured DNS filter profile, even if the profile is defined globally or under Security Profiles.

Exam trap

The trap here is that candidates often assume configuring a DNS filter profile globally or under Security Profiles is sufficient, but FortiGate requires explicit policy attachment for the profile to take effect on traffic.

How to eliminate wrong answers

Option A is wrong because SSL deep inspection is not required for DNS filtering; DNS traffic is typically unencrypted, and enabling SSL inspection would add unnecessary overhead without improving DNS inspection. Option B is wrong because configuring the FortiGuard DNS filtering service is part of the DNS filter profile setup, not an additional configuration on the firewall policy; the policy itself needs the profile applied. Option C is wrong because while proxy-based inspection can support DNS filtering, flow-based inspection also supports DNS filtering in FortiOS 6.0 and later; the inspection mode is not a prerequisite for applying a DNS filter profile to a policy.

137
MCQeasy

Which IPS detection method analyzes traffic patterns over time to identify attacks that are characterized by a threshold of events?

A.Protocol decoder-based detection
B.Rate-based detection
C.Signature-based detection
D.Anomaly-based detection
AnswerB

Rate-based detection continuously samples traffic and compares event frequency against a configured threshold within a time window, flagging anomalies when the count is exceeded. This directly satisfies the stem's requirement for analysing patterns over time to catch threshold-characterised attacks, unlike signature or anomaly methods.

Why this answer

Rate-based detection (also known as threshold-based detection) monitors traffic patterns over a defined time window and triggers an alert when the number of events (e.g., connection attempts, SYN packets) exceeds a predefined threshold. This method is specifically designed to identify attacks that are characterized by a threshold of events, such as DoS/DDoS floods or brute-force login attempts, rather than relying on static signatures or protocol anomalies.

Exam trap

Fortinet often tests the distinction between rate-based and anomaly-based detection, and the trap here is that candidates confuse 'threshold of events' with 'anomaly detection,' but anomaly detection uses baselines and statistical deviations, not fixed thresholds, while rate-based detection explicitly uses a predefined event count over time.

How to eliminate wrong answers

Option A is wrong because protocol decoder-based detection analyzes traffic by validating protocol fields and state transitions (e.g., checking if an HTTP request conforms to RFC 7230), not by counting events over time. Option C is wrong because signature-based detection matches traffic against predefined patterns (e.g., a specific byte sequence in a packet payload) and does not use temporal thresholds or event counts. Option D is wrong because anomaly-based detection establishes a baseline of normal behavior and flags deviations (e.g., sudden spike in DNS queries), but it does not rely on a fixed threshold of events; instead, it uses statistical models or machine learning to detect outliers.

138
MCQmedium

An administrator wants to prevent employees from uploading sensitive credit card numbers via web forms. Which security profile feature is MOST appropriate to achieve this?

A.Antivirus with FortiSandbox integration
B.Data Leak Prevention (DLP) with a credit card number sensor
C.Web Filter to block all upload sites
D.Application Control to block web forms
AnswerB

Data Leak Prevention (DLP) with a credit card number sensor is correct because DLP examines the actual content of traffic and matches it against predefined sensors, such as the credit card number sensor, which uses pattern matching and Luhn algorithm validation to identify PCI-DSS regulated data. When the sensor triggers, the DLP policy can block the upload session in real time, preventing the sensitive information from leaving the network.

Why this answer

Data Leak Prevention (DLP) with a credit card number sensor is the most appropriate feature because it uses pattern matching (e.g., Luhn algorithm) to detect and block sensitive credit card numbers in HTTP POST requests, preventing data exfiltration via web forms. Unlike other security profiles, DLP is specifically designed to inspect content for sensitive data patterns and enforce policy actions such as blocking or logging.

Exam trap

The trap here is that candidates often confuse DLP with other security profiles like web filtering or application control, mistakenly thinking that blocking upload sites or web forms is a more direct solution, when DLP is the only feature designed for content-based data inspection and policy enforcement.

How to eliminate wrong answers

Option A is wrong because Antivirus with FortiSandbox integration focuses on detecting malware and analyzing suspicious files, not on identifying sensitive data patterns like credit card numbers in web form submissions. Option C is wrong because Web Filter to block all upload sites would prevent all file uploads, which is overly restrictive and does not address the specific need to detect and block credit card numbers within web forms. Option D is wrong because Application Control to block web forms would prevent all web form submissions entirely, disrupting legitimate business processes, rather than selectively scanning for sensitive data.

139
MCQeasy

An administrator needs to ensure that IPS signatures are updated automatically on the FortiGate. Which configuration should be verified?

A.The IPS engine is upgraded to the latest version.
B.The intrusion prevention profile is applied to the firewall policy.
C.The application control profile is set to 'monitor' for all applications.
D.The FortiGuard service is enabled and the signature update schedule is configured.
AnswerD

To automatically maintain up-to-date IPS signatures, the FortiGate must have the FortiGuard service enabled, which requires a valid subscription contract and network access to the FortiGuard distribution servers. Additionally, an administrator must configure a signature update schedule (e.g., daily or every 2 hours) so the device periodically downloads and installs the latest IPS signature package from FortiGuard. This combination directly ensures the signature database is refreshed without manual intervention, fulfilling the administrator's requirement.

Why this answer

Automatic IPS signature updates require the FortiGuard service to be enabled and a signature update schedule to be configured. Without a schedule, updates occur only manually; without the service enabled, the FortiGate cannot connect to FortiGuard distribution servers to retrieve new signatures.

Exam trap

The trap here is confusing IPS signature updates with IPS engine updates or profile application, leading candidates to select options that affect detection or inspection rather than the update mechanism itself.

How to eliminate wrong answers

Option A is wrong because upgrading the IPS engine version improves detection capabilities but does not enable automatic signature updates; signature updates and engine updates are separate processes. Option B is wrong because applying an intrusion prevention profile to a firewall policy enables IPS inspection on traffic but does not control how signatures are updated. Option C is wrong because setting the application control profile to 'monitor' for all applications configures application visibility, not IPS signature updates.

140
Multi-Selecthard

An administrator is configuring an IPS profile on FortiGate to detect and block SQL injection attacks. The profile must be applied to inbound traffic to a web server. Which TWO settings should the administrator enable to achieve this goal? (Choose two.)

Select 2 answers
A.Add the 'SQL.Injection' signature to the IPS sensor and set action to 'block'.
B.Create a DoS policy to limit the number of connections per second.
C.Enable the HTTP protocol decoder in the application control profile.
D.Configure the IPS sensor to bypass traffic from trusted IP addresses.
E.Enable the IPS sensor in the firewall policy.
AnswersA, E

The 'SQL.Injection' signature is the specific pattern-matching rule that flags SQL injection attempts in HTTP payloads. Adding it to the IPS sensor and configuring the action as 'block' ensures FortiGate drops any matching traffic. Without this explicit inclusion, the signature must be part of a filter or default set; otherwise, the attack is not detected. This is the core action for IPS-based threat prevention.

Why this answer

SQL injection attacks are identified by specific IPS signatures, and adding 'SQL.Injection' to an IPS sensor with the action set to 'block' directly instructs FortiGate to detect and block those attacks. Option E is correct because an IPS sensor must be enabled within a firewall policy to apply its inspection to the traffic passing through that policy, ensuring the profile is active on inbound traffic to the web server.

Exam trap

The trap here is that candidates often confuse DoS policies (rate limiting) with IPS (signature-based detection), or mistakenly think application control profiles handle IPS signatures, when in fact IPS sensors are separate and must be explicitly enabled in a firewall policy.

141
MCQmedium

A network administrator notices that users can access websites categorized as 'Pornography' despite a web filter profile blocking that category. The firewall policy uses the web filter profile and is applied to the users' traffic. What is the MOST likely cause?

A.The FortiGate cannot reach the FortiGuard servers
B.The web filter profile is applied to the wrong policy
C.The users are bypassing the FortiGate using a proxy
D.The web filter profile has the 'Override' feature enabled
AnswerA

When the FortiGate cannot reach the FortiGuard servers, web filtering cannot obtain real-time URL category ratings. In FortiOS, unrated or unknown URLs are treated as 'unrated' by default, and the default action for unrated URLs is 'allow' (fail-open). This means every visited website becomes accessible regardless of the web filter profile's block rules, because the firewall has no data to classify the site. The administrator should verify FortiGuard connectivity via `diagnose webfilter fortiguard-status` and confirm that outbound HTTPS (TCP/443) to FortiGuard servers is not being blocked by an upstream firewall or NAT policy.

Why this answer

The most likely cause is that the FortiGate cannot reach the FortiGuard servers. Web filter profiles rely on FortiGuard's cloud-based URL categorization to block categories like 'Pornography'. If the FortiGate loses connectivity to the FortiGuard servers (e.g., due to firewall rules, DNS issues, or proxy settings), it cannot retrieve the category rating for requested URLs, and the default action (often 'allow' if not explicitly set to block) will permit the traffic.

Exam trap

The trap here is that candidates often assume the web filter profile is misapplied or that users are bypassing the firewall, but the real issue is typically a connectivity failure to FortiGuard servers, which causes the filter to default to allowing unrated or uncategorized sites.

How to eliminate wrong answers

Option B is wrong because if the web filter profile were applied to the wrong policy, users would not be subject to that profile at all, but the question states the policy is applied to the users' traffic, so the profile is in the correct policy. Option C is wrong because while users could bypass the FortiGate using a proxy, this would mean their traffic does not traverse the FortiGate, so the web filter profile would not be applied; however, the question implies the traffic is going through the FortiGate (the policy is applied), making this less likely than a FortiGuard connectivity issue. Option D is wrong because the 'Override' feature allows users to bypass blocked categories after authentication, but it does not cause the block to be ignored entirely; it requires explicit user action and is not enabled by default.

142
MCQhard

A large enterprise uses a FortiGate 600E in NAT mode to protect its internal network. The security team has implemented an Application Control profile that categorizes applications and allows only 'Business' and 'General-Interest' categories. They have also applied an IPS sensor with default settings and enabled SSL inspection for outbound traffic. Recently, the helpdesk has received reports that some users cannot access a critical cloud-based CRM application, while others can. The CRM uses HTTPS on port 443. The Application Control profile is applied to the firewall policy for outbound traffic. The IPS sensor is also applied. The FortiGate is not configured for load balancing. Which of the following is the most likely cause of the issue?

A.The IPS sensor is detecting and blocking the CRM traffic as an attack.
B.The CRM application is not categorized in the Application Control database.
C.The FortiGate is performing load balancing and some users are directed to a different path.
D.SSL inspection is blocking the CRM traffic due to certificate validation failure.
AnswerB

Application Control in FortiGate matches traffic against a constantly updated signature database, and each signature is associated with a category. If the CRM application uses a proprietary protocol or a less-common of a known service, it may remain 'Uncategorized,' and any security policy whose Application Control profile sets the uncategorized action to 'deny' will block that traffic. This blocking is policy-specific, so if some users have a policy that omits or allows uncategorized traffic while others have a policy that denies it, only the latter group will experience the outage. This aligns perfectly with the reported symptom of only some users being unable to reach the CRM.

Why this answer

The Application Control profile is configured to allow only 'Business' and 'General-Interest' categories. If the CRM application is not categorized in FortiGuard's Application Control database, or if it falls under a different category (e.g., 'Uncategorized' or 'Unknown'), the FortiGate will block the traffic by default. This explains why some users can access the CRM (if they are using a different path or the application is categorized differently) while others cannot, as the FortiGate enforces the profile based on the application signature match.

Exam trap

The trap here is that candidates often assume IPS or SSL inspection is the culprit for selective access issues, but the key clue is that the problem affects only some users, pointing to a categorization mismatch in Application Control rather than a global block.

How to eliminate wrong answers

Option A is wrong because the IPS sensor with default settings is unlikely to block legitimate CRM HTTPS traffic on port 443 unless it matches a known attack signature, and the issue is user-specific, not global. Option C is wrong because the FortiGate 600E is explicitly stated as not configured for load balancing, so this cannot be the cause. Option D is wrong because SSL inspection certificate validation failure would affect all users equally, not just some, and the issue is isolated to a specific application, not all HTTPS traffic.

143
Multi-Selecthard

Which TWO of the following are best practices when configuring IPS on a FortiGate in a high-throughput environment?

Select 2 answers
A.Set all signatures to block action to maximize security.
B.Set the IPS severity filter to high and above only.
C.Disable all custom signatures to simplify management.
D.Enable only relevant signatures based on the network environment.
E.Use flow-based inspection for better performance.
AnswersD, E

Enabling only signatures that matter to your deployed OS, applications, and services is the central best practice because it dramatically reduces false positive noise and the performance overhead of matching irrelevant rules. FortiGate allows you to create IPS policies that reference specific rule sets, and you can also use the 'Network Inspection' view to quickly see which signatures match your actual traffic. This approach keeps detection fidelity high and aligns with the recommendation to never run a blanket signature set.

Why this answer

Enabling only relevant signatures based on the network environment reduces false positives and unnecessary processing overhead, ensuring that IPS resources are focused on threats that actually apply to the traffic traversing the FortiGate. Option E is correct because flow-based inspection uses a single-pass, pattern-matching engine that offers higher throughput and lower latency compared to proxy-based inspection, making it ideal for high-throughput environments.

Exam trap

The trap here is that candidates often assume 'maximum security' means enabling all signatures or using the strictest action, but the NSE4 exam emphasizes that effective IPS in high-throughput environments requires balancing security with performance by selectively enabling relevant signatures and using flow-based inspection.

144
MCQmedium

A network administrator configures an application control profile to block social media applications. Users can still access Facebook through a web browser. What is the MOST likely reason?

A.The application signatures are outdated
B.Application control is not enabled for HTTPS traffic without deep inspection
C.The firewall policy is in proxy-based mode
D.The application control profile is not applied to the correct policy
AnswerB

This is the root cause. Facebook uses HTTPS by default, and application control identifies applications by inspecting the content and patterns within the traffic flow. Without SSL/TLS deep inspection (also called SSL inspection or decryption), the FortiGate only sees the encrypted payload and cannot match the application signature against the actual application data. While it might see the SNI (Server Name Indication) field or the destination IP, that information can be misleading or blocked by TLS 1.3 encrypted SNI, so the firewall cannot confidently identify Facebook as the application. Therefore, enabling deep inspection in the firewall policy is mandatory for application control to work on HTTPS traffic.

Why this answer

Application control relies on deep inspection (SSL/TLS decryption) to identify applications within encrypted HTTPS traffic. Without deep inspection enabled, the FortiGate can only see the encrypted tunnel and cannot inspect the payload to determine that the traffic is Facebook, even if the application control profile is correctly applied. Option B is correct because HTTPS traffic must be decrypted via deep inspection for application control to function.

Exam trap

The trap here is that candidates assume application control works on all traffic by default, overlooking that HTTPS encryption hides application signatures and requires explicit deep inspection configuration.

How to eliminate wrong answers

Option A is wrong because outdated signatures would cause a broader failure to block social media, not a selective failure where Facebook works via HTTPS but might be blocked over HTTP; the issue is specifically with encrypted traffic. Option C is wrong because proxy-based mode is not required for application control; flow-based mode also supports application control and deep inspection, and the mode does not determine whether HTTPS traffic is decrypted. Option D is wrong because if the profile were not applied to the correct policy, no social media would be blocked at all, including HTTP access; the fact that users can access Facebook via browser suggests the profile is applied but cannot inspect encrypted traffic.

145
MCQeasy

An administrator wants to block the use of social media applications like Facebook and Twitter on the company network. Which security profile should be used?

A.DNS Filter profile
B.Web Filter profile
C.Application Control profile
D.IPS profile
AnswerC

Application Control is the correct mechanism because it inspects packet byte patterns, protocol behavior, and other traffic attributes against the FortiGuard application database to identify applications regardless of the URL, port, or destination domain. It enables a firewall policy to log, allow, or block specific apps such as Facebook or Twitter even when they are accessed through a web browser, a mobile client, or different domains. This provides the granular visibility needed to block social media application usage rather than merely filtering web pages.

Why this answer

The Application Control profile is designed to identify and block specific applications, including social media platforms like Facebook and Twitter, regardless of the port or protocol they use. Unlike web filtering, which relies on URL categorization, application control inspects traffic patterns and signatures to enforce granular policies on application usage.

Exam trap

The trap here is that candidates often confuse web filtering (URL-based) with application control (signature-based), assuming that blocking a URL category like 'Social Networking' will stop all social media traffic, but native apps and encrypted streams bypass URL filtering entirely.

How to eliminate wrong answers

Option A is wrong because a DNS Filter profile blocks or redirects traffic based on domain name queries, but social media apps may use hardcoded IP addresses or non-DNS methods, making DNS filtering insufficient. Option B is wrong because a Web Filter profile controls access based on URL categories (e.g., 'Social Networking'), but it cannot block traffic from native mobile apps or encrypted connections that bypass HTTP inspection. Option D is wrong because an IPS profile focuses on detecting and preventing network-based attacks and vulnerabilities, not on enforcing acceptable use policies for specific applications.

146
Multi-Selectmedium

A FortiGate administrator is configuring intrusion prevention (IPS) for a web server. The administrator wants to both block known exploits and detect anomalous traffic patterns. Which TWO features should be enabled? (Choose two.)

Select 2 answers
A.IPS signatures
B.Web filter
C.Antivirus
D.Anomaly detection
E.Application control
AnswersA, D

IPS signatures are the core of intrusion prevention: the FortiGate inspector compares each packet's payload and header fields against a database of known exploit patterns and CVE-based indicators. This allows the device to match, log, and drop malicious traffic in real time, flagging only packets that precisely match a recognized attack signature. It is the only option here that actively inspects for exploit content, so it directly addresses the administrator's goal of blocking intrusion attempts.

Why this answer

IPS signatures (A) are correct because they contain predefined patterns of known exploits, allowing the FortiGate to match and block malicious traffic against a web server. Anomaly detection (D) is correct because it establishes a baseline of normal traffic and alerts on deviations, enabling detection of zero-day or unusual patterns that signatures may miss.

Exam trap

The trap here is that candidates confuse 'anomaly detection' with 'application control' or 'web filter', thinking those features also detect unusual traffic patterns, but anomaly detection is a distinct IPS sub-feature for behavioral analysis.

147
MCQeasy

Which FortiGate feature allows the administrator to scan SMTP, IMAP, and POP3 traffic for spam and apply actions such as tagging or discarding?

A.Email filter profile
B.Application control profile
C.Antivirus profile
D.Web filter profile
AnswerA

The Email filter profile is the correct FortiGate feature for SMTP scanning. It performs protocol-aware inspection of SMTP, IMAP, and POP3 traffic, applying spam rules, IP reputation, header/content analysis, and optional greylisting to classify and block unsolicited messages. This is the only profile specifically designed to detect spam and phishing content inside email traffic, including SMTP relay conversations.

Why this answer

The Email Filter profile is the correct feature because it is specifically designed to scan SMTP, IMAP, and POP3 traffic for spam and phishing content. It allows administrators to apply actions such as tagging the subject line, discarding the email, or quarantining based on spam scores, blacklists, and heuristics.

Exam trap

The trap here is that candidates confuse the Email Filter profile with the Antivirus profile, thinking spam is a type of virus, but spam detection uses different heuristics and databases (e.g., FortiGuard Antispam) than antivirus signatures.

How to eliminate wrong answers

Option B (Application control profile) is wrong because it identifies and controls application traffic (e.g., Facebook, Skype) using signatures, not email content scanning for spam. Option C (Antivirus profile) is wrong because it scans for malware signatures in files and attachments, not for spam classification or tagging. Option D (Web filter profile) is wrong because it controls access to web URLs and categories, not email protocols like SMTP, IMAP, or POP3.

148
MCQhard

An administrator configures a web filter profile to block the URL category 'Pornography'. The profile is applied to a policy for the sales department. Users report they can still access some sites that should be blocked. The administrator verifies that the FortiGuard web filter service is licensed and the FortiGate has internet connectivity. What should the administrator check next?

A.Verify that the antivirus profile is not interfering with web filtering.
B.Ensure the web filter profile has 'FortiGuard category based filter' enabled and the action for 'Pornography' is set to 'Block'.
C.Check if the sales department policy is using NAT that might bypass the FortiGate.
D.Confirm that the FortiGate has a static route to the FortiGuard servers.
AnswerB

In FortiOS, a web filter profile must have the FortiGuard Category Based Filter toggle enabled, and the specific category (e.g., 'Pornography') must have its action explicitly set to 'Block'. Even if the category is listed, if the action is 'Monitor' or 'Allow', or if a URL exemption or override rule matches the request, the traffic will not be blocked. The policy must also reference this profile and be applied to the correct source/destination, but the most direct cause of a failure to block is an incorrect category action or profile configuration.

Why this answer

In FortiOS, a web filter profile only enforces FortiGuard category blocking if the 'FortiGuard category based filter' toggle is enabled within the profile and the specific category (e.g., Pornography) has its action set to 'Block'. If the toggle is off, or the category action is left at 'Allow' or 'Monitor', the profile will not block those sites even though the FortiGuard license is valid and connectivity is fine. This is the most common misconfiguration when categories appear to be ignored.

Exam trap

NSE4 often tests the assumption that a valid FortiGuard license alone enables category blocking — candidates overlook that the 'FortiGuard category based filter' toggle must be explicitly enabled and each category's action set to Block.

How to eliminate wrong answers

Option A is wrong because antivirus profiles operate on file inspection and do not override or bypass web filter category decisions — they are independent security profiles applied in the same policy. Option C is wrong because NAT is performed by the FortiGate itself; it cannot 'bypass' the FortiGate's own policy enforcement, and the policy is already matching the sales department traffic. Option D is wrong because the administrator already verified the FortiGate has internet connectivity and the FortiGuard service is licensed, which implies FortiGuard server reachability is functional.

149
Multi-Selectmedium

A FortiGate administrator needs to prevent data leakage by blocking the upload of files containing credit card numbers via web traffic. Which THREE components must be configured? (Choose three.)

Select 3 answers
A.Application control profile to block file upload applications
B.DLP profile with a rule to detect credit card numbers
C.Firewall policy that applies the DLP profile and SSL inspection to the traffic
D.Antivirus profile to scan the files for malware
E.SSL deep inspection to decrypt HTTPS traffic
AnswersB, C, E

A DLP profile is the FortiGate component responsible for content inspection to prevent data leakage. It includes predefined signatures for sensitive patterns such as credit card numbers, social security numbers, and other PII, as well as support for custom regular expressions. When a rule detects a match in the traffic, the configured action (block, log, or allow with notification) is enforced. This forms the core detection mechanism needed to stop credit card data from being uploaded.

Why this answer

A DLP (Data Loss Prevention) profile is specifically designed to inspect content for sensitive data patterns, such as credit card numbers, using predefined or custom data patterns. When configured with a rule to detect credit card numbers, the DLP profile can block or log the upload of files containing such data over web traffic.

Exam trap

The trap here is that candidates may think application control (option A) or antivirus (option D) can detect sensitive data, but they are designed for different purposes—application control manages app usage, and antivirus detects malware, not data patterns.

150
MCQhard

An administrator configures SSL deep inspection with a CA certificate. Users accessing an internal site (internal.company.com) receive a certificate error. The administrator wants to avoid the error without disabling deep inspection. What should be done?

A.Replace the CA certificate with a self-signed one
B.Use certificate inspection instead of deep inspection
C.Disable certificate validation in the deep inspection profile
D.Add internal.company.com to the SSL/SSH inspection exemption list
AnswerD

Adding internal.company.com to the SSL/SSH inspection exemption list instructs the FortiGate to pass those sessions without decrypting or re-signing the certificate, so the client receives the original certificate issued by the company's internal PKI. This eliminates the certificate error because the client sees a chain it already trusts, while allowing deep inspection to continue for other traffic. It is the recommended approach for internal domains that have their own CA or for applications with certificate pinning that cannot tolerate interception.

Why this answer

Adding internal.company.com to the SSL/SSH inspection exemption list tells the FortiGate to bypass deep inspection for that specific site, allowing the internal CA certificate to be used without triggering a certificate error. This avoids the error while keeping deep inspection enabled for all other traffic, which is the administrator's goal.

Exam trap

The trap here is that candidates may think disabling certificate validation (Option C) is a quick fix, but that compromises security and is not the intended method to handle trusted internal sites; the correct approach is to use the exemption list to selectively bypass inspection.

How to eliminate wrong answers

Option A is wrong because replacing the CA certificate with a self-signed one would still cause certificate errors for clients that do not trust the self-signed CA, and it does not address the root cause of the mismatch between the internal site's certificate and the CA used for deep inspection. Option B is wrong because certificate inspection only examines the certificate metadata without decrypting traffic, which would not resolve the certificate error and would lose the security benefits of deep inspection. Option C is wrong because disabling certificate validation in the deep inspection profile would bypass all certificate checks, making the system vulnerable to man-in-the-middle attacks and defeating the purpose of deep inspection.

← PreviousPage 2 of 3 · 182 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Profiles questions.