Courseiva

CCNA Nse4 Ha Diagnostics Questions

75 of 101 questions · Page 1/2 · Nse4 Ha Diagnostics topic · Answers revealed

1
MCQeasy

What is the function of Zero Trust Network Access (ZTNA) on a FortiGate?

A.It allows users to securely access internal applications without a VPN, based on identity and device posture
B.It replaces the firewall policy for all traffic
C.It encrypts all traffic between the FortiGate and the internet
D.It is a cloud-based subscription for antivirus updates
AnswerA

ZTNA enables per-application, identity-based access control: the FortiGate acts as an access proxy, authenticating the user (via SAML, LDAP, or local login) and verifying device posture (using FortiClient or other telemetry) before allowing a short-lived, encrypted session to a specific internal application. This eliminates the need for a full VPN tunnel, enforcing least-privilege access while keeping the user unaware of the complete internal network.

Why this answer

ZTNA on FortiGate provides secure, identity-based access to internal applications without requiring a traditional VPN tunnel. It evaluates user identity and device posture before granting access, ensuring that only authorized users and compliant devices can reach specific applications. This aligns with the Zero Trust principle of 'never trust, always verify' and is implemented via FortiGate's ZTNA features, often integrated with FortiClient and FortiAuthenticator.

Exam trap

NSE4 often tests the misconception that ZTNA is a replacement for VPNs or firewalls, when it is actually a complementary access control mechanism that requires identity and posture checks.

How to eliminate wrong answers

Option B is wrong because ZTNA does not replace firewall policies; it works alongside them to provide granular, application-level access control, and firewall policies still govern other traffic. Option C is wrong because ZTNA does not encrypt all traffic between the FortiGate and the internet; encryption is typically handled by IPsec or TLS VPNs, and ZTNA focuses on access control, not bulk encryption. Option D is wrong because ZTNA is not a cloud-based subscription for antivirus updates; that describes FortiGuard services, while ZTNA is a network access security feature.

2
MCQhard

An administrator is configuring ZTNA (Zero Trust Network Access) on a FortiGate. The administrator needs to ensure that only clients with a valid posture assessment can access an internal application. Which access proxy setting must be configured to enforce this requirement?

A.Enable SSL deep inspection on the access proxy
B.Configure a ZTNA rule with a ZTNA tag requirement
C.Set the access proxy to use certificate-based authentication
D.Enable multi-factor authentication on the access proxy
AnswerB

Configuring a ZTNA rule with a ZTNA tag requirement is the only option that directly enforces security posture. The FortiGate requires that the connecting client present a specific tag that is only issued after the endpoint passes posture checks such as patching and host firewall status. If the tag is absent or does not match the required value, the rule blocks access. This tag-based enforcement is the core mechanism for zero-trust posture verification in Fortinet's ZTNA.

Why this answer

ZTNA on FortiGate enforces zero trust by requiring clients to present a valid ZTNA tag, which is issued only after a successful posture assessment by FortiClient EMS. Configuring a ZTNA rule with a tag requirement ensures that only endpoints meeting the posture policy can reach the protected application through the access proxy. This is the mechanism that ties posture validation to access enforcement.

Exam trap

The trap is conflating authentication mechanisms (certificates, MFA) with posture assessment; candidates pick certificate or MFA options thinking they enforce device health when only ZTNA tags reflect posture.

How to eliminate wrong answers

Option A is wrong because SSL deep inspection decrypts and inspects traffic content; it does not perform endpoint posture assessment or enforce tag-based access. Option C is wrong because certificate-based authentication verifies client identity, not device posture; a compliant certificate does not prove the endpoint meets security requirements like antivirus or patch level. Option D is wrong because MFA strengthens user authentication but does not evaluate device health or posture, so it cannot enforce the posture requirement alone.

3
MCQeasy

An administrator wants to monitor real-time traffic flows on a FortiGate, specifically to see packet details for traffic matching certain criteria. Which command should the administrator use to capture live packets on an interface?

A.diagnose sniffer packet
B.diagnose debug enable and diagnose debug flow trace
C.diagnose sys session list
D.execute system grep from CLI
AnswerA

diagnose sniffer packet is the correct command for real-time packet-level monitoring. It instructs the FortiGate's kernel to capture raw packets on a specified interface (or 'any') and displays their headers and payload directly in the terminal, optionally filtered by protocol, host, or port. This is equivalent to tcpdump on Linux and is the go-to tool when you need to see the actual bytes crossing the wire, not just session summaries.

Why this answer

The 'diagnose sniffer packet' command is FortiGate's built-in packet capture tool, allowing administrators to capture live packets on a specified interface with optional filters for host, port, and protocol. It provides real-time packet-level visibility similar to tcpdump, which is exactly what is needed to inspect packet details for traffic matching specific criteria.

Exam trap

NSE4 often tests the distinction between 'diagnose sniffer packet' (raw packet capture) and 'diagnose debug flow' (session/flow tracing) — candidates confuse the two because both are used for traffic troubleshooting.

How to eliminate wrong answers

Option B is wrong because 'diagnose debug flow' traces session setup and packet processing through the kernel but does not capture raw packet contents or headers. Option C is wrong because 'diagnose sys session list' only displays the session table entries (state, NAT, timeouts) and does not show packet-level details. Option D is wrong because 'execute system grep' is not a valid FortiGate command for packet capture and cannot inspect live traffic.

4
MCQmedium

A FortiGate administrator notices that after upgrading the firmware, the HA cluster fails to form. Both units show the correct HA configuration. What is the most likely cause?

A.The HA heartbeat interfaces are not connected
B.The HA mode is set to active-active on one unit and active-passive on the other
C.The firmware versions are different on the two units
D.The HA priority values are identical
AnswerC

The most common cause of an HA cluster refusing to form after a firmware upgrade is that FortiGate HA does not support mixed FortiOS versions across cluster members. When one unit runs a newer build than the other, the cluster cannot synchronize because the internal protocol/data structures differ, and the HA status will report a firmware version mismatch. Since the problem appeared right after the upgrade, verifying that both units are on the same upgraded firmware build is the correct first step.

Why this answer

FortiGate HA requires that all cluster members run the same firmware version. After an upgrade, if one unit is upgraded and the other is not, the HA cluster will not form because the HA protocol version and heartbeat packet format may differ. The units will show correct HA configuration but will not establish a heartbeat due to version mismatch.

This is a common issue during firmware upgrades in an HA cluster.

Exam trap

NSE4 often tests the misconception that HA configuration parameters like priority or mode are the primary cause of cluster formation failure, when in fact firmware version mismatch is a critical and common cause after upgrades.

How to eliminate wrong answers

Option A is wrong because if the HA heartbeat interfaces were not connected, the cluster would not form, but the question states both units show correct HA configuration, implying physical connectivity is likely fine; moreover, this is a basic check that would be noticed immediately. Option B is wrong because FortiGate HA requires both units to have the same HA mode (active-active or active-passive); if they differ, the cluster will not form, but the question says both units show the correct HA configuration, which would include matching HA mode. Option D is wrong because identical HA priority values do not prevent cluster formation; priority only determines which unit becomes the primary (master), and if priorities are equal, the unit with the higher serial number or longer uptime may become primary, but the cluster still forms.

5
Multi-Selecthard

An administrator is troubleshooting a FortiGate that is not sending logs to FortiCloud. The FortiGate has internet connectivity and a valid FortiCloud subscription. Which THREE steps should the administrator take to resolve this issue? (Select three.)

Select 3 answers
A.Ensure that the log types (traffic, event, security) are enabled for FortiCloud
B.Verify the FortiCloud status in the dashboard
C.Check if the FortiGate can resolve FortiCloud's FQDN
D.Increase the log buffer size
E.Disable the antivirus profile temporarily
AnswersA, B, C

FortiCloud log forwarding is configured under Log Settings, where the administrator must explicitly select which log types (traffic, event, security) are sent to FortiCloud. If only the default or local log types are enabled, or if these categories are left unchecked, the FortiGate will not upload the corresponding logs even though local logging works. This is a common misconfiguration because enabling local logging does not automatically enable cloud forwarding for every log type; each category must be individually selected in the FortiCloud log settings.

Why this answer

Option A is correct because FortiCloud log forwarding only transmits the log categories that are explicitly enabled under Log & Report > Log Settings > FortiCloud, so traffic, event, and security logs must each be turned on for them to be uploaded. Option B is correct because the dashboard FortiCloud widget shows the registration/entitlement status and whether the FortiGate is successfully connected to FortiCloud, which is the fastest way to confirm the subscription is actually active on the device. Option C is correct because the FortiGate must resolve the FortiCloud FQDN (for example, the service endpoint such as fortigate.forticloud.com or the region-specific logging endpoint) via DNS; if name resolution fails, logs cannot be sent even with working internet and a valid subscription.

Option D is incorrect because increasing the log buffer size only affects local disk/memory log retention and does not fix FortiCloud delivery. Option E is incorrect because disabling an antivirus profile has no bearing on log transmission and would only weaken security.

Exam trap

NSE4 often tests the assumption that internet connectivity alone guarantees FortiCloud logging, ignoring the need for correct log category enablement, registration status, and DNS resolution.

6
MCQmedium

A FortiGate administrator needs to ensure that traffic logs are sent to a FortiAnalyzer even when the FortiGate's local disk is full. What configuration is required?

A.Enable 'disk logging' with rollover policy
B.Increase the log severity to 'emergency' only
C.Enable 'remote log' under Log Settings and specify the FortiAnalyzer IP
D.Configure a log filter to send only security logs
AnswerC

Enabling remote logging under Log Settings and specifying the FortiAnalyzer IP address configures the FortiGate to stream logs directly to FortiAnalyzer over the network using its dedicated logging protocols. This is the correct method because it establishes FortiAnalyzer as a log destination, ensuring that traffic logs are continuously transferred to the central analyzer regardless of local disk capacity or local retention policies.

Why this answer

To ensure logs are sent to FortiAnalyzer even when the local disk is full, the administrator must enable remote logging under Log Settings and specify the FortiAnalyzer IP. This configures the FortiGate to send logs to the remote server independently of local disk status.

Exam trap

NSE4 often tests the confusion between local and remote logging, where candidates might think that enabling disk logging or adjusting severity will automatically send logs to FortiAnalyzer, but remote logging must be explicitly configured.

How to eliminate wrong answers

Option A is wrong because disk logging with rollover policy only manages local storage and does not guarantee remote logging when disk is full. Option B is wrong because increasing log severity to emergency only reduces the number of logs but does not ensure remote logging. Option D is wrong because a log filter only selects which logs to send, but without enabling remote logging, no logs are sent to FortiAnalyzer.

7
MCQhard

An administrator configures HA override on a cluster with priority 200 on primary and 100 on secondary. The primary fails, secondary takes over. When primary recovers, what happens?

A.Both units become active, causing a conflict
B.Secondary remains active until next failover
C.The administrator must manually trigger failback
D.Primary immediately takes over as active
AnswerD

When override is enabled on the cluster, a recovered primary unit with a higher priority will immediately take over as active, preempting the current secondary. The takeover occurs after the cluster re-establishes heartbeat and synchronizes session state, ensuring that traffic convergence is orderly. This preemptive behavior is the defining feature of HA override, and it distinguishes the mode from non-preemptive operation where the current active unit would otherwise remain active.

Why this answer

With HA override enabled, the primary unit with higher priority (200) will preempt the secondary (100) once it recovers and rejoins the cluster. The primary immediately takes over as active because override allows a higher-priority unit to force a failback. This is the intended behavior of override in FortiGate HA.

Exam trap

NSE4 often tests the difference between HA override enabled vs disabled, and candidates may confuse override with manual failback or assume both units become active.

How to eliminate wrong answers

Option A is wrong because HA cluster ensures only one unit is active at a time; both becoming active would cause a split-brain, which is prevented by heartbeat and priority. Option B is wrong because without override, the secondary would remain active; with override, the primary preempts. Option C is wrong because override automates failback; manual intervention is not required.

8
MCQmedium

A FortiGate administrator has configured an active-passive HA cluster with two units. During a failover test, they notice that existing TCP sessions are dropped and must be re-established. What configuration change should the administrator make to ensure sessions are preserved during failover?

A.Enable session synchronization between the cluster members
B.Configure a dedicated heartbeat interface
C.Enable HA override
D.Increase the HA priority on the primary unit
AnswerA

Enabling session synchronization (session sync) in the HA cluster causes the active FortiGate to continuously replicate its entire session table — including NAT mappings, TCP sequence numbers, and timers — to the standby unit over the heartbeat link. Because the standby now possesses an up-to-date copy of all state, it can immediately assume forwarding during a failover and existing TCP sessions remain intact without client reconnection. Without this feature, no amount of heartbeat, priority, or override tuning can save sessions; this is the only mechanism that directly addresses session preservation.

Why this answer

Session synchronization (session sync) allows the active unit to share session table entries with the passive unit. During failover, the new active unit has the session table pre-populated, so existing sessions continue without interruption.

9
MCQmedium

A FortiGate administrator wants to ensure that in an active-passive HA cluster, a specific unit becomes the primary (active) unit after a reboot. Which configuration parameter should be set to a higher value on that unit?

A.HA session pickup delay
B.HA override
C.HA priority
D.HA group-id
AnswerC

HA priority is the configurable value (1 to 255, with higher being better) that directly determines which FortiGate unit becomes the active unit in an HA cluster. During the election process, the unit with the highest priority is selected as active; if priorities are equal, other factors like uptime and port monitoring are used as tie-breakers. This is the standard and primary method for controlling the active/standby role in FortiGate HA, making it the correct answer.

Why this answer

In a FortiGate active-passive HA cluster, the HA priority value determines which unit becomes the primary (active) unit. The unit with the higher priority value will be elected as the primary, provided that HA override is enabled. Therefore, setting a higher HA priority on the desired unit ensures it becomes active after a reboot.

Exam trap

NSE4 often tests the interaction between HA priority and HA override, and candidates may forget that override must be enabled for priority to take effect in preemption.

How to eliminate wrong answers

Option A is wrong because HA session pickup delay is used to delay session pickup after a failover to allow the network to converge, not to determine primary election. Option B is wrong because HA override is a setting that allows a unit with higher priority to preempt the current primary, but by itself it does not set the priority; it must be enabled along with a higher priority. Option D is wrong because HA group-id is used to identify the HA cluster and must match on all members; it does not influence primary election.

10
MCQeasy

What is the purpose of the 'override' setting in FortiGate HA?

A.It enables the higher-priority unit to reclaim the primary role after recovery
B.It allows management access to the cluster via a virtual IP
C.It disables HA failover during maintenance windows
D.It forces the secondary unit to become primary immediately
AnswerA

Override is an HA election control in FortiGate. When enabled, if a unit with a higher configured priority fails and later recovers, it will preempt the current primary (which may have a lower priority) and reclaim the primary role automatically. This ensures the preferred unit is always active after recovery, but it can cause a brief service interruption. Without override, the recovered higher-priority unit would rejoin the cluster as a secondary and remain so until the active primary fails.

Why this answer

The 'override' setting in FortiGate HA allows a higher-priority unit to reclaim the primary role after it recovers from a failure. Without override, the primary role does not automatically revert to the original unit even if it comes back online with a higher priority. This ensures predictable failback behavior.

Exam trap

NSE4 often tests the difference between HA priority and override, where candidates might think priority alone causes failback, but without override, the original primary does not automatically reclaim the role.

How to eliminate wrong answers

Option B is wrong because management access via a virtual IP is enabled by configuring an HA management interface, not by the override setting. Option C is wrong because disabling HA failover during maintenance is done by setting the device to standby or using maintenance mode, not by override. Option D is wrong because override does not force the secondary to become primary immediately; it only allows the higher-priority unit to take over when it is available.

11
MCQeasy

Which of the following log types on FortiGate records traffic that is denied by a firewall policy?

A.HA logs
B.Event logs
C.Traffic logs
D.Security logs
AnswerC

Traffic logs are the FortiGate log type that records every session attempt processed by the firewall, including both permitted and denied traffic. Each traffic log entry contains source and destination addresses, ports, service, action (allow/deny), policy ID, and byte counts, and it is generated from the session table when a session closes or at a configured periodic interval. This is the correct answer because traffic logs are specifically designed to log all session activity.

Why this answer

Traffic logs on a FortiGate record all traffic that passes through or is denied by the firewall, including the source/destination, service, action (accept/deny), and policy that matched. When a firewall policy blocks traffic, the deny action is captured in the traffic log with the corresponding policy ID, making it the correct log type for identifying denied sessions.

Exam trap

NSE4 often tests the confusion between traffic logs (per-session allow/deny records) and security logs (UTM inspection events) — candidates incorrectly assume any 'denied' event belongs in the security log category.

How to eliminate wrong answers

Option A is wrong because HA logs record high availability cluster events such as failover, heartbeat status, and synchronization issues between FortiGate units — they have nothing to do with per-session traffic decisions. Option B is wrong because event logs capture system-level events such as administrator logins, configuration changes, and system daemon activity, not individual traffic flows. Option D is wrong because security logs (also called security event logs) record IPS, antivirus, web filter, and other UTM inspection events — while a denied session may generate a UTM event, the canonical record of a policy deny is in the traffic log.

12
MCQeasy

An administrator wants to send logs from a FortiGate to an external syslog server. Which log forwarding method should they configure?

C.NetFlow
AnswerA

Syslog is the standard protocol for forwarding system logs from network devices to a centralized log collector. FortiGate supports sending syslog messages to external servers over UDP (default 514), TCP, or TLS, with configurable severity and formats like RFC 3164 or RFC 5424. This makes it the correct choice for delivering FortiGate's full event logs to an external system.

Why this answer

FortiGate supports external log forwarding via syslog, which is the standard protocol for sending event and traffic logs to a remote server. Configuring syslog on the FortiGate involves specifying the server IP, port (default 514), and facility, and it allows the FortiGate to send logs in a structured format that can be parsed by SIEM or log management tools. SMTP is for email alerts, NetFlow is for traffic flow metadata, and SNMP is for monitoring and traps, not for general log transport.

Exam trap

NSE4 often tests the confusion between log forwarding methods and monitoring protocols, so candidates might mistakenly choose SNMP or NetFlow because they are also used for network management, but only syslog is designed for sending detailed logs to an external server.

How to eliminate wrong answers

Option B is wrong because SMTP is used for sending email notifications or alerts, not for streaming logs to a syslog server. Option C is wrong because NetFlow exports summarized traffic flow information (IP addresses, ports, byte counts) for analysis, but it does not carry the detailed event logs that syslog provides. Option D is wrong because SNMP is a protocol for monitoring device health and receiving traps, not for forwarding full log messages to an external log server.

13
MCQhard

An administrator is configuring HA on two FortiGates. Both units have the same model and firmware. When they are connected, neither unit becomes active. The admin checks the HA status and sees that the cluster is not formed. What is the MOST likely cause?

A.The heartbeat interface is not configured
B.The management interface is used as a heartbeat
C.The HA password is incorrect
D.The HA group-id does not match
AnswerA

In FortiGate HA, dedicated heartbeat interfaces are mandatory because they carry the Hello packets that allow units to discover each other and elect the active unit. If no heartbeat interface is configured, the FortiGates never exchange any HA traffic, so they remain in standalone mode even if all other HA settings, such as group ID and password, are correctly set. This is the most direct and fundamental cause of the inability to form a cluster.

Why this answer

For a FortiGate HA cluster to form, the heartbeat interfaces must be properly configured and connected. The heartbeat interface is used for HA synchronization and monitoring between the units. If the heartbeat interface is not configured, the FortiGates cannot communicate, and the cluster will not form, leaving both units in a non-active state.

Since both units have the same model and firmware, and the issue is that neither becomes active, the most likely cause is that the heartbeat interface is not configured.

Exam trap

NSE4 often tests the misconception that HA cluster formation only requires matching model, firmware, and HA password, overlooking the necessity of a properly configured heartbeat interface.

How to eliminate wrong answers

Option B is wrong because using the management interface as a heartbeat is not a recommended practice and would not prevent cluster formation if configured correctly; however, it is not the most likely cause when the heartbeat is not configured at all. Option C is wrong because an incorrect HA password would cause authentication failures, but the units would still attempt to form a cluster and might show specific error messages; moreover, the password is typically set during configuration and would be a less likely oversight if both units are newly configured. Option D is wrong because a mismatched HA group-id would prevent cluster formation, but it is a less common cause than a missing heartbeat interface configuration, especially when the units are connected and neither becomes active.

14
MCQhard

A FortiGate administrator is diagnosing a performance issue. They notice that the CPU usage is consistently high. Which command can provide a real-time view of the processes consuming CPU?

A.get system performance status
B.diagnose sys session stat
C.diagnose debug flow
D.diagnose sys top
AnswerD

This command functions like the Linux 'top' utility, presenting a real-time, updating list of FortiOS processes with per-process CPU and memory consumption. It is the correct tool for identifying which specific process is causing high CPU during a performance issue. By observing the process list, an administrator can pinpoint the culprit, such as an overactive log daemon or the antivirus scanning engine, and take targeted action.

Why this answer

'diagnose sys top' provides a real-time, top-like view of running processes on the FortiGate, sorted by CPU and memory consumption, refreshing periodically. It is the correct tool to identify which specific process (e.g., ipsengine, wad, scanunitd) is driving sustained high CPU. This directly answers the need for a live process-level CPU view.

Exam trap

NSE4 often tests the distinction between summary performance commands ('get system performance status') and live per-process monitoring ('diagnose sys top'), so candidates choose the summary command thinking it shows process-level detail.

How to eliminate wrong answers

Option A is wrong because 'get system performance status' gives a one-shot summary of overall CPU, memory, and uptime averages, not a per-process real-time breakdown. Option B is wrong because 'diagnose sys session stat' reports session table statistics (session counts, setup rates) and does not show process CPU usage. Option C is wrong because 'diagnose debug flow' traces individual packet flows through the policy engine and is used for traffic troubleshooting, not for identifying CPU-consuming processes.

15
MCQmedium

An administrator needs to configure a FortiGate to send logs to an external FortiAnalyzer. Which setting is required?

A.Setting the log disk quota
B.Configuring syslog server
C.Enabling FortiCloud logging
D.Configuring FortiAnalyzer under Log Settings
AnswerD

Configuring FortiAnalyzer under Log Settings is the correct procedure: in the FortiGate GUI, navigate to Log & Report > Log Config > Log Settings, and add a new FortiAnalyzer entry by specifying its IP address, serial number (optional), and communication settings. This enables the FortiGate to send logs to the FortiAnalyzer using the proprietary FortiAnalyzer protocol, which supports efficient log forwarding, encryption, and integration with FortiAnalyzer's analytics and reporting engines. It is the dedicated method for forwarding logs to a FortiAnalyzer device.

Why this answer

FortiGate uses the 'Log Device' or 'FortiAnalyzer' configuration to send logs to an external FortiAnalyzer.

16
MCQeasy

An administrator wants to troubleshoot a traffic flow issue on a FortiGate. They suspect packets are being dropped. Which command should they use to perform a real-time packet capture on an interface?

A.diagnose sniffer packet
B.get system performance status
C.diagnose sys session list
D.diagnose debug flow
AnswerA

diagnose sniffer packet is the standard FortiGate packet capture tool, analogous to tcpdump or Wireshark. It captures raw packets at the kernel level on specified interfaces or VLANs, displaying actual packet headers and payload in real time. This command is essential for analyzing the exact traffic content, checksums, and any malformed packets, making it the correct choice for troubleshooting traffic flow issues at Layer 2-4.

Why this answer

The command 'diagnose sniffer packet' is used on FortiGate to perform real-time packet capture on an interface. It allows administrators to see packet details, including headers and payloads, to troubleshoot traffic flow issues and identify dropped packets.

Exam trap

NSE4 often tests the distinction between packet capture tools (sniffer) and flow tracing tools (debug flow), causing candidates to confuse their specific purposes.

How to eliminate wrong answers

Option B is wrong because 'get system performance status' displays system resource usage (CPU, memory) and is not used for packet capture. Option C is wrong because 'diagnose sys session list' shows current session information but does not capture live packets. Option D is wrong because 'diagnose debug flow' traces packet flow through the FortiGate's policy engine and provides debug output, but it is not a packet capture tool; it shows how packets are processed, not the raw packets themselves.

17
MCQeasy

Which log severity level indicates a failure that requires immediate attention?

A.Debug
B.Emergency
C.Warning
D.Information
AnswerB

Emergency is the highest severity level in FortiGate logging, reserved for conditions that render the system unusable or that require immediate administrator intervention, such as a detected power loss, fatal system error, or hardware malfunction. Unlike other levels, Emergency signals an active, often catastrophic failure that demands urgent action to restore service and prevent data loss or security compromise. This directly matches the question's requirement for a failure that necessitates immediate response, making Emergency the correct choice.

Why this answer

In Fortinet's FortiOS, log severity levels follow the standard syslog protocol (RFC 5424). The 'Emergency' level (severity 0) indicates a system is unusable or has experienced a critical failure that requires immediate administrator intervention, such as a hardware failure or a security breach. This is the highest severity level, designed to alert for urgent action.

Exam trap

The trap here is that candidates often confuse 'Warning' with a critical failure, but 'Warning' only indicates a potential problem, while 'Emergency' is the only level that signifies a system-wide failure requiring immediate attention.

How to eliminate wrong answers

Option A is wrong because 'Debug' (severity 7) is the lowest severity level, used for detailed troubleshooting information and does not indicate any failure. Option C is wrong because 'Warning' (severity 4) indicates a potential issue that might require attention but does not denote an immediate failure requiring urgent action. Option D is wrong because 'Information' (severity 6) is a normal operational message, such as a successful login or configuration change, and does not represent any failure.

18
MCQeasy

In an active-active HA cluster, which of the following must be identical on both FortiGate units?

A.HA priority
B.Management IP address
C.Virtual cluster ID
D.Hostname
AnswerC

The virtual cluster ID is a mandatory HA parameter that must be the same on both units to ensure they belong to the same cluster and can synchronize correctly. This ID is used in heartbeat negotiation and for VDOM partitioning to separate multiple clusters on the same Layer 2 segment. If the virtual cluster IDs differ, the units will not form an HA cluster, even if all other settings are identical.

Why this answer

In an active-active HA cluster, the virtual cluster ID must be identical on both FortiGate units because it defines the cluster group and ensures that only units with the same ID can form an HA cluster. This ID is used in heartbeat packets to verify cluster membership and prevent accidental merging of separate clusters. Without a matching virtual cluster ID, the units will not recognize each other as part of the same HA group.

Exam trap

The trap here is that candidates often confuse 'must be identical' with configuration values that are typically synchronized (like priority or hostname), but the virtual cluster ID is the only parameter that must match before cluster formation can occur, while others can differ or are overwritten during synchronization.

How to eliminate wrong answers

Option A is wrong because HA priority determines the role (primary or secondary) within the cluster and can differ between units to establish a preferred leader; it does not need to be identical. Option B is wrong because the management IP address is a unique per-unit setting used for individual administrative access, and in an HA cluster, a separate virtual management IP (or floating IP) is used for cluster management, not the individual unit's management IP. Option D is wrong because the hostname is a local identifier for each FortiGate and can be different; it does not affect HA cluster formation or operation.

19
MCQeasy

What is the purpose of the heartbeat interface in a FortiGate HA cluster?

A.To exchange HA heartbeat messages for health monitoring
B.To synchronize session tables and configuration
C.To provide out-of-band management access
D.To forward user traffic between cluster members
AnswerA

The heartbeat interface is dedicated to carrying HA heartbeat packets—typically UDP probes—that each cluster member sends and expects to receive. Loss of these heartbeats indicates a peer, link, or interface failure, prompting the primary unit to initiate failover and the backup to take over. Its sole primary purpose is to continuously assess peer liveness and trigger the designated failover logic, not to move user traffic or serve as a management path.

Why this answer

The heartbeat interface in a FortiGate HA cluster is dedicated to exchanging HA heartbeat messages between cluster members. These messages are used to monitor the health and availability of each unit, enabling failover detection and ensuring cluster stability. It does not handle session synchronization, management access, or user traffic forwarding.

Exam trap

The trap here is that candidates often confuse the heartbeat interface with the HA sync interface, assuming it handles session synchronization or configuration replication, when in fact it only performs health monitoring.

How to eliminate wrong answers

Option B is wrong because session table and configuration synchronization is performed over the dedicated HA sync interface, not the heartbeat interface. Option C is wrong because out-of-band management access is typically provided by a dedicated management interface or VLAN, not the heartbeat interface. Option D is wrong because forwarding user traffic between cluster members is the role of the cluster link or inter-chassis links, while the heartbeat interface only carries health-check messages.

20
MCQhard

An administrator runs 'diagnose debug flow' for a specific policy and sees the following output: id=20085 trace_id=10 func=vf_ip_route_in msg='No matching interface to route packet' What does this indicate?

A.The packet is being blocked by a firewall policy
B.The source interface is down
C.The destination IP address has no matching route in the routing table
D.The session table is full
AnswerC

The debug flow message 'No matching interface to route packet' means the FortiGate found no route entry for the destination IP, so the packet cannot be forwarded. The routing table lookup failed, indicating a missing or incorrect route rather than a policy or interface issue.

Why this answer

The trace indicates that FortiGate cannot find a route to forward the packet, meaning the destination is unreachable.

21
Multi-Selecthard

An administrator is configuring an active-passive HA cluster on two FortiGate devices. The administrator wants to ensure that the cluster can fail over if the primary unit's internal interface (port1) fails, and also wants to minimize the chance of a split-brain scenario. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Configure two heartbeat interfaces and enable heartbeat failover.
B.Configure port1 as a monitored interface in the HA settings.
C.Enable HA override to force the primary unit to always be primary.
D.Set the HA mode to active-active to avoid split-brain.
E.Enable session synchronization to prevent split-brain.
AnswersA, B

Configuring two heartbeat interfaces provides redundancy for heartbeat communication. If one heartbeat link fails, the other can still carry heartbeat packets, reducing the risk of split-brain. Enabling heartbeat failover allows the cluster to use the secondary heartbeat interface when the primary fails. This is a recommended practice to maintain cluster integrity and avoid both units becoming primary.

Why this answer

To fail over on internal interface failure, port1 must be monitored. To minimize split-brain, redundant heartbeat interfaces should be configured, and heartbeat failover should be enabled so that if one heartbeat link fails, the other maintains communication. Session synchronization and active-active mode do not prevent split-brain, and HA override does not address heartbeat redundancy.

Exam trap

The trap here is confusing session synchronization or HA override with split-brain prevention, when actually split-brain is mitigated by redundant heartbeat links.

22
MCQmedium

A FortiGate administrator needs to send logs to an external FortiAnalyzer for centralized monitoring. Which log configuration step is required?

A.Configure syslog server
B.Add the FortiAnalyzer as a logging device in System > FortiAnalyzer
C.Enable FortiCloud logging
D.Enable disk logging on the FortiGate
AnswerB

Adding the FortiAnalyzer as a logging device in System > FortiAnalyzer is the correct method because FortiGate communicates with FortiAnalyzer using the FortiAnalyzer protocol—a proprietary, secure connection that registers the FortiGate, handles authentication, and forwards logs to the FortiAnalyzer's dedicated log database. In the FortiAnalyzer settings you specify the FortiAnalyzer IP address, the serial number for registration, and optionally enable SSL encryption; this creates a direct log-forwarding pipeline beyond simple syslog. This integration is the designed path for an external FortiAnalyzer to receive logs, enabling centralized management, advanced search, and reporting.

Why this answer

To send logs from a FortiGate to an external FortiAnalyzer for centralized monitoring, the administrator must add the FortiAnalyzer as a logging device under System > FortiAnalyzer. This step establishes the secure, authenticated connection (typically using FortiGate's proprietary protocol over TCP/514 or TCP/3000) and enables log forwarding to the FortiAnalyzer. Without this configuration, the FortiGate will not send logs to the FortiAnalyzer, even if other logging methods are enabled.

Exam trap

The trap here is that candidates often confuse the FortiAnalyzer configuration with a generic syslog server setup, assuming any external logging destination works the same way, but FortiAnalyzer requires a specific device registration and protocol that differs from standard syslog.

How to eliminate wrong answers

Option A is wrong because configuring a syslog server sends logs in standard syslog format (RFC 3164/5424) to a generic syslog collector, not to a FortiAnalyzer, which uses a proprietary protocol for enhanced features like log correlation and reporting. Option C is wrong because enabling FortiCloud logging sends logs to FortiGate Cloud, not to an on-premises FortiAnalyzer, and is a separate service requiring a different subscription. Option D is wrong because enabling disk logging on the FortiGate stores logs locally on the FortiGate's hard disk or SSD, which does not forward logs to an external FortiAnalyzer; it only retains logs for local viewing and troubleshooting.

23
MCQhard

A FortiGate administrator has configured an active-passive HA cluster. After a failover event, the former primary unit comes back online and immediately takes over as primary again, causing another failover. The administrator wants the original primary to stay in standby until the current primary fails. Which setting should be configured?

A.Enable HA override on both units
B.Set the HA mode to active-active
C.Disable HA override on both units
D.Increase the HA priority on the primary unit
AnswerC

Disabling HA override on both units is the correct solution because this setting prevents a unit with a higher priority from preempting the current primary as long as that primary is functioning normally. With override disabled, the active primary remains the primary until it actually fails, eliminating the automatic failback event that would otherwise occur when the recovered unit comes online. This ensures stable operation and avoids unnecessary traffic interruption in an active-passive HA deployment.

Why this answer

HA override (set ha-override enable) causes a device to resume primary role when it becomes available with higher priority. Disabling override prevents this preemptive behavior.

24
MCQmedium

An administrator has configured an active-passive HA cluster. During a failover test, the standby unit becomes active but existing user sessions are lost, requiring users to re-establish connections. Which configuration change would prevent this behavior?

A.Lower HA priority on the primary
B.Enable session pickup
C.Set HA override to enabled
D.Increase the heartbeat interval
AnswerB

Enabling session pickup enables FortiOS to continuously replicate the active unit's session table, including NAT mappings and firewall state, to the standby unit over the synchronization link. On failover, the standby unit promotes itself to primary and already has all active sessions queued, enabling established connections to survive without re-handshake. This is the only option that directly addresses the requirement for stateful failover and is the standard way to preserve sessions in an active-passive HA cluster.

Why this answer

In an active-passive FortiGate HA cluster, session pickup (also called session synchronization) is the feature that replicates the session table from the primary to the standby unit. Without it enabled, when failover occurs the standby unit has no knowledge of existing sessions and drops them, forcing users to reconnect. Enabling session pickup ensures the standby has a mirrored session table so established connections continue through the failover.

Exam trap

NSE4 often tests the confusion between HA election/priority settings (override, priority) and stateful failover features (session pickup, session synchronization) — candidates pick priority or override thinking it preserves sessions, when only session pickup does.

How to eliminate wrong answers

Option A is wrong because lowering HA priority on the primary only affects which unit becomes primary during election (or with override enabled, forces the other unit to take over) — it does not synchronize session state. Option C is wrong because HA override controls whether a higher-priority unit preempts the current primary after it recovers; it has no bearing on session table synchronization. Option D is wrong because the heartbeat interval (hb-interval) only controls how frequently HA heartbeat packets are sent to detect failures; increasing it actually slows failure detection and does nothing to preserve sessions.

25
MCQmedium

A FortiGate receives log messages with severity 'warning'. What is the log severity level number for 'warning' according to FortiGate's log severity levels?

A.3
B.6
C.4
D.5
AnswerC

In FortiGate's syslog-compatible severity numbering, 4 is exactly Warning, which signals that an abnormal condition has been detected that may require action before a failure occurs. Examples include a VPN tunnel flapping or a security policy denying traffic; these are logged and displayed with the warning icon. Determining that a received log has severity 'warning' therefore maps to the numeric value 4, making this the correct answer.

Why this answer

FortiGate severity levels: Emergency=0, Alert=1, Critical=2, Error=3, Warning=4, Notification=5, Information=6, Debug=7.

26
MCQhard

A FortiGate in an active-active HA cluster is experiencing asymmetric routing. The administrator runs 'diagnose debug flow' on a packet from a client to a server. The flow trace shows the packet is allowed by policy, but the response is dropped. What is the most likely cause?

A.The TTL of the packet is too low
B.The HA mode should be changed to active-passive
C.The policy on the secondary unit has a different schedule
D.The session synchronization is not enabled between cluster members
AnswerD

In an active-active HA cluster, traffic for a single connection can egress and ingress through different members, and each member must have a copy of the session table. Without session synchronization, the secondary unit that receives the response has no record of the session created by the primary, so it treats the packet as unsolicited traffic and drops it. Enabling session synchronization (for example with 'set session-sync-dev' or using session pickup on FortiGate) ensures both units share session state and can forward replies correctly.

Why this answer

In an active-active HA cluster, session synchronization (session-pickup / session-sync) must be enabled so that return traffic arriving on a different cluster member finds the existing session. If sync is disabled, the secondary unit has no session entry and drops the response, producing the asymmetric-routing drop seen in the debug flow.

Exam trap

NSE4 often tests HA session synchronization — candidates blame HA mode or routing when the real issue is that session-pickup is disabled, causing the secondary to drop return traffic.

How to eliminate wrong answers

Option A is wrong because a low TTL would cause the packet to be dropped with a TTL-expired message, not a response drop after policy allow. Option B is wrong because changing to active-passive does not fix asymmetric routing by itself and is not the root cause; session sync is the actual fix. Option C is wrong because schedule mismatches would cause the initial packet to be denied, not the response to be dropped after the policy allowed it.

27
MCQhard

A company has two FortiGate 100F units in an active-passive HA cluster with firmware version 7.2.5. The cluster is configured with session pickup and all interfaces are monitored. The network consists of three VLANs: VLAN10 (Users), VLAN20 (Servers), and VLAN30 (DMZ). The cluster is connected to two ISPs: ISP1 (port1) and ISP2 (port2). The internal network uses a single aggregated link (port3 and port4) as a LAG to the core switch. One day, the primary FortiGate experiences a hardware failure and the secondary takes over. After the primary is replaced and rejoins the cluster, the administrator notices that traffic passing through the cluster is intermittently dropping for a few seconds every minute. The administrator checks the cluster status and sees that the new primary (previously secondary) is in 'primary' state and the old primary (newly replaced) is in 'secondary' state. What is the most likely cause of the intermittent traffic drops?

A.The LAG configuration on the new FortiGate does not match the active cluster configuration.
B.Session pickup is not enabled on the new FortiGate.
C.The HA cluster is in split-brain state.
D.The heartbeat interface is configured on the LAG, causing HA instability.
AnswerA

In an HA cluster, all interface and link aggregation group (LAG) settings—including member ports, negotiation mode, and hashing algorithm—must be identical across both units. If the replacement FortiGate's LAG configuration differs from the active cluster configuration, the cluster members cannot synchronize interface states, resulting in link instability, frequent flapping, and interrupted traffic. Traffic drops occur because the secondary's mismatched LAG is unable to pass traffic in the same manner as the primary, violating HA consistency requirements. This matches the symptom, making it the correct root cause.

Why this answer

The most likely cause is that the LAG configuration on the newly replaced FortiGate does not match the active cluster configuration. In an HA cluster, all LAG member interfaces (port3 and port4) must have identical settings—including LACP mode, speed, duplex, and VLAN membership—on both units. When the secondary FortiGate became primary and the replaced unit rejoined as secondary, any mismatch in the LAG configuration would cause the cluster to continuously renegotiate or flap the aggregated link, leading to intermittent traffic drops every few seconds as the HA cluster attempts to synchronize and stabilize the interface state.

Exam trap

The trap here is that candidates often attribute intermittent traffic drops to session pickup or split-brain issues, but the key clue is the periodic nature of the drops (every minute), which points to a configuration mismatch on the aggregated link rather than a session synchronization or HA state problem.

How to eliminate wrong answers

Option B is wrong because session pickup is a feature that synchronizes existing sessions between HA members to prevent traffic loss during failover; it does not cause intermittent drops after the cluster is stable, and it is already enabled on the cluster per the scenario. Option C is wrong because a split-brain state would cause both units to claim primary status and actively forward traffic, leading to duplicate packets and network loops, not intermittent drops every minute, and the cluster status shows one primary and one secondary. Option D is wrong because the heartbeat interface is typically a dedicated interface (e.g., port5 or a separate management port) and is not configured on the LAG; even if it were, HA instability would manifest as constant failovers or loss of heartbeat, not as periodic traffic drops of a few seconds every minute.

28
MCQmedium

A FortiGate administrator needs to send logs to a FortiAnalyzer device for long-term storage and analysis. Which log configuration must be set up?

A.Configure an IPsec tunnel to FortiAnalyzer
B.Add the FortiAnalyzer as a logging destination in Log Settings
C.Enable disk logging on the FortiGate
D.Configure syslog server pointing to FortiAnalyzer IP
AnswerB

To forward logs to FortiAnalyzer, you must explicitly configure it as a remote logging destination under Log & Report > Log Setting. You add the FortiAnalyzer's IP address, specify the log types to transmit, and set the upload schedule or real-time mode. This action enables the FortiGate to establish a session using the FortiTelemetry protocol (or FortiTelemetry over SSL/TLS) and stream logs to FortiAnalyzer, which then stores them centrally and provides reporting and analysis.

Why this answer

To send logs to FortiAnalyzer, the administrator must add FortiAnalyzer as a logging destination in the FortiGate's Log Settings (under Log & Report > Log Settings or via CLI 'config log fortianalyzer setting'). This enables the FortiGate to forward logs to the FortiAnalyzer IP address for storage and analysis.

Exam trap

NSE4 often tests the confusion between syslog and FortiAnalyzer logging, so candidates pick 'configure syslog server' thinking any log forwarding works, missing the FortiAnalyzer-specific protocol and features.

How to eliminate wrong answers

Option A is wrong because an IPsec tunnel is not required for FortiAnalyzer logging; FortiAnalyzer communication uses its own protocol (OFTP) over TCP port 514 or 443, and encryption can be enabled without IPsec. Option C is wrong because enabling disk logging on the FortiGate stores logs locally, not on FortiAnalyzer; it is a separate local storage setting. Option D is wrong because configuring a generic syslog server pointing to the FortiAnalyzer IP does not use the FortiAnalyzer protocol and will not provide the full FortiAnalyzer features like log indexing, reports, and dashboards.

29
MCQhard

A FortiGate admin wants to inspect SSL-encrypted traffic for threats using IPS. The admin creates an SSL inspection profile with 'full SSL inspection' and applies it to the policy. What additional configuration is necessary for the IPS engine to process the decrypted traffic?

A.Enable 'set ssl-ssh-profile' under the IPS sensor
B.Enable 'IPS' under the SSL inspection profile
C.Configure the FortiGate's CA certificate on clients
D.Apply an IPS sensor to the same firewall policy
AnswerD

An IPS sensor must be explicitly applied to the same firewall policy that references the SSL/SSH inspection profile. After the SSL/SSH proxy decrypted the traffic, the flow or proxy engine passes the decrypted payload to the IPS sensor, which matches it against configured intrusion signatures and enforces the defined action. Policy-level binding is essential: without both the SSL/SSH profile and the IPS sensor on the same policy, the FortiGate cannot inspect the decrypted content for threats.

Why this answer

IPS inspection requires that the security profile (IPS sensor) is also applied to the same firewall policy. SSL inspection alone only decrypts; the IPS profile inspects the decrypted traffic.

30
MCQmedium

A FortiGate cluster in active-passive HA is configured with two heartbeat interfaces. The primary unit fails completely. The secondary unit detects the failure and becomes primary. After the original primary recovers, it remains in passive mode. What is the most likely reason for this behavior?

A.The heartbeat interfaces are not properly configured
B.The HA override setting is disabled
C.The priority of the original primary is lower than the current primary
D.The HA override setting is enabled
AnswerB

The HA override setting directly controls preemption after recovery: when override is disabled, a formerly failed primary that rejoins the cluster negotiates as a standby and does not force the active unit to step down, even if it has a higher configured priority. This exactly matches the described behavior of an active-passive cluster that stays with the current primary after the original primary recovers. Since override is disabled by default on FortiGate, the cluster remains in its current role assignment.

Why this answer

When override is disabled (the default), the recovered unit will not preempt the current primary. The cluster stays with the current primary until it fails. This is the expected behavior for graceful recovery.

31
Multi-Selectmedium

An active-passive HA cluster is experiencing frequent failovers. Which TWO factors could cause unnecessary failovers? (Choose two.)

Select 2 answers
A.Using a data interface as the heartbeat interface
B.An unstable network link for the heartbeat
C.Different firmware versions on cluster members
D.Mismatched HA passwords between cluster members
E.Mismatched HA priority values
AnswersA, B

Data interfaces may have fluctuating link status, triggering failover.

Why this answer

Incorrect heartbeat interface configuration (e.g., using a busy data port) can cause false positives. A mismatched HA password prevents proper communication, but may not cause failover; mismatched priority affects role selection, not failover frequency. Unstable heartbeat links cause failover.

32
MCQmedium

A FortiGate administrator wants to configure ZTNA to secure access to an internal application. Which of the following components is essential for ZTNA to function?

A.FortiCloud
B.FortiClient EMS
C.FortiAnalyzer
D.A VPN tunnel to the client
AnswerB

FortiClient EMS is the cornerstone of Fortinet's ZTNA solution because it collects and reports user identity, endpoint inventory, and device compliance posture to FortiGate. FortiGate then uses this telemetry and EMS tags to make per-session, application-aware access decisions based on the endpoint's trust level. This identity and posture verification is what ZTNA needs to ensure that only authorized users on healthy devices can reach internal applications.

Why this answer

FortiClient EMS (Enterprise Management Server) is essential for ZTNA because it manages endpoints, enforces compliance, and provides the client certificate and posture information required for zero-trust access decisions. Without FortiClient EMS, the FortiGate cannot verify device identity and health.

Exam trap

NSE4 often tests the misconception that ZTNA requires a VPN or FortiCloud, when the essential component is FortiClient EMS for endpoint management and compliance.

How to eliminate wrong answers

Option A is wrong because FortiCloud is a cloud management platform but is not required for ZTNA functionality; it can be used for logging and management but not for endpoint identity. Option C is wrong because FortiAnalyzer is for logging and reporting, not for ZTNA enforcement. Option D is wrong because ZTNA does not require a traditional VPN tunnel; in fact, ZTNA replaces VPN with per-application access, so a VPN tunnel is not essential.

33
Multi-Selectmedium

A FortiGate administrator is troubleshooting an issue where HTTPS traffic is not being properly inspected by the web filter. The policy has SSL inspection enabled. Which TWO commands would provide the most useful real-time debugging information? (Choose two.)

Select 2 answers
A.diagnose test application ips 1
B.diagnose debug flow filter dport 443 ; diagnose debug flow show function-name ; diagnose debug enable
C.diagnose sys session filter dport 443 ; diagnose sys session list
D.execute log display
E.diagnose sniffer packet any 'port 443' 4
AnswersB, E

This sequence enables real-time flow debugging filtered to destination port 443, with function-name output to display each FortiOS inspection stage (e.g., SSL proxy, application control, IPS). The 'diagnose debug enable' command activates the trace, streaming event details to the console as the packet traverses the engine. It is the most direct way to pinpoint exactly where an HTTPS session is accepted, decrypted, blocked, or dropped.

Why this answer

Option B is correct because the debug flow commands (diagnose debug flow filter dport 443, diagnose debug flow show function-name, diagnose debug enable) provide real-time packet-path tracing that shows whether the HTTPS session is being matched to the firewall policy and whether SSL inspection is applied, which is essential for troubleshooting web-filter inspection issues. Option E is correct because diagnose sniffer packet any 'port 443' 4 captures live packets on port 443 with interface information, allowing the administrator to verify that HTTPS traffic is actually reaching the FortiGate and to observe the handshake behavior in real time. Option A is not appropriate because diagnose test application ips 1 only tests IPS engine operation and does not trace HTTPS web-filter or SSL-inspection processing.

Option C is not the best choice because diagnose sys session filter dport 443 with diagnose sys session list only shows the session table entries and does not provide real-time debugging of the inspection path. Option D is not suitable because execute log display only shows already-generated log entries and does not deliver live debugging information.

Exam trap

NSE4 often tests the specific debug commands for SSL inspection, and candidates may choose session list or logs instead of real-time debug flow and sniffer.

34
MCQmedium

A FortiGate HA cluster is running in active-passive mode with two units. The administrator notices that the primary unit fails over to the secondary unit every few minutes, causing service disruption. The heartbeat interfaces are configured on port1 and port2. What is the MOST likely cause of the frequent failovers?

A.Session synchronization is consuming too much bandwidth
B.The HA priority is set to 0 on the primary unit
C.The heartbeat interfaces are experiencing high packet loss
D.The HA override setting is enabled, causing the secondary to take over
AnswerC

The HA heartbeat link is the liveness mechanism between cluster members. High packet loss or jitter on that link causes heartbeat messages to be dropped, leading the standby unit to believe the primary is unhealthy and triggering a failover. This can result in repeated failover flaps as the primary is falsely deemed dead, then recovers. For this reason, FortiGate recommends a dedicated, reliable physical interface for HA heartbeat, not a link prone to congestion or loss.

Why this answer

In an active-passive FortiGate HA cluster, the primary and secondary units continuously exchange FGCP heartbeats over the configured heartbeat interfaces (port1 and port2). If those links experience packet loss — due to duplex mismatch, cabling issues, or a flapping switch port — the secondary stops receiving heartbeats and triggers a failover. Frequent, periodic failovers every few minutes are the classic symptom of intermittent heartbeat loss rather than a configuration error.

Exam trap

NSE4 often tests the misconception that HA priority or override settings cause failovers, when in fact intermittent heartbeat loss on the HA links is the most common cause of cluster flapping.

How to eliminate wrong answers

Option A is wrong because session synchronization (session pickup) uses a separate path and consumes negligible bandwidth relative to HA heartbeat traffic; it does not cause failovers. Option B is wrong because an HA priority of 0 does not force failover — priority 0 is a valid value and only affects election order when override is enabled; it does not cause repeated flapping. Option D is wrong because enabling override only causes the higher-priority unit to reclaim the primary role after it recovers; it does not cause the primary to fail over every few minutes while it is healthy.

35
MCQeasy

A FortiGate administrator needs to capture packets on the DMZ interface to troubleshoot a connectivity issue. Which CLI command should be used to start a packet capture?

A.diagnose sniffer packet
B.diagnose debug flow
C.diagnose sys session list
D.execute packet-capture start
AnswerA

diagnose sniffer packet is the correct FortiGate CLI command for capturing raw packets on an interface. It accepts an interface name (or 'any'), a BPF filter, a count, and a verbosity level, functioning much like tcpdump. This command provides direct visibility into the actual frames on the wire, making it the go-to tool for packet-level troubleshooting.

Why this answer

The correct CLI command to start a packet capture on a FortiGate is 'diagnose sniffer packet'. This command allows you to capture packets on a specific interface with various filters and verbosity levels. It is the standard tool for troubleshooting connectivity issues at the packet level.

Exam trap

NSE4 often tests the correct syntax for packet capture, and candidates may confuse it with debug flow or other diagnose commands.

How to eliminate wrong answers

Option B is wrong because 'diagnose debug flow' is used to trace the flow of packets through the FortiGate, showing policy lookups and forwarding decisions, but it does not capture raw packet data. Option C is wrong because 'diagnose sys session list' displays the current session table, not packet captures. Option D is wrong because 'execute packet-capture start' is not a valid FortiGate CLI command; packet capture is done via the diagnose sniffer command.

36
MCQmedium

An administrator configures a FortiGate HA cluster in active-active mode. After enabling session synchronization, they notice that new sessions are not being synced to the secondary unit. The cluster is using a dedicated heartbeat interface. What could be the reason?

A.The HA mode is set to active-passive
B.The firewall policy does not have session sync enabled
C.The session TTL is too short
D.The heartbeat interface is not configured with an IP address
AnswerB

In FortiGate active-active HA, session synchronization is not automatic — it must be enabled individually on each firewall policy using the 'session sync' option in the policy's advanced settings. Without this setting, each session is tracked only by the specific cluster unit that received its first packet, and if that unit fails or return traffic is load-balanced to a peer, the session is unknown to the other unit. This directly prevents the session table from being shared, which is exactly why the administrator observes no session synchronization.

Why this answer

In active-active HA, session synchronization requires that the session sync flag is enabled on the firewall policy. Without it, sessions are not synced.

37
MCQmedium

A company has two FortiGate units in an active-active HA cluster. They want to ensure that sessions initiated from the internet through a virtual IP are synchronized to the peer unit in case of failover. Which HA setting is required?

A.Enable 'set ha-mgmt-status enable' on the WAN interface
B.Set 'set schedule' to 'round-robin' for the VIP
C.Configure the same virtual IP on both units
D.Enable 'session-pickup' under config system ha
AnswerD

Enabling session-pickup under the 'config system ha' block instructs the FortiGate to send session table information to the secondary unit on a continuous basis, allowing the standby to have a warm copy of all active connections, including those generated via virtual IPs. When a failover occurs, the backup unit has the necessary state to keep those VIP sessions active, so users do not experience a disruption. This is the central mechanism that makes stateful failover possible in FortiGate HA and is also required for sessions that originate through the VIP to be resumed on the new active device.

Why this answer

In a FortiGate active-active HA cluster, session-pickup (also called session synchronization) must be enabled under 'config system ha' to ensure that sessions — including those initiated through a virtual IP from the internet — are synchronized to the peer unit. Without session-pickup, a failover would drop existing sessions because the new primary has no state for them. This is the specific HA setting that controls whether firewall sessions are mirrored across cluster members.

Exam trap

NSE4 often tests the distinction between HA settings that sound related — candidates pick 'configure the same VIP on both units' because it seems logical, but VIP configuration is automatic in HA; the actual requirement is enabling session-pickup.

How to eliminate wrong answers

Option A is wrong because 'ha-mgmt-status' enables a dedicated HA management interface for out-of-band access, not session synchronization. Option B is wrong because 'schedule' with 'round-robin' is not a valid VIP setting for HA session handling; VIP scheduling is unrelated to session pickup. Option C is wrong because configuring the same VIP on both units is already inherent to HA VIP behavior — it does not by itself synchronize sessions; session-pickup is the required setting.

38
MCQhard

During a failover in an active-passive HA cluster, the newly active unit does not have the same session table as the previous primary, causing all existing sessions to drop. Which setting should the administrator verify?

A.HA override is enabled on both units
B.The heartbeat interface is configured as a dedicated management interface
C.The session pickup setting is enabled
D.The cluster is operating in active-active mode
AnswerC

In an active-passive HA cluster, the session pickup feature continuously synchronizes the session table from the primary unit to the standby unit, so that the standby can take over existing sessions seamlessly on failover. When session pickup is enabled, the secondary unit maintains a fully updated copy of all session entries, and the newly active unit can continue forwarding traffic for those connections without interruption. If this setting were disabled, all sessions would need to be re-established after a failover, causing connection drops for clients.

Why this answer

Session synchronization must be enabled and properly configured to replicate sessions to the standby unit.

39
MCQhard

In an active-active HA cluster, what is the purpose of the 'session sync' configuration?

A.To synchronize configuration changes between cluster members
B.To balance the number of sessions across cluster members
C.To replicate session state so that if one unit fails, another can take over without interruption
D.To synchronize the time between cluster members
AnswerC

Session synchronization replicates the full state of active sessions—including TCP sequence numbers, NAT translations, and timers—from the unit that owns the session to every other member of the cluster. If the owning unit fails, a peer that has an identical session record can immediately resume forwarding traffic without requiring clients to re-establish their connections. This stateful takeover is critical for seamless failover in high-availability clusters.

Why this answer

Session sync ensures that sessions are shared between cluster units so that any unit can handle traffic for a given session.

40
MCQhard

An administrator runs 'diagnose sys session filter dport 443' and then 'diagnose sys session list'. The output shows many sessions with 'proto_state=01' and 'expire=3599'. What does 'expire=3599' indicate?

A.The session has 3599 packets
B.The session has been alive for 3599 seconds
C.The session has 3599 bytes of data transferred
D.The session will timeout in 3599 seconds
AnswerD

The expire counter shows the remaining lifetime before FortiGate removes the session from its session table, decrementing each second from the configured timeout. With proto_state=01 confirming an established TCP session, expire=3599 means roughly one hour remains before idle timeout eviction, directly answering what the field indicates.

Why this answer

In FortiGate diagnostics, the 'expire' field in the session list output indicates the remaining time in seconds before the session times out. A value of 3599 seconds means the session will be removed from the session table after that many seconds of inactivity, assuming no further traffic matches the session. This is a key metric for understanding session lifecycle and timeout behavior.

Exam trap

The trap here is confusing 'expire' (remaining time until timeout) with 'duration' (time since session creation), leading candidates to incorrectly select option B.

How to eliminate wrong answers

Option A is wrong because 'expire' does not represent a packet count; packet counts are shown in separate fields like 'packets' or 'pkt_in/pkt_out'. Option B is wrong because 'expire' is the remaining time until timeout, not the elapsed time since the session was created; the 'duration' field tracks how long the session has been alive. Option C is wrong because 'expire' is unrelated to data transfer size; byte counts are displayed in fields such as 'bytes' or 'total_bytes'.

41
MCQeasy

Which FortiGate log type records information about firewall policy matches and traffic statistics?

A.Event logs
B.Traffic logs
C.Audit logs
D.Security logs
AnswerB

Traffic logs are written by the FortiGate session table when a flow matches an explicit or implicit firewall policy. Each entry records the policy ID, session ID, source and destination IP/port, interfaces, NAT translations, and byte/packet counts for both directions. They also indicate the action taken, such as accept, deny, or SSL-negotiation failure. This is the dedicated log type for reviewing which firewall policies allowed or blocked specific sessions and how much bandwidth they consumed.

Why this answer

FortiGate traffic logs record information about firewall policy matches, including source and destination IP addresses, ports, protocols, and the action taken (allow/deny). They also include traffic statistics such as bytes sent and received. Therefore, traffic logs are the correct log type for this information.

Exam trap

NSE4 often tests the distinction between log types, and candidates may confuse traffic logs with event or security logs, especially when the question mentions 'firewall policy matches' which could be misconstrued as security events.

How to eliminate wrong answers

Option A is wrong because event logs record system events such as administrator logins, configuration changes, and HA events, not traffic details. Option C is wrong because audit logs are a subset of event logs that specifically record administrative actions and configuration changes. Option D is wrong because security logs are not a standard FortiGate log type; security-related events are typically found in event logs or specific security logs like IPS or antivirus logs, but they do not record general traffic statistics.

42
MCQmedium

A FortiGate is configured in an active-passive HA cluster. The administrator wants to verify which unit is currently the primary and also see the HA uptime and priority of each unit. Which command should the administrator use?

A.get system ha status
B.diagnose sys ha status
C.show system ha
D.diagnose sys ha dump
AnswerA

This command displays the HA cluster status, including which unit is primary, the HA uptime, and the priority of each member. It provides a concise summary directly from the CLI, making it ideal for quickly verifying the active unit and its attributes in an active-passive setup.

Why this answer

The command 'get system ha status' is the correct way to view the current HA status on a FortiGate. It shows which unit is the primary, the HA uptime, and the priority of each cluster member. This directly answers the administrator's need to verify the active unit and its attributes in an active-passive cluster.

Exam trap

The trap here is confusing configuration display commands like 'show system ha' with operational status commands like 'get system ha status'.

43
MCQmedium

An administrator needs to ensure that in an active-passive HA cluster, the primary unit always remains the preferred master unless it fails, regardless of other factors. The administrator sets the primary's HA priority to 200 and the secondary to 100. However, after a reboot of the primary, the secondary becomes the primary. What additional step is required?

A.Set 'set ha-mgmt-status enable' on the primary
B.Reduce the secondary priority to 0
C.Increase the primary priority to 255
D.Set 'set override enable' under config system ha
AnswerD

Enabling 'override' in the HA configuration is the correct way to allow a higher-priority unit to preempt and become primary again after it recovers from a failure. When 'override' is enabled, the cluster continuously compares the priority of all units, and if a unit with a higher priority comes back online, it will actively take over the primary role. This ensures that in an active-passive setup, the preferred primary unit will regain mastership after a failover, instead of letting the secondary remain as primary indefinitely. The command is configured under 'config system ha' and is essential for automatic failback.

Why this answer

In HA, the 'override' setting (or 'set override enable') ensures that when the primary recovers, it will preempt the current primary and become active again. Without override, the cluster uses a non-preemptive mode: once a unit becomes primary, it stays primary even if a higher-priority unit comes back online.

44
Multi-Selectmedium

A FortiGate administrator needs to ensure that a specific traffic flow is fully inspected by the antivirus and IPS profiles. The traffic is HTTPS. Which THREE configuration items are required? (Select three.)

Select 3 answers
A.Enable flow-based inspection mode globally
B.Apply an IPS profile to the firewall policy
C.Apply an antivirus profile to the firewall policy
D.Enable SSL/TSL deep inspection on the firewall policy
E.Configure a DNS filter profile
AnswersB, C, D

An IPS profile contains signatures and anomaly detection rules that inspect traffic for known vulnerabilities, exploits, and attack patterns. By applying this profile to the firewall policy, the FortiGate can block malicious packets in real time, which directly addresses the requirement to secure the specific traffic flow. Without the profile, even with flow-based inspection enabled, the device would not have the rulebase to identify intrusion attempts.

Why this answer

Option B is correct because an IPS profile must be attached to the firewall policy for the FortiGate to inspect the traffic flow for intrusions and exploits. Option C is correct because an antivirus profile must also be applied to the firewall policy so that the same traffic is scanned for malware and viruses. Option D is correct because the traffic is HTTPS, so SSL/TLS deep inspection must be enabled on the firewall policy to decrypt the traffic and allow the antivirus and IPS engines to inspect the payload.

Option A is not required because flow-based inspection mode is a global inspection setting and is not a mandatory item for applying antivirus and IPS profiles to a specific HTTPS policy. Option E is not required because a DNS filter profile is used for DNS security filtering and does not enable antivirus or IPS inspection of HTTPS traffic.

Exam trap

NSE4 often tests the misconception that simply applying antivirus and IPS profiles to a policy is enough to inspect HTTPS traffic, but without SSL deep inspection, the FortiGate cannot see inside the encrypted tunnel, so the profiles are ineffective.

45
Multi-Selectmedium

A FortiGate administrator is troubleshooting a traffic issue where users cannot access a specific website. The administrator runs 'diagnose debug flow' and sees the output indicating that traffic is being denied by a firewall policy. Which two actions should the administrator take to identify the specific policy denying the traffic? (Choose two.)

Select 2 answers
A.Run 'diagnose debug enable' and then reproduce the issue
B.Use 'diagnose sys session list' to find the policy ID
C.Review the policy list and look for the policy ID shown in the debug output
D.Check the traffic log for the session to see the policy ID
E.Disable all firewall policies temporarily
AnswersC, D

When you run 'diagnose debug flow', the output includes a log line that states the matching policy ID, for example "op=... policyid=..." for each packet. By reviewing the firewall policy list and looking up that specific policy ID, the administrator can directly inspect the action, schedule, source/destination addresses, and services configured on that policy to determine why it is handling the traffic unexpectedly.

Why this answer

Option C is correct because the 'diagnose debug flow' output explicitly prints the policy ID (e.g., 'matched policy 5') that denied the traffic, so reviewing the firewall policy list for that ID pinpoints the exact offending policy. Option D is correct because FortiGate traffic logs record the policy ID (policyid) for each session, so checking the log entry for the denied session reveals the same policy identifier and confirms which rule blocked the traffic. Option A is not the right action because 'diagnose debug enable' only turns on debug output; it does not itself identify the policy, and the administrator has already captured the flow output.

Option B is incorrect because 'diagnose sys session list' shows session details such as source/destination and state, but it does not reliably surface the denying policy ID for a denied flow. Option E is incorrect and dangerous because disabling all firewall policies would remove security enforcement and is not a valid troubleshooting step.

Exam trap

NSE4 often tests whether candidates know that debug flow output itself contains the policy ID, so they waste time on session list or disabling policies instead of reading the trace and correlating with logs.

46
MCQmedium

An administrator notices that the FortiGate HA cluster has two units, but only one is shown as 'primary' and the other as 'standby'. The administrator did not configure any load balancing. Which HA mode is in use?

A.Active-passive
B.Load-balanced cluster
C.Standalone
D.Active-active
AnswerA

Active-passive is the standard FortiGate HA mode in which one cluster unit holds the primary/active role and processes all production traffic, while the second unit remains in standby, synchronizing configuration and (if session pickup is enabled) session state via the dedicated HA heartbeat link. When the active unit fails or loses heartbeats, the standby unit is promoted to active and takes over the virtual cluster interfaces, providing transparent failover with minimal disruption.

Why this answer

In active-passive HA mode, one FortiGate unit is the primary (active) and the other is the standby (passive), with no traffic load balancing between them. The scenario describes exactly one primary and one standby with no load balancing configured, which matches active-passive. Active-active would show both units processing traffic, and load-balanced cluster is not a FortiGate HA mode.

Exam trap

NSE4 often tests the visual signature of HA modes — one primary plus one standby equals active-passive — so candidates confuse it with active-active or invent a 'load-balanced' mode that does not exist.

How to eliminate wrong answers

Option B is wrong because 'load-balanced cluster' is not a valid FortiGate HA mode; FortiGate HA modes are active-passive and active-active. Option C is wrong because standalone means a single FortiGate with no HA cluster at all, which contradicts the presence of two units in a cluster. Option D is wrong because active-active HA would show both units actively processing traffic (often with session distribution), not one primary and one standby.

47
MCQeasy

A FortiGate administrator needs to check the current HA status of a two-unit cluster. The administrator wants to see which unit is the primary, the HA mode, and the uptime of each unit. Which command should the administrator use?

A.diagnose sys ha status
B.show system ha
C.diagnose sys ha checksum
D.get system ha status
AnswerA

The 'diagnose sys ha status' command displays detailed HA status information, including the current primary unit, HA mode, cluster uptime, and the status of each member. It is the correct command to quickly assess the HA cluster's health and roles. This command is commonly used for troubleshooting and verification.

Why this answer

To view the current HA status, including which unit is primary, the HA mode, and uptime, the administrator should use 'diagnose sys ha status'. This command provides a comprehensive overview of the cluster's operational state and is the standard tool for HA monitoring and troubleshooting.

Exam trap

The trap here is confusing configuration commands like 'show system ha' with status commands; 'show' displays settings, while 'diagnose sys ha status' reveals real-time operational status.

48
MCQmedium

An administrator is configuring a FortiGate HA cluster and wants to ensure that the primary unit is always preferred based on its configuration priority. Which setting should be enabled to allow the primary unit to resume its role after a failover if it regains connectivity?

A.set ha-inherit-priority enable
B.set override enable
C.set session-pickup enable
D.set ha-priority 255
AnswerB

Setting 'override enable' is the correct way to make a higher-priority FortiGate unit reclaim the primary role in a cluster. When enabled, a unit that becomes healthy and has a higher configured priority than the current primary will preempt the role back, ensuring the preferred unit resumes active control. This is essential for deterministic failback after maintenance or an outage, because without override the lower-priority unit would stay primary until it fails.

Why this answer

The 'set override enable' setting allows the primary unit to resume its role after a failover if it regains connectivity, based on its configured priority. Without override, the cluster does not preempt; the current primary remains primary even if a higher-priority unit rejoins. Enabling override ensures the primary unit always takes back its role when available.

Exam trap

The trap is confusing priority setting with override; candidates might think setting a high priority alone ensures preemption, but override must be enabled for the priority to take effect after failover.

How to eliminate wrong answers

Option A is wrong because 'set ha-inherit-priority enable' is not a valid FortiGate command; HA priority inheritance is not a standard feature. Option C is wrong because 'set session-pickup enable' enables session failover, not priority-based preemption. Option D is wrong because 'set ha-priority 255' sets the priority value but does not enable override; without override, the priority is not used for preemption.

49
MCQmedium

A FortiGate administrator manages an active-passive HA cluster of two FGCP units. The administrator needs to upgrade the firmware on the cluster with minimal downtime. The administrator has already uploaded the new firmware image to both units. Which step should the administrator take next to ensure the secondary unit is upgraded first and the cluster remains available?

A.Run 'execute ha manage 1' to access the secondary unit, then run 'execute restore image <firmware_file>' to install the new firmware.
B.Run 'diagnose sys ha upgrade' to trigger the firmware upgrade process on the secondary unit.
C.Run 'execute ha synchronize start' to push the firmware from the primary to the secondary.
D.Run 'execute ha manage 1' to access the secondary unit, then run 'execute reboot' to reboot it into the new firmware.
AnswerA

After uploading the firmware to both units, the administrator should log into the secondary unit via 'execute ha manage 1' and then use 'execute restore image' to install the new firmware. This upgrades the secondary first, then the primary can be upgraded later, minimizing downtime. This is the recommended HA firmware upgrade procedure.

Why this answer

In an active-passive HA cluster, upgrading firmware with minimal downtime involves upgrading the secondary unit first, then triggering a failover so the upgraded secondary becomes primary, and finally upgrading the original primary. Accessing the secondary via 'execute ha manage' and using 'execute restore image' is the correct method. This ensures the cluster remains available during the upgrade process.

Exam trap

The trap here is assuming that simply rebooting the secondary unit or using HA synchronization commands will upgrade its firmware, when in fact firmware must be installed locally on each unit using the restore image command.

50
MCQeasy

Which FortiGate diagnostic command allows you to capture packets on an interface for troubleshooting network connectivity issues?

A.diagnose debug flow
B.diagnose sniffer packet
C.diagnose sys session list
D.diagnose test application
AnswerB

The `diagnose sniffer packet` command is FortiGate's built-in packet capture utility, equivalent to tcpdump. It allows you to capture raw packets on one or more interfaces with flexible BPF-style filters (e.g., host, port, protocol) and verbosity levels (1 for headers, 2 for headers+payload, 3 for full packet details). This is the canonical command for performing a packet capture on FortiGate, making it the correct answer for capturing packets.

Why this answer

The 'diagnose sniffer packet' command on a FortiGate captures packets on a specified interface, similar to tcpdump. It allows administrators to see live packet data for troubleshooting connectivity, filtering by interface, protocol, host, port, and verbosity level. This is the correct tool for packet-level capture.

Exam trap

NSE4 often tests the distinction between 'diagnose sniffer packet' (packet capture) and 'diagnose debug flow' (flow tracing) — candidates confuse the two when asked about capturing packets on an interface.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug flow' traces the flow of packets through the FortiGate's inspection engine, showing policy lookups and forwarding decisions — it does not capture raw packets on an interface. Option C is wrong because 'diagnose sys session list' displays the session table, not packet captures. Option D is wrong because 'diagnose test application' runs diagnostic tests on FortiGate applications/daemons, not packet capture.

51
MCQmedium

An administrator is troubleshooting a FortiGate HA cluster that is experiencing frequent failovers. The heartbeat interfaces are configured on port1 and port2. Which diagnostic command should the administrator use to check heartbeat packet loss?

A.diagnose sys ha status
B.get system ha status
C.diagnose sys ha heartbeat
D.diagnose sys session list
AnswerC

This command queries the HA daemon's internal statistics and specifically reports the number of consecutive sent and received heartbeat packets as well as the computed packet loss rate. It is the only command in this list that directly measures the reliability of the heartbeat link, which is essential for diagnosing intermittent failovers or a split-brain condition. A non-zero loss percentage here indicates a degraded heartbeat path, pointing to physical-layer issues such as bad cables, duplex mismatches, or congested interfaces.

Why this answer

The 'diagnose sys ha heartbeat' command is the dedicated diagnostic tool for inspecting HA heartbeat interface statistics, including packet counts, errors, and loss on the configured heartbeat ports (port1 and port2 in this scenario). It shows per-interface heartbeat traffic details that directly reveal whether heartbeats are being dropped, which is the root cause of frequent failovers. This is the only option that targets heartbeat packet-level diagnostics rather than general HA state.

Exam trap

NSE4 often tests the confusion between HA status commands ('get system ha status', 'diagnose sys ha status') and the heartbeat-specific diagnostic, so candidates pick a status command that shows roles but not packet loss.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys ha status' displays HA cluster status information (member roles, priorities, uptime) but does not provide heartbeat packet loss statistics. Option B is wrong because 'get system ha status' is a configuration/status summary command showing HA mode, group name, and member health, not heartbeat packet counters. Option D is wrong because 'diagnose sys session list' shows the session table for traffic flows and has nothing to do with HA heartbeat interface diagnostics.

52
Multi-Selecthard

A FortiGate is configured in an A-P HA cluster. The administrator wants to ensure that session failover occurs for UDP-based voice traffic. Which TWO settings must be enabled?

Select 2 answers
A.Enable UDP session synchronization.
B.Set HA override to enabled.
C.Enable configuration synchronization.
D.Enable session pickup.
E.Set failover hold time to 1 second.
AnswersA, D

Enabling UDP session synchronization directly instructs the FGCP cluster to replicate UDP session table entries from the primary unit to the standby. Because UDP is connectionless, the standby cannot infer active flows from handshake packets, so without this explicit setting, return traffic for existing UDP conversations will be dropped after failover. This setting is protocol-specific and works alongside session pickup to ensure NAT bindings and idle timers are preserved on the new primary.

Why this answer

UDP session synchronization must be enabled to replicate UDP session state between HA cluster members, ensuring that active sessions for voice traffic (which typically uses UDP) are seamlessly taken over by the standby unit during a failover. Without this setting, UDP sessions are not synchronized by default, and voice calls would drop.

Exam trap

The trap here is that candidates often confuse configuration synchronization (which replicates config files) with session synchronization (which replicates dynamic session state), leading them to incorrectly select Option C instead of A.

53
MCQmedium

An administrator wants to view the current session table entries filtered by destination port 443. Which command should be used?

A.diagnose sys session filter dport 443; diagnose sys session list
B.execute session list dport 443
C.diagnose debug flow filter dport 443
D.diagnose sys session list dport 443
AnswerA

The correct workflow in FortiOS for inspecting the session table is to first set a filter with 'diagnose sys session filter dport 443', which configures the current CLI session to show only sessions with a destination port of 443. Then 'diagnose sys session list' prints the matching entries from the kernel session table. This two-step approach lets you combine multiple filter criteria without passing them as command arguments.

Why this answer

FortiGate session table inspection uses the 'diagnose sys session filter' command to set filter criteria (such as dport 443), followed by 'diagnose sys session list' to display matching entries. This two-step filter-then-list pattern is the correct syntax.

Exam trap

NSE4 often tests whether candidates confuse 'diagnose sys session filter/list' (session table inspection) with 'diagnose debug flow filter' (real-time packet debugging), leading them to pick the debug flow command.

How to eliminate wrong answers

Option B is wrong because 'execute session list' is not a valid FortiGate command — session inspection is done via 'diagnose sys session,' not 'execute.' Option C is wrong because 'diagnose debug flow filter' is used for real-time packet flow debugging, not for viewing existing session table entries. Option D is wrong because 'diagnose sys session list dport 443' is invalid syntax — the filter must be set separately with 'diagnose sys session filter' before listing.

54
MCQeasy

Which log severity level indicates that a device is unusable and requires immediate attention?

A.Error
B.Critical
C.Emergency
D.Alert
AnswerC

Emergency (severity 0) is the highest syslog severity level and specifically denotes that the system is unusable. On FortiGate, this log is generated when a fatal condition halts operations, such as a kernel panic or a catastrophic disk failure that prevents booting. Unlike lower severities, Emergency means the device cannot perform its security functions or be administered until it is restarted or repaired.

Why this answer

FortiGate log severity levels are: Emergency (0), Alert (1), Critical (2), Error (3), Warning (4), Notification (5), Information (6), Debug (7). Emergency is the highest severity, indicating the system is unusable.

55
MCQmedium

An organization wants to send FortiGate logs to a central log management system for long-term storage and compliance. Which FortiGate feature is specifically designed for collecting and analyzing logs from multiple FortiGate devices?

A.Disk logging
B.FortiGuard
C.FortiCloud
D.FortiAnalyzer
AnswerD

FortiAnalyzer is Fortinet's dedicated log management and analysis appliance, purpose-built to aggregate logs from FortiGate and other Fortinet devices to a central location. It provides high-capacity storage, real-time search, reporting, and event correlation, making it the standard for enterprise centralized logging. Configuring FortiGate to send logs to FortiAnalyzer via the FortiGate's log settings or Security Fabric fully meets the organization's central log collection need.

Why this answer

FortiAnalyzer is Fortinet's dedicated centralized logging, analysis, and reporting appliance (physical or virtual) designed to collect logs from multiple FortiGate devices, FortiSwitches, FortiAPs, and other Fortinet products. It provides long-term storage, compliance reporting, and advanced analytics such as event correlation and security fabric rating. Unlike local disk logging, FortiAnalyzer aggregates logs from many devices into a single repository, making it the correct choice for centralized log management.

Exam trap

NSE4 often tests the distinction between local logging (disk logging) and centralized logging (FortiAnalyzer), and candidates may confuse FortiCloud with FortiAnalyzer because both offer cloud-based log storage; however, FortiAnalyzer is the dedicated on-prem or virtual appliance for multi-device log collection and analysis.

How to eliminate wrong answers

Option A is wrong because disk logging refers to storing logs locally on the FortiGate's internal disk or a connected USB drive, which is limited to that single device and not designed for central collection from multiple FortiGates. Option B is wrong because FortiGuard is a suite of subscription-based security services (e.g., antivirus, IPS, web filtering) that provide threat intelligence and updates, not a log management system. Option C is wrong because FortiCloud is a cloud-based management and logging service that can collect logs, but it is not specifically designed for multi-device log aggregation and analysis in the same way as FortiAnalyzer; FortiCloud is more focused on management and basic logging for smaller deployments, whereas FortiAnalyzer is the dedicated enterprise-grade solution.

56
MCQmedium

A network admin receives an alert that the FortiGate disk logs are no longer being written. The admin checks the disk status and sees that the disk is full. However, the admin needs to preserve the logs for compliance purposes. Which action should the admin take to continue logging while preserving the existing logs?

A.Configure log upload to FortiAnalyzer and manually archive current logs, then clear the local disk
B.Increase the log disk quota to allow more logs
C.Delete all logs from the disk and restart logging
D.Compress the existing log files and set a higher compression level for future logs
AnswerA

Offloading new logs to FortiAnalyzer frees local disk space while retaining compliance evidence, and archiving existing logs before clearing preserves them. This satisfies the stem's dual constraint: continue logging and keep the current logs, which simply deleting or disabling logging would violate.

Why this answer

The correct action is to configure log upload to FortiAnalyzer and manually archive the current logs, then clear the local disk. This preserves the logs for compliance by offloading them to an external server, while freeing up disk space to allow new logging to continue. Other options are incorrect: increasing the disk quota does not solve the full issue, deleting logs loses compliance data, and compression alone may not free enough space immediately.

57
MCQhard

A FortiGate administrator runs 'diagnose sys session filter dport 443' followed by 'diagnose sys session list' and sees the following output for a session: src=10.0.1.10 dst=192.168.2.20 sport=12345 dport=443 proto=6 vrf=0 What does the 'proto=6' indicate about this session?

A.The session is using UDP
B.The session is using ESP
C.The session is using TCP
D.The session is using ICMP
AnswerC

TCP, or Transmission Control Protocol, is indeed assigned IP protocol number 6, which is what the session filter output indicates. This is standard across all IP networks, as defined by the IANA protocol numbers. A FortiGate session for applications such as HTTP, SSH, or SMTP would show 'Proto=6' to represent TCP. Therefore, the correct interpretation of the protocol numeral in the diagnostic output is that the session is using TCP as its transport layer protocol.

Why this answer

In IP protocol numbers, 6 represents TCP. The session output shows proto=6, which means the session is using TCP. This is consistent with dport=443, the standard HTTPS port over TCP.

The FortiGate session table uses IANA protocol numbers to identify the transport protocol.

Exam trap

NSE4 often tests whether candidates know IANA protocol numbers in session output, trapping those who confuse proto=6 with UDP or assume the protocol from the port number alone.

How to eliminate wrong answers

Option A is wrong because UDP is protocol number 17, not 6. Option B is wrong because ESP (Encapsulating Security Payload) is protocol number 50, not 6. Option D is wrong because ICMP is protocol number 1, not 6.

58
MCQmedium

A FortiGate administrator notices that the HA cluster is frequently failing over even though no hardware failure has occurred. The heartbeat link shows some packet loss. What is the best action to reduce unnecessary failovers?

A.Lower the heartbeat interval
B.Change HA mode to active-active
C.Increase the failover threshold
D.Disable session synchronization
AnswerC

The failover threshold (often called the missed-heartbeat threshold) specifies how many consecutive heartbeat packets from the primary must be lost before the secondary unit declares a failover. Increasing this threshold from the default of 3 to a larger value allows the cluster to tolerate small bursts of packet loss or a momentary HA link issue without triggering a failover. This directly reduces spurious failovers while still detecting a true primary outage if the primary remains silent for a longer period, making it the correct corrective action.

Why this answer

The failover threshold (also called heartbeat loss threshold) determines how many consecutive heartbeat packets must be missed before a failover is triggered. By increasing this threshold, the FortiGate will tolerate more packet loss on the heartbeat link before declaring a failure, thus reducing unnecessary failovers caused by transient network issues. This directly addresses the root cause: intermittent packet loss on the heartbeat link.

Lowering the interval would make the problem worse, and changing HA mode or disabling session sync does not affect failover sensitivity.

Exam trap

NSE4 often tests the misconception that lowering the heartbeat interval improves HA responsiveness, but it actually increases sensitivity to packet loss and can cause more failovers.

How to eliminate wrong answers

Option A is wrong because lowering the heartbeat interval increases the frequency of heartbeat packets, which can exacerbate the issue by causing more missed heartbeats in a lossy network, leading to more failovers. Option B is wrong because changing HA mode to active-active does not affect the failover threshold; it only changes how traffic is distributed, and failover still occurs based on heartbeat loss. Option D is wrong because disabling session synchronization does not impact the failover mechanism; it only affects session state sharing between cluster members, which is unrelated to failover triggers.

59
Multi-Selecteasy

A FortiGate administrator wants to send logs to both a local disk and a remote FortiCloud account. Which two conditions must be met for this to work? (Choose two.)

Select 2 answers
A.The FortiGate must be configured to log to both destinations simultaneously
B.The FortiGate must have a valid FortiCloud subscription
C.The FortiGate must be in NAT mode
D.The FortiGate must have a hard disk or SSD installed
E.The FortiGate must have a policy to allow outbound traffic to FortiCloud
AnswersB, D

A valid FortiCloud subscription is mandatory because FortiCloud logging is a licensed cloud service. The FortiGate must authenticate to FortiCloud's servers using the registered account's credentials and entitlement; without an active subscription, log upload attempts will be rejected even if local disk storage is available. This subscription is a hard prerequisite that cannot be bypassed by configuration alone.

Why this answer

The FortiGate must have local storage (disk) to store logs locally. It also must have connectivity to FortiCloud servers, and logging to FortiCloud must be enabled. The local disk logging is a separate configuration.

60
MCQeasy

Which of the following FortiGate log types records information about user authentication and administrative access?

A.Event logs
B.Traffic logs
C.System logs
D.Security logs
AnswerA

Event logs are the correct FortiGate log type for authentication records, as they capture administrative login/logout, user authentication attempts, and enforcement of authentication policies. They also log configuration changes and system policy events, making them the central repository for user-access accountability. For example, both successful and failed logins via the web GUI or SSH are written to the event log with timestamps and source IPs.

Why this answer

Event logs on a FortiGate record system-level and administrative activity, including administrator logins, configuration changes, user authentication events, and system operations. This is the log category that captures both user authentication and administrative access events, making it the correct answer. Traffic logs record session-level data (source/destination, bytes, action), while security logs cover UTM events like IPS and antivirus detections.

Exam trap

NSE4 often tests the confusion between Event logs and System logs — candidates assume 'System logs' is a real FortiGate category when system-level events are actually recorded under Event logs.

How to eliminate wrong answers

Option B is wrong because traffic logs record forwarded, denied, or allowed network sessions with Layer 3/4 details — they do not capture authentication or admin access events. Option C is wrong because 'System logs' is not a distinct FortiGate log category in the FortiView/log-type taxonomy; system-level events are folded into Event logs. Option D is wrong because security logs capture UTM inspection results (IPS, antivirus, web filter, app control) rather than authentication or administrative access records.

61
Multi-Selecthard

An administrator is troubleshooting an issue where users cannot access an internal web server via the internet through a FortiGate. The FortiGate has a virtual IP (VIP) configured for the web server. The administrator runs 'diagnose debug flow filter daddr <public-ip>' and 'diagnose debug flow trace start 100'. The output shows 'msg: forward to x.x.x.x via intf port2' but then 'msg: policy deny'. Which TWO actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Ensure that a static route exists to the internet via the WAN interface
B.Check if the public DNS resolution for the domain is correct
C.Confirm that the firewall policy's destination is set to the internal web server's IP address (or the VIP's mapped IP)
D.Verify that the firewall policy allowing the traffic has the correct source interface (WAN)
E.Recreate the virtual IP object with a different port
AnswersC, D

After DNAT, the destination IP changes to the internal server. The firewall policy must allow traffic to that internal IP. If the policy's destination is set to the VIP's public IP, it may not match post-DNAT. The correct approach is to set the destination to the mapped IP address.

Why this answer

Option C is correct because when a VIP is used, the firewall policy must reference the VIP object (or its mapped internal IP) as the destination; if the policy destination is left as 'all' or points to the wrong address, the flow trace will show 'policy deny' even though the packet is forwarded toward port2. Option D is correct because the policy permitting inbound access must match the actual ingress interface (the WAN interface where the public IP is reached); if the source interface is set to the internal/LAN interface or 'any' incorrectly, the policy lookup fails and produces 'policy deny'. Option A is not the issue here since the trace already shows the packet being forwarded out via intf port2, meaning routing toward the server exists and the deny occurs at policy evaluation, not at the routing stage.

Option B is irrelevant because DNS resolution only affects name-to-IP mapping and would not cause a FortiGate policy deny for an already-arriving packet. Option E is unnecessary because the VIP is functioning (traffic is being forwarded), and changing the port would not fix a policy-match failure.

Exam trap

NSE4 often tests the interpretation of 'diagnose debug flow' output, and candidates may focus on routing or DNS instead of recognizing that 'policy deny' points directly to a firewall policy mismatch in source interface or destination address.

62
Multi-Selectmedium

An administrator needs to configure HA on a pair of FortiGates with the following requirements: the cluster must support session failover for TCP, UDP, and ICMP; the management interface should be accessible on both units; and the failover must be triggered if port2 goes down. Which TWO settings must be configured? (Choose two.)

Select 2 answers
A.Enable session pickup
B.Configure a dedicated management interface
C.Add port2 to the monitored interfaces
D.Set the HA mode to active-passive
E.Set the HA override to enabled
AnswersA, C

Enabling session pickup is essential for stateful failover in a FortiGate HA cluster. It synchronizes the session table, including NAT translations, TCP/UDP state, and even application-layer protocol states, between the primary and standby units. This ensures that when a failover occurs, existing connections are not dropped and can continue seamlessly on the new primary. Without session pickup, even if the interface goes down and failover is triggered, all active sessions would be lost, causing disruption to users.

Why this answer

Option A (Enable session pickup) is correct because session pickup is the FortiGate HA setting that synchronizes session state tables across cluster members, which is exactly what enables TCP, UDP, and ICMP sessions to survive a failover to the other unit. Option C (Add port2 to the monitored interfaces) is correct because HA monitors only the interfaces explicitly listed in the monitored-interface configuration; adding port2 ensures that if that link goes down, the unit's HA priority is reduced or it fails over as required. Option B is not required because the requirement is that the management interface be reachable on both units, which is achieved by allowing management access on the HA interfaces or via reserved management interfaces, not by a mandatory dedicated management interface setting.

Option D is not required because session failover and interface monitoring work in both active-passive and active-active modes, so the mode does not have to be active-passive. Option E is not required because override only controls whether a unit with higher priority preempts the primary after it recovers; it is not needed to trigger failover on a link-down event.

Exam trap

NSE4 often tests the misconception that active-passive mode alone provides session failover, when in fact session pickup must be explicitly enabled and monitored interfaces must be configured to trigger failover.

63
MCQmedium

In an active-active HA cluster, session synchronization is enabled. What is the primary purpose of session synchronization in this mode?

A.To synchronize firewall policies between cluster members
B.To load balance traffic across the cluster
C.To reduce the number of sessions on each unit
D.To ensure that sessions are not lost if a cluster unit fails
AnswerD

Session synchronization's core purpose is to ensure stateful high availability: if one firewall unit fails or is taken out of service, the cluster's other unit(s) already possess the full session information—including NAT mappings, TCP sequence state, and application-level data—required to continue forwarding traffic without resetting connections. This is achieved by continuously transmitting session updates over the HA heartbeat link from the unit that owns each session to its standby or peer units. By doing so, the cluster can fail over in milliseconds, and existing sessions survive the failure. This is fundamental to delivering uninterrupted connectivity in an enterprise network.

Why this answer

Session synchronization in an active-active HA cluster ensures that session state (such as TCP connection state, NAT translations, and sequence numbers) is replicated between cluster members. If one unit fails, the surviving unit already has the session information and can continue forwarding traffic without dropping existing connections.

Exam trap

NSE4 often tests the confusion between session synchronization (runtime session state) and configuration synchronization (policies and objects), leading candidates to pick the policy-related answer.

How to eliminate wrong answers

Option A is wrong because firewall policies are synchronized via configuration synchronization, not session synchronization — session sync deals with runtime session state, not policy definitions. Option B is wrong because load balancing is handled by the HA load-balancing algorithm and virtual MAC/ARP mechanisms, not by session synchronization. Option C is wrong because session synchronization replicates sessions to peers, which can increase the number of sessions on each unit rather than reduce them.

64
MCQeasy

Which FortiGate log severity level indicates that a system is unusable and requires immediate attention?

A.Error
B.Critical
C.Emergency
D.Alert
AnswerC

Emergency (severity 0) is the highest log severity level and is reserved for situations where the FortiGate system is completely unusable, such as a kernel panic, total configuration failure, or unrecoverable hardware fault. This level indicates that the firewall cannot perform any of its security functions, and immediate intervention is required, which is exactly what the question asks to identify.

Why this answer

Emergency is the highest severity level in syslog/FortiGate, indicating a system is unusable. Critical indicates critical conditions but not necessarily unusable.

65
MCQmedium

An administrator wants to view the current session table on a FortiGate. Which command should they use?

A.diagnose debug flow
B.show full-configuration
C.diagnose sys session list
D.get system performance statistics
AnswerC

'diagnose sys session list' is the correct command to view the current session table. It reads the kernel session table and outputs every active connection, including source/destination IP addresses, ports, protocol, session state, and timers. This is the standard tool for troubleshooting NAT, policy, and asymmetric routing because it shows exactly what the firewall is tracking in real time.

Why this answer

The command 'diagnose sys session list' displays the current session table on a FortiGate, showing active sessions with source/destination, protocol, state, and policy information. It is the standard CLI command for inspecting the session table in real time.

Exam trap

NSE4 often tests the confusion between 'diagnose debug flow' (packet tracing) and 'diagnose sys session list' (session table inspection), since both are used in troubleshooting but serve different purposes.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug flow' traces packet flow through the FortiGate for troubleshooting policy and routing decisions, not for listing the session table. Option B is wrong because 'show full-configuration' dumps the entire device configuration, not the runtime session table. Option D is wrong because 'get system performance statistics' displays system performance counters such as CPU and memory, not session entries.

66
MCQeasy

Which FortiGate log type records user authentication events, such as successful logins and failed login attempts?

A.ZTNA logs
B.Event logs
C.Traffic logs
D.Security logs
AnswerB

Event logs are the correct log type for user authentication events. They record auditable system events, including successful and failed login attempts for administrators, VPN users, and other service accounts, as well as authentication failures and lockouts. Event logs are specifically designed to capture user authentication and accounting information for security auditing.

Why this answer

Event logs on a FortiGate record system-level activities including user authentication events such as successful logins, failed login attempts, and administrative actions. These logs are specifically designed to capture events that are not traffic-related, making them the correct choice for authentication events.

Exam trap

NSE4 often tests the confusion between log types, especially event vs. security logs; candidates may incorrectly assume that authentication events are part of security logs because they relate to security, but FortiGate classifies them as event logs.

How to eliminate wrong answers

Option A is wrong because ZTNA logs focus on Zero Trust Network Access events, such as proxy access and device posture checks, not general user authentication. Option C is wrong because traffic logs record network traffic flows (source/destination IP, ports, bytes) and do not include authentication events. Option D is wrong because security logs capture security profile events like IPS, antivirus, and web filtering, not user login activities.

67
MCQeasy

Which FortiGate feature allows administrators to verify if a specific IP address is being blocked by a security policy?

A.diagnose sys session list
B.get system ha status
C.diagnose debug flow
D.diagnose sniffer packet
AnswerC

This command runs a trace of a specific user-selected packet or flow through the FortiGate's processing pipeline, displaying each stage including policy lookup, routing decisions, and the final action (accept or drop). It captures the exact policy ID matched and the reason for any drop, such as implicit deny or traffic-shaping constraints. As a debug utility, it is the proper tool for verifying the policy decision for a given flow, making it the correct answer.

Why this answer

The 'diagnose debug flow' command allows administrators to trace the path of a packet through the FortiGate, showing which security policy, routing, and other checks it matches. By filtering on a specific IP address, administrators can see if traffic from that IP is being blocked by a policy and the reason for the block.

Exam trap

NSE4 often tests the confusion between session listing and flow tracing, leading candidates to choose 'diagnose sys session list' when they need to see policy enforcement details.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys session list' displays existing sessions but does not show policy evaluation or blocking reasons. Option B is wrong because 'get system ha status' shows high availability status, unrelated to policy blocking. Option D is wrong because 'diagnose sniffer packet' captures packets but does not indicate whether they are blocked by a security policy; it only shows if packets are present on the interface.

68
Multi-Selecthard

A FortiGate administrator is troubleshooting why traffic from a specific source IP is not being logged. The traffic is allowed by a firewall policy with logging enabled. Which TWO commands could the administrator use to verify if the traffic is hitting the expected policy? (Choose two.)

Select 2 answers
A.get system performance status
B.diagnose debug flow
C.diagnose sniffer packet any 'host 10.0.0.1'
D.diagnose sys session filter src 10.0.0.1
E.diagnose debug application fnbamd
AnswersB, D

The 'diagnose debug flow' command is the definitive real-time tracing tool for FortiGate traffic. It allows you to apply filters (e.g., by source IP, destination IP, port, or VLAN) and then traces each packet through the entire data path, showing the exact policy ID matched, the action taken (accept or drop), and any profile-based processing or session errors. This output directly answers the question of 'which policy did this traffic match?' making it the correct troubleshooting method.

Why this answer

Option B (diagnose debug flow) is correct because it traces a packet through the FortiGate's inspection path, showing which firewall policy matches the traffic and whether it is allowed or denied, which directly verifies if the source IP hits the expected policy. Option D (diagnose sys session filter src 10.0.0.1) is correct because it filters the session table by the source IP so the administrator can run 'diagnose sys session list' and confirm the session was created and which policy ID it matched. Option A (get system performance status) only shows CPU, memory, and uptime statistics and provides no policy-matching information.

Option C (diagnose sniffer packet any 'host 10.0.0.1') captures raw packets but does not reveal which firewall policy processed them. Option E (diagnose debug application fnbamd) debugs the Fortinet non-blocking authentication daemon, which is unrelated to firewall policy matching for this traffic.

Exam trap

NSE4 often tests the difference between packet capture (sniffer) and policy-lookup tracing (debug flow), causing candidates to choose sniffer when the question asks which policy the traffic hits.

69
MCQmedium

In a FortiGate HA cluster, the administrator needs to perform a firmware upgrade without causing a full service outage. Which procedure should be followed?

A.Upgrade the primary unit first, then the secondary unit
B.Upgrade the secondary unit first, then perform a failover, then upgrade the primary unit
C.Disable HA and upgrade each unit separately
D.Upgrade both units simultaneously
AnswerB

The correct procedure is to upgrade the standby unit first, verify it has booted and joined the cluster with a healthy synchronization, then manually fail over so that the upgraded unit becomes primary and handles traffic. After that, upgrade the former primary (now standby) to the same version, ensuring both units finally run identical firmware. This rolling upgrade preserves a live unit for every step, avoiding an outage and keeping the HA pair in a supported configuration throughout.

Why this answer

In a FortiGate HA cluster, the correct upgrade procedure is to upgrade the secondary (subordinate) unit first, then trigger a failover so it becomes primary, then upgrade the former primary. This maintains service continuity because at least one unit is always running the stable firmware and passing traffic. Upgrading the primary first would cause an outage during the upgrade window.

Exam trap

NSE4 often tests the order of HA firmware upgrades — candidates incorrectly assume upgrading the primary first is fine because it 'leads' the cluster, missing that it causes an outage.

How to eliminate wrong answers

Option A is wrong because upgrading the primary first takes the active traffic-handling unit offline, causing a full outage until the upgrade completes and the cluster reconverges. Option C is wrong because disabling HA removes redundancy and requires manual reconfiguration, and it does not preserve seamless failover during the upgrade. Option D is wrong because upgrading both units simultaneously causes a complete cluster outage and can also cause HA heartbeat/firmware mismatch issues during the process.

70
MCQmedium

A FortiGate admin runs 'diagnose sys session filter dport 443' and then 'diagnose sys session list'. The output shows a session with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the session?

A.The session is in a half-open state, waiting for SYN-ACK
B.The session is closing with a FIN flag
C.The session is fully established and transferring data
D.The session was blocked by a firewall policy
AnswerA

The session's proto_state value of 01 corresponds to SYN_SENT, indicating the client's SYN has been sent but no SYN-ACK has yet been received from the server. This creates a half-open session that is stuck waiting for the server to respond, often due to packet loss, a misconfigured server, or an intermediate device silently dropping the SYN-ACK. Until that reply arrives, the session cannot transition to the fully established state.

Why this answer

Protocol 6 is TCP, proto_state=01 indicates TCP SYN_SENT state (the first step of the three-way handshake). Duration and expire are in seconds. The session has been open for 3600 seconds (1 hour) and will expire in 3599 seconds, which is unusual for a TCP session that should have completed handshake quickly.

This suggests the session is stuck in SYN_SENT, likely due to no SYN-ACK response.

71
MCQmedium

A FortiGate administrator configures a ZTNA rule to protect an internal web server. The rule uses an access proxy. Which component on the FortiGate terminates the incoming ZTNA connection?

A.ZTNA tag
B.SSL inspection profile
C.ZTNA application
D.ZTNA gateway
AnswerD

The ZTNA gateway is the correct answer because it is the network entity that accepts inbound client connections, terminates the TLS session, authenticates the user, validates ZTNA tags, and proxies the session to the configured ZTNA application. In FortiOS, you configure a ZTNA gateway with a virtual host, a port, and an SSL certificate. This is where the client's connection logically ends and the internal connection to the backend application begins.

Why this answer

In FortiGate ZTNA, the access proxy is hosted on the FortiGate itself, and the component that terminates the incoming ZTNA connection from the endpoint is the ZTNA gateway (also called the access proxy gateway). The ZTNA gateway performs the TLS termination and enforces the ZTNA rule, then proxies the traffic to the protected internal server. This is why the FortiGate can inspect and apply zero-trust policy without exposing the server directly.

Exam trap

NSE4 often tests the confusion between the ZTNA application (the protected resource) and the ZTNA gateway (the component that terminates the connection), so candidates pick the resource instead of the terminator.

How to eliminate wrong answers

Option A is wrong because a ZTNA tag is a metadata label applied to endpoints (via EMS or manual tagging) used in policy matching, not a connection terminator. Option B is wrong because an SSL inspection profile decrypts and inspects traffic but does not terminate the ZTNA tunnel or host the access proxy. Option C is wrong because the ZTNA application is the protected resource definition (the internal web server) referenced by the rule, not the component that terminates the client connection.

72
MCQmedium

A FortiGate cluster is configured in active-passive HA. The administrator wants to manage the cluster using a single IP address that always points to the current primary unit. Which configuration should be applied?

A.Configure a virtual IP (VIP) for HTTPS management
B.Set the HA management IP as a dedicated interface IP on each unit
C.Enable 'management IP' under HA configuration with the desired IP
D.Use the same IP address on both units and disable ARP
AnswerC

The 'management IP' field under the HA configuration is the correct method because it defines a floating IP (with optional netmask and gateway) that is owned by the primary unit and automatically moves to the failover unit during a failure. This IP is not a regular interface IP; it is added as an alias on the primary unit's management interface, enabling uninterrupted HTTPS management of the cluster via the same address before and after failover. Ensure the management IP is on the same subnet as your management network and that you allow HTTPS on that interface.

Why this answer

The management interface in HA can have a virtual IP that follows the primary unit, accessible via the floating (virtual) management IP.

73
MCQeasy

A FortiGate administrator wants to see real-time debugging output for traffic matching a specific source IP address. Which command sequence would achieve this?

A.diagnose sys session filter src 10.0.1.10 ; diagnose sys session list
B.diagnose debug flow filter src 10.0.1.10 ; diagnose debug flow show function-name ; diagnose debug enable
C.diagnose sniffer packet any 'host 10.0.1.10' 4
D.diagnose debug reset ; diagnose debug enable ; diagnose debug flow show iprope
AnswerB

This correct sequence first installs a flow trace filter for the source IP, then selects the `function-name` output mode to display the names of kernel functions that process the matching packets, and finally enables debug output. The order is critical because the filter must be active before debugging starts to avoid capturing unrelated traffic, and the `show` option must be set before `enable` takes effect. Once enabled, the FortiGate outputs a step-by-step traversal of the packet through the firewall, including policy lookups, session setup, and any drops, which is exactly what real-time debugging requires.

Why this answer

The 'diagnose debug flow' command sequence is specifically designed for real-time debugging of traffic flows, allowing filtering by source IP with the 'filter src' option. Enabling debug output with 'diagnose debug enable' then shows flow trace information for packets matching the filter, which is the standard method for live traffic debugging on FortiGate.

Exam trap

The trap here is confusing packet sniffing (Option C) with flow debugging (Option B), as both can show traffic for a specific IP, but only debug flow reveals the firewall's internal processing decisions (e.g., policy ID, NAT action) in real time, which is essential for diagnosing policy-related issues.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys session list' shows current session table entries, not real-time debugging output; it provides a static snapshot, not a live trace. Option C is wrong because 'diagnose sniffer packet' captures raw packets but does not provide the flow-level debugging details (e.g., firewall policy decisions, NAT translations) that 'debug flow' offers; it is a packet capture tool, not a flow debugger. Option D is wrong because the command sequence is incomplete and incorrect: 'diagnose debug reset' clears all debug settings, 'diagnose debug enable' enables debug without a filter, and 'diagnose debug flow show iprope' is not a valid command (the correct command is 'diagnose debug flow show function-name' or 'diagnose debug flow show ip-address'); this sequence would either produce no output or show unfiltered debug data.

74
MCQmedium

A FortiGate is configured with an active-passive HA cluster. The admin notices that when the primary unit fails, the secondary takes over, but after the primary recovers, it does not automatically become active again. What is the most likely reason?

A.The primary has a lower priority than the secondary
B.Override is not enabled
C.Session pickup is disabled
D.The heartbeat interface is down
AnswerB

When override is enabled in FortiGate HA, a device with higher priority can preempt the current primary when it comes back online after a failover. Without override, the cluster maintains the current primary even if a higher-priority unit is available, so the original primary remains active after recovery. This is exactly the observed behavior: the higher-priority unit is primary initially, fails over, and on recovery does not reclaim primary because override is off. The priority is used for initial election and for override-based decisions, but failback requires override enabled.

Why this answer

In FortiGate HA, when the primary unit recovers after a failover, it does not automatically reclaim the primary role unless 'override' is enabled. Without override, the current primary (formerly secondary) retains the active role, and the recovered unit becomes the secondary. Enabling override allows the unit with the higher priority (or lower monitor priority value) to take over as primary when it comes back online.

Exam trap

NSE4 often tests the misconception that the original primary automatically reclaims the active role after recovery — candidates must remember that without override enabled, the current primary retains the role.

How to eliminate wrong answers

Option A is wrong because if the primary had a lower priority than the secondary, the secondary would have been primary from the start — the question states the primary failed and the secondary took over, which is normal behavior. Option C is wrong because session pickup (session synchronization) affects whether sessions survive failover, not whether the original primary reclaims the active role. Option D is wrong because a down heartbeat interface would cause failover, not prevent the recovered primary from becoming active again.

75
MCQhard

A company has two remote sites connected via an SD-WAN overlay. The headquarters uses a FortiGate with two WAN links: Fiber (priority 1) and LTE (priority 2). The SD-WAN rule for business-critical traffic uses the 'best quality' strategy with SLA targets for latency and jitter. The fiber link occasionally experiences high jitter but low latency. The engineer notices that traffic is not failing over to LTE even when jitter exceeds the threshold. What is the most likely reason?

A.The performance SLA for jitter is not configured, only latency.
B.The SD-WAN rule has SLA match set to 'either' instead of 'all'.
C.The LTE link has a higher cost and is not considered for failover.
D.The fiber link has a higher interface weight.
AnswerA

The 'best quality' strategy only fails over when the configured SLA performance criteria are breached. If the performance SLA monitors latency alone, high jitter never triggers a member failure, so traffic stays on the fiber link despite exceeding the jitter threshold.

Why this answer

The SD-WAN rule uses the 'best quality' strategy, which selects the best link based on configured SLA metrics. If only latency is configured in the performance SLA, jitter exceeding the threshold will not trigger a failover, as the SLA only evaluates the configured metrics. The fiber link may still meet the latency SLA, so traffic remains on it despite high jitter.

Exam trap

The trap here is that candidates assume jitter is automatically monitored in SD-WAN SLA, but FortiGate requires explicit configuration of each metric (latency, jitter, packet loss) in the performance SLA; otherwise, unconfigured metrics are ignored for failover decisions.

How to eliminate wrong answers

Option B is wrong because the 'either' vs 'all' setting in SLA match determines whether any or all configured SLA targets must be met for the link to be considered compliant; it does not prevent failover when jitter exceeds the threshold if jitter is not configured. Option C is wrong because SD-WAN failover decisions are based on SLA compliance and strategy, not link cost; cost influences route selection in routing protocols but not SD-WAN rule failover. Option D is wrong because interface weight affects load-balancing ratios in strategies like 'lowest cost' or 'maximize bandwidth', not failover decisions in 'best quality' strategy.

Page 1 of 2 · 101 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Nse4 Ha Diagnostics questions.