Courseiva

CCNA Security Profiles Questions

32 of 182 questions · Page 3/3 · Security Profiles · Answers revealed

151
MCQmedium

An administrator has configured the policy shown in the exhibit. Traffic to the web server at 10.0.1.10 over HTTPS is allowed, but users complain that they cannot access the web server's login page. The IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts. The application list 'Block_Social_Media' blocks Facebook and Twitter. What is the most likely cause of the issue?

A.The IPS sensor is blocking the login page due to a false positive.
B.The firewall policy action is set to 'deny' but the exhibit shows 'accept'.
C.The HTTPS service is not correctly defined and blocking the traffic.
D.The application control profile is blocking the web application.
AnswerD

The application control profile is the only profile configured in the policy that can identify and block specific web applications by their signatures, even when the underlying HTTP/HTTPS service is valid. When a user attempts to access the login page, the FortiGate can classify the traffic as a known application and apply the profile's 'block' action, denying the request. This is a common cause of access failure when the base policy action is accept and HTTPS is correctly defined.

Why this answer

The policy explicitly allows HTTPS traffic to 10.0.1.10, but the application control profile 'Block_Social_Media' is applied. This profile blocks Facebook and Twitter, which are web-based applications. If the web server's login page is served over HTTPS and is incorrectly classified by the FortiGate as a social media application (e.g., due to shared CDN or similar traffic patterns), the application control profile will block it, preventing user access despite the firewall policy allowing the service.

Exam trap

The trap here is that candidates assume the IPS sensor is the cause of the block, but the question specifies the IPS sensor only blocks SQL injection attempts, not login pages, while the application control profile explicitly blocks social media applications that could be misclassifying the web server's traffic.

How to eliminate wrong answers

Option A is wrong because the IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts, not login pages; a false positive for SQL injection would block specific HTTP requests containing malicious patterns, not the entire login page. Option B is wrong because the exhibit shows the policy action as 'accept', and the question states traffic is allowed; a 'deny' action would block all traffic, not just the login page. Option C is wrong because HTTPS is a well-defined service (TCP/443) and the policy explicitly allows it; if the service were misdefined, all HTTPS traffic would be blocked, not just the login page.

152
MCQmedium

A FortiGate administrator receives reports that some users are receiving spam emails despite an email filter profile being applied to the SMTP traffic. The email filter profile has 'spam' action set to 'discard'. What is the most likely reason spam is still reaching users?

A.The internal email server receives email directly from the internet without passing through the FortiGate
B.The spam dictionary is not updated with latest spam signatures
C.The email filter profile is not configured to scan outbound emails
D.The email filter profile is applied to the wrong policy direction (inbound vs outbound)
AnswerA

If the internal mail server's MX record points to a public IP that is reachable directly from the internet (i.e., not behind the FortiGate), SMTP packets will never traverse the firewall. Since the FortiGate can only inspect traffic that physically passes through its interfaces, the email filter profile—regardless of how it is configured—will never see these messages. This is the definitive root cause: the FortiGate is completely out of the data path for inbound SMTP, so no email filtering can occur.

Why this answer

If the internal email server receives email directly from the internet without passing through the FortiGate, the email filter profile applied to SMTP traffic on the FortiGate will never inspect those messages. The FortiGate can only filter traffic that actually traverses it; any email routed around the FortiGate bypasses all security profiles entirely.

Exam trap

The trap here is that candidates often assume the email filter profile is correctly applied and focus on configuration details (like dictionary updates or policy direction), rather than verifying whether the traffic actually passes through the FortiGate at the network level.

How to eliminate wrong answers

Option B is wrong because the spam action is set to 'discard', which relies on the FortiGate's real-time spam detection (e.g., FortiGuard AntiSpam, heuristics, or RBL checks), not a static dictionary; an outdated dictionary would reduce detection accuracy but would not cause all spam to pass through. Option C is wrong because the issue is about spam reaching users from external sources, not outbound emails; outbound scanning is irrelevant to incoming spam delivery. Option D is wrong because the email filter profile is applied to SMTP traffic, and the direction (inbound vs outbound) is already implied by the traffic flow; if the profile were applied to the wrong direction, it would not inspect the traffic at all, but the question states the profile is applied to SMTP traffic, so the more fundamental issue is that the traffic never reaches the FortiGate.

153
MCQeasy

Which of the following security profiles is used to prevent malicious files from being downloaded via HTTP, FTP, or email by inspecting the content of the traffic?

A.Antivirus
B.Application Control
C.Web Filter
D.Intrusion Prevention System (IPS)
AnswerA

The Antivirus security profile is the correct answer because it is specifically designed to detect and block malware such as viruses, worms, and trojans by scanning file content and network traffic against a signature database. It operates at the file level, inspecting uploaded/downloaded files, email attachments, and other data streams, and can also use heuristics and sandboxing to catch unknown threats. This is the direct mechanism for preventing infections, which is the goal of the question.

Why this answer

Antivirus (option A) is the correct security profile because it performs deep content inspection of files transferred via HTTP, FTP, or email protocols. It uses signature-based detection and heuristics to identify and block malicious files (e.g., executables, scripts, or archives) before they reach the user, directly preventing malware downloads.

Exam trap

The trap here is confusing 'content inspection for malicious files' with broader security functions like IPS (which inspects network-level exploits) or Web Filter (which inspects URLs), leading candidates to overlook that Antivirus is the only profile specifically designed for file-level malware detection.

How to eliminate wrong answers

Option B (Application Control) is wrong because it identifies and controls application traffic (e.g., Facebook, YouTube) based on signatures and behavior, not file content inspection for malware. Option C (Web Filter) is wrong because it controls access to websites based on URL categories or reputation, not scanning the actual file payload for malicious content. Option D (Intrusion Prevention System) is wrong because it analyzes network traffic for exploit signatures and anomaly patterns (e.g., SQL injection, buffer overflows), not file-level malware scanning.

154
MCQeasy

What is the purpose of the 'safe search' option in a FortiGate web filter profile?

A.It enforces the use of HTTPS for search engines
B.It allows users to bypass URL filters during safe search
C.It filters explicit content from search engine results
D.It blocks all search engine traffic
AnswerC

The safe search option in FortiGate is designed to force search engines to enable their built-in safe search modes, effectively stripping adult or explicit content from the search results returned to users. It accomplishes this by manipulating DNS or rewriting URLs so that the search engine applies its restrictive content settings for every query. This ensures that even if a user has not configured their own search preferences, the network policy enforces a family-friendly search experience.

Why this answer

The 'safe search' option in a FortiGate web filter profile forces supported search engines (such as Google, Bing, and Yahoo) to filter explicit content from search results. This is achieved by appending specific parameters to the search engine URLs (e.g., &safe=active for Google), ensuring that adult or offensive material is suppressed regardless of the user's individual search settings.

Exam trap

The trap here is that candidates often confuse 'safe search' with 'HTTPS enforcement' or 'URL filtering', assuming it blocks or bypasses traffic rather than understanding it modifies search engine queries to filter explicit content.

How to eliminate wrong answers

Option A is wrong because safe search does not enforce HTTPS; HTTPS enforcement is a separate feature in the web filter or SSL inspection profile. Option B is wrong because safe search does not allow users to bypass URL filters; it operates independently to modify search engine queries, not to grant exceptions. Option D is wrong because safe search does not block all search engine traffic; it only modifies the search results to exclude explicit content while still allowing legitimate searches.

155
MCQmedium

An organization uses Application Control to allow only business-critical applications and block social media. The administrator has configured the profile to block Facebook and Twitter, but users can still access Facebook. The firewall policy applies the profile correctly. What is the most likely cause?

A.The application control profile is applied to the wrong direction.
B.Facebook is not included in the default application signatures.
C.SSL inspection is not enabled on the firewall policy.
D.The FortiGate is in flow-based inspection mode.
AnswerC

Without SSL deep inspection, HTTPS sessions appear as opaque flows to the security engine, allowing FortiGate to see only the initial TLS ClientHello (including SNI) and encrypted data afterward. Application control cannot read the HTTP Host header, cookies, or URI paths needed to confidently match the traffic to the 'Facebook' application, so HTTPS requests like news feed or chat are not blocked. The correct remedy is to enable an SSL/SSH inspection profile (typically 'deep-inspection') on the policy and install the FortiGate CA on client devices, allowing the Security Processing Unit to decrypt, inspect, and re-encrypt the session. This is why the answer identifies missing SSL inspection as the root cause.

Why this answer

Application Control relies on SSL inspection to identify applications like Facebook that use HTTPS. Without SSL inspection enabled on the firewall policy, FortiGate can only see encrypted traffic as generic SSL/TLS flows and cannot match the application signatures for Facebook. Enabling SSL inspection (deep inspection or certificate-based inspection) allows the FortiGate to decrypt the traffic and apply the application control profile correctly.

Exam trap

The trap here is that candidates assume application control works on encrypted traffic by default, but FortiGate requires explicit SSL inspection to decrypt and identify HTTPS applications like Facebook.

How to eliminate wrong answers

Option A is wrong because the application control profile is applied to the firewall policy, which is bidirectional by default; the direction is not the issue since the policy is correctly applied and the traffic is passing through it. Option B is wrong because Facebook is included in the default application signatures provided by FortiGuard; the administrator would not need to add it manually. Option D is wrong because flow-based inspection mode does not prevent application control from working; it actually supports application control and can still identify applications, but without SSL inspection, encrypted traffic remains opaque regardless of inspection mode.

156
MCQeasy

A FortiGate administrator wants to block access to a list of known malicious websites. The list is updated frequently by a third-party threat intelligence feed. Which FortiGate feature should the administrator use to dynamically block these sites without manual intervention?

A.Static URL filter
B.External threat feed connector
C.DNS filter
D.FortiGuard web filter category
AnswerB

External threat feed connectors allow the FortiGate to subscribe to external feeds and automatically update blocklists. These can be used in firewall policies or web filter profiles to block malicious sites. This provides dynamic, automatic updates without manual intervention, satisfying the requirement.

Why this answer

External threat feed connectors enable the FortiGate to ingest blocklists from external sources and use them in policies. They support automatic updates, so the administrator does not need to manually maintain the list. This is the correct feature for dynamically blocking sites from a third-party threat intelligence feed.

Exam trap

The trap here is confusing FortiGuard categories with external threat feeds; FortiGuard is Fortinet-maintained, while external feeds are third-party and require a connector.

157
MCQmedium

An administrator configures an email filter profile to block spam. Users complain that legitimate emails from a specific partner are being blocked. The admin wants to allow emails from that partner's domain without disabling spam filtering for other domains. What is the BEST approach?

A.Add the partner's domain to the IP allowlist in the email filter profile
B.Increase the spam threshold until the emails pass
C.Disable spam filtering for the entire firewall policy
D.Create a separate firewall policy for the partner's traffic without email filtering
AnswerA

Adding the partner's domain to the IP allowlist (or domain allowlist) in the email filter profile explicitly exempts that sender from spam scanning and blocking. This is a targeted action: only the partner's emails bypass the spam and content checks, while all other traffic remains subject to the full email filtering policy. It is the most efficient and secure way to ensure legitimate business emails are delivered without weakening protection for everyone else.

Why this answer

Adding the partner's domain to the IP allowlist in the email filter profile is the best approach because it creates a specific exception for that domain while keeping spam filtering active for all other traffic. The allowlist overrides the spam detection engine for matching senders, ensuring legitimate emails are not blocked without weakening the overall security posture.

Exam trap

The trap here is that candidates often confuse increasing the spam threshold (a global sensitivity adjustment) with creating a targeted exception, or they incorrectly assume that disabling filtering entirely is the simplest fix, when FortiOS allows precise allowlisting within the same profile.

How to eliminate wrong answers

Option B is wrong because increasing the spam threshold would reduce the sensitivity of the filter globally, allowing more spam to pass for all domains, not just the partner's. Option C is wrong because disabling spam filtering for the entire firewall policy removes protection for all traffic, which is an overly broad and insecure solution. Option D is wrong because creating a separate firewall policy without email filtering would require duplicating all other security profiles and could introduce policy order issues, plus it still disables filtering entirely for that traffic rather than creating a targeted exception.

158
MCQeasy

Which security profile is used to detect and prevent network-based attacks by analyzing traffic patterns and comparing them against known attack signatures?

A.DLP profile
B.IPS profile
C.Web filter profile
D.Antivirus profile
AnswerB

The IPS security profile uses a continuously updated FortiGuard IPS signature database, protocol anomaly detection, and packet-level deep inspection to identify and block network attack attempts in real time. It covers known CVE exploits, SQL injection, cross-site scripting, and other malicious network traffic. As the dedicated intrusion prevention mechanism, it is the correct profile for detecting and preventing network attacks.

Why this answer

The Intrusion Prevention System (IPS) profile is specifically designed to detect and prevent network-based attacks by inspecting traffic patterns and comparing them against a database of known attack signatures. Unlike other security profiles that focus on content or application-layer threats, the IPS profile operates at the network and transport layers to identify malicious patterns such as exploit attempts, buffer overflows, and denial-of-service attacks.

Exam trap

The trap here is that candidates often confuse the IPS profile with the Antivirus profile, mistakenly thinking that antivirus handles all signature-based detection, but antivirus only scans files for malware, not network traffic patterns for attack signatures.

How to eliminate wrong answers

Option A is wrong because a DLP (Data Loss Prevention) profile is used to monitor and prevent the unauthorized transmission of sensitive data, not to detect network-based attacks via traffic pattern analysis. Option C is wrong because a Web filter profile controls access to websites based on categories, URLs, or content, and does not analyze traffic patterns for attack signatures. Option D is wrong because an Antivirus profile scans files and content for malware signatures, but it does not analyze general network traffic patterns or detect network-layer attacks like those identified by an IPS.

159
Multi-Selectmedium

An administrator wants to ensure that all DNS traffic from internal users is filtered by the FortiGate to block malicious domains. Which TWO configurations are necessary? (Choose two.)

Select 2 answers
A.Set DNS server to FortiGate's IP
B.Apply the DNS filter profile to a firewall policy that matches DNS traffic
C.Create a DNS filter profile and set action for malicious domains to 'block'
D.Enable sinkhole on the DNS filter profile
E.Configure SSL deep inspection for DNS over HTTPS
AnswersB, C

To enforce DNS filtering, the administrator must create a firewall policy that matches outbound DNS traffic (typically UDP/TCP port 53 from internal clients) and attach the DNS filter profile to that policy. Only when the profile is referenced by a policy does the FortiGate's DNS proxy engine evaluate each query against the FortiGuard category database. Without this policy binding, the profile remains an unused configuration object and all DNS traffic passes unfiltered.

Why this answer

A DNS filter profile must be applied to a firewall policy that matches DNS traffic for the filtering to take effect. Without this policy-level binding, the DNS filter profile is not enforced, even if it is configured. This ensures that all DNS queries from internal users are inspected by the FortiGate.

Exam trap

The trap here is that candidates often think configuring the DNS filter profile alone is enough, forgetting that it must be explicitly applied to a firewall policy to be enforced.

160
MCQmedium

An administrator configures a web filter profile with FortiGuard category blocking and URL filter to allow example.com. Users report that example.com is still blocked. What is the most likely cause?

A.The URL filter requires deep inspection to be enabled
B.The URL filter entry is placed after the FortiGuard category in the policy
C.The DNS filter is blocking example.com before the web filter is evaluated
D.The FortiGuard category action is set to 'block' and takes precedence over the URL filter allow rule
AnswerD

In FortiOS, when a category is set to block, it blocks all URLs in that category regardless of individual URL filter entries unless the URL filter uses an allow action and is configured to override categories.

Why this answer

When both FortiGuard category blocking and a URL filter are configured in the same web filter profile, the FortiGuard category action (e.g., 'block') is evaluated first and takes precedence over any URL filter allow rule. This is because FortiGate processes web filter rules in a specific order: FortiGuard category blocking is applied before URL filter entries. Therefore, even if a URL filter explicitly allows example.com, the FortiGuard category block will prevent access.

Exam trap

The trap here is that candidates assume URL filter entries are evaluated before FortiGuard categories, or that a URL filter allow rule can override a FortiGuard block, when in fact FortiGuard category blocking takes precedence regardless of URL filter order.

How to eliminate wrong answers

Option A is wrong because deep inspection is not required for URL filtering to work; URL filtering can operate with certificate inspection or no inspection, and deep inspection is only needed for HTTPS content scanning. Option B is wrong because the order of URL filter entries within the URL filter list does not affect precedence over FortiGuard categories; the FortiGuard category check occurs before the URL filter is evaluated. Option C is wrong because DNS filtering is a separate security profile that can block domains, but the question states the web filter profile is configured, and DNS filter would not block example.com unless explicitly configured; the most likely cause is the FortiGuard category taking precedence.

161
MCQmedium

A network administrator notices that an IPS sensor is generating excessive false positives for a specific signature. The administrator wants to exclude traffic from a trusted internal server (IP 10.1.1.100) from inspection for that signature only, while keeping other signatures active. Which configuration change should the administrator apply?

A.Set the signature action to 'pass' and use an application control profile to bypass the server.
B.Disable the signature in the IPS sensor configuration.
C.Add the server's IP to the exempt list in the IPS sensor.
D.Create an IPS filter that excludes the server's source IP address from the signature.
AnswerD

An IPS filter allows you to create a conditional override for a specific signature based on attributes such as the source IP address. In Fortinet, you can set the signature's action to 'pass' or 'monitor' only when the source IP matches the trusted server, leaving the default (typically 'block') intact for all other sources. This gives exactly the required selectivity: the false positive is silently allowed, while the signature remains fully active for the rest of the network.

Why this answer

An IPS filter allows the administrator to define a rule that excludes traffic from a specific source IP address (10.1.1.100) from inspection for a particular signature, while leaving all other signatures active. This granular approach ensures that false positives for that signature are reduced without disabling the signature entirely or affecting other traffic.

Exam trap

The trap here is that candidates often confuse the 'exempt list' (which bypasses all IPS inspection for a host) with an 'IPS filter' (which can exclude traffic from a specific signature only), leading them to choose option C incorrectly.

How to eliminate wrong answers

Option A is wrong because setting the signature action to 'pass' would bypass inspection for that signature globally, not just for the trusted server, and using an application control profile does not apply to IPS signatures. Option B is wrong because disabling the signature entirely would stop all inspection for that signature across all traffic, which is too broad and would miss real threats from other sources. Option C is wrong because the exempt list in an IPS sensor typically excludes traffic from all inspection, not just for a specific signature, which would bypass all IPS signatures for that server.

162
Multi-Selecthard

An administrator has configured an IPS profile to detect SQL injection attacks. However, some SQL injection attempts are still reaching the web server. Which TWO actions should the administrator take to improve detection?

Select 2 answers
A.Configure anomaly detection for SQL traffic
B.Update the IPS signature database
C.Disable flow-based inspection and use proxy-based only
D.Enable protocol decoders for HTTP and SQL
E.Enable SSL deep inspection on the policy
AnswersB, D

Updating the FortiGuard IPS signature database is the core step because SQL injection detection depends on signature patterns that recognize specific attack syntax and variations. Signature packages are regularly updated with new and refined rules for recent SQL injection techniques, such as union-based or time-based blind injection. If the database is outdated, the IPS engine lacks those rules, and the policy may silently ignore crafted SQL payloads. Therefore, to detect SQL injection effectively, an administrator must ensure the IPS database is current.

Why this answer

IPS signatures are the primary mechanism for detecting known SQL injection patterns. If attacks are reaching the web server, the signature database is likely outdated or missing recent attack vectors. Updating the signature database ensures the IPS has the latest patterns to match against SQL injection attempts.

Exam trap

The trap here is that candidates may confuse anomaly detection (which is for behavioral baselines) with signature-based detection, or assume that switching inspection modes (flow vs. proxy) fixes detection gaps when the real issue is outdated signatures or missing protocol decoders.

163
MCQhard

A FortiGate is configured with SSL deep inspection using a locally generated CA certificate. A user reports that they cannot access https://www.example.com and receive a certificate error. The administrator checks the firewall policy and sees that the SSL inspection profile is set to 'certificate-inspection' instead of 'deep-inspection'. What is the MOST likely effect?

A.The FortiGate decrypts the traffic but does not re-sign, causing mismatch errors.
B.The FortiGate does not decrypt the traffic, so the original server certificate is presented to the client, which may be valid; the error is unrelated.
C.The FortiGate blocks the connection because certificate-inspection cannot handle deep inspection profiles.
D.The user will see a warning about the certificate but will be able to proceed after accepting it.
AnswerB

Certificate-inspection mode only checks the certificate chain; it does not re-sign. The client sees the original server certificate. If that certificate is valid, there should be no error. The issue likely stems from a different problem.

Why this answer

When the SSL inspection profile is set to 'certificate-inspection', the FortiGate does not decrypt the traffic; it only checks the certificate's validity (e.g., expiry, revocation). Therefore, the original server certificate from www.example.com is passed directly to the client. Since the client receives the actual server certificate (which is likely valid), the reported certificate error is unrelated to the FortiGate's configuration.

Option B correctly identifies that the error is not caused by the FortiGate's inspection profile.

Exam trap

The trap here is that candidates often confuse 'certificate-inspection' with 'deep-inspection', assuming that any SSL inspection profile decrypts traffic, leading them to incorrectly select option A or D.

How to eliminate wrong answers

Option A is wrong because 'certificate-inspection' does not decrypt traffic at all, so there is no re-signing to cause mismatch errors; decryption and re-signing only occur with 'deep-inspection'. Option C is wrong because 'certificate-inspection' does not block connections; it simply passes the original server certificate to the client, and the firewall policy still allows the traffic based on other criteria. Option D is wrong because 'certificate-inspection' does not generate a warning or prompt the user to accept a certificate; it does not modify the certificate chain, so the client sees the original server certificate without any FortiGate intervention.

164
MCQmedium

A FortiGate administrator wants to block all traffic to a known malicious IP address range using the Intrusion Prevention System (IPS). Which IPS configuration method is most appropriate?

A.Use a predefined IPS signature for known malicious IPs
B.Create a custom IPS signature that matches the IP range
C.Configure an IPS anomaly detection rule to block the IP range
D.Use a local IPS signature database
AnswerB

Creating a custom IPS signature allows specifying source or destination IP addresses or ranges using filters like 'source-ip' or 'destination-ip', making it the most direct method to block traffic to a known malicious IP range.

Why this answer

FortiGate's IPS allows administrators to create custom signatures that can match specific IP addresses or ranges using the 'source-ip' or 'destination-ip' filter criteria. This is the most direct and precise method to block traffic to a known malicious IP range, as predefined signatures typically target application-layer vulnerabilities or exploit patterns, not arbitrary IP addresses.

Exam trap

The trap here is that candidates may confuse IPS anomaly detection (which blocks based on traffic patterns) with the ability to block specific IPs, or assume predefined signatures cover all threats including IP-based blocks, when in fact custom signatures are required for IP-specific filtering.

How to eliminate wrong answers

Option A is wrong because predefined IPS signatures are designed to detect known attack patterns (e.g., SQL injection, buffer overflows) and do not include signatures for arbitrary IP addresses or ranges. Option C is wrong because IPS anomaly detection rules are used to detect deviations from normal traffic baselines (e.g., port scans, traffic floods), not to block specific IP ranges. Option D is wrong because a local IPS signature database is simply a repository for storing custom or downloaded signatures; it is not a configuration method to block traffic to an IP range.

165
MCQmedium

An administrator runs the CLI command 'diagnose debug rating' and sees that all FortiGuard web filter requests are timing out. What is the most likely cause?

A.The web filter profile has an incorrect action configured
B.The web filter is set to 'monitor all' which causes all requests to timeout
C.The FortiGuard web filtering license has expired
D.The DNS server configured on the FortiGate is not resolving the FortiGuard FQDN
AnswerD

Before it can send a rating request to FortiGuard, the FortiGate must resolve the FortiGuard server's FQDN (such as 'fortiguard.fortinet.net') via its configured DNS servers. If DNS resolution fails, the FortiGate has no IP address to connect to, so the HTTPS request never leaves the device and the rating operation eventually times out. This matches the timeout symptom in the 'diagnose debug rating' output, because the lookup cannot complete. To confirm, an administrator should check the FortiGate's DNS settings with 'get system dns' and test name resolution for the FortiGuard domain.

Why this answer

The 'diagnose debug rating' command shows real-time FortiGuard web filter request status. When all requests are timing out, it indicates that the FortiGate cannot reach the FortiGuard servers. The most common cause is a DNS resolution failure, where the FortiGate cannot resolve the FortiGuard FQDN (e.g., service.fortiguard.net) due to an incorrect or unreachable DNS server configuration.

Without proper DNS, the FortiGate cannot establish the necessary HTTPS connections to query the FortiGuard rating service.

Exam trap

The trap here is that candidates often assume timeouts are caused by license expiration or profile misconfiguration, but the debug output clearly distinguishes between 'timeout' (connectivity/DNS issue) and 'license expired' (licensing issue), so reading the exact debug message is critical.

How to eliminate wrong answers

Option A is wrong because an incorrect action in the web filter profile (e.g., 'block' vs 'monitor') affects how traffic is handled after a rating is received, not the ability to reach FortiGuard servers. Option B is wrong because 'monitor all' is not a valid setting; the web filter profile has an 'Action' setting with options like 'monitor' or 'block', but this does not cause timeouts. Option C is wrong because an expired FortiGuard web filtering license would result in a 'license expired' or 'unlicensed' error message in the debug output, not a timeout; timeouts indicate a connectivity or DNS issue, not a licensing problem.

166
MCQhard

A FortiGate receives a file via SMTP that contains a virus. The antivirus profile is set to 'Block' for viruses and the action is set to 'Quarantine'. However, the email is delivered to the user with the infected attachment. What could be the reason?

A.The email filter profile is overriding the antivirus action
B.The antivirus profile is using flow-based inspection and the SMTP scan is not enabled
C.The antivirus signatures are outdated
D.The file is larger than the FortiGate's virus database can handle
AnswerB

Flow-based antivirus inspection does not scan every protocol by default; the antivirus profile must explicitly enable each protocol such as SMTP. In a flow-based profile, if SMTP scanning is left unchecked, mail attachments bypass the antivirus engine entirely — even when signatures are current and the same virus would be caught over HTTP or FTP. Proxy-based inspection, by contrast, scans all supported protocols (SMTP, POP3, IMAP, HTTP, FTP) out of the box, which is why this behavior is specifically tied to a flow-based profile with SMTP disabled.

Why this answer

B is correct because when an antivirus profile uses flow-based inspection, it must have SMTP scanning explicitly enabled in the profile settings. If SMTP scan is not enabled, the FortiGate will not inspect SMTP traffic for viruses, allowing infected attachments to pass through regardless of the antivirus action set to 'Block' and 'Quarantine'. Proxy-based inspection, by contrast, scans all protocols by default, but flow-based requires per-protocol enablement.

Exam trap

The trap here is that candidates assume the 'Block' and 'Quarantine' actions apply globally to all traffic, overlooking that flow-based inspection requires explicit protocol selection within the antivirus profile for SMTP scanning to occur.

How to eliminate wrong answers

Option A is wrong because email filter profiles handle spam, phishing, and content filtering, not virus detection; they cannot override the antivirus action for viruses. Option C is wrong because outdated signatures would cause missed detection of new viruses, but the question states the file contains a virus that the antivirus profile is configured to block, implying the signatures should detect it; the issue is inspection mode, not signature age. Option D is wrong because FortiGate's antivirus engine can scan files up to the configured buffer size (default 10 MB for flow-based, larger for proxy-based), and there is no indication the file exceeded this limit; the problem is that SMTP scanning is not enabled in the flow-based profile.

167
MCQeasy

What is the difference between certificate inspection and full SSL deep inspection on a FortiGate?

A.Certificate inspection decrypts traffic; deep inspection does not
B.Certificate inspection only validates the server certificate; deep inspection decrypts and inspects the content
C.Deep inspection is faster than certificate inspection
D.Both provide the same level of security
AnswerB

Certificate inspection reads only the server certificate's subject and issuer fields to validate trust, leaving payload encrypted. Deep inspection terminates the TLS session, decrypts traffic, and inspects content, which is the actual axis distinguishing the two inspection modes.

Why this answer

Certificate inspection only validates the server certificate's authenticity and checks for revocation, but does not decrypt the traffic payload. Full SSL deep inspection (also called SSL inspection) decrypts the entire SSL/TLS session, allowing the FortiGate to inspect the content for threats like malware, data leaks, or policy violations. This is why option B is correct: certificate inspection validates the certificate, while deep inspection decrypts and inspects the content.

Exam trap

The trap here is that candidates often confuse 'certificate inspection' with 'deep inspection,' assuming both decrypt traffic, but Fortinet specifically defines certificate inspection as a non-decrypting, lightweight validation method.

How to eliminate wrong answers

Option A is wrong because certificate inspection does not decrypt traffic; it only validates the certificate, whereas deep inspection does decrypt. Option C is wrong because deep inspection is actually slower than certificate inspection due to the overhead of decrypting and re-encrypting traffic. Option D is wrong because certificate inspection provides far less security than deep inspection, as it cannot inspect the encrypted payload for threats.

168
MCQhard

An administrator wants to block users from uploading files to cloud storage services like Google Drive via HTTPS. Which security profile combination is required?

A.Application control profile to block cloud storage applications, with deep inspection enabled
B.IPS profile to block file uploads to cloud services
C.DNS filter to block Google Drive domain
D.Web filter profile with URL filter to block Google Drive
AnswerA

Deep inspection decrypts the TLS session, exposing the HTTPS upload stream so application control can identify and block Google Drive by its application signature. Without it, the traffic stays encrypted and only SNI or certificate metadata is visible, which cannot reliably stop file uploads to cloud storage.

Why this answer

To block file uploads to cloud storage services like Google Drive over HTTPS, an application control profile is required because it can identify and control specific application actions (e.g., file uploads) within encrypted traffic. Deep inspection must be enabled to decrypt the HTTPS traffic, allowing the FortiGate to inspect the application-layer payload and enforce the upload blocking rule.

Exam trap

The trap here is that candidates often assume a web filter or DNS filter can block specific actions within an encrypted session, but only application control with deep inspection can inspect HTTPS payloads to differentiate between uploading, downloading, or browsing.

How to eliminate wrong answers

Option B is wrong because an IPS profile is designed to detect and prevent network-based attacks and vulnerabilities, not to control application-specific actions like file uploads to cloud services. Option C is wrong because a DNS filter blocks domains at the DNS resolution level, but it cannot block file uploads within an already-established HTTPS session to Google Drive. Option D is wrong because a web filter profile with a URL filter can block access to the entire Google Drive domain, but it cannot selectively block only file uploads while allowing other activities like viewing or downloading.

169
MCQhard

A FortiGate administrator needs to configure a policy so that traffic to a specific external server is exempted from SSL deep inspection. Which method should be used?

A.Add the server's address to the 'SSL/SSH Inspection Profile' exemptions list
B.Create a separate firewall policy without SSL inspection for that server
C.Disable the IPS sensor on that policy
D.Set the antivirus profile to 'monitor' only
AnswerA

The Exemptions list inside an SSL/SSH Inspection Profile lets the administrator define destination addresses that FortiGate should not attempt to decrypt, even though the deep-inspection profile remains attached to the firewall policy. Matched traffic is allowed to pass through the gateway without a TLS/SSL man-in-the-middle re-signing handshake, so it avoids certificate-validation failures for servers that use certificate pinning or restricted ciphers. This is the recommended approach because it keeps the policy architecture clean and confines exception handling to the inspection profile itself.

Why this answer

The SSL/SSH Inspection Profile includes an 'Exemptions' list where you can specify destination addresses that should bypass SSL deep inspection. This allows traffic to a specific external server to be excluded from SSL inspection without creating a separate firewall policy, ensuring that other security profiles (like antivirus, IPS, and web filtering) still apply to that traffic.

Exam trap

The trap here is that candidates often think they must create a separate firewall policy to bypass SSL inspection, but FortiGate's design intentionally centralizes SSL exemption within the inspection profile to maintain policy simplicity and avoid unintended security gaps.

How to eliminate wrong answers

Option B is wrong because creating a separate firewall policy without SSL inspection would require duplicating all other security profile settings and could lead to policy management complexity; the intended method is to use the exemption list within the SSL/SSH Inspection Profile. Option C is wrong because disabling the IPS sensor does not affect SSL inspection; it only disables intrusion prevention, leaving SSL deep inspection still active. Option D is wrong because setting the antivirus profile to 'monitor' only changes the action for antivirus detection (from block to log-only) but does not exempt traffic from SSL deep inspection.

170
MCQmedium

An administrator configures an application control profile to block social media applications. Users can still access Facebook and Twitter via web browsers. What is the most likely reason?

A.The application signatures for Facebook and Twitter are not up to date
B.The firewall policy has SSL/SSH inspection set to 'certificate-inspection' instead of 'deep-inspection'
C.The application control profile is set to 'monitor' instead of 'block'
D.The firewall policy is configured with flow-based inspection
AnswerB

The correct reason for the failure is that the firewall policy uses certificate-inspection instead of deep-inspection. In certificate-inspection mode, the FortiGate validates the server certificate but does not decrypt the HTTPS payload, so the application control engine is blind to the actual web requests and cannot identify Facebook or Twitter traffic. Deep-inspection performs a man-in-the-middle decryption by presenting a generated CA certificate to the client, decrypting the session, scanning the content with application control and other security profiles, then re-encrypting the traffic. Without deep-inspection, application control can at best rely on incomplete heuristics like SNI, which is often insufficient for modern applications that use encrypted transports or certificate pinning.

Why this answer

When SSL/SSH inspection is set to 'certificate-inspection' (default), the FortiGate only inspects the certificate handshake and cannot decrypt the encrypted application-layer traffic. Social media applications like Facebook and Twitter use HTTPS, so without deep inspection (full decryption), the application control profile cannot identify and block the application signatures within the encrypted payload. Deep inspection is required to decrypt the traffic and allow the IPS engine to match application signatures.

Exam trap

The trap here is that candidates often assume application control works on all traffic regardless of encryption, but FortiGate requires deep inspection to inspect encrypted application payloads, and certificate inspection alone is insufficient for application control to function on HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because outdated signatures would affect all traffic equally, not just encrypted traffic, and the administrator would likely see a signature update warning; the issue here is decryption, not signature freshness. Option C is wrong because if the profile were set to 'monitor', the administrator would see log entries for the blocked applications, but the question states users can still access the sites, implying no action is being taken—this points to a decryption failure, not a profile action setting. Option D is wrong because flow-based inspection is a processing mode (flow vs. proxy) that affects how the firewall processes traffic, but it does not prevent application control from working; deep inspection can still be applied in flow mode, so this is not the root cause.

171
MCQhard

A FortiGate is configured with flow-based antivirus and an IPS profile on a policy. The administrator runs 'diagnose ips packet-list' and sees that packets are being forwarded without inspection. What is the most likely reason?

A.The session is offloaded to the NPU and is not being sent to the IPS engine
B.The antivirus profile is set to proxy-based, conflicting with flow-based IPS
C.The IPS profile is configured with 'monitor' mode instead of 'protect'
D.The traffic is UDP and flow-based inspection does not inspect UDP
AnswerA

In flow-based inspection, FortiGate ASICs such as the NP6/NP7 processors can offload entire sessions after the initial SYN/connection-setup packets are examined by the CPU. Once offloaded, the IPS engine never sees the remaining packets, so the IPS statistics and logs will show no inspection activity for that flow. This is by design in flow-based mode when the session meets offload criteria, and it does not indicate a misconfiguration or failure.

Why this answer

When a FortiGate offloads a session to the NPU (Network Processor Unit), the traffic bypasses the CPU and therefore does not reach the IPS engine for inspection. The 'diagnose ips packet-list' command shows packets forwarded without inspection because the NPU handles them directly, and flow-based inspection requires the session to be processed by the IPS engine on the CPU. This is the most likely reason when the administrator observes packets bypassing inspection despite having flow-based antivirus and IPS profiles applied.

Exam trap

The trap here is that candidates assume 'diagnose ips packet-list' always shows all traffic, but they overlook that NPU offloading can bypass the IPS engine entirely, making the command show no inspected packets even when inspection is configured.

How to eliminate wrong answers

Option B is wrong because flow-based and proxy-based profiles can coexist on the same policy; the antivirus profile being proxy-based does not conflict with a flow-based IPS profile, as each security profile operates independently. Option C is wrong because 'monitor' mode in an IPS profile logs or alerts on detected threats but still sends traffic to the IPS engine for inspection; it does not cause packets to be forwarded without inspection. Option D is wrong because flow-based inspection does inspect UDP traffic; UDP sessions are inspected by the IPS engine just like TCP sessions, and there is no protocol-based exclusion in flow-based inspection.

172
MCQhard

An administrator notices that traffic to a specific HTTPS website is being blocked. The FortiGate has SSL inspection enabled, and the web filter profile is set to monitor all categories. The URL is not in any blocked category. What should the administrator check next?

A.Check if the SSL inspection policy is using certificate inspection instead of full SSL inspection.
B.Review the SSL/SSH inspection profile's certificate revocation check settings.
C.Ensure that the FortiGate has the latest web filter database.
D.Verify that the web filter has the correct rating for the URL.
AnswerB

The SSL/SSH inspection profile contains certificate revocation check settings that validate the server certificate against Certificate Revocation Lists (CRL) and/or OCSP responders. If the revocation check is enabled and the site's certificate is revoked, the FortiGate will refuse to establish the TLS connection and block the HTTPS session, even if the URL category is allowed. This directly explains why traffic to a specific HTTPS site fails while other sites still work, making it the correct first step to review. Additionally, strict blocking can also occur if the OCSP responder is unreachable, so reviewing these settings is essential.

Why this answer

When SSL inspection is enabled and a specific HTTPS site is blocked despite not being in a blocked category, the issue often lies in the SSL/SSH inspection profile's certificate revocation check. If the FortiGate cannot verify the server's certificate revocation status (e.g., via OCSP or CRL), it may block the connection as a security precaution, even if the web filter category allows the URL. Option B directly addresses this by suggesting a review of the revocation check settings.

Exam trap

The trap here is that candidates often assume HTTPS blocking is always due to web filter categories or inspection depth, overlooking that certificate revocation checks in the SSL inspection profile can independently block traffic even when the URL is allowed by the web filter.

How to eliminate wrong answers

Option A is wrong because certificate inspection only examines the SNI and certificate metadata, not the full payload, but the question states SSL inspection is enabled and the web filter is set to monitor all categories; the blocking is likely due to certificate validation failure, not inspection depth. Option C is wrong because the web filter database being outdated would affect URL categorization, but the URL is not in any blocked category, so the database is likely current; the issue is with SSL certificate validation, not URL ratings. Option D is wrong because the administrator already knows the URL is not in a blocked category, so re-verifying the rating would not resolve a block caused by certificate revocation check failure.

173
Multi-Selecteasy

Which TWO types of inspection can be used for HTTPS traffic in a FortiGate security policy?

Select 2 answers
A.Deep inspection
B.Certificate inspection
C.Full inspection
D.Flow-based inspection
E.Proxy-based inspection
AnswersA, B

Deep inspection decrypts SSL/TLS traffic, inspects the full payload and headers for threats, then re-encrypts it before forwarding. This allows FortiGate to detect malicious content hidden inside encrypted sessions, but requires clients to trust a FortiGate CA certificate. It is one of the two valid HTTPS inspection types in Fortinet's NSE4 curriculum.

Why this answer

FortiGate security policies can inspect HTTPS traffic using either deep inspection or certificate inspection. Deep inspection decrypts the SSL/TLS session, inspects the full payload for threats like malware or data leakage, and re-encrypts the traffic, while certificate inspection only validates the server certificate without decrypting the content, checking for certificate validity and revocation.

Exam trap

The trap here is that candidates confuse processing modes (flow-based and proxy-based) with inspection types (deep and certificate), leading them to select flow-based or proxy-based as inspection methods instead of recognizing them as underlying operational modes.

174
MCQmedium

A FortiGate is configured for SSL deep inspection using a CA certificate. Users report that some websites show certificate errors. The administrator wants to allow these sites without inspection. Which setting should be used?

A.Disable certificate validation in the SSL inspection profile
B.Create a separate firewall policy without SSL inspection
C.Set the action for invalid certificates to 'allow'
D.Add the websites to the SSL/SSH exemption list
AnswerD

Adding the websites to the SSL/SSH exemption list tells the FortiGate to skip deep inspection for those specific domains, so the original server certificate is passed directly to the client without interception. This preserves the exact certificate and avoids breaking apps that use certificate pinning, while all other web traffic continues to be inspected with the CA-signed proxy certificate. It is the recommended, granular approach because only the listed destinations are exempted, not the entire inspection policy.

Why this answer

The SSL/SSH exemption list allows administrators to specify websites that should bypass SSL deep inspection entirely, preventing certificate errors for sites that use self-signed, expired, or otherwise untrusted certificates. This is the intended mechanism in FortiOS to exclude specific destinations from inspection while maintaining inspection for all other traffic.

Exam trap

The trap here is that candidates often confuse 'allowing invalid certificates' (Option C) with 'exempting from inspection' (Option D), not realizing that allowing invalid certificates still performs inspection and may break sites with certificate pinning, whereas exemption completely bypasses inspection.

How to eliminate wrong answers

Option A is wrong because disabling certificate validation in the SSL inspection profile would allow invalid certificates for all inspected traffic, not just specific websites, and would weaken security by accepting any certificate. Option B is wrong because creating a separate firewall policy without SSL inspection would require duplicating all other policy settings and could lead to policy misconfiguration or order issues; it is not the designed method for selective bypass. Option C is wrong because setting the action for invalid certificates to 'allow' would permit invalid certificates for all inspected traffic, not just the problematic websites, and would still attempt to inspect the traffic rather than exempting it.

175
Multi-Selecthard

A FortiGate is configured with an IPS profile to detect and block anomalous network behavior. Which THREE types of detection does IPS anomaly detection include? (Choose three.)

Select 3 answers
A.Protocol decoding
B.Port scan detection
C.SYN flood detection
D.Signature-based detection
E.UDP flood detection
AnswersB, C, E

Port scan detection in FortiGate's IPS is an anomaly-based behavioral technique that tracks the number of unique destination ports or distinct IP addresses contacted by a single source within a defined time window. When this activity exceeds a configured threshold, the IPS flags it as a port scan, even if no individual packet matches a known signature. This is a rate-based or heuristic anomaly detection approach, making it a correct example of the IPS anomaly detection mode.

Why this answer

Port scan detection is a type of anomaly detection in FortiGate's IPS profile that identifies reconnaissance attempts by monitoring for multiple connection attempts to different ports from a single source. This behavior deviates from normal traffic patterns and is flagged as anomalous, allowing the IPS to block potential scanning activity before an attack progresses.

Exam trap

The trap here is that candidates often confuse signature-based detection (Option D) with anomaly detection, but FortiGate explicitly separates these into distinct IPS detection methods, and the question asks specifically for anomaly detection types.

176
MCQhard

An administrator runs 'diagnose ips anomaly list' and sees many 'tcp_syn_flood' entries. The IPS profile has anomaly detection enabled with action 'pass'. The administrator wants to block such attacks. What change is required?

A.Increase the threshold for the anomaly
B.Enable flow-based inspection on the policy
C.Add a DoS policy from the same source
D.Change the action for the anomaly from 'pass' to 'block'
AnswerD

The 'block' action for an IPS anomaly instructs the FortiGate's IPS engine to drop packets that match the anomaly signature, thereby preventing the malicious traffic from reaching the destination. Since the current setting is 'pass', the anomaly detection only observes and allows the traffic, which is why the diagnosed anomalies are not being stopped. Setting the action to 'block' is the direct fix, as it changes the response from permitting to actively dropping the offending packets.

Why this answer

The 'pass' action in the IPS anomaly detection configuration instructs the FortiGate to only log the detected anomaly without taking any blocking action. Changing the action to 'block' ensures that when the 'tcp_syn_flood' anomaly is detected, the FortiGate will actively drop the offending packets, thereby mitigating the SYN flood attack.

Exam trap

The trap here is that candidates may think increasing the threshold (Option A) or enabling flow-based inspection (Option B) will block the attack, when in fact the anomaly action must be explicitly changed from 'pass' to 'block' to enforce dropping of malicious traffic.

How to eliminate wrong answers

Option A is wrong because increasing the threshold would make the anomaly detection less sensitive, potentially allowing more SYN flood traffic to pass before triggering, which is counterproductive to blocking attacks. Option B is wrong because flow-based inspection is a processing mode (versus proxy-based) that affects how traffic is examined, but it does not change the action taken when an anomaly is detected; the anomaly action must still be set to 'block'. Option C is wrong because adding a DoS policy from the same source is a separate mechanism for rate-based DoS protection, but it does not modify the behavior of the already-configured anomaly detection entry; the anomaly action must be changed directly.

177
MCQmedium

An administrator configures an IPS profile to block SQL injection attacks. However, SQL injection traffic is still passing through the FortiGate. The administrator confirms the IPS profile is applied to the correct policy. What is the most likely reason?

A.The firewall policy is in proxy-based mode
B.The IPS profile is configured for anomaly detection only
C.IPS signatures for SQL injection are disabled in the profile
D.Deep inspection is required for IPS to work
AnswerC

IPS in FortiGate detects SQL injection by matching traffic against a set of pre-defined signatures in the IPS database. If the administrator has not enabled those signatures in the IPS profile, or has set them to 'pass' rather than 'block,' the attack traffic will be allowed through even though the IPS profile is applied to the policy. Each signature in FortiOS has an individual action (allow, monitor, block) that can be overridden, so the most direct reason a SQL injection would not be blocked is that the corresponding signatures are disabled or set to pass. This is the correct answer because it precisely identifies the signature-level configuration as the cause.

Why this answer

IPS profiles in FortiGate consist of a set of IPS signatures that can be individually enabled or disabled. If the administrator configured an IPS profile to block SQL injection attacks but the specific SQL injection signatures are disabled within that profile, the FortiGate will not inspect or block that traffic, even if the profile is correctly applied to the policy.

Exam trap

The trap here is that candidates assume applying an IPS profile automatically blocks all attacks, but they overlook that individual signatures within the profile must be explicitly enabled and set to 'block' for the desired attacks.

How to eliminate wrong answers

Option A is wrong because firewall policy mode (proxy-based vs. flow-based) affects how traffic is processed, but IPS can operate in both modes; proxy-based mode does not prevent IPS from blocking attacks. Option B is wrong because an IPS profile configured for anomaly detection only would still block anomalies, but the question states SQL injection traffic is passing through, implying the profile is not blocking it; the issue is not about anomaly vs. signature detection but about signature enablement. Option D is wrong because deep inspection (SSL/TLS decryption) is required for IPS to inspect encrypted traffic, but SQL injection attacks typically occur in unencrypted HTTP traffic, where deep inspection is not necessary for IPS to function.

178
MCQmedium

A FortiGate administrator wants to integrate with FortiSandbox to analyze suspicious files detected by antivirus. The administrator configures the FortiSandbox settings under Security Fabric. However, files are not being sent to FortiSandbox. The antivirus profile is set to 'flow-based' inspection. What could be the reason?

A.The antivirus profile is set to 'Monitor' instead of 'Block'.
B.The firewall policy is using NAT, which interferes with FortiSandbox connectivity.
C.The FortiGate does not have a valid FortiSandbox license.
D.Flow-based inspection does not support FortiSandbox integration; proxy-based inspection is required.
AnswerD

FortiSandbox file submission is only supported in proxy-based inspection mode on FortiGate models. Flow-based inspection does not buffer complete files for upload; it can only perform hash-based outbreak prevention queries against the FortiSandbox database. Because the file must be fully sent to FortiSandbox for analysis, the antivirus and sandboxing features must be configured with proxy mode in the security policy. Therefore, if the policy uses flow-based inspection, FortiSandbox integration will not perform file submissions.

179
MCQeasy

What is the function of an IPS 'protocol decoder'?

A.Encode traffic to prevent attacks
B.Parse and normalize protocol traffic to improve detection accuracy
C.Rate-limit traffic based on protocol
D.Decrypt SSL traffic for inspection
AnswerB

A protocol decoder parses and normalises traffic for a specific protocol, extracting fields and enforcing syntax so signatures match reliably despite evasion or fragmentation. This directly satisfies the stem's requirement to define the decoder's function: improving detection accuracy by presenting consistent, decoded data to the IPS engine.

Why this answer

An IPS protocol decoder parses and normalizes traffic for a specific protocol (e.g., HTTP, SMB, DNS) to reconstruct the application-layer data stream. This normalization strips away evasion techniques like chunked encoding or whitespace obfuscation, allowing the IPS to match attack signatures against the true payload, which significantly improves detection accuracy.

Exam trap

The trap here is that candidates confuse 'protocol decoder' with 'SSL inspection' or 'traffic shaping,' assuming any deep packet inspection function must involve decryption or rate control, when in fact the decoder's sole purpose is to parse and normalize protocol fields for accurate signature matching.

How to eliminate wrong answers

Option A is wrong because protocol decoders do not encode traffic; encoding would alter the payload and potentially hide attacks, whereas decoders normalize to reveal the original data. Option C is wrong because rate-limiting is a function of traffic shaping or QoS policies, not of protocol decoders, which focus on parsing and normalization. Option D is wrong because decrypting SSL/TLS traffic is performed by a separate SSL/SSH inspection component, not by a protocol decoder; decoders operate on already-decrypted or plaintext traffic.

180
MCQmedium

An administrator applies an application control profile to a firewall policy that allows outbound traffic. Users report that a specific business-critical application, which uses TLS on port 443, is now being blocked even though the application is not listed as blocked in the profile. The administrator wants to allow this application while still controlling other applications. What is the most likely reason the application is being blocked?

A.The firewall policy is using flow-based inspection, which cannot identify applications on port 443.
B.The application is being blocked by a separate IPS sensor that is applied to the same firewall policy.
C.The application control profile requires an SSL inspection profile to detect applications on port 443, and none is applied.
D.The application control profile is configured to block all applications that are not explicitly allowed.
AnswerD

When an application control profile is set to block unknown applications or has a default action of block for categories not explicitly allowed, applications not recognized or not listed may be blocked. This is a common misconfiguration where the administrator must either add the application to an allow list or adjust the default action to allow.

Why this answer

The correct answer is that the application control profile is configured to block all applications that are not explicitly allowed. In FortiGate application control, each category and application can have an action, and there is a default action for applications not explicitly listed. If the default action is set to block, any application not in the allow list will be blocked, even if it is not explicitly blocked.

The administrator should either add the application to the allow list or change the default action to allow.

Exam trap

The trap here is assuming that only explicitly blocked applications are blocked, while overlooking the default action for unknown applications.

181
MCQmedium

A network administrator notices that HTTP traffic to a specific website is being blocked by the web filter profile, but the website is categorized as 'General – Personal' in FortiGuard, which is allowed. What could cause this block?

A.The web filter profile has an incorrect FortiGuard category override
B.The antivirus profile is blocking the website
C.A URL filter entry is blocking the specific website
D.DNS filter is blocking the domain
AnswerC

URL filter entries are local, rule-based patterns evaluated before FortiGuard category lookup. If a block entry matches the specific domain or URL, the session is dropped immediately, regardless of the category's default action. This is why a single website can be blocked while other sites in the same FortiGuard category remain accessible, as described in the scenario.

Why this answer

A URL filter entry can explicitly block a specific website regardless of its FortiGuard category. Even if the category 'General – Personal' is allowed in the web filter profile, a more specific URL filter rule with a higher priority (lower order number) can override the category-based action. This is a common scenario where an administrator creates a custom URL block for a particular domain or URL pattern, which takes precedence over the FortiGuard category lookup.

Exam trap

The trap here is that candidates often assume the FortiGuard category is the sole determinant of web access, forgetting that URL filter entries have higher precedence and can block individual sites even when their category is permitted.

How to eliminate wrong answers

Option A is wrong because a FortiGuard category override would change the category assigned to the website, but if the override incorrectly set it to a blocked category, the traffic would be blocked for that reason—however, the question states the category is allowed, so an override would not cause a block unless it changed the category to a blocked one, which is not indicated. Option B is wrong because antivirus profiles inspect file downloads and HTTP content for malware, not the initial HTTP request to a website; they would not block the website itself unless a virus was detected in a downloaded file, which is not mentioned. Option D is wrong because DNS filter blocks domains at the DNS query level, preventing resolution entirely, but the question indicates HTTP traffic is blocked, implying the DNS query succeeded and the TCP connection was attempted, so a DNS filter block would manifest as a DNS resolution failure, not an HTTP block.

182
MCQeasy

What is the primary difference between flow-based and proxy-based Antivirus inspection on a FortiGate?

A.Flow-based inspection is only available on hardware models with CP8
B.Proxy-based inspection reassembles the file before scanning, while flow-based scans as the file passes through
C.Proxy-based inspection uses fewer resources than flow-based
D.Flow-based inspection supports virus outbreak detection, but proxy-based does not
AnswerB

Proxy-based inspection buffers and reassembles the complete file before scanning, enabling full content inspection and blocking. Flow-based scanning examines packets as they traverse the FortiGate, trading depth for throughput and lower latency. This directly satisfies the stem's request for the primary architectural difference between the two antivirus inspection modes.

Why this answer

The primary difference is that proxy-based antivirus inspection fully reassembles the file in memory before scanning, allowing for more thorough detection of threats like polymorphic viruses and archives. Flow-based inspection scans data as it passes through the FortiGate in a single pass, using pattern matching without full file reassembly, which reduces latency but may miss threats that require file-level analysis.

Exam trap

The trap here is that candidates often assume proxy-based is always more resource-efficient because it is 'thorough,' but in reality, proxy-based consumes more memory and CPU due to file buffering and reassembly, while flow-based is optimized for performance.

How to eliminate wrong answers

Option A is wrong because flow-based inspection is not limited to hardware models with CP8; it is available on all FortiGate models and leverages CP8/CP9 accelerators for performance but does not require them. Option C is wrong because proxy-based inspection typically uses more resources (memory and CPU) due to file reassembly and buffering, while flow-based is designed for lower resource consumption. Option D is wrong because both flow-based and proxy-based inspection support virus outbreak detection through FortiGuard updates; the difference is in the scanning method, not feature support.

← PreviousPage 3 of 3 · 182 questions total

Ready to test yourself?

Try a timed practice session using only Security Profiles questions.